Heights Consulting Group

Security Policy, Standards and Awareness

Security policy work produces the written rules an organization is prepared to enforce, the standards that make those rules operable, and the training that makes them understood by the people expected to follow them.

What you receive

Part of
The decisions, records and oversight that turn security activity into something leadership can direct.
Engaged as
A defined piece of work, or as part of an ongoing vCISO engagement.
Sits under
Executive ownership of the cybersecurity program.

The problem

Why this comes up

Downloaded policy templates create a documented gap between what an organization says it does and what it does. That gap is the first thing an assessor finds, and the last thing anyone wants to explain after an incident.

The second failure is quieter. Policies exist, are technically accurate, and nobody outside the IT team has read them, so the behaviors they describe never actually change.

The service

What this engagement is

Who it is for

  • Organizations whose policies were inherited, downloaded or written for a single audit.
  • Companies where an assessment identified missing, unapproved or unenforced policies.
  • Leadership teams that want a briefing built around governance decisions rather than a technical presentation.
  • Organizations whose staff have no consistent guidance for handling sensitive data or suspected incidents.

Policy work that starts from current operating reality and closes the distance to the intended state deliberately, rather than declaring a target state and hoping practice catches up.

Alongside the documents, the governance that keeps them alive: who approves, how often they are reviewed, how an exception is requested and recorded, and who decides when a policy meets an operational reality nobody anticipated.

Awareness work is scoped by role. The judgment an executive needs about disclosure and escalation is not the judgment a billing clerk needs about handling a suspicious email.

Scope

What Heights does

  • A policy set scoped to your organization

    A library sized to the organization and its obligations, rather than a generic enterprise set nobody will maintain.

  • Standards and procedures

    The operational detail beneath each policy, so a requirement can be followed in practice and evidenced afterwards.

  • Review, approval and version control

    Who approves, how often policies are reviewed, and how changes are tracked, the trail an assessor asks for.

  • Exception handling

    A route for the cases a policy did not anticipate, so exceptions are recorded and time-bounded rather than becoming undocumented practice.

  • Executive and board briefings

    Sessions built around the decisions leadership makes: oversight, funding, disclosure and escalation.

  • Workforce awareness programs

    Role-relevant training covering the scenarios each group is most likely to encounter, with oversight of completion and follow-up.

Timing

When organizations engage this

  • Policies exist but do not describe how the organization actually operates.
  • An assessment or audit identified missing or unapproved policies.
  • A customer contract or framework requires a documented, approved policy set.
  • Staff have no consistent guidance for handling sensitive data or reporting a suspected incident.
  • The executive team has asked for a briefing suited to the decisions they actually make.

What you receive

  • Approved policy set with version control and a review schedule
  • Supporting standards and procedures
  • Policy exception process and exception register
  • Executive briefing materials and a workforce training plan

Alignment

Frameworks this work touches

Establishing which of these apply to you

NIST CSF
A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
ISO 27001
An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list.
SOC 2
An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
HIPAA
The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.

The flagship

A vCISO owns the policy lifecycle rather than just its creation: annual review, exception decisions, and the judgment calls that arise when a written rule meets an operational reality nobody anticipated.

Read about vCISO leadership

First steps

How an engagement begins

The same three steps whichever service you start with.

  1. A confidential conversation

    What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.

  2. Scope agreed in writing

    What Heights will do, what stays with you, the working rhythm, and how progress will be reported.

  3. Work begins

    Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.

FAQ

Questions we are asked about this

Broader questions about executive security leadership are answered on the vCISO page.

How many policies do we actually need?

Fewer than most template sets suggest. The right number is the smallest set that covers your obligations and that you will genuinely maintain, typically somewhere between eight and twenty documents for a mid-sized organization.

A library of sixty unmaintained policies is worse than a dozen accurate ones, because it creates documented commitments the organization is demonstrably not meeting.

Can you use policies we already have?

Usually, yes. Existing policies often need reworking rather than replacing, most commonly to reflect how the organization actually operates, to add the supporting standards that make them actionable, and to establish approval and review that has never been formalised.

How do we know whether awareness training is working?

Completion rates tell you very little on their own. More useful signals are whether staff report suspected incidents, whether reports arrive early enough to matter, and whether the same category of mistake keeps recurring.

We set out what will be measured before the program starts, so it is not judged retrospectively on whichever number looks best.

Insights

  • Governance

    What Security Documentation an Assessor Requests First and Why It Matters

    Before a SOC 2, ISO 27001 or HITRUST assessment begins, an assessor requests specific documentation in a predictable sequence. Leadership must understand what gaps stop an assessment entirely, what can be addressed during fieldwork, and what delays certification. This article explains the documentation sequence, identifies who owns each category, and clarifies what adequate preparation looks like.

  • Compliance

    What Sarbanes-Oxley IT General Controls Actually Require and How They Are Tested

    Public company executives are accountable for IT general controls under Sarbanes-Oxley Section 404, yet many face audits without clarity on what is tested, what constitutes a deficiency, or who owns the outcome. This article explains what auditors examine, what delays sign-off, and how vCISO leadership provides the executive ownership needed to close this gap.

Schedule a Confidential Consultation

Four questions, answered by the person who would be at your table. If Heights is not the right fit for what you need, you will hear that in the first conversation.

In Central Florida? Make it coffee, breakfast, lunch or a drink at the end of the day. Dan buys. Say so in the message and name a part of town.

A short description is enough, what prompted you to get in touch, and what a useful outcome would look like.