Skip to content

Lab 02 — Build an Information Security Policy

Lab 02 — Build an Information Security Policy

Section titled “Lab 02 — Build an Information Security Policy”

Welcome to Lab 02 of the Enterprise Governance, Risk & Compliance (GRC) module.

In this lab, you’ll take on the role of a Cloud Security Engineer at CloudNova Technologies.

Following the successful completion of the enterprise risk assessment, executive management has requested a formal Information Security Policy that will govern security practices across the organization.

Your task is to develop a professional policy document that establishes the organization’s security objectives, defines responsibilities, protects information assets, and aligns with international standards such as ISO/IEC 27001, NIST Cybersecurity Framework (CSF), and CIS Controls.

This lab mirrors the work performed by Information Security Managers, Cloud Security Engineers, Security Architects, GRC Analysts, Compliance Officers, and CISOs.


Item Details
Lab Name Build an Information Security Policy
Difficulty Intermediate
Estimated Time 90–120 Minutes
Lab Type Governance & Compliance
Environment Documentation, AWS Reference Architecture
Skills Security Governance, Policy Development, Documentation, Compliance

By completing this lab, you will learn how to:

  • Develop an enterprise Information Security Policy.
  • Define governance responsibilities.
  • Classify information assets.
  • Define acceptable use requirements.
  • Create access control requirements.
  • Establish incident reporting procedures.
  • Align policies with compliance frameworks.
  • Prepare documentation suitable for executive approval.

CloudNova Technologies has expanded globally and now serves customers across:

  • Banking
  • Healthcare
  • Retail
  • Government
  • Technology

As the organization grows, each department has adopted different security practices.

Executive leadership wants a single enterprise-wide Information Security Policy that applies to all employees, contractors, vendors, and cloud environments.

You have been assigned to develop the first official policy for the organization.


Your policy should define:

  • Security Objectives
  • Governance Structure
  • Security Responsibilities
  • Information Classification
  • Acceptable Use
  • Access Control
  • Data Protection
  • Incident Reporting
  • Compliance Requirements
  • Policy Review Process

Document what the policy covers.

Include:

  • Employees
  • Contractors
  • Third-Party Vendors
  • Cloud Resources
  • Applications
  • Networks
  • Endpoints
  • Information Assets

Example Scope Statement:

“This policy applies to all CloudNova Technologies employees, contractors, consultants, third-party service providers, and information systems used to process, store, or transmit organizational information.”


Identify the organization’s security goals.

Examples include:

  • Protect Confidentiality
  • Maintain Integrity
  • Ensure Availability
  • Support Business Operations
  • Meet Compliance Requirements
  • Reduce Cyber Risk
  • Improve Customer Trust

Task 3 — Define Roles & Responsibilities

Section titled “Task 3 — Define Roles & Responsibilities”

Assign responsibilities.

Example:

Role Responsibility
Board of Directors Security Governance
CEO Executive Support
CIO Technology Governance
CISO Security Program
Cloud Team Cloud Security Controls
SOC Team Monitoring & Incident Response
Employees Policy Compliance

Task 4 — Define Information Classification

Section titled “Task 4 — Define Information Classification”

Create a classification model.

Example:

Classification Example
Public Marketing Material
Internal Internal Procedures
Confidential Customer Information
Restricted Financial Records & Credentials

Document handling requirements for each classification level.


Task 5 — Define Acceptable Use Requirements

Section titled “Task 5 — Define Acceptable Use Requirements”

Include requirements such as:

  • Company devices only
  • No unauthorized software
  • Approved cloud services
  • Secure internet usage
  • Strong password practices
  • MFA required
  • Secure remote access

Document employee responsibilities.


Task 6 — Define Access Control Requirements

Section titled “Task 6 — Define Access Control Requirements”

Your policy should include:

  • Least Privilege
  • Role-Based Access Control (RBAC)
  • Multi-Factor Authentication (MFA)
  • Periodic Access Reviews
  • Privileged Access Management (PAM)
  • Account Lifecycle Management

Access should be granted based on business need.


Task 7 — Define Data Protection Requirements

Section titled “Task 7 — Define Data Protection Requirements”

Document controls for protecting organizational data.

Examples include:

  • Encryption at Rest
  • Encryption in Transit
  • Secure Backups
  • Data Retention
  • Secure Disposal
  • Data Loss Prevention (DLP)
  • Secure File Sharing

Protect sensitive information throughout its lifecycle.


Task 8 — Define Incident Reporting Requirements

Section titled “Task 8 — Define Incident Reporting Requirements”

Create a simple reporting workflow.

Security Incident
Employee Reports Incident
SOC Investigation
Incident Response Team
Containment
Recovery
Lessons Learned

Document reporting timelines and responsibilities.


Reference applicable frameworks.

Examples:

  • ISO/IEC 27001
  • NIST CSF
  • CIS Controls
  • PCI DSS
  • GDPR
  • HIPAA
  • SOC 2
  • DPDP Act (India)

The policy should support regulatory compliance across multiple business sectors.


Specify how the policy will be maintained.

Example:

  • Annual Review
  • Major Technology Changes
  • Regulatory Changes
  • Significant Security Incidents
  • Executive Approval Required
  • Version Control Maintained

Policies should evolve with the organization.


By the end of the lab, produce:

  • Information Security Policy
  • Security Objectives
  • Roles & Responsibilities Matrix
  • Information Classification Table
  • Access Control Requirements
  • Data Protection Requirements
  • Incident Reporting Process
  • Compliance Mapping
  • Policy Review Schedule

Upon successful completion of this lab, you will have:

  • Developed a professional enterprise Information Security Policy.
  • Defined governance responsibilities.
  • Established security requirements.
  • Created a policy suitable for executive approval.
  • Aligned organizational security objectives with international standards.

This is a common responsibility for Cloud Security Engineers, Security Architects, Compliance Officers, Information Security Managers, and GRC professionals.


While creating the policy:

  • Keep language clear and business-focused.
  • Align with organizational objectives.
  • Reference industry standards.
  • Define ownership clearly.
  • Avoid unnecessary technical details.
  • Maintain version control.
  • Review policies regularly.
  • Obtain executive approval before publication.

Congratulations!

You have successfully developed an Enterprise Information Security Policy.

You now understand how organizations establish governance through policies, define security expectations, assign responsibilities, support compliance, and create the foundation for a mature cybersecurity program.

This experience reflects the real-world work performed by Information Security Managers, Cloud Security Engineers, GRC Analysts, Security Architects, Compliance Officers, and CISOs.


➡️ Lab 03 — Conduct an ISO/IEC 27001 Gap Assessment

In the next lab, you’ll evaluate CloudNova Technologies against the requirements of ISO/IEC 27001, identify security gaps, assess compliance maturity, recommend remediation actions, and prepare a professional gap assessment report suitable for executive review and certification planning.