Governance and Audit / document it

Policy frameworks

A documented backbone of policies and procedures that matches how you work and satisfies the standards you are assessed against. Written by a team that runs its own information security management system, certified for ISO 27001 and ISO 9001 by a UKAS-accredited certification body.

Governance and Audit / 01 · What a policy framework is

What is a policy framework?

A policy framework is the set of written policies and procedures that govern how your organisation protects information, manages access, handles incidents and meets its obligations. Cyber Essentials, ISO 27001, GDPR and your sector's rules all expect this documentation to exist, to be current, and to describe what you do. We write each policy to describe what you actually do, so it stands up when an assessor reads it closely.

Governance and Audit / 02 · What we write

The policies most organisations need, scoped to your size and sector

01Protect

Information security policies

The core security policy and its supporting documents: acceptable use, data classification, and the rules that govern how information is handled day-to-day.

02Control

Access and data procedures

Access control procedures, data retention requirements, and the email and communications security protocols that close the most common ways in.

03Recover

Continuity and incident response

Business continuity plans and incident response procedures that tell people what to do on the worst day.

04Govern

People and governance

Staff security awareness training records, supplier and data protection policies, and the governance documents that show who owns and manages security.

Governance and Audit / 03 · Proof of practice

Our own policies and certifications

We publish our own policies and work to them. We operate an information security management system, we hold Cyber Essentials Plus, and we are certified for ISO 27001 and ISO 9001 by a UKAS-accredited certification body. You can read several of our policies here:

A good policy is specific, owned, version controlled and reviewed on a schedule. Those four things are what an auditor or a prime contractor looks for.

Governance and Audit / 04 · How we work

How we build a framework

01

Understand

We learn how you work and which standards apply, so the framework fits your organisation rather than a generic shape.

02

Draft

We develop the policies and procedures you need, mapped to the controls each standard expects.

03

Embed

We put the procedures into practice, with the training records and ownership that show a policy is operating, not just written.

04

Review

We set version control and review dates so the framework stays current, the way our own ISO 27001 system is kept alive.

Governance and Audit / 05 · How this fits

Policies describe the controls behind them

Policy frameworks are part of our governance and audit work, and they underpin compliance readiness and CAF alignment, both of which need documented policy to demonstrate their outcomes. For the defence and aerospace supply chain, a credible framework is often the first thing a prime contractor checks.

FAQ

Common questions

Why not just use a policy template?

A template can be a useful starting point, but a policy that describes a business that is not yours will not survive an audit, and it will not protect you. An assessor reads the policy against how the business actually runs. We write policies specific to how you work and mapped to the standards you face, so people can follow them.

Which policies does my organisation actually need?

It depends on your size, your sector, and the standards you are assessed against, but most organisations need a recognisable core: an information security policy, access control and data retention procedures, an incident response plan, business continuity arrangements, and staff awareness records. We scope the set to what applies to you.

How often should policies be reviewed?

At least annually, and whenever something significant changes, such as a new system, a new regulation, or an incident that exposes a gap. The review date and version history matter as much as the content, because an auditor wants to see the framework is alive and owned. We build that review discipline in, the same way we run it for our own published policies.

Do your policies cover GDPR and data protection?

Yes. Data protection runs through the framework, from how personal data is classified and retained to how a data subject access request is handled. We make sure the documentation supports your obligations under the UK data protection regime, and it dovetails with our compliance readiness work where GDPR is one of several standards you need to meet.

Can you write the policies and run the controls behind them?

Yes. We write the policy and then operate the control it describes as part of our cyber security and managed services. One team does both, so the policy and the reality stay aligned between audits.

Talk to us about policy frameworks

Tell us which standards you are working to and we will build a framework that fits how your organisation actually works.

Reading, Berkshire  /  ISO 27001 and 9001 certified via a UKAS-accredited body  /  reply within one working day