Governance
Policies & standardsThe umbrella policy: commitments, roles and the program in one place.
Two pages people will actually read, with an acknowledgment record.
Who gets access, how it's approved and removed, and where MFA is required.
Policies, plans and records developed from assessed reality: specific to your environment, traceable to the requirements they satisfy, and maintained as your program changes.
Generic templates describe someone else's controls, and an examiner can tell. Every document we develop reflects how your organization actually operates.
Drafted from assessment findings. A document never promises a control you don't have; gaps go on the remediation plan instead.
Your systems, roles, vendors and notification obligations, named and accurate.
Each section maps to the requirement it satisfies, so evidence requests are answered in minutes.
Version history, scheduled reviews and updates when your environment or the rules change.
Documents arrive around 80% complete, built from what the assessment established. What remains are the decisions only your leadership should make, each presented with a recommendation.
Systems, people, vendors and obligations, documented during the assessment.
Each document is drafted against your actual environment and the requirements that apply.
Open decisions are reviewed together and finalized, usually in a single working session per document.
Annual reviews, change-driven updates and records retained for the periods regulators expect.
Included in Program Assessment & Development and maintained under a fractional CISO engagement. Individual documents are available as targeted engagements.
The umbrella policy: commitments, roles and the program in one place.
Two pages people will actually read, with an acknowledgment record.
Who gets access, how it's approved and removed, and where MFA is required.
How risk is rated and treated, plus the register that proves it.
Every gap with an owner, a date and evidence of completion.
The required documentation for all 22 addressable safeguards, which most practices never write down.
A one-page quick card, a contact sheet, and every notification deadline that applies to you.
The documented analysis that decides whether an incident is a reportable breach.
Recovery priorities, backup standard, restore-test log and downtime procedures.
Tiers, due diligence and the agreements required before data is shared.
Every vendor, what they hold, which agreements are on file, and a short questionnaire they'll actually answer.
Two pages: are we OK, what changed, what we need from you.
Risk-rated findings and a prioritized 90-day plan, readable in ten minutes.
Sector add-ons: HIPAA Notice of Privacy Practices review, FERPA data sharing agreements, PCI DSS evidence binders and NCUA exam document-request preparation.
Tell us what you've been asked for and when it's due. We'll tell you what it takes.