What usually brings people to this.
- Security controls exist in practice but not in documented policy
- Compliance evidence assembled reactively before each audit
- No clear ownership of security decisions
Policy and governance frameworks that hold up under audit
We help you establish security policy and governance frameworks tailored to how the organisation actually works — robust controls, documented ownership, and a compliance position that can be evidenced rather than asserted.
-
01
Policy development
Security policy written for your organisation rather than adapted from a template.
-
02
Governance frameworks
Control ownership, decision rights and review cadence.
-
03
Framework alignment
Mapping of controls to recognised frameworks such as ISO 27001 and NIST.
-
04
Gap identification
Identification of the gaps between current practice and the target framework.
Technologies and frameworks in scope
- ISO 27001
- NIST
How the engagement runs.
A defined sequence, so you know what is happening at any point and what comes out of each stage.
-
01
Establish scope and drivers
Fix what the governance framework has to satisfy before writing any of it.
- Business drivers
- Regulatory obligations
- Applicable frameworks
-
02
Current-state review
Establish what the organisation does today and what is written down.
- Existing policy
- Practice in place
- Ownership
-
03
Gap identification
Identify the gaps between current practice and the target framework.
- Practice vs framework
- Documentation gaps
-
04
Policy development
Security policy written for your organisation rather than adapted from a template.
- Written for the organisation
- Reviewed with stakeholders
-
05
Governance framework
Control ownership, decision rights and review cadence.
- Control ownership
- Decision rights
- Review cadence
-
06
Framework alignment and handover
Map the control set to recognised frameworks and hand over a maintainable position.
- ISO 27001
- NIST
- Control mapping
What you receive.
- 01Security policy set written for your organisation
- 02Governance framework with control ownership and decision rights
- 03Control mapping to frameworks such as ISO 27001 and NIST
- 04Gap analysis between current practice and the target framework
- 05Review cadence and maintenance plan
What changes afterwards.
- Controls documented as policy, not only present in practice
- Clear ownership of security decisions
- A compliance position that can be evidenced rather than asserted
- Governance that holds up under audit
Before you get in touch.
Is this the same as Compliance Management under Managed Services?
They're related but different — this establishes the policy and governance framework itself (ownership, decision rights, review cadence); Compliance Management then maintains evidence against it continuously.
Do you write policy from a template?
No — policy is written for your organisation rather than adapted from a template, based on how it actually works.
Which frameworks do you align governance to?
ISO 27001 and NIST.
What does gap identification produce?
The specific gaps between current practice and the target framework — the basis for the remediation and governance work that follows.