Service · IT security

Security policies and documentation

Security documentation is rarely written for its own sake. There is nearly always a trigger: a large industrial customer sends a supplier questionnaire with eighty questions, a client that falls under NIS2 and the Austrian NIS Act passes its obligations down the supply chain, or the insurer wants to know how emergencies are handled before renewing the cyber policy. Under time pressure it is tempting to download a template, and any auditor spots that within two pages: policies naming systems the company does not own, roles nobody fills, procedures no one has heard of. We work the other way round. First we find out how your business really operates, then we write down what already applies and close the gaps this process exposes. The result is documentation that survives an audit and that your staff recognise as describing their own working day.

ISO 27001
as the structure, even without a certification goal
Austrian security handbook
as a practical reference
One policy
of four pages at most, signed by management
Every year
reviewed, not written once and forgotten

Everything this covers

The scope depends on the purpose. A supplier questionnaire can often be covered by a lean set of documents; an essential or important entity under NIS2 needs more depth and clear accountability at board level.

Settle the details with an engineer

Security policy

A short statement from management covering objectives, scope, responsibilities and review frequency. Not a declaration packed with buzzwords, but a commitment that everything else can later be measured against.

Asset list and risk assessment

What does the business depend on, what threatens it, how likely is that and what would the damage be? We rate this together with you, for instance the loss of production planning at a component supplier or of client files at a law firm.

Everyday rules

Passwords and multi-factor sign-in, mobile devices, working from home, email and file sharing, use of AI services. Each rule is short enough to be read and names the person to ask.

Procedures and contingency plans

Incident handling including reporting routes to CERT.at and to the competent authority where required, backup and recovery, granting access, dealing with suppliers. Written as workflows with names, deadlines and contact channels.

Supplier questionnaires

We answer questionnaires from major customers by pointing to your documents instead of ticking “yes” with nothing behind it. Anything that cannot honestly be answered with yes today becomes an action item.

Mapping to frameworks

A cross-reference of your documents against ISO 27001, the Austrian Information Security Handbook (Österreichisches Informationssicherheitshandbuch) or NIS2 requirements shows what is covered and what is still missing.

Our working method

Writing is the smaller part of the job. The larger part is finding out what really applies in your organisation.

01

Interviews

Two to four video sessions with management, IT staff and department heads. We ask about practice rather than rules: who creates new accounts, what happens when a laptop goes missing, who decides in an emergency.

02

Risk assessment

A joint rating of the key assets and threats in a simple spreadsheet you can keep updating without us.

03

Drafts and review

We write the policy, rules and procedures and review them with the people responsible. Whatever does not work in practice gets changed, not glossed over.

04

Approval and follow-up

Management signs off, staff are briefed and the annual review goes into the calendar. We can take on the updates as well if you wish.

An auditor does not just read your policies; he asks whether they are lived. A password rule demanding twelve characters while the directory still accepts eight is worse than having no rule, because it puts the gap in writing. We compare every document with the real configuration before it is approved.

Frequently asked questions

Because essential and important entities have to take the security of their supply chain into account. That reaches you as a questionnaire, a contract clause or an audit. With coherent documentation you can answer such requests in hours instead of weeks. If you like, we can do a first check of whether your company might fall within scope based on sector and size; the binding assessment belongs with your legal adviser.

A manageable amount: a policy of three to four pages, five to eight rules of one or two pages each, a risk table and three to five procedures, including incident handling and recovery. More paper does not mean more security.

Yes. We work to the principles of ISO 27001 and structure the documents so they can serve as the basis of a management system. The certification itself is carried out by an accredited certification body, which we are not.

A freely available handbook of measures and recommendations, originally written for public administration but equally useful for businesses. It is not mandatory. We like using it as a reference because it uses Austrian terminology and gives practical examples.

Every document names an owner and a review date. Many companies ask us to carry out the annual review; others do it themselves using the checklist we provide.

Documentation that holds up in an audit

Let us know why you need the documentation and what already exists. We will suggest a scope that fits your size and the occasion.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.