Security policy
A short statement from management covering objectives, scope, responsibilities and review frequency. Not a declaration packed with buzzwords, but a commitment that everything else can later be measured against.
The scope depends on the purpose. A supplier questionnaire can often be covered by a lean set of documents; an essential or important entity under NIS2 needs more depth and clear accountability at board level.
A short statement from management covering objectives, scope, responsibilities and review frequency. Not a declaration packed with buzzwords, but a commitment that everything else can later be measured against.
What does the business depend on, what threatens it, how likely is that and what would the damage be? We rate this together with you, for instance the loss of production planning at a component supplier or of client files at a law firm.
Passwords and multi-factor sign-in, mobile devices, working from home, email and file sharing, use of AI services. Each rule is short enough to be read and names the person to ask.
Incident handling including reporting routes to CERT.at and to the competent authority where required, backup and recovery, granting access, dealing with suppliers. Written as workflows with names, deadlines and contact channels.
We answer questionnaires from major customers by pointing to your documents instead of ticking “yes” with nothing behind it. Anything that cannot honestly be answered with yes today becomes an action item.
A cross-reference of your documents against ISO 27001, the Austrian Information Security Handbook (Österreichisches Informationssicherheitshandbuch) or NIS2 requirements shows what is covered and what is still missing.
Writing is the smaller part of the job. The larger part is finding out what really applies in your organisation.
Two to four video sessions with management, IT staff and department heads. We ask about practice rather than rules: who creates new accounts, what happens when a laptop goes missing, who decides in an emergency.
A joint rating of the key assets and threats in a simple spreadsheet you can keep updating without us.
We write the policy, rules and procedures and review them with the people responsible. Whatever does not work in practice gets changed, not glossed over.
Management signs off, staff are briefed and the annual review goes into the calendar. We can take on the updates as well if you wish.
An auditor does not just read your policies; he asks whether they are lived. A password rule demanding twelve characters while the directory still accepts eight is worse than having no rule, because it puts the gap in writing. We compare every document with the real configuration before it is approved.
Because essential and important entities have to take the security of their supply chain into account. That reaches you as a questionnaire, a contract clause or an audit. With coherent documentation you can answer such requests in hours instead of weeks. If you like, we can do a first check of whether your company might fall within scope based on sector and size; the binding assessment belongs with your legal adviser.
A manageable amount: a policy of three to four pages, five to eight rules of one or two pages each, a risk table and three to five procedures, including incident handling and recovery. More paper does not mean more security.
Yes. We work to the principles of ISO 27001 and structure the documents so they can serve as the basis of a management system. The certification itself is carried out by an accredited certification body, which we are not.
A freely available handbook of measures and recommendations, originally written for public administration but equally useful for businesses. It is not mandatory. We like using it as a reference because it uses Austrian terminology and gives practical examples.
Every document names an owner and a review date. Many companies ask us to carry out the annual review; others do it themselves using the checklist we provide.
Let us know why you need the documentation and what already exists. We will suggest a scope that fits your size and the occasion.
Your enquiry has arrived
Our reply reaches you within one working day. Outages that leave your staff unable to work are dealt with first.
We could not find that town. Try another spelling, or choose whichever provincial capital lies closest; as everything is handled remotely, you get the same service in all nine Austrian states.