Single Policy or SOP
5 Days

One policy or SOP, up to six pages, mapped to a single framework. Two revision rounds.
One policy or SOP, up to six pages, mapped to a single framework. Two revision rounds.
I write security policies and standard operating procedures that hold up under audit. Twenty-one years running security programs, an accredited ISO/IEC 27001 Lead Auditor certification, and enterprise policy authored from inception for federal and critical-infrastructure clients.
Most policy documents fail for the same reason: they were downloaded, not written. An auditor spots a template in under a minute, and a policy nobody can follow does not survive contact with an incident. What you get here is a document written to your actual environment, your actual controls, and the framework you are actually being measured against.
What you receive:
One policy or SOP, authored to your scope and environment.
Mapped to the framework you name: ISO/IEC 27001:2022 Annex A, NIST CSF 2.0, NIST 800-53, SOC 2 Trust Services Criteria, or HIPAA.
Roles, responsibilities, and review cadence defined rather than left implicit.
Two revision rounds.
What I need from you: the framework you are working toward, your organization size and industry, any existing policy to be replaced, and whether an audit date is fixed.
How I work. I start from your environment rather than from a template. That means reading what you already have, understanding which controls actually operate and which are aspirational, and writing to the gap between them. A policy that describes a control you do not run is worse than no policy at all, because an auditor will test it and you will fail on your own document.
Who this is for. Organizations preparing for certification or a first audit, teams inheriting a policy set nobody wrote, and regulated businesses that need documentation an assessor will accept. I have written enterprise policy from inception for federal, healthcare, and critical-infrastructure clients, and I have sat on the other side of the table as the auditor testing it.
5 Days
7 Days
14 Days

21 years directing security programs across 14 countries, from a 238-site, 28-state US footprint to embedded country security roles with Ericsson and the Inter-American Development Bank. I work across the line most organizations draw between physical and cyber. Accredited ISO/IEC 27001 Lead Auditor, five OCEG credentials, and a Technical Committee seat on the Board of Executive Protection Professionals, which authored ANSI/BEP EPS 2026. Assessments, audits, policy, program design.
21 years directing security programs across 14 countries, from a 238-site, 28-state US footprint to embedded country security roles with Ericsson and the Inter-American Development Bank. I work across the line most organizations draw between physical and cyber. Accredited ISO/IEC 27001 Lead Auditor, five OCEG credentials, and a Technical Committee seat on the Board of Executive Protection Professionals, which authored ANSI/BEP EPS 2026. Assessments, audits, policy, program design.








Terms and conditions apply