Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Security Policy Management Pack — Guide

Security Policy Management Pack

Most organisations have security policies; few have policies anyone reads. They were copied from a template years ago and name people who have left. When an auditor asks who has read them, nobody can show it. This pack helps you build a smaller set of documents that people follow, keep it current, and prove it has been read.

Is this for you?

This pack is for you if:

  • you inherited a folder of policies and are not sure which ones are in force;
  • your policies have no owner, or a review date nobody checks;
  • an auditor asked for evidence that staff have read them, and you had none.

How many documents you need

Fewer than you might think. The pack lists 18 topics, and when each is needed:

Your organisationTopics to cover
Core: every organisation7
Growing: about 50 people or more15
Regulated: NIS2 essential or important entity, or DORA financial entity18

Developing software in-house adds secure development and change management to any profile.

A policy says what the organisation commits to; the detail goes into standards and procedures, approved lower down. Every document sits in one of four tiers:

TierWho approves itReviewed at least every
PolicyExecutive management12 months
StandardHead of Information Security (the document owner is consulted)12 months
ProcedureThe process owner, with information security consulted24 months
Guideline (advice, not mandatory)Information security24 months

Review sooner after a major incident, a material change, a change in law, an audit finding or a shift in threats. Keep each policy to four pages of body at most.

Start with these three

  1. Policy Framework Standard — the twelve rules every security document follows.
  2. Security Policy Document Template — nine sections, with requirements an auditor can test.
  3. Policy Register & Review Schedule — the one authoritative list of your documents and their review dates.

Your first month

WhenWhat to doYou’re done when
Week 1Name the approver for each tier in the Framework Standard. Collect every security document.Management has approved the Standard.
Week 2Register every document with an owner. Run the gap assessment.You know what is missing, duplicated or overdue.
Week 3Rewrite the top policy and the most overdue one in the template. Consult those who must follow them.Both are with their approvers.
Week 4Publish approved versions in one place, withdraw the old ones, and ask people to acknowledge them.Acknowledgements are in the tracker.

Four numbers to report

Report these to management quarterly.

NumberTarget
Documents past their review dateZero policies; no document more than 30 days overdue
Documents in force without approval at the right levelZero
Acknowledgement coverage: people in scope with a current acknowledgement95% or more
Overdue acknowledgements, named by managerNone older than 30 days

New starters acknowledge within 10 working days, everyone again within 30 days of a material change, and everyone once a year.

Everything in the pack

DocumentWhat it doesFormat
Policy Framework StandardThe rules management approvesWord
Policy Lifecycle Operating ProcedureA document’s path from draft to retirementWord
Security Policy Document TemplateA policy short enough to read and specific enough to auditWord
Security Policy Hierarchy & Document MapWhich documents your profile needsExcel
Policy Register & Review ScheduleEvery document and when it is next reviewedExcel
Policy Attestation & Acknowledgement TrackerWho has acknowledged which versionExcel
Policy Coverage Gap AssessmentTopics missing, duplicated or out of dateExcel
Policy Development & Approval Responsibility MatrixWho drafts, is consulted, approves and communicatesExcel
Policy Health & Attestation Reporting WorkbookThe four numbers: what is overdue and who has not signedExcel

Adapting it

  • Small organisation: cover the seven Core topics first. One person may own several documents, but each still needs a named owner and a review date.
  • Regulated entity (NIS2, DORA): cover all 18 topics. NIS2 Article 21(2)(a) and (f) expect policies on information system security and on assessing whether your measures work. DORA Article 6(5) requires a review at least once a year and after major ICT-related incidents. Delegated Regulation (EU) 2024/1774, Article 2(2), sets what each policy contains, including its approval date and the consequences of non-compliance; the template has a place for each.
  • IT run by an outside provider: the provider’s procedures can sit in your hierarchy, but the policies and their approval stay yours. Register the provider documents you rely on, and have its staff acknowledge the policies that apply to them.

Where it maps

  • ISO/IEC 27001:2022 — Annex A 5.1 and Clause 7.5.
  • NIST CSF 2.0 — GV.PO-01 and GV.PO-02.
  • NIS2 — Article 21(2)(a) and (f).
  • DORA — Article 6(5) and 9(4)(a); Delegated Regulation (EU) 2024/1774, Article 2(2).