Information security policies
The core security policy and its supporting documents: acceptable use, data classification, and the rules that govern how information is handled day-to-day.
A documented backbone of policies and procedures that matches how you work and satisfies the standards you are assessed against. Written by a team that runs its own information security management system, certified for ISO 27001 and ISO 9001 by a UKAS-accredited certification body.
A policy framework is the set of written policies and procedures that govern how your organisation protects information, manages access, handles incidents and meets its obligations. Cyber Essentials, ISO 27001, GDPR and your sector's rules all expect this documentation to exist, to be current, and to describe what you do. We write each policy to describe what you actually do, so it stands up when an assessor reads it closely.
The core security policy and its supporting documents: acceptable use, data classification, and the rules that govern how information is handled day-to-day.
Access control procedures, data retention requirements, and the email and communications security protocols that close the most common ways in.
Business continuity plans and incident response procedures that tell people what to do on the worst day.
Staff security awareness training records, supplier and data protection policies, and the governance documents that show who owns and manages security.
We publish our own policies and work to them. We operate an information security management system, we hold Cyber Essentials Plus, and we are certified for ISO 27001 and ISO 9001 by a UKAS-accredited certification body. You can read several of our policies here:
A good policy is specific, owned, version controlled and reviewed on a schedule. Those four things are what an auditor or a prime contractor looks for.
We learn how you work and which standards apply, so the framework fits your organisation rather than a generic shape.
We develop the policies and procedures you need, mapped to the controls each standard expects.
We put the procedures into practice, with the training records and ownership that show a policy is operating, not just written.
We set version control and review dates so the framework stays current, the way our own ISO 27001 system is kept alive.
The controls your policies describe. We write the policy and operate the control, so the two do not drift apart.
Go to Cyber Security Evidence itPolicies are the first thing an assessor asks for, then the evidence they are followed. Audit and assurance captures that proof between assessments.
See audit and assurancePolicy frameworks are part of our governance and audit work, and they underpin compliance readiness and CAF alignment, both of which need documented policy to demonstrate their outcomes. For the defence and aerospace supply chain, a credible framework is often the first thing a prime contractor checks.
A template can be a useful starting point, but a policy that describes a business that is not yours will not survive an audit, and it will not protect you. An assessor reads the policy against how the business actually runs. We write policies specific to how you work and mapped to the standards you face, so people can follow them.
It depends on your size, your sector, and the standards you are assessed against, but most organisations need a recognisable core: an information security policy, access control and data retention procedures, an incident response plan, business continuity arrangements, and staff awareness records. We scope the set to what applies to you.
At least annually, and whenever something significant changes, such as a new system, a new regulation, or an incident that exposes a gap. The review date and version history matter as much as the content, because an auditor wants to see the framework is alive and owned. We build that review discipline in, the same way we run it for our own published policies.
Yes. Data protection runs through the framework, from how personal data is classified and retained to how a data subject access request is handled. We make sure the documentation supports your obligations under the UK data protection regime, and it dovetails with our compliance readiness work where GDPR is one of several standards you need to meet.
Yes. We write the policy and then operate the control it describes as part of our cyber security and managed services. One team does both, so the policy and the reality stay aligned between audits.
Tell us which standards you are working to and we will build a framework that fits how your organisation actually works.
Hello, I am Ainsley, the AI assistant here at Dead Simple Computing. Ask me anything about managed IT, cyber security, software and AI, or governance and audit. I can also put you in touch with a person.
Replies are AI generated and can be wrong. Your messages are sent to a third-party AI service to produce them, and a member of our team can read this chat and may join it. Do not type anything confidential. See our privacy notice.