Advisory · 03/07
Policies & Compliance
A set of guidelines and rules that make the use of technology appropriate, secure and compliant, written so that people can follow them.
- Typical duration
- 4 to 10 weeks
- Team
- Compliance lead (ISO 27001 LI), policy writer, BCM specialist
01Overview
Policies regulate how technology is used, protect sensitive information and demonstrate compliance with legal and industry standards. Too often they are copied from a template, signed once and forgotten.
We write policy frameworks that fit how your organization really works, from the top-level information security policy down to procedures and checklists. Then we help you build the evidence that they are followed.
02What we do
- 01
Policy framework design
A structured hierarchy of policies, standards and procedures with clear ownership and review cycles.
- 02
Information security policies
Acceptable use, access control, classification, cryptography, incident response and more, aligned with ISO/IEC 27001 Annex A.
- 03
Data protection
Processing records, retention rules and procedures under the GDPR and Estonia’s Personal Data Protection Act.
- 04
Business continuity
Business impact analysis, continuity and disaster recovery plans, and tested recovery procedures.
- 05
Compliance monitoring
Control libraries, evidence calendars and dashboards so compliance is visible all year, not only before audits.
- 06
Awareness programs
Short, role-based training and phishing simulations so policies turn into habits.
03What you get
- Policies people read, understand and follow
- Clear evidence for auditors and regulators
- Reduced risk of data breaches and fines
- A sustainable review and update cycle
Typical deliverables
- 01Policy framework and document set
- 02Statement of Applicability (ISO/IEC 27001)
- 03Business continuity and DR plans
- 04Compliance calendar
- 05Awareness materials
04How the engagement runs
- 01
Inventory
Review of existing documents, obligations and how work is actually done.
- 02
Drafting
Policies written in plain language and reviewed with the people who must apply them.
- 03
Approval
Governance sign-off, communication plan and publication.
- 04
Embedding
Training, evidence collection and periodic compliance checks.
05Technologies & partners
06Questions clients ask
Frequently asked questions
01Can you prepare us for ISO/IEC 27001 certification?
Yes. We take organizations from gap analysis through implementation and internal audit to a certification-ready state. The certification audit itself is performed by an accredited body.
02Our policies exist in English only. Can you provide Estonian and Russian versions?
Yes. We deliver policy sets in English, Estonian and Russian, written and reviewed by people, not machine-translated.
03How often should policies be reviewed?
At least once a year, and whenever there is a significant change in regulation, technology or organization. We set up the review calendar for you.
07Related services
IT Governance
Strategy, risk and control frameworks that tie IT spend to business goals.
Learn more 02IT Audit
Independent assessment of your IT controls, data reliability and compliance.
Learn more 04Cybersecurity
Risk assessment, testing and protection against malware, phishing and ransomware.
Learn moreStart a conversation
Tell us where things stand. We will tell you honestly what it takes.
A 30-minute call with a senior consultant, no sales script. You leave with a clear next step, whether or not we work together.


