Governance and requirements
An information security policy and standards library, ready to tailor.
An information security policy and the full standards library that makes it enforceable, mapped to NIST CSF 2.0 and ISO 27001. Written by security practitioners who have implemented the controls they describe.
Instant download
Editable Word
Two frameworks, one price
Written by practising security professionals
What’s in the package
- The information security policy
- The standards library
Editable Word
Instant download
Where this fits
Most buyers of this package have been asked for an information security policy by a customer questionnaire, a procurement team, or an ISO 27001 gap assessment, and have found they do not have one written down in the form that was requested.
Writing one from scratch means deciding how many policies you need, how policies and standards relate to each other, and which of the 93 Annex A controls apply to an organisation of your size.
This package covers that documentation layer. It does not run your security programme for you, but it removes the slowest and most specialised part of getting it onto paper.
What you get
Two connected documents:
The information security policy
The governing document. States what management requires, what needs protecting, and what level of risk the organisation is willing to accept. It is written at a level that stays stable, so it can go in front of a board or a customer without quarterly edits.
The standards library
The specific, measurable requirements behind each policy statement. Where the policy says access must be controlled, the standards set out review cadences, authentication requirements, and joiner-mover-leaver expectations. This is the layer auditors test against.
The two are cross-referenced. Every standard traces to a policy statement, and every policy statement has standards beneath it.
Mapped to both frameworks
Most documentation sets are built for a single framework, so a NIST CSF set has to be reworked when a customer asks about ISO 27001.
This one is mapped to NIST CSF 2.0 (including the Govern function) and ISO 27001 at the same time. The tailoring you do once applies to both.
What this doesn’t do
Three limits worth knowing before you buy.
This will not make you compliant.
Documentation is one layer of evidence. Compliance depends on operating the controls the documents describe.
It's not finished when it arrives.
You will need to name owners, set your own thresholds and review cadences, and delete sections that do not apply. The structure and drafting are done; the specifics that only you know are not.
It's not a substitute for judgment.
Whether a given control applies to your environment is a decision the document cannot make for you.
What it does is remove roughly 300 hours of research, structuring, drafting, and framework mapping, and give you a sound starting point.
Who wrote it
The documents were written by information security practitioners who have built and run security programmes, been audited against them, and had to justify control scoping to an assessor.
In practice that means:
- Clauses are written so they can be tested
- Scope language is written to hold up when challenged
- Every standard maps to a control; there is no filler
Each clause was written by someone with a security background who can explain why it is there.
See it before you buy
Free extracts from the package, so you can judge the writing first.
No email address required.
What it costs to do this yourself
| Route | Realistic effort | Realistic cost |
|---|---|---|
| Write it in-house | 250-350 hours across several months | €20,000-€30,000 in diverted time |
| Hire a consultant | 6-12 weeks of engagement | €35,000-€60,000 |
| This package | Days of tailoring | €1,795 |
Figures are estimates based on typical rates and drafting effort; your numbers will differ.
FAQ
Is this a fill-in-the-blanks template?
No. It is fully written prose that you tailor. Apart from identifying details, there are no blanks to fill in.
What format?
Editable Microsoft Word, which also opens in LibreOffice and Google Docs. There is no platform or login.
Do we own it? Can we edit it freely?
Yes. It is a single-organisation licence. You can edit it freely and keep it in your own systems, with nothing to renew.
We're a 30-person company. Is this overkill?
Probably not. Smaller organisations typically delete a meaningful portion and simplify the rest. The structure works at any size; the level of detail is what you scale.
What if the frameworks update?
One year of updates is included. If NIST or ISO revises something material, you get the revised documents.
Can we get help tailoring it?
Yes. Contact us and we will tell you whether you need it.
Read the samples, then decide.
The extracts show the structure, tone and level of detail. If they are not better than what you would write yourself, do not buy the package.
€1,795 one-time · instant download
Not available for purchase just yet. Read the samples first and check back soon.