01 / 12
Acceptable Use Policy
What employees may and may not do on company systems and networks. Foundational for cyber-insurance applications.
02 / 12
BYOD Policy
Rules for employee-owned devices accessing company data. Required if any staff use personal phones or laptops for work.
03 / 12
Remote Work Security Policy
Security expectations for employees working off-premises. Covers VPN, home networks, unsanctioned cloud storage, and physical screen exposure.
04 / 12
Password & MFA Policy
Account credential and authentication standards. Covers complexity, rotation, shared accounts, and multi-factor authentication requirements.
05 / 12
Data Retention & Destruction Policy
How long data lives, in what form, and how it is securely destroyed. Required for CCPA, HIPAA-adjacent, and most cyber-insurance questionnaires.
06 / 12
Vendor Risk Management Policy
Vetting and ongoing oversight of third-party software and service providers. Covers SaaS tools, payment processors, and IT contractors.
07 / 12
Incident Response Plan
What the organization does when something breaks or gets breached. Defines roles, escalation paths, and notification timelines.
08 / 12
Backup & Disaster Recovery Policy
Keeping the business running through data loss and system failure. Covers backup frequency, offsite storage, and recovery time objectives.
09 / 12
Mobile Device Management Policy
Governance of company-owned mobile devices — distinct from BYOD. Covers MDM enrollment, remote wipe, and acceptable use on company phones and tablets.
10 / 12
Email & Communication Security Policy
Phishing defense, approved channels by data type, and secure email handling. Covers wire-fraud awareness, encryption, and prohibited attachments.
11 / 12
Physical Security Policy
Office access control, visitor policy, clean-desk, and paper record handling. Covers key card management, after-hours access, and camera placement.
12 / 12
Onboarding & Offboarding Checklist
Provisioning and deprovisioning access, equipment, and acknowledgements. Prevents credential sprawl when employees join or leave.