Doc owner: Head of Product
Rationale: Information Security Management Plan
Applies to
Design notes
The page previously contained only a heading stub. This scaffold adds standard ISMP sections — purpose, scope, roles, risk management, incident response, access control, training, and review — so the document is usable as a starting point for review and refinement.
Section choices follow common ISMS frameworks (broadly aligned with ISO 27001 themes) but are kept lightweight and plain-language to match the handbook's style. The intent is a practical internal plan, not a compliance checklist.
The policy ID POL-DIG-001 was assigned as the first digital-domain policy.
Owner change to Head of Product
Ownership transferred from DDE to Head of Product to reflect current accountability for information security within the organisation.
Data retention section
Data retention was a gap in the original lightweight ISMP. Explicit retention requirements reduce the volume of data stored beyond its useful life, which limits exposure in the event of a breach and aligns with good practice around data minimisation. The section keeps the same practical tone as the rest of the plan — short rules that asset owners can act on without a separate procedures document.
Related decisions
No decision records linked yet.
Changelog
See Git history for this file and for the definitive page.