The challenge

What the organization was facing.

Security policies were inconsistent in age, format and ownership. Some referenced technology no longer in use, several had no identifiable approver, and there was no record of which staff had read which version. Auditors had raised repeat findings on policy currency and attestation evidence.

What ISC did

The approach.

  1. 01

    Designed a policy hierarchy separating policy, standard and procedure, so each document had a defined altitude and audience.

  2. 02

    Drafted the full suite aligned to the organization's framework obligations, written to be followed by the teams who actually operate the controls.

  3. 03

    Established review, approval and version control workflows with named owners and scheduled review dates.

  4. 04

    Published the suite with staff attestation tracking, producing auditable evidence of acknowledgement per version.

  5. 05

    Handed over a maintenance calendar so policies stay current rather than degrading between audits.

Outcomes

What changed.

  1. 01

    A complete, internally consistent policy suite with named owners and approval records.

  2. 02

    Attestation evidence available per document version, satisfying prior audit findings.

  3. 03

    A maintenance lifecycle preventing the recurrence of stale, unowned policies.

Services used

Capabilities behind this engagement.