Complete program

The full documentation layer for a security programme.

Policies, standards, control library, procedures, and assurance metrics, aligned to NIST CSF 2.0 and ISO 27001 together. The documentation needed to stand up a security programme and evidence that it is operating.

Download a sample first€4,995 one-time · instant download

Instant download

Editable Word and Excel

Two frameworks, one price

Written by practising security professionals

What’s in the package

  • Information security policy
  • Standards library
  • Control library
  • Procedures
  • Assurance metrics
  • Supporting templates

Editable Word + Excel

Instant download

Where this fits

At programme level, a policy alone is not enough. An auditor or enterprise customer will want to see the control library you work from, the procedures people follow, and the metrics showing those procedures are running.

Building that stack from scratch, with policies, standards, controls, procedures, and a measurement layer mapped to both NIST CSF 2.0 and ISO 27001, is well over a thousand hours of specialist work. Few teams have that time, and consultancy to do it instead is expensive.

This package is that documentation layer, written and mapped, ready for your specifics.

What you get

Information security policy

The governing statement of management intent and risk appetite.

Standards library

The measurable requirements that make each policy statement enforceable.

Control library

The full control set, mapped to both NIST CSF 2.0 and ISO 27001 Annex A. It is the single reference for what you are implementing and why, and what you hand an assessor who asks for your control inventory.

Procedures

Step-level operational documentation mapped one-to-one to the standards, so there is no gap between what you require and how it is performed. Most documentation sets stop before this layer, and it is usually where audits fail.

Assurance metrics

Measurement definitions tied to controls, so you can evidence operating effectiveness over time rather than design alone.

Supporting templates

Registers, assessment worksheets, and the recurring documents a programme generates.

Both frameworks, every layer

Single-framework documentation becomes expensive when obligations change, because at programme level you are re-mapping an entire control library and every procedure attached to it, not editing one policy.

Every layer in this package carries both NIST CSF 2.0 and ISO 27001 mappings. A customer asking for CSF alignment and a certification body asking for Annex A coverage are looking at the same documents, from different angles.

Comparable single-framework documentation from the larger US vendors is typically priced at around this level per framework.

What this doesn’t do

It doesn't certify you.

No document set does. Certification requires an accredited body auditing your operations. This gives you the documentation an auditor expects to see, structured the way they expect it.

It doesn't run itself.

Procedures describe work people still have to do, and metrics describe measurements someone still has to take. The programme needs an owner.

It still needs your specifics.

Owners, systems, thresholds, escalation paths and scope boundaries cannot be pre-written. Allow time for tailoring, particularly on procedures, which are the most environment-specific layer.

Buy it knowing what work remains.

Who this is for

A good fit if you’re:

  • Preparing for ISO 27001 certification and starting from thin documentation
  • Answering enterprise security questionnaires and repeatedly failing on evidence
  • Standing up a security function and needing a structure to build on
  • Running a programme that grew organically and now needs to be coherent on paper

Probably not the right fit if you’re:

  • Only being asked for a policy (the policies and standards package at €1,795 may be enough)
  • Looking for a compliance platform rather than documentation
  • Expecting something you can hand over without tailoring

If you are unsure which package applies, contact us and describe your situation.

Who wrote it

Written by information security practitioners who have implemented these controls, been audited against them, and produced the evidence.

Procedures are where the difference shows. Generic procedure text describes an idealised process. Procedures written by someone who has done the work describe what happens, in a form a person can follow and an auditor can test.

The same applies to metrics: knowing which measurements demonstrate operating effectiveness comes from having reviewed them in practice.

See it before you buy

Free extracts from the package, so you can judge the writing first.

Sample: policy and standards extractComing soon
Sample: procedure extractComing soonthe most environment-specific layer
Sample: control libraryComing soonsee the dual mapping
Sample: assurance metric definitionsComing soon

No email address required.

What it costs to do this yourself

RouteRealistic effortRealistic cost
Write it in-house900-1,200 hours over 9-18 months€70,000-€100,000 in diverted time
Hire a consultant4-9 months of engagement€120,000-€200,000
This packageWeeks of tailoring€4,995

Figures are estimates based on typical rates and drafting effort; your numbers will differ. Time is usually the deciding factor, since the deal or certification driving the work has a date attached.

FAQ

How is this different from the policies and standards package?

That one is the governance layer: policy plus standards. This adds the control library, procedures, assurance metrics, and supporting templates, which are the operational and evidence layers. If you need to demonstrate a programme rather than describe one, this is the package.

We already bought the smaller package. Can we upgrade?

Yes. Contact us and we will credit what you paid against this price.

Format?

Editable Word for narrative documents, Excel for the control library and mappings. No proprietary platform.

How long does tailoring take?

It depends on your size and how much already exists. A small organisation with an engaged owner typically needs a few weeks. Larger or more complex environments take longer, mostly on procedures and scope.

Will this get us through an ISO 27001 audit?

It gives you the documentation an auditor expects. Passing depends on whether you are operating the controls.

Do we get updates?

One year included. Material framework revisions are reissued.

Read the samples, then decide.

Start with the procedure sample; it is the layer where documentation quality is most visible. If it does not read as if it was written by someone who has done the work, do not buy the package.

€4,995 one-time · instant download

Not available for purchase just yet. Read the samples first and check back soon.