Komplyo blog

Documentation and governance

The documentation an auditor or a customer asks for comes down to a limited set of policies and evidence, provided they all derive from a single assessment. This section covers the NIST CSF 2.0 framework, writing an information security policy, security budgeting and awareness training. The aim is documentation that gets used internally, not documentation produced for the audit.

Get the security policy template

An information security policy template in .docx format, structured around NIST CSF 2.0 and ISO 27001. Delivered by email, usable as a documentation baseline.

No spam. Unsubscribe in one click.