How to Write an Information Security Policy (ISO 27001 Clause 5.2)
The top-level information security policy is one or two pages, signed by a founder, and confused with the entire policy library by almost everyone. Here's what ISO 27001 Clause 5.2 requires it to contain, what belongs in sub-policies instead, and how to evidence that it was actually communicated.