return to Consultancy Services

Policy and Standards Review

Array
Policy and Standards need to be clear, usable and aligned to how people actually work, enabling staff to consistently make the right security decisions.

The ISF Policy and Standards Review provides a focused expert assessment of your existing documentation, highlighting where it supports your security objectives and where refinement is needed to improve clarity, consistency and alignment with recognised good practice. It’s ideal for organisations with existing policies and standards that need rapid, pragmatic insight into how to strengthen them.

Build a solid foundation for effective information security

Our solution:

Through a short, structured review, ISF experts assess how well your policies and standards:

  • Support your organisation’s security objectives
  • Cover relevant external standards and frameworks
  • Are structured, written and formatted for practical use

The focus is on clarity, usability and maintainability, ensuring documents enable secure behaviour, not just compliance.

What you receive:
  • Document‑level assessments with clear recommendations
  • Mapping to the ISF Standard of Good Practice (SOGP) or another major framework
  • Identification of missing or under‑represented content
  • Thematic observations across the document set
  • A recommended target structure to support improvement

With the SOGP already mapped to ISO, NIST CSF and CIS frameworks and standards, and the expertise of the ISF team, we were agile and efficient in meeting our goals…

Download case study
Want to find out more?