Avalon
Policy and Documentation Development for IT Security
Pages
2
Time to read
2 mins
Publication
Language
English
Pages
2
Time to read
2 mins
Publication
Language
English
This document is a guide focused on the development of policies and documentation essential for IT and information security programs within organizations. It outlines the importance of clear, documented policies in meeting legal, regulatory, and standard compliance. The guide details how Avalon’s cybersecurity experts can assist in creating or maturing these policies, procedures, and audit evidence necessary for confirming that organizational controls are appropriately designed. It describes the process of updating policy documentation to adhere to industry best practices related to administrative, technical, and physical controls. The guide also lists various policy topics that can be addressed, such as acceptable use, access control, asset inventory, and incident response. Furthermore, it emphasizes the mapping of policies to common security frameworks like NIST and CIS Controls, ensuring a comprehensive approach to security documentation.