Govern
Who decides and who is accountable ?
We build your Information Systems Security Policy to formalise the security rules, responsibilities, procedures and requirements that apply to your organisation, your staff, your providers and your systems.
An ISSP your teams can actually use — not a generic 80-page document left in a folder.
What you get
Tailored ISSP deliverables
An ISSP core adapted to your context, plus complementary documentation (charter, procedures) according to the selected package. Full BCP and DRP are scoped separately.
80% of security incidents could have been avoided with formalised procedures and a security policy
Definition
The ISSP is the framework document that defines the security rules applicable to an organisation's information system. It turns security objectives into concrete rules: responsibilities, access, tool usage, data protection, incident management, backups, providers and continuity.
Who decides and who is accountable ?
Which rules must be followed ?
What to do when an incident occurs ?
How to check that the rules are actually applied ?
ISSP contents
These chapters form the typical content of an ISSP. They set the rules; the deliverable pack then turns them into usable documents.
Workstations, mobiles, removable media.
Perimeter, segmentation, administration.
Frequency, retention, tests.
Detection, response, communication.
Access, clauses, supervision.
Remote access, off-site devices.
Resilience principles — not a BCP or a DRP.
Reviews, indicators, updates.
The exact content is calibrated to the IT landscape, the risks, the business and the requirements that apply to the organisation.
Supporting policies
The ISSP is not a standalone Word document. It breaks down into supporting policies : operational documents that explain how to apply the framework.
ISSP
The ISSP defines the framework ; operational policies and procedures explain how to apply it.
ISSP ≠ IT user charter
A global governance document designed to structure information-system security.
Rules for using digital tools that apply to users.
The IT user charter can follow from the ISSP, but it does not replace it.
ISSP vs ISMS ISO 27001
Formalises the organisation's security orientations and rules.
Organises security management more broadly :
A structured ISSP is an important building block of an ISO 27001 approach, but drafting an ISSP is not enough to obtain certification.
Preparing for ISO 27001 ?
See our certification supportGovernance & GRC
Cybersecurity GRC (governance, risk, compliance) is broader than a policy. The ISSP is the documentary foundation: it sets the rules, it does not replace the system.
Who owns security ?
Which risks should the policy address ?
Which requirements must be taken into account ?
How to check that the rules are applied ?
The ISSP is the foundation. Cybersecurity GRC is the system.
Mini diagnostic
Maturity of your security policy
ISSP + operational procedures
Indicative diagnostic that does not constitute a cybersecurity audit.
Our method
This is how we structure an applicable business IT security policy: we scope, analyse, write with the business, validate, roll out, then review. Not a generic template.
Organisation, scope, IT landscape and constraints.
Documents, risks, architecture, practices.
Management, IT, HR, business lines…
Responsibilities and principles.
ISSP and associated documents.
Management and stakeholders.
Communication and awareness.
Procedures and controls.
Update as the IT landscape and risks evolve.
An applicable ISSP is built with your teams. It is not imported from a template.
Applicable ISSP
An IT security policy only has value if teams can apply it. That is the gap between a generic template and a tailored ISSP.
An ISSP only has value if it is applied.
Example rule
A workable rule is not a vague intention. It states the principle, the owner, the scope of application, the control and the evidence.
Fictitious example
Fictitious example intended to illustrate the structure of a rule. It is not a universal recommendation.
A workable rule states who does what, how it is checked, and what evidence is kept.
Rule owner
Without an owner, the ISSP remains a document. With a responsible person, controls and a review, it becomes a living system.
Every rule must have an owner, a control mechanism and a review frequency.
Updates
The policy is not static. Each significant change to the IT landscape, the organisation or the regulatory framework should trigger a check that the rules remain fit for purpose.
A periodic review is recommended, but above all each significant change should trigger a check that the policy remains fit for purpose.
Our cybersecurity services
Complete IT assessment: systems, networks, access, applications and sensitive data.
Real attack simulation to identify exploitable vulnerabilities before hackers do.
Define and formalise your security rules, access, incident management and IT compliance.
Deploy technical and organisational measures to block and detect attacks.
Deliverables
We formalise the chapters of your IT security policy into a documentary pack. An ISSP core in every package. Charter and procedures are added as needed. A full BCP or DRP is scoped separately.
ISSP core
Objectives, scope and principles of your information systems security policy
Who decides, who applies and who controls: leadership, IT, staff, providers
Access management policy, entitlements, authentication and access reviews
Inventory, classification and protection of information-system assets
Principles of detection, classification, response and communication — the framework, not yet the detailed procedure
Backup policy: frequency, retention, tests and responsibilities
Expected usage, obligations and behaviours — the internal framework, distinct from the signed charter
Security requirements applicable to third parties, subcontractors and external access
Resilience orientations in the ISSP — without replacing an operational BCP or DRP
Complementary documentation — according to package
Operational document for staff, distinct from the ISSP framework document
Operational procedures — including incident management — to apply the core in day-to-day work
Business continuity plan: a resilience piece of work in its own right, heavier than an ISSP chapter
Disaster recovery plan: restoration of systems and data after an incident
Action plans, tests and rollout arrangements adapted to your organisation
Support — according to package
So your staff understand and concretely apply the ISSP, beyond signing the charter
Presentation of the documentation set, decisions and validation with leadership and IT managers
Operational rollout of the ISSP in the organisation — so it is applied, not left in a folder
Who is it for?
An ISSP becomes essential as soon as the IT landscape, teams, providers or client requirements outgrow informal practice.
Your teams are growing, your tools are multiplying. Without an ISSP, the rules stay unclear and every incident reveals a procedural gap.
The IT landscape grew tool by tool. Practices exist; written rules do not. The ISSP formalises what is already done — and what is missing.
A structured ISSP is a building block of certification. Without a formalised IT security policy, an ISO 27001 programme does not hold.
Security questionnaires, contractual clauses, supplier audits: the ISSP is often the first document requested.
After a cyberattack or data breach, formalising the ISSP and incident procedures is the first organisational response.
Healthcare, finance, industry, sensitive operators: the policy formalises the expected level of control, without replacing sector-specific texts.
External access, SaaS and subcontractors multiply the surface. The ISSP sets the security requirements that apply to third parties.
Our pricing
Cost depends on the ISSP core and the procedures actually required. A full BCP or DRP is not a simple package add-on. What does the price depend on?
Essential ISSP
€1,800 – 3,500 excl. VAT
Starting documentary framework
ISSP + operational procedures
€3,500 – 6,500 excl. VAT
A policy you can apply day to day
Full security governance
€5,000 – 9,000 excl. VAT+
Corpus, training and leadership
Indicative pricing — a tailored quote is provided within 24 hours based on your exact scope. Full BCP/DRP engagements are sized according to IT complexity and can be scoped separately. See the price factors.
What determines the price
The price of an ISSP is calculated from the actual scope — not a single flat fee. These elements are confirmed during the first discussion.
ISSP stands for Information Systems Security Policy. It is the usual name for the framework document of an organisation's IT security policy. See the definition →
The ISSP is the framework document that defines the security rules applicable to an organisation's information system. It turns security objectives into concrete rules: responsibilities, access, tool usage, data protection, incident management, backups, providers and continuity. See what an ISSP is →
It formalises security rules, responsibilities and requirements: who decides, which practices are expected, how to react to an incident and how to check. It aligns leadership, IT, business teams and providers on a shared framework that can be applied day to day — not a theoretical document left in a folder. See what makes an ISSP workable →
An ISSP typically covers governance and responsibilities, access management, endpoint and device security, networks and infrastructure, backups, incident management, provider security, remote work and mobility, business continuity, and control. The exact content is calibrated to the IT landscape, the risks, the business and the applicable requirements. Operational policies and procedures (charter, access, incidents, backup, etc.) then explain how to apply it. See typical ISSP contents →
Scope the perimeter, review the existing setup, interview business and IT teams, define responsibilities and principles, draft an applicable document — not a generic template —, have leadership validate it, roll it out, then control and review. An ISSP is built with your teams; it is not imported from a template. See the drafting method →
Leadership owns it. Drafting is usually led by the CISO, the CIO or an external provider, with the relevant business teams. It is not an “IT-only” document: without leadership validation and team ownership, it remains a dead letter.
An ISSP named as such is not universally mandatory for every business. It becomes required or strongly expected depending on particular obligations and context: ISO 27001 certification, NIS2, public procurement, customer contracts, regulated sectors. Even without a formal obligation, it remains useful as soon as the IT landscape, the data or the providers justify it.
The ISSP is the global governance document designed to structure information-system security. The IT user charter defines the rules for using digital tools that apply to users (passwords, messaging, equipment, Internet, software, storage, expected behaviours). The charter can follow from the ISSP, but it does not replace it. See ISSP vs IT user charter →
The ISSP is the framework document: it sets security orientations and rules. The ISMS (information security management system), notably under ISO 27001, organises management more broadly: governance, risks, objectives, controls, improvement and evidence. The ISSP is a building block of the ISMS, not the ISMS itself. See the ISSP / ISO 27001 link →
A structured ISSP is an important building block of an ISO 27001 approach. Drafting an ISSP is not enough to obtain certification: the ISMS also requires risks, controls, evidence and continual improvement. See ISSP and ISO 27001 →
The ISSP sets the security framework, including continuity principles. The Business Continuity Plan (BCP) is an operational plan: how the organisation continues operating in degraded mode during an incident. It is a resilience piece of work heavier than a simple ISSP chapter; it is sized according to IT complexity and can be scoped separately.
The BCP (Business Continuity Plan) defines how the organisation continues operating in degraded mode during an incident. The DRP (Disaster Recovery Plan) defines how to return to normal after the incident. They are complementary, not interchangeable. A full BCP or DRP is scoped separately.
Yes as a basis for thinking — but not as an operational document without adaptation. A generic template will not reflect your IT landscape, your business or your obligations. It generally will not pass an ISO 27001 audit. See the gap between a template and a workable ISSP →
As a guide: Essential ISSP €1,800–3,500 excl. VAT, ISSP + operational procedures €3,500–6,500 excl. VAT, full security governance €5,000–9,000 excl. VAT+. Price depends in particular on IT landscape size, sites, entities, maturity, documentation, number of supporting policies, sector requirements, need for BCP/DRP, interviews, training and deployment. A full BCP or DRP is scoped separately. See pricing →
In practice, often 4 to 8 weeks, depending on scope, available documentation, number of interviews and validation time. An essential ISSP can be faster; full governance, with procedures, training and deployment, takes longer. This is not a universal duration. See the drafting steps →
An annual update is not a universal obligation: it depends on the context and the applicable requirements. A periodic review is recommended, but above all each significant change (new tool, cloud, incident, merger, regulation, critical provider) should trigger a check that the policy remains fit for purpose. See update triggers →
No. It organises the security rules but must be accompanied by technical, human and organisational measures that are actually implemented: access, backups, detection, awareness, incident procedures. Without application, the ISSP remains a document. See the audit, pentest, protection and ISO 27001 journey →
Our experts draft your tailored ISSP — adapted to your context, operational and compliant with regulatory requirements. First conversation free, no commitment.
Quick, free estimate with no commitment — we usually reply within 24 hours.
By submitting this form, you accept our privacy policy.
Choose a day and then a time slot. We will confirm your appointment by email or phone.
Preferred time slot
Request sent successfully
We will get back to you shortly to confirm your time slot.
Availability shown is indicative; final confirmation is provided by our team.