Audit & Consulting · Security Policy

Information Security Policy: the framework for your security.

We define the framework, rules and responsibilities for security across your organisation — a clear, enforceable information security policy aligned with your business and regulatory drivers.

Our approach — a continuous cycle
1 · Assess 2 · Protect 3 · Comply 4 · Monitor 5 · Evolve Our approach
Certifications & accreditations
What it is

Set the reference framework.

The Information Security Policy (ISP) is the founding document of your governance: it formalises your security objectives, the rules to follow and how responsibilities are shared across your organisation.

We build it to be readable, enforceable and binding — aligned with ISO 27001, ISO 27002 and your regulatory obligations.

  • A clear security framework endorsed by leadership
  • Roles and responsibilities explicitly assigned
  • Rules that apply to every employee and third party
  • A documentation baseline aligned with recognised standards
What the policy covers

A complete and coherent framework.

From defining scope to awareness, the information security policy structures your entire security posture.

Framework & scopeField of application, security objectives and guiding principles of the policy.
Roles & responsibilitiesCISO, asset owners, users: who decides, who applies, who controls.
Topic-specific policiesPasswords, endpoints, mobility, backups, outsourcing and development.
Information classificationSensitivity levels, labelling and data handling rules.
Access managementLeast-privilege principle, account lifecycle and access reviews.
Awareness & sanctionsEmployee commitment, ongoing training and disciplinary rules.
Our approach

From scoping to ongoing maintenance.

A structured method for a policy that is adopted and alive, not a document left to gather dust in a drawer.

  1. 1

    Scoping

    Business drivers, regulatory context and policy scope defined together with you.

  2. 2

    Current-state review

    Analysis of existing documentation, practices and gaps against the standards.

  3. 3

    Drafting

    Writing the policy and its topic-specific policies, tailored to your organisation.

  4. 4

    Approval & rollout

    Leadership approval, communication and employee commitment.

  5. 5

    Ongoing maintenance

    Periodic reviews and updates as things evolve and lessons are learned.

Deliverables

An operational documentation baseline.

Audit & Consulting

Other consulting services.

The security policy is part of a broader governance and risk management approach.

Ready to structure your security?

Give your organisation a clear, enforceable security framework. Leave us your details and an expert will get back to you to scope your security policy.