The written program behind every control
A 20+ document information security governance suite, anchored to NIST CSF 2.0 and mapped to PCI DSS v4.0.1, HIPAA, and the NY SHIELD Act — written for your organization, adopted by your leadership, and maintained on a review cycle.
What's in the suite
Every document follows our controlled-document standard — versioned, owned, and dated — so an auditor sees a managed program, not a folder of downloads.
| Governance | Information Security Policy, roles & responsibilities, policy management, risk management |
|---|---|
| People | Acceptable use, security awareness & training, onboarding/offboarding, remote work |
| Access | Access control, password & authentication, privileged access |
| Technology | Endpoint protection, patch & vulnerability management, network security, logging & monitoring, encryption |
| Resilience | Backup & recovery, incident response, disaster recovery / business continuity |
| Third parties | Vendor management, data classification & handling, physical security |
Not a template dump
Generic policy packs fail audits because they describe a company that isn't yours. We interview your team, match policies to your actual tools and practices, and flag the gaps between what the policy says and what happens — then help you close them.
How the suite gets built
1. Discover
Interviews and technical review to learn how your business actually operates.
2. Draft
Policies written to your environment and mapped to your frameworks.
3. Adopt
Leadership review, revision, and formal adoption with training for staff.
4. Maintain
Annual review cycle, change management, and evidence collection.