By the Ethica team · Updated

Free Information Security Policy Template (No Legalese)

If your employees touch customer data, email, or company software, you need an Information Security Policy. The problem? Many templates are long documents full of dense legalese that nobody actually reads.

An ignored policy is completely useless during a security audit (or a breach).

Below, we provide a free, human-readable Information Security Policy template designed specifically for small-to-medium businesses. It covers the essentials—data classification, phishing, and safeguarding personal information—in plain English.

Download the Free Template

Click the link below to download the boilerplate template. It is provided in RTF (Rich Text Format) so you can easily open it in Microsoft Word, Google Docs, or Apple Pages to add your company name and distribute it to your team.

Download the Template (.rtf)

What is included in this template?

This streamlined policy focuses on actionable rules rather than legal jargon:

  1. Data Classification: Three labels for company information (Public, Internal, and Confidential or Personal), so employees know how carefully to handle what's in front of them.
  2. Safeguarding Data: Clear rules on passwords, turning on two-factor authentication (2FA: a code from your phone as well as your password), locking screens, and securing physical documents.
  3. Email Security & Phishing: How to spot a phishing attempt, what to do if you aren't sure, and the golden rule: "When in doubt, don't click."
  4. Device Policies: Basic expectations for company laptops and for personal phones used for work ("bring your own device", or BYOD).
  5. Incident Reporting: Exactly who to contact (and how) if a laptop is lost or a suspicious email is clicked. (Hint: quick reporting is never punished.)
  6. An acknowledgment block: a line for the version and effective date, and space for a name, signature and date if you collect signatures on paper.

What it doesn't cover

This is a short, everyday policy for staff. It is not a complete security program. It doesn't cover:

If a customer or auditor has asked for a security program, use this as the employee-facing part and ask your IT provider about the rest.


How to Get Your Employees to Read and Sign This Policy

Drafting the policy is the first half. The second is getting every employee to acknowledge it, and keeping track of those acknowledgments for an audit.

If you email the document to your team, they will probably ignore it. You will then spend weeks chasing people down and manually logging their electronic signatures in a spreadsheet.

The Ethica Way (Automated)

Instead of managing PDF signatures via email threads, you can automate the entire workflow using Ethica.

  1. Upload the Policy: Save your finalized policy as a PDF and upload it to Ethica.
  2. Add Acknowledgment Text: Set a required acknowledgment (e.g., "I have read, understand, and agree to abide by the company's Information Security Policy").
  3. Assign it to the Team: Ethica emails every employee a private link. They don't need to log in or remember a password.
  4. One-Click Signature: Employees open the link, review the document on their phone or computer, tick the acknowledgment and click Submit Acknowledgment.

Ethica records when they acknowledged, their IP address and browser, and exactly which version of the policy they saw. Anyone who hasn't signed gets reminders as the deadline approaches. When you revise the policy, upload the new version and collect fresh acknowledgments.

Read next: employee handbook and policy acknowledgments: what to keep, or watch how to add a policy for employees to sign.

Keep reading

Send your policy for signature today

Upload the PDF and assign it. Each employee reads and signs from an email link, with no account to create. Ethica records the version, the time, the IP address and browser, and reminds anyone who hasn't signed.

30 days free, no credit card.