Govern & Assure
Policy Development
New or refreshed information security policies written around how your organisation works, singly or as a suite, for good practice, ISO 27001, PCI DSS, or other requirements.
- Policies that reflect the organisation
- Support for compliance and good practice
- A joined-up policy suite
- Clear ownership and review
- Clear enough to be followed
Policies should set clear expectations for how security is managed in your organisation. Too often they are copied from templates, written to satisfy an audit, or left disconnected from the people and processes they are meant to govern.
We take a more practical approach. We start with the organisation, the risks, the way responsibilities are split, and any specific framework or compliance requirements that need to be met. We review any existing policies, so useful material is kept and gaps are addressed rather than everything being rewritten for the sake of it.
The output might be a focused policy for one area or a broader suite covering areas such as information security, access control, acceptable use, incident management, data classification, supplier security, and change management.
Where policies support ISO 27001, PCI DSS, or another framework, we make sure the relevant requirements are reflected without turning the documents into copies of the standard.
You finish with policies that are clear, proportionate, and usable, with ownership and review expectations understood, not a set of documents that sit untouched until the next audit.
Get a quote for Policy Development
Tell us your scope and objectives, and we’ll come back with a clear, fixed proposal, usually the same working day.
Get a Quoteor call +44 (0) 203 393 7795- CREST-accredited
- UK-based specialists
- Crown Commercial Service supplier
How it works
- 01
Understand the requirement
We start with what is driving the work, whether that is a compliance gap, an ISO 27001 programme, PCI DSS, a wider security improvement initiative, or the need to replace an outdated policy suite.
- 02
Review what already exists
Where policies, standards, or procedures are already in place, we review them against the organisation's needs and any relevant framework requirements.
- 03
Identify the gaps
We agree which policies need to be created, refreshed, consolidated, or retired, and where supporting procedures or guidance may also be needed.
- 04
Draft around how you work
We develop the documents using your terminology, governance model, and operating practices, working with the people who will own or apply them.
- 05
Review and agree
Drafts are reviewed with the relevant stakeholders so the final policies are accurate, workable, and ready for approval.
- 06
Put ownership in place
We make sure ownership, approval, and review expectations are clear so the policy set can be maintained after the project ends.
What you get
Policies that reflect the organisation
We write around your actual structure, systems, responsibilities, and ways of working rather than starting from a generic template and changing the logo.
Support for compliance and good practice
We develop policies to support ISO 27001, PCI DSS, or wider security governance, depending on what is driving the work.
A joined-up policy suite
Where several policies are needed, we make sure they fit together, use consistent terminology, and do not create conflicting expectations.
Clear ownership and review
We help define who owns each policy, who approves it, and how it should be reviewed so the documents remain current.
Clear enough to be followed
We write in plain language with concise requirements, not legal-style documents, so people can understand and apply each policy.
Frequently asked questions
Straight answers to what prospective clients ask us most.
Do we need a full set of security policies?
Not necessarily. Some organisations need a complete policy suite, while others have a specific gap or a small number of documents that need attention. We start by reviewing what you already have and only recommend the work that is actually needed.
Can you develop policies for ISO 27001 or PCI DSS?
Yes. Policy development often forms part of a wider compliance or improvement programme. We develop or refresh policies to support the relevant requirements while making sure they still reflect how your organisation operates.
Will you use templates?
We use established structures and good practice, but the final documents are written around your governance, systems, and responsibilities, not generic templates with the names changed.
Can you review and improve our existing policies?
Yes. In many cases that is the best starting point. We assess the current set, identify gaps, remove duplication, and update documents that no longer reflect the organisation or its requirements.
What happens after the policies are written?
We do not hand over a draft and walk away. Policies are reviewed with the relevant stakeholders and refined based on feedback, and that review cycle is part of the project. You finish with policies that have been challenged, agreed, and are ready for approval.
What is the difference between a policy, standard, and procedure?
A policy sets the organisation's expectations and rules, including what must happen and who is responsible. It should be clear enough to guide decisions without becoming an instruction manual. A standard adds specific mandatory requirements beneath a policy, such as an approved encryption standard or minimum password configuration. A procedure explains how a particular activity is carried out in practice, usually as a defined sequence of steps.
Not every policy needs a separate standard or procedure. We help work out the right level of documentation for the organisation, rather than creating documents simply to fill out a hierarchy.
Related services
Ready to talk about policy development?
Get a fixed-scope quote, usually the same working day.