AboutCareersApproachFAQContact Request an assessment
AREN

Services · 07

Security Policies & Procedures

تطوير السياسات والإجراءات والمعايير الأمنية

Written rules that people can actually follow. We draft the policy set your obligations require, in language your staff will read, and keep it short enough to stay current.

At a glance

  • Drafted for your organisation, not copied from a template
  • Written for staff, not only for auditors
  • Deliverable: an approved, versioned policy set

What this covers

Policies fail in two ways. They are copied from a template and describe an organisation that does not exist, or they are so long that nobody past the first page has read them. Either way the auditor is satisfied and the staff are not protected.

We write policies against how your organisation actually works, and we write the procedures that make each policy executable — who does what, in what order, with which system. The set stays deliberately small: every document we add is a document somebody has to maintain.

What you get

Information Security Policy

The top-level document your other policies hang from.

Access Control & Password Policy

Who gets access to what, how it is granted and how it is removed.

Incident Response Procedures

Step-by-step actions for the first hour of an incident.

Vulnerability Management Procedures

How findings are triaged, assigned and closed.

Data Classification Policy

Which data is sensitive and what handling each class requires.

Business Continuity Procedures

What happens when a critical system is unavailable.

How we run it

01

Determine obligations

What your regulator, your clients and your insurers actually require of you.

02

Draft against reality

Documents written around your real processes, reviewed with the people who must follow them.

03

Approve and publish

Version control, approval trail and a distribution your staff can find.

04

Review cycle

A scheduled review so the set does not quietly go out of date.

Common questions

Can't we just buy a policy template?

You can, and it will pass a superficial check. It will not survive a serious audit, and more importantly it will not tell your staff what to do, because it was not written about your organisation.

How many policies do we need?

Fewer than most vendors sell. We start from your actual obligations and add only what they require — an unmaintained policy is worse than none, because it documents a control you are not applying.

Related services

Contact

Not sure this is the right starting point?

Tell us what your setup looks like. We will say plainly whether this service fits — or point you to the one that does.

Write to us
Hours
Sunday — Thursday · 9:00 — 17:00
Services
All services