Talk to us

Advisory · 03/07

Policies & Compliance

A set of guidelines and rules that make the use of technology appropriate, secure and compliant, written so that people can follow them.

Typical duration
4 to 10 weeks
Team
Compliance lead (ISO 27001 LI), policy writer, BCM specialist

01Overview

Policies regulate how technology is used, protect sensitive information and demonstrate compliance with legal and industry standards. Too often they are copied from a template, signed once and forgotten.

We write policy frameworks that fit how your organization really works, from the top-level information security policy down to procedures and checklists. Then we help you build the evidence that they are followed.

02What we do

  1. 01

    Policy framework design

    A structured hierarchy of policies, standards and procedures with clear ownership and review cycles.

  2. 02

    Information security policies

    Acceptable use, access control, classification, cryptography, incident response and more, aligned with ISO/IEC 27001 Annex A.

  3. 03

    Data protection

    Processing records, retention rules and procedures under the GDPR and Estonia’s Personal Data Protection Act.

  4. 04

    Business continuity

    Business impact analysis, continuity and disaster recovery plans, and tested recovery procedures.

  5. 05

    Compliance monitoring

    Control libraries, evidence calendars and dashboards so compliance is visible all year, not only before audits.

  6. 06

    Awareness programs

    Short, role-based training and phishing simulations so policies turn into habits.

03What you get

  • Policies people read, understand and follow
  • Clear evidence for auditors and regulators
  • Reduced risk of data breaches and fines
  • A sustainable review and update cycle

Typical deliverables

  1. 01Policy framework and document set
  2. 02Statement of Applicability (ISO/IEC 27001)
  3. 03Business continuity and DR plans
  4. 04Compliance calendar
  5. 05Awareness materials

04How the engagement runs

  1. 01

    Inventory

    Review of existing documents, obligations and how work is actually done.

  2. 02

    Drafting

    Policies written in plain language and reviewed with the people who must apply them.

  3. 03

    Approval

    Governance sign-off, communication plan and publication.

  4. 04

    Embedding

    Training, evidence collection and periodic compliance checks.

05Technologies & partners

  • ISACA
  • Microsoft
  • Teramind

06Questions clients ask

Frequently asked questions

01Can you prepare us for ISO/IEC 27001 certification?

Yes. We take organizations from gap analysis through implementation and internal audit to a certification-ready state. The certification audit itself is performed by an accredited body.

02Our policies exist in English only. Can you provide Estonian and Russian versions?

Yes. We deliver policy sets in English, Estonian and Russian, written and reviewed by people, not machine-translated.

03How often should policies be reviewed?

At least once a year, and whenever there is a significant change in regulation, technology or organization. We set up the review calendar for you.

Start a conversation

Tell us where things stand. We will tell you honestly what it takes.

A 30-minute call with a senior consultant, no sales script. You leave with a clear next step, whether or not we work together.