ISSP & security documentation IT security policy: a tailored ISSP adapted to your business

We build your Information Systems Security Policy to formalise the security rules, responsibilities, procedures and requirements that apply to your organisation, your staff, your providers and your systems.

An ISSP your teams can actually use — not a generic 80-page document left in a folder.

ISSP compliant with ISO 27001 & NIS2
Operational documents, not templates
ISSP core included, extra docs by package

What you get

Tailored ISSP deliverables

An ISSP core adapted to your context, plus complementary documentation (charter, procedures) according to the selected package. Full BCP and DRP are scoped separately.

4–8 weeks
100% tailored
pack docs + support

80% of security incidents could have been avoided with formalised procedures and a security policy

What is an ISSP or Information Systems Security Policy ?

The ISSP is the framework document that defines the security rules applicable to an organisation's information system. It turns security objectives into concrete rules: responsibilities, access, tool usage, data protection, incident management, backups, providers and continuity.

Govern

Who decides and who is accountable ?

Protect

Which rules must be followed ?

Respond

What to do when an incident occurs ?

Control

How to check that the rules are actually applied ?

What should an IT security policy contain ?

These chapters form the typical content of an ISSP. They set the rules; the deliverable pack then turns them into usable documents.

Governance & responsibilities

  • executive management
  • IT department
  • CISO
  • staff
  • providers

Access management

  • accounts
  • authorisations
  • privileges
  • authentication

Endpoint & device security

Workstations, mobiles, removable media.

Networks & infrastructure

Perimeter, segmentation, administration.

Backups

Frequency, retention, tests.

Incident management

Detection, response, communication.

Provider security

Access, clauses, supervision.

Remote work & mobility

Remote access, off-site devices.

Business continuity

Resilience principles — not a BCP or a DRP.

Control & improvement

Reviews, indicators, updates.

The exact content is calibrated to the IT landscape, the risks, the business and the requirements that apply to the organisation.

From the ISSP to operational policies

The ISSP is not a standalone Word document. It breaks down into supporting policies : operational documents that explain how to apply the framework.

ISSP

  • access control policy
  • password policy
  • backup policy
  • incident management policy
  • asset management policy
  • provider policy
  • remote-work rules
  • continuity policy
  • IT user charter

The ISSP defines the framework ; operational policies and procedures explain how to apply it.

What is the difference between an ISSP and an IT user charter ?

ISSP

A global governance document designed to structure information-system security.

IT user charter

Rules for using digital tools that apply to users.

  • passwords
  • messaging
  • equipment
  • Internet
  • software
  • storage
  • expected behaviours

The IT user charter can follow from the ISSP, but it does not replace it.

ISSP and ISO 27001: what is the link ?

ISSP

Formalises the organisation's security orientations and rules.

ISMS

Organises security management more broadly :

  • governance
  • risks
  • objectives
  • controls
  • improvement
  • evidence

A structured ISSP is an important building block of an ISO 27001 approach, but drafting an ISSP is not enough to obtain certification.

Preparing for ISO 27001 ?

See our certification support

The ISSP: the foundation of your governance and cybersecurity GRC

Cybersecurity GRC (governance, risk, compliance) is broader than a policy. The ISSP is the documentary foundation: it sets the rules, it does not replace the system.

Governance

Who owns security ?

Risk

Which risks should the policy address ?

Compliance

Which requirements must be taken into account ?

Control

How to check that the rules are applied ?

The ISSP is the foundation. Cybersecurity GRC is the system.

Does your organisation need to structure its ISSP ?

Maturity of your security policy

Maturity 46 / 100
Documentation Partial
Priorities 5
  • Governance55 %
  • Access50 %
  • Incidents40 %
  • Continuity30 %
  • Providers40 %
  • Awareness60 %

Priority documents

  • ISSP
  • incident procedure
  • access-rights rules
  • user charter

Recommended assignment

ISSP + operational procedures

Structure my security policy

Indicative diagnostic that does not constitute a cybersecurity audit.

How do we draft an ISSP that is actually applicable ?

This is how we structure an applicable business IT security policy: we scope, analyse, write with the business, validate, roll out, then review. Not a generic template.

  1. Scoping

    Organisation, scope, IT landscape and constraints.

  2. Review of the existing setup

    Documents, risks, architecture, practices.

  3. Business & technical interviews

    Management, IT, HR, business lines…

  4. Framework definition

    Responsibilities and principles.

  5. Drafting

    ISSP and associated documents.

  6. Validation

    Management and stakeholders.

  7. Roll-out

    Communication and awareness.

  8. Implementation

    Procedures and controls.

  9. Review

    Update as the IT landscape and risks evolve.

An applicable ISSP is built with your teams. It is not imported from a template.

A good ISSP must not stay theoretical

An IT security policy only has value if teams can apply it. That is the gap between a generic template and a tailored ISSP.

Bad ISSP

  • generic template
  • unrealistic rules
  • nobody knows who does what
  • no procedures
  • no follow-up
  • never updated

Workable ISSP

  • tailored to the context
  • clear responsibilities
  • understandable rules
  • associated procedures
  • identified owners
  • planned controls
  • scheduled reviews

An ISSP only has value if it is applied.

What does an ISSP rule look like ?

A workable rule is not a vague intention. It states the principle, the owner, the scope of application, the control and the evidence.

Fictitious example

Subject : Administrator accounts

Principle
Privileged accounts must be distinct from standard user accounts.
Owner
CIO
Application
All internal administrators and providers.
Control
Periodic review of privileged accounts.
Evidence
Account list and review history.

Fictitious example intended to illustrate the structure of a rule. It is not a universal recommendation.

A workable rule states who does what, how it is checked, and what evidence is kept.

Every major policy has a rule owner

Without an owner, the ISSP remains a document. With a responsible person, controls and a review, it becomes a living system.

An objective

A scope

An owner

Rules

Exceptions

Controls

A review frequency

Every rule must have an owner, a control mechanism and a review frequency.

An ISSP must evolve with your information system

The policy is not static. Each significant change to the IT landscape, the organisation or the regulatory framework should trigger a check that the rules remain fit for purpose.

  • new tool
  • cloud migration
  • new application
  • merger / acquisition
  • new site
  • incident
  • regulatory change
  • organisational change
  • new critical provider

A periodic review is recommended, but above all each significant change should trigger a check that the policy remains fit for purpose.

Operational documents, not generic templates Compliant with ISO 27001, NIS2 & GDPR Training & procedures according to package

+90 ISSPs drafted

4–8 weeks deployment

4.9/5 client satisfaction

Your documentary and operational security pack

We formalise the chapters of your IT security policy into a documentary pack. An ISSP core in every package. Charter and procedures are added as needed. A full BCP or DRP is scoped separately.

ISSP core

Framework document

Objectives, scope and principles of your information systems security policy

Responsibilities

Who decides, who applies and who controls: leadership, IT, staff, providers

Access security

Access management policy, entitlements, authentication and access reviews

Asset management

Inventory, classification and protection of information-system assets

Incidents

Principles of detection, classification, response and communication — the framework, not yet the detailed procedure

Backups

Backup policy: frequency, retention, tests and responsibilities

Staff rules

Expected usage, obligations and behaviours — the internal framework, distinct from the signed charter

Providers

Security requirements applicable to third parties, subcontractors and external access

Continuity principles

Resilience orientations in the ISSP — without replacing an operational BCP or DRP

Complementary documentation — according to package

IT user charter

Operational document for staff, distinct from the ISSP framework document

Procedures

Operational procedures — including incident management — to apply the core in day-to-day work

BCP

Business continuity plan: a resilience piece of work in its own right, heavier than an ISSP chapter

DRP

Disaster recovery plan: restoration of systems and data after an incident

Operational plans

Action plans, tests and rollout arrangements adapted to your organisation

Support — according to package

Team awareness

So your staff understand and concretely apply the ISSP, beyond signing the charter

Leadership debrief

Presentation of the documentation set, decisions and validation with leadership and IT managers

Deployment support

Operational rollout of the ISSP in the organisation — so it is applied, not left in a folder

Who needs an IT security policy?

An ISSP becomes essential as soon as the IT landscape, teams, providers or client requirements outgrow informal practice.

Growing SMEs & mid-market companies

Your teams are growing, your tools are multiplying. Without an ISSP, the rules stay unclear and every incident reveals a procedural gap.

Businesses that built their IT landscape over time

The IT landscape grew tool by tool. Practices exist; written rules do not. The ISSP formalises what is already done — and what is missing.

Businesses preparing for ISO 27001

A structured ISSP is a building block of certification. Without a formalised IT security policy, an ISO 27001 programme does not hold.

Organisations facing client requirements

Security questionnaires, contractual clauses, supplier audits: the ISSP is often the first document requested.

Post-incident businesses

After a cyberattack or data breach, formalising the ISSP and incident procedures is the first organisational response.

Sectors with high security requirements

Healthcare, finance, industry, sensitive operators: the policy formalises the expected level of control, without replacing sector-specific texts.

Organisations with many providers / cloud

External access, SaaS and subcontractors multiply the surface. The ISSP sets the security requirements that apply to third parties.

How much does drafting an ISSP cost?

Cost depends on the ISSP core and the procedures actually required. A full BCP or DRP is not a simple package add-on. What does the price depend on?

Essential ISSP

€1,800 – 3,500 excl. VAT

Starting documentary framework

  • Documentary diagnostic
  • Tailored ISSP
  • IT user charter
  • Debrief
Request a quote

Full security governance

€5,000 – 9,000 excl. VAT+

Corpus, training and leadership

  • Complete ISSP
  • Strengthened documentary corpus
  • Continuity according to scope
  • Training
  • Deployment
  • Leadership support
Request a quote

Indicative pricing — a tailored quote is provided within 24 hours based on your exact scope. Full BCP/DRP engagements are sized according to IT complexity and can be scoped separately. See the price factors.

What does the price of an ISSP depend on?

The price of an ISSP is calculated from the actual scope — not a single flat fee. These elements are confirmed during the first discussion.

IT landscape size

Number of sites

Number of entities

Existing maturity level

Available documentation

Organisational complexity

Number of supporting policies

Sector requirements

Need for BCP/DRP

Number of interviews

Training need

Deployment support

Your questions about the ISSP

Our experts respond within 24 hours to all your questions about your IT security policy.

Contact us
What does ISSP mean?

ISSP stands for Information Systems Security Policy. It is the usual name for the framework document of an organisation's IT security policy. See the definition →

What is an ISSP?

The ISSP is the framework document that defines the security rules applicable to an organisation's information system. It turns security objectives into concrete rules: responsibilities, access, tool usage, data protection, incident management, backups, providers and continuity. See what an ISSP is →

What is an IT security policy for?

It formalises security rules, responsibilities and requirements: who decides, which practices are expected, how to react to an incident and how to check. It aligns leadership, IT, business teams and providers on a shared framework that can be applied day to day — not a theoretical document left in a folder. See what makes an ISSP workable →

What does an ISSP contain?

An ISSP typically covers governance and responsibilities, access management, endpoint and device security, networks and infrastructure, backups, incident management, provider security, remote work and mobility, business continuity, and control. The exact content is calibrated to the IT landscape, the risks, the business and the applicable requirements. Operational policies and procedures (charter, access, incidents, backup, etc.) then explain how to apply it. See typical ISSP contents →

How do you draft an ISSP?

Scope the perimeter, review the existing setup, interview business and IT teams, define responsibilities and principles, draft an applicable document — not a generic template —, have leadership validate it, roll it out, then control and review. An ISSP is built with your teams; it is not imported from a template. See the drafting method →

Who should draft the ISSP?

Leadership owns it. Drafting is usually led by the CISO, the CIO or an external provider, with the relevant business teams. It is not an “IT-only” document: without leadership validation and team ownership, it remains a dead letter.

Is an ISSP mandatory?

An ISSP named as such is not universally mandatory for every business. It becomes required or strongly expected depending on particular obligations and context: ISO 27001 certification, NIS2, public procurement, customer contracts, regulated sectors. Even without a formal obligation, it remains useful as soon as the IT landscape, the data or the providers justify it.

What is the difference between an ISSP and an IT user charter?

The ISSP is the global governance document designed to structure information-system security. The IT user charter defines the rules for using digital tools that apply to users (passwords, messaging, equipment, Internet, software, storage, expected behaviours). The charter can follow from the ISSP, but it does not replace it. See ISSP vs IT user charter →

What is the difference between an ISSP and an ISMS?

The ISSP is the framework document: it sets security orientations and rules. The ISMS (information security management system), notably under ISO 27001, organises management more broadly: governance, risks, objectives, controls, improvement and evidence. The ISSP is a building block of the ISMS, not the ISMS itself. See the ISSP / ISO 27001 link →

What is the link between an ISSP and ISO 27001?

A structured ISSP is an important building block of an ISO 27001 approach. Drafting an ISSP is not enough to obtain certification: the ISMS also requires risks, controls, evidence and continual improvement. See ISSP and ISO 27001 →

What is the difference between an ISSP and a BCP?

The ISSP sets the security framework, including continuity principles. The Business Continuity Plan (BCP) is an operational plan: how the organisation continues operating in degraded mode during an incident. It is a resilience piece of work heavier than a simple ISSP chapter; it is sized according to IT complexity and can be scoped separately.

What is the difference between a BCP and a DRP?

The BCP (Business Continuity Plan) defines how the organisation continues operating in degraded mode during an incident. The DRP (Disaster Recovery Plan) defines how to return to normal after the incident. They are complementary, not interchangeable. A full BCP or DRP is scoped separately.

Can you use an ISSP template found online?

Yes as a basis for thinking — but not as an operational document without adaptation. A generic template will not reflect your IT landscape, your business or your obligations. It generally will not pass an ISO 27001 audit. See the gap between a template and a workable ISSP →

How much does drafting an ISSP cost?

As a guide: Essential ISSP €1,800–3,500 excl. VAT, ISSP + operational procedures €3,500–6,500 excl. VAT, full security governance €5,000–9,000 excl. VAT+. Price depends in particular on IT landscape size, sites, entities, maturity, documentation, number of supporting policies, sector requirements, need for BCP/DRP, interviews, training and deployment. A full BCP or DRP is scoped separately. See pricing →

How long does it take to draft an ISSP?

In practice, often 4 to 8 weeks, depending on scope, available documentation, number of interviews and validation time. An essential ISSP can be faster; full governance, with procedures, training and deployment, takes longer. This is not a universal duration. See the drafting steps →

How often should an ISSP be updated?

An annual update is not a universal obligation: it depends on the context and the applicable requirements. A periodic review is recommended, but above all each significant change (new tool, cloud, incident, merger, regulation, critical provider) should trigger a check that the policy remains fit for purpose. See update triggers →

Is an ISSP enough to secure a business?

No. It organises the security rules but must be accompanied by technical, human and organisational measures that are actually implemented: access, backups, detection, awareness, incident procedures. Without application, the ISSP remains a document. See the audit, pentest, protection and ISO 27001 journey →

Ready to formalise your IT security policy?

Our experts draft your tailored ISSP — adapted to your context, operational and compliant with regulatory requirements. First conversation free, no commitment.

Draft my ISSP
First conversation free 100% tailored Compliant with ISO 27001 & NIS2
Innovation hub