Board-level frameworks for digital risks

How do you develop information security policy that helps you stay in control?

Kynexis Information Security helps you to develop or update information security policies from the context of your organisation. We will identify which processes, information and dependencies are important and which risks require a conscious choice. This gives the management a clear framework to steer and the organisation knows what agreements apply.

Do you recognize this?
  • Information security policy is missing or needs to be updated.
  • Critical business processes and digital dependencies are still not sufficiently visible.
  • Policy papers are distributed, overlap or have no clear owner.
  • IT or quality needs policies for an audit, certification or customer demand in the short term.

What are the risks? A general policy document may look complete, while important processes, dependencies and responsibilities remain unclear. The board then lacks a reliable basis to steer, employees lack practical arrangements and in an incident or audit it is difficult to explain how risks are controlled.

Our promise of service

Policy based on what your organisation really has to protect

The organisational context, critical business processes, dependencies and risks form the basis. From that insight we develop the policy pieces and practical arrangements that your organisation needs.

  • Management and IT involved from the start
  • Policy tailored to processes, risks and obligations
  • Practical arrangements which can be clearly expressed

information security policy

What is information security policy?

Information security policy is the board-level framework in which an organisation defines what it wants to protect, what principles apply, how responsibilities are divided and how it deals with digital risks. Underlying manuals, protocols and working instructions translate these agreements into daily work.

FOR WHOMFor the board and executive management
WHENFor board members who want security and direction
RESULTPolicies to further manage and organise governance

When does this service fit?

For board members who want security and direction

This service is in line with organisations that want to develop, update or better connect information security policies to their business operations. The board member is central, with IT, quality and other key players as key interlocutors. Do you need policies for ISO 27001, an audit, procurement or customer demand in the short term? Then we will agree a targeted assignment and you will receive honest advice on the steps that add value afterwards.

For the board and executive managementFor IT and quality managersFor SMEs and civil society organisations

Organisational policy

First understand, then capture

We decide together which documents are needed and how deep the organisation fits. The basis remains clear and is complemented when legislation, stakeholders, risks or business operations require it.

Context and obligations

We discuss the organisation, legislation, standards, contractual requirements and expectations of clients, industry organisations and other stakeholders.

Processes and dependencies

Critical business processes, information, systems, suppliers and interdependence are the starting point.

Risk analysis and choices

We identify relevant risks and discuss how the organisation wants to control, accept, avoid or transfer them.

Policy and practical documents

We will work out the agreed set, for example a basic information security policy, manual digitally secure working and necessary protocols or theme policy.

Approval and ownership

Management or management determines the policy. We record who owns, when assessment takes place and what information the board needs to send.

Introduction and safeguards

When you need it, I help with a workshop, internal communication, awareness, checks, quarterly reports and periodic advice.

Your result

Policies to further manage and organise governance

You will receive the documents we have agreed upon in advance, written for your organisation and ready for internal review and determination. You can then take care of the introduction yourself or involve Kynexis in communication, implementation and permanent assurance.

  • New or updated information security policy
  • Clear connection to processes, risks and liabilities
  • Clear roles, owner and approval route
  • Annual assessment and interim updating moments
  • Additional manuals and protocols according to the agreed scope
  • Optional advice and guidance on introduction and assurance
KYNEXISinformation security policy
1Board-level framework2Basic documents12Months review rhythm
FocusSending risks, responsibilities and implementationRisk-driven and enforceable

Floor and follow-up

This is how explanations, policies and control are linked

The knowledge article explains what information security policy means. On this page you can read how I develop policy for your organisation. Internal control is then about periodic monitoring and board-level reporting.

EXPLANATION

Knowledge Article

Read what information security policy is, what topics belong to it and what the construction looks like.

See this route →
MONITOR AND ADJUST

Internal control

Follow risks, controls, incidents, suppliers and improvement measures in a fixed cycle.

See this route →

How we work

This is how we arrive at defined policies.

  1. 01

    Getting to know and explore

    In a first brainstorm via Teams we discuss what is going on, what is missing and what you need.

  2. 02

    Understanding organisation

    I am talking to the management and the IT manager about context, processes, systems, suppliers and risks.

  3. 03

    Writing and discussing

    I will work out the agreed documents and check the contents with the responsible persons.

  4. 04

    Setting up and moving forward

    Management or management approves the policy. Afterwards, the organisation can choose whether to continue or support itself in the case of introduction and guarantee.

Policy cycle

The steps in an organisational approach

Each step builds on insight from the previous one. This allows the final agreements to be linked to the organisation and can be specifically promoted and kept up to date.

01 CONTEXT

Understanding organisation

Getting goals, commitments and stakeholders clear.

02 PROCESSES

Identifying interests

Identify critical processes and dependencies.

03 RISKS

Make choices

To assess risks and determine the desired manner of handling.

05 ASSURANCE

To be transmitted and updated

Following operation and assessing at least annually.

Make your next step concreteFirst, explore what your organisation needs?

In a first brainstorm via Teams we discuss what is going on, what is missing and what form of policy development fits in with it.

Plan a first brainstorm

Frequently Asked Questions

Practical answers on information security policy

Can Kynexis develop information security policy for us?

Yes. Kynexis can develop new information security policies, update existing policies or develop an agreed set of policy documents and protocols. The content is tailored to the organisational context, business processes, dependencies, risks and obligations.

How does a policy assignment begin?

We start with a first brainstorm via Teams about what's going on, what's missing and what you need. For the substantive impact I speak to the management or director and the IT-responsible. Where relevant, we also involve quality, privacy and other key people.

What documents does an organisation need at least?

The basis is usually an organisationally oriented information security policy and a manual for employees to work securely digitally. Supplements follow from legislation, standards, risks and requirements of stakeholders. Think of a protocol notification requirement data leaks, a processing register and appropriate theme policy.

Can you develop information security policy for ISO 27001 or an audit?

Yes. When short term information security policy for ISO 27001 requires an audit, procurement or customer demand, we can agree on a targeted scope. You will be given a clear idea of what is feasible within this mission and what I would recommend to follow to further align the policy with the organisation.

Does Kynexis help with the introduction?

Yeah, if you need it. Possible follow-up steps are a workshop, communication to employees, awareness, practical checks and periodic advice. You can also take care of the introduction within your own organisation.

How often do you assess information security policy?

Review the policy at least annually. An incident, security audit or significant change in processes, systems, suppliers, legislation or organisational structure may give rise to an earlier update.

Does Kynexis use templates or AI when writing?

Standards, templates and AI can support structure, completeness and consistency. The content is derived from conversations with people, knowledge of the organisation and professional assessment of processes, dependencies and risks. Management and responsible personnel shall check the documents before they are adopted.

What's the difference with internal control information security?

Policy development focuses on the creation, updating and establishment of frameworks and agreements. Internal control then organises the periodic checks, incident information, supplier follow-up, improvement measures and reporting that allow the board and management to adjust.

Wouter Parent

I get the most satisfaction when policies are actually applied within an organisation. Then I see that agreements become clearer, people act more consciously and the organisation becomes more visibly less vulnerable.

Current
WebinarFree webinars on NIS2, cyber risk management and oversight

Choose a live session for the board, executive team, supervisory board or board of trustees and register directly.

View webinars and dates