The Cyber Governance GroupSecurity · Risk · Compliance
[ Program documentation ]

Documentation that stands up to examination.

Policies, plans and records developed from assessed reality: specific to your environment, traceable to the requirements they satisfy, and maintained as your program changes.

01 — The standard

Written for your organization, not a template's.

Generic templates describe someone else's controls, and an examiner can tell. Every document we develop reflects how your organization actually operates.

D-01

Grounded in evidence

Drafted from assessment findings. A document never promises a control you don't have; gaps go on the remediation plan instead.

D-02

Specific

Your systems, roles, vendors and notification obligations, named and accurate.

D-03

Traceable

Each section maps to the requirement it satisfies, so evidence requests are answered in minutes.

D-04

Maintained

Version history, scheduled reviews and updates when your environment or the rules change.

02 — How it's developed

Most of the work is done before you review it.

Documents arrive around 80% complete, built from what the assessment established. What remains are the decisions only your leadership should make, each presented with a recommendation.

01 · Assess

Establish the facts

Systems, people, vendors and obligations, documented during the assessment.

02 · Draft

Develop to match

Each document is drafted against your actual environment and the requirements that apply.

03 · Decide

Leadership decisions

Open decisions are reviewed together and finalized, usually in a single working session per document.

04 · Maintain

Keep it current

Annual reviews, change-driven updates and records retained for the periods regulators expect.

03 — The library

The documents examiners, auditors and insurers ask for.

Included in Program Assessment & Development and maintained under a fractional CISO engagement. Individual documents are available as targeted engagements.

Governance

Policies & standards
Information Security PolicyExaminers · Auditors

The umbrella policy: commitments, roles and the program in one place.

Acceptable Use PolicyEvery workforce member

Two pages people will actually read, with an acknowledgment record.

Access Control & MFA StandardInsurers · HIPAA · PCI

Who gets access, how it's approved and removed, and where MFA is required.

Risk

Assess & remediate
Risk Management Policy & Risk RegisterHIPAA · NCUA · PCI

How risk is rated and treated, plus the register that proves it.

Plan of Action & MilestonesBoards · Examiners

Every gap with an owner, a date and evidence of completion.

HIPAA Addressable Decision RecordHIPAA

The required documentation for all 22 addressable safeguards, which most practices never write down.

Response

Incidents & breaches
Incident Response PlanInsurers · HIPAA · NCUA · PCI

A one-page quick card, a contact sheet, and every notification deadline that applies to you.

Breach Risk Assessment WorksheetHIPAA

The documented analysis that decides whether an incident is a reportable breach.

Continuity

Backup & recovery
Backup & Contingency PlanHIPAA · Insurers

Recovery priorities, backup standard, restore-test log and downtime procedures.

Vendors

Third-party risk
Vendor Risk Management PolicyHIPAA · NCUA · PCI · FERPA

Tiers, due diligence and the agreements required before data is shared.

Vendor Register & QuestionnaireExaminers · Auditors

Every vendor, what they hold, which agreements are on file, and a short questionnaire they'll actually answer.

Reporting

Leadership
Board Cybersecurity ReportBoards · NCUA

Two pages: are we OK, what changed, what we need from you.

Security Baseline Assessment ReportOwners · Executives

Risk-rated findings and a prioritized 90-day plan, readable in ten minutes.

Sector add-ons: HIPAA Notice of Privacy Practices review, FERPA data sharing agreements, PCI DSS evidence binders and NCUA exam document-request preparation.

Ready for the next request.

Tell us what you've been asked for and when it's due. We'll tell you what it takes.