All Projects
Policy Development · 05

Policy & Procedure Documentation

Client
Confidential Client
Role
GRC Analyst
Year
2025
Category
Policy Development

Overview

Development of a structured policy and procedure library covering information security, acceptable use, access control and incident response, written to be enforceable and auditable rather than boilerplate.

Key Activities

  • Audited existing policies against applicable frameworks and identified gaps
  • Drafted and restructured core information-security policies and supporting procedures
  • Aligned document ownership, review cycles and approval workflows
  • Coordinated stakeholder review and sign-off across departments

Outcome

Delivered a coherent, version-controlled policy set that stood up to audit scrutiny and gave staff clear, actionable guidance.

Frameworks & Standards

ISO/IEC 27001NIST CSF