How to Answer Information Security Policy Questions
Your customer asked: “Do you maintain a written information security policy?”
The short answer
Answer “yes” only if a written policy actually exists in a current, approved form. A policy describes expectations and requirements; it does not by itself prove that every stated practice or control is operating.
Educational guidance only. This page does not determine what is true about your company and does not create a security, compliance, testing, or certification claim.
What the customer is really asking
Understand the question before you answer it.
The reviewer wants to know whether security responsibilities and expectations are documented rather than existing only in people's heads. They may later ask who approved the policy, how often it is reviewed, whether employees acknowledge it, and whether supporting procedures exist.
How to answer accurately
Start with the version that matches reality.
If a current written policy exists
State that it exists and, when appropriate, identify approval or review status. Share the document or a summary only according to your company's disclosure rules.
If you have several separate security policies
Explain that the security program is documented across multiple approved policies if that is the real structure.
If practices exist but no written policy exists
Answer “no” or “not currently documented.” Do not call informal practices a written policy.
A useful answer structure
Status → scope → current practice → supporting information. Start with the direct answer, narrow it to what you can verify, explain how the practice works, and reference evidence only when that evidence actually exists.
Evidence that may help
These are examples, not requirements and not proof that your company has the practice. Use only evidence that really exists and is appropriate to share.
- Approved policy document
- Version and review history
- Approval record
- Policy distribution or acknowledgment record, if applicable
What not to say
- That having a policy means every control in it is implemented.
- That a draft is approved unless approval occurred.
- That employees were trained merely because a policy was distributed.
How Oredra handles this
Answer it once. Keep the truth behind the answer.
Policy-versus-practice is foundational to Oredra: the platform can create a policy only from approved answers, while keeping implementation and evidence as separate states.
Inside Oredra, a written policy, stated company practice, implemented control, available evidence, tested control, and independent certification remain distinct. Oredra uses approved information to draft future answers and flags questions that the approved profile cannot support.
Authoritative references
Oredra uses primary guidance where a technical or assurance concept benefits from verification. These references do not determine your company's answer.
Related questionnaire questions
Do you assess the security of vendors and third parties?
Describe how your company evaluates vendors that can affect customer data or important operations. A small business may perform practical due diligence without running a formal enterprise vendor-risk program; the answer should reflect the process that actually exists.
Are you SOC 2 compliant, certified, or do you have a SOC 2 report?
SOC 2 is an examination and resulting report on controls at a service organization; it is not a SOC 2 certification. If your company does not have a current SOC 2 report, do not describe the business as SOC 2 certified or imply that a policy set makes you SOC 2 compliant.
Are you ISO 27001 certified?
ISO/IEC 27001:2022 defines requirements for an information security management system. A company can use the standard without being certified. Answer “certified” only when the organization actually holds a valid certificate covering the relevant scope.