Home / Governance / Governance Policy Suite
Policy Suite

The written program behind every control

A 20+ document information security governance suite, anchored to NIST CSF 2.0 and mapped to PCI DSS v4.0.1, HIPAA, and the NY SHIELD Act — written for your organization, adopted by your leadership, and maintained on a review cycle.

What's in the suite

Every document follows our controlled-document standard — versioned, owned, and dated — so an auditor sees a managed program, not a folder of downloads.

GovernanceInformation Security Policy, roles & responsibilities, policy management, risk management
PeopleAcceptable use, security awareness & training, onboarding/offboarding, remote work
AccessAccess control, password & authentication, privileged access
TechnologyEndpoint protection, patch & vulnerability management, network security, logging & monitoring, encryption
ResilienceBackup & recovery, incident response, disaster recovery / business continuity
Third partiesVendor management, data classification & handling, physical security

Not a template dump

Generic policy packs fail audits because they describe a company that isn't yours. We interview your team, match policies to your actual tools and practices, and flag the gaps between what the policy says and what happens — then help you close them.

NC-POL-GOV-001 Versioned Owner-assigned
Discuss the suite
Delivery

How the suite gets built

1. Discover

Interviews and technical review to learn how your business actually operates.

2. Draft

Policies written to your environment and mapped to your frameworks.

3. Adopt

Leadership review, revision, and formal adoption with training for staff.

4. Maintain

Annual review cycle, change management, and evidence collection.

Policies gathering dust — or no policies at all?

Either way, we've seen it, and either way it's fixable in a quarter.

Talk to Northern Computers