An Information Security Policy is a set of guidelines and practices an organization implements to ensure the confidentiality, integrity, and availability of its information assets. It outlines the responsibilities of employees and the procedures for managing and protecting sensitive information.