Policy Development · 05
Policy & Procedure Documentation
- Client
- Confidential Client
- Role
- GRC Analyst
- Year
- 2025
- Category
- Policy Development
Overview
Development of a structured policy and procedure library covering information security, acceptable use, access control and incident response, written to be enforceable and auditable rather than boilerplate.
Key Activities
- Audited existing policies against applicable frameworks and identified gaps
- Drafted and restructured core information-security policies and supporting procedures
- Aligned document ownership, review cycles and approval workflows
- Coordinated stakeholder review and sign-off across departments
Outcome
Delivered a coherent, version-controlled policy set that stood up to audit scrutiny and gave staff clear, actionable guidance.
Frameworks & Standards
ISO/IEC 27001NIST CSF