Advisory
IT Policies and Procedures
Policy documents that are specific enough to be testable, short enough to be read, and traceable to the framework or regulation that requires them.
Why most policy sets fail an audit
The typical policy suite we inherit was downloaded, lightly renamed, and approved without anyone checking whether the organisation could actually comply with it. It fails on audit for predictable reasons: it commits to controls that do not exist, it contradicts itself between documents, it has no version control or review evidence, and no one below the CIO has read it.
A policy you cannot evidence compliance with is worse than no policy — it converts an operational gap into a documented control failure.
What we produce
- Policy — the board-approved statement of intent and mandatory requirement. Short. Rarely changes.
- Standards — the specific, measurable technical requirements. Testable. Changes with technology.
- Procedures — the step-by-step operational instructions for the people doing the work.
- Records and templates — the forms and registers that generate the evidence an auditor will ask for.
Four document types, four audiences
Typical policy suite
Scoped to your regulatory obligations, but usually covering: information security policy; acceptable use; access control and identity management; change management; asset management and classification; cryptography and key management; physical and environmental security; operations security including backup, logging and malware; network security; secure development; supplier and third-party security; incident management; business continuity; data protection and privacy; and human resources security.
Traceability
Every requirement in the suite is mapped back to its source — an ISO 27001 Annex A control, a COBIT objective, a regulatory clause, or an internal risk decision. When an auditor asks why a control exists, the answer is in the document. When a framework changes, you can see exactly which policies are affected.
How the engagement runs
-
1
Obligation mapping
Establish every framework, regulation and contractual commitment the policy set must satisfy.
-
2
Gap review
Review existing documentation against those obligations. We reuse what works rather than starting from zero.
-
3
Architecture
Design the document hierarchy, ownership model, numbering and review cycle.
-
4
Drafting
Write to your actual operating reality, validated with the people who will have to comply.
-
5
Review and approval
Support the governance passage through to board or committee approval.
-
6
Rollout
Awareness material, acknowledgement tracking and the evidence trail that shows the policy landed.
What you receive
Frequently asked questions
Related services
Related regulatory frameworks
Need an independent view?
Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.
Request a proposal