Security Policy, Standards and Awareness
Security policy work produces the written rules an organization is prepared to enforce, the standards that make those rules operable, and the training that makes them understood by the people expected to follow them.
- Part of
- The decisions, records and oversight that turn security activity into something leadership can direct.
- Engaged as
- A defined piece of work, or as part of an ongoing vCISO engagement.
- Sits under
- Executive ownership of the cybersecurity program.
The problem
Why this comes up
Downloaded policy templates create a documented gap between what an organization says it does and what it does. That gap is the first thing an assessor finds, and the last thing anyone wants to explain after an incident.
The second failure is quieter. Policies exist, are technically accurate, and nobody outside the IT team has read them, so the behaviors they describe never actually change.
The service
What this engagement is
Who it is for
- Organizations whose policies were inherited, downloaded or written for a single audit.
- Companies where an assessment identified missing, unapproved or unenforced policies.
- Leadership teams that want a briefing built around governance decisions rather than a technical presentation.
- Organizations whose staff have no consistent guidance for handling sensitive data or suspected incidents.
Policy work that starts from current operating reality and closes the distance to the intended state deliberately, rather than declaring a target state and hoping practice catches up.
Alongside the documents, the governance that keeps them alive: who approves, how often they are reviewed, how an exception is requested and recorded, and who decides when a policy meets an operational reality nobody anticipated.
Awareness work is scoped by role. The judgment an executive needs about disclosure and escalation is not the judgment a billing clerk needs about handling a suspicious email.
Scope
What Heights does
-
A policy set scoped to your organization
A library sized to the organization and its obligations, rather than a generic enterprise set nobody will maintain.
-
Standards and procedures
The operational detail beneath each policy, so a requirement can be followed in practice and evidenced afterwards.
-
Review, approval and version control
Who approves, how often policies are reviewed, and how changes are tracked, the trail an assessor asks for.
-
Exception handling
A route for the cases a policy did not anticipate, so exceptions are recorded and time-bounded rather than becoming undocumented practice.
-
Executive and board briefings
Sessions built around the decisions leadership makes: oversight, funding, disclosure and escalation.
-
Workforce awareness programs
Role-relevant training covering the scenarios each group is most likely to encounter, with oversight of completion and follow-up.
Timing
When organizations engage this
- Policies exist but do not describe how the organization actually operates.
- An assessment or audit identified missing or unapproved policies.
- A customer contract or framework requires a documented, approved policy set.
- Staff have no consistent guidance for handling sensitive data or reporting a suspected incident.
- The executive team has asked for a briefing suited to the decisions they actually make.
What you receive
- Approved policy set with version control and a review schedule
- Supporting standards and procedures
- Policy exception process and exception register
- Executive briefing materials and a workforce training plan
- NIST CSF
- A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
- ISO 27001
- An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list.
- SOC 2
- An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
- HIPAA
- The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
The flagship
How this fits under vCISO leadership
A vCISO owns the policy lifecycle rather than just its creation: annual review, exception decisions, and the judgment calls that arise when a written rule meets an operational reality nobody anticipated.
Sectors
Where this comes up most
- Healthcare Statutory obligations for protected health information, clinical availability requirements that constrain how controls can be applied, and growing security scrutiny from payers and partners.
- Financial Services Several supervisory regimes at once, and several of them expecting a named individual to be accountable for the information security program.
- Government and Defense Contractors Contractual security requirements that determine eligibility to bid, and assessment regimes that verify them before an award rather than after an incident.
- Technology and SaaS Companies assessed by their own customers, where security maturity shows up in the sales cycle long before it shows up in an audit.
First steps
How an engagement begins
The same three steps whichever service you start with.
-
A confidential conversation
What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.
-
Scope agreed in writing
What Heights will do, what stays with you, the working rhythm, and how progress will be reported.
-
Work begins
Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.
FAQ
Questions we are asked about this
Broader questions about executive security leadership are answered on the vCISO page.
How many policies do we actually need?
Fewer than most template sets suggest. The right number is the smallest set that covers your obligations and that you will genuinely maintain, typically somewhere between eight and twenty documents for a mid-sized organization.
A library of sixty unmaintained policies is worse than a dozen accurate ones, because it creates documented commitments the organization is demonstrably not meeting.
Can you use policies we already have?
Usually, yes. Existing policies often need reworking rather than replacing, most commonly to reflect how the organization actually operates, to add the supporting standards that make them actionable, and to establish approval and review that has never been formalised.
How do we know whether awareness training is working?
Completion rates tell you very little on their own. More useful signals are whether staff report suspected incidents, whether reports arrive early enough to matter, and whether the same category of mistake keeps recurring.
We set out what will be measured before the program starts, so it is not judged retrospectively on whichever number looks best.
Insights
Related reading
-
Governance
What Security Documentation an Assessor Requests First and Why It Matters
Before a SOC 2, ISO 27001 or HITRUST assessment begins, an assessor requests specific documentation in a predictable sequence. Leadership must understand what gaps stop an assessment entirely, what can be addressed during fieldwork, and what delays certification. This article explains the documentation sequence, identifies who owns each category, and clarifies what adequate preparation looks like.
-
Compliance
What Sarbanes-Oxley IT General Controls Actually Require and How They Are Tested
Public company executives are accountable for IT general controls under Sarbanes-Oxley Section 404, yet many face audits without clarity on what is tested, what constitutes a deficiency, or who owns the outcome. This article explains what auditors examine, what delays sign-off, and how vCISO leadership provides the executive ownership needed to close this gap.
Portfolio
Related services
- Cyber Risk Management One register of the risks that could genuinely disrupt the business, rated consistently, owned by name, and reviewed on a schedule leadership can rely on.
- Vendor, MSP and Third-Party Oversight Clear accountability for the security work your providers perform: defined expectations, stated evidence requirements, and a review process that holds over the life of the contract.
- Security Program Assessment A documented picture of what your security program actually covers, measured against a recognized framework, with the gaps ranked by business consequence.