// POLICY PACK · HANS STUDY · ONTARIO, CANADA

Policy pack

An insurer's questionnaire, a customer security review, or a contract clause has asked for policies that don't exist yet. If you need a CPCSC or CMMC Level 1 set and can fill in your own details, start with the free policy builder. The policy pack is for when you want them written for your shop.

Free builder or written for you

  • The policy builder, free. 13 policies assembled in your browser from reviewed clauses, for CPCSC Level 1, CMMC Level 1, or a general set for ISO 27001 buyers. You answer the questions and export Word, Markdown, or PDF. Nobody looks at your environment, so the policies are only as true as your answers.
  • The policy pack. I talk to the people who run your systems, write the policies against the network and tools you actually have, add the procedures behind each one, and map each policy to the requirements it answers and the evidence it produces. It covers what the builder doesn't: CPCSC Level 2, CMMC Level 2, ISO 27001, and whatever your insurer or customer has put in writing.

Plenty of shops start in the builder and bring that draft to a policy pack engagement. That's a good use of both.

What it covers

The policy set your trigger asks for: information security, acceptable use, access control, incident response, change management, data classification and handling, and backup and business continuity, plus the procedures that carry each one out. Written against your systems and practices, so the policy and the screenshot an assessor asks for say the same thing.

What you receive

  • The policy set and its procedures as editable documents in your own branding
  • A map from each policy to the requirements it answers and the evidence it produces
  • A review call to walk through what each policy commits the organization to
  • A revision after the first read-through, included

Questions

What's the difference between the policy pack and the free policy builder?

The policy builder is free and assembles 13 policies in your browser from reviewed clauses, so the policies are only as true as your answers. For the policy pack I talk to the people who run your systems and write the policies against the network and tools you actually have.

Which policies does the policy pack cover?

Information security, acceptable use, access control, incident response, change management, data classification and handling, and backup and business continuity, plus the procedures that carry each one out.

Does it cover CPCSC Level 2, CMMC Level 2, or ISO 27001?

Yes. The pack covers what the builder doesn't: CPCSC Level 2, CMMC Level 2, ISO 27001, and whatever your insurer or customer has put in writing.

Can I start in the builder and bring the draft to you?

Yes. Plenty of shops start in the builder and bring that draft to a policy pack engagement, which is a good use of both.

What do I receive?

The policy set and its procedures as editable documents in your own branding, a map from each policy to the requirements it answers and the evidence it produces, and a review call. A revision after the first read-through is included.

How is the policy pack priced?

Bring whatever questionnaire or clause triggered the request, and your builder draft if you have one. The scope is agreed on a call, and a written quote comes before any work starts.

Book a scoping call

Bring whatever questionnaire or clause triggered the request, and your builder draft if you have one. A short call confirms the scope.