| name | information-security-policy |
| title | Information Security Policy |
| description | Drafts a board-approvable Information Security Policy covering data classification, access controls, encryption, incident response, breach notification, and enforcement. Tailored by industry and regulatory environment (HIPAA, GDPR, CCPA, GLBA, FERPA, PCI DSS). Use when drafting or overhauling an organization's foundational information security governance framework or cybersecurity policy. |
| author | CaseMark |
| author_url | https://github.com/CaseMark/skills/tree/main/skills/legal/information-security-policy |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | cybersecurity |
| language | en |
| tags | ["drafting","policy","regulatory","research"] |
Information Security Policy
Drafts a formal Information Security Policy satisfying multi-framework regulatory requirements with enforceable operational guidance.
Prerequisites
- Org profile — industry sector, employee count, jurisdictions of operation
- Regulatory triggers — applicable frameworks (HIPAA, GDPR, CCPA, GLBA, FERPA, PCI DSS, SOC 2, ISO 27001, NIST CSF)
- Existing governance docs — current policies, data classification schemes, incident response plans
- Data inventory — sensitive data categories handled (PHI, PII, payment card data, student records, trade secrets)
- Approving authority — CEO, Board, CISO, General Counsel signature blocks needed
Output Structure
Document Control Block
| Field | Content |
|---|
| Policy Title | Information Security Policy |
| Version / Effective Date | [#] / [Date] |
| Approved By / Owner | [Title] / CISO or equivalent |
| Next Review | [Date + 1 year] |
| Supersedes | [Prior version or N/A] |
Section Outline
1. Purpose & Authority
- Business rationale (financial, reputational, regulatory risk)
- Authorizing resolution; relationship to other org policies
2. Scope
- Entities: parent, subsidiaries, affiliates, JVs
- Personnel: employees, contractors, vendors, partners
- Assets: electronic data, physical records, IP, BYOD, remote environments
- Exclusions: publicly available info, de-identified data (define standard)
3. Definitions
Define with legal precision; flag where definitions vary by jurisdiction:
- Confidential Information, Personal Data / PII (per GDPR Art. 4, CCPA § 1798.140, HIPAA 45 C.F.R. § 160.103)
- Data Breach, Security Incident, Data Owner, Data Custodian, Authorized User
- Classification Levels: Public / Internal / Confidential / Restricted
4. Data Classification