Home/Questions/Data handling and policy/Written security policy
Data handling and policy

Does the Applicant have written information security policy reviewed and updated annually?

The policy itself is rarely read by an underwriter. Its existence, its date, and whether reality matches it are what get examined.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether a written information security policy exists, whether it is approved at an appropriate level, and whether it is reviewed and updated annually. Some forms ask which framework it aligns to, which is a separate question in the governance section.

Why it is underwritten

The policy is the document that makes every other control attributable to a decision rather than to habit. It also becomes evidence in litigation and regulatory inquiry, where a policy that describes controls the organisation does not operate is worse than no policy at all.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Policy documents live in your governance repository, so this is attested. The technical controls the policy describes are measurable, which is where drift becomes visible.

PlatformWhere the setting livesWhat has to be true
Policy repositoryThe policy document, its version, approval, and review dateApproved at management level, reviewed within the last year, with a documented review record. Attested
Policy contentCoverage of access control, data handling, incident response, third parties, and acceptable useThe topics the rest of the application asks about are addressed rather than omitted
Microsoft 365Whether the technical settings match what the policy assertsConsistency between the stated policy and the configured state, which is where the document either helps or hurts
Training recordsPolicy acknowledgement by workforceAcknowledgement recorded at onboarding and on material change
Exception registerDocumented deviations from policy with owners and end datesExceptions handled explicitly, since an unrecorded deviation is a policy contradiction
A policy that overstates is worse than none

If the policy says passwords rotate every sixty days and logs are retained for a year, and neither is true, you have documented the gap yourself. Regulators and plaintiffs read policies precisely because they are the organisation's own account of what it should have been doing.

What a defensible yes requires

  • The policy is written, approved at management level, and dated within the last year.
  • It covers the domains the application asks about.
  • It matches what the environment actually does, or the differences are recorded as exceptions.
  • The workforce acknowledges it, and the acknowledgement is recorded.
  • The review is a real review, with a record of what changed.

How this answer goes wrong

The policy was written for a certification effort three years ago, describes an on-premises estate the organisation has since left, and has been reviewed in name each year without changes. It reads as current and describes a company that no longer exists, which is exactly the document you do not want quoted back to you.

Frequently asked

How long should it be?

Long enough to cover the domains and short enough to be read. A concise policy with supporting standards works better than a single long document nobody opens.

Does a template count?

As a starting point. A template not adapted to your environment produces exactly the mismatch that causes trouble later.

Who should approve it?

Executive management or the board. Approval level is part of what the question is asking, because it establishes that security has ownership above the IT function.

What does annual review mean?

A documented review with a record of what was examined and what changed. A date stamp with no substance is what a claims review will characterise it as.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture