Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Service

Security policies, controls, and evidence your team can maintain

We help you write policies people follow, define controls that fit how you operate, and set up an evidence routine so proof is ready when a customer, auditor, or assessor asks for it.

What we deliver

Policy, control, and evidence design to help clients build repeatable security programs.

References
NIST CSF 2.0CIS Controls v8.1

Who it's for

A good fit for

  • Organizations whose policies came from templates and don't match how they work
  • Teams preparing for a SOC 2 examination, an ISO/IEC 27001 certification audit, or another formal assessment that need controls and evidence in order first
  • Companies that scramble for screenshots and records every time a customer or auditor asks
  • Organizations meeting several frameworks at once that want one set of controls instead of several

Not the right fit for

  • Organizations that want an untailored policy template pack
  • Teams looking for the formal audit itself rather than preparation for it
  • Organizations looking for legal drafting of contracts, privacy notices, or regulatory filings

Problems it addresses

  • Policies say one thing and teams do another, which turns into a finding in every review.
  • Evidence is gathered in a rush before each audit and lives in personal folders.
  • Each framework has its own spreadsheet, so the same control is tested and documented several times.
  • No one is sure who owns each control or how often it should run.

Scope

Included

  • A policy set tailored to your organization, covering areas such as access control, change management, incident response, vendor management, and acceptable use
  • A control library that records each control's owner, frequency, and how it operates
  • Mapping of each control to the frameworks you're working toward
  • An evidence plan listing the proof each control produces, where it's stored, and who collects it
  • A recurring evidence calendar and collection routine your team can run without us
  • Training for control owners on what to do and what to keep

Not included

  • Operating controls for you, such as running access reviews or approving changes
  • Administering compliance automation software on your behalf
  • Legal review of policies or contracts

Deliverables

  • Approved policy set in editable formats, with version history and review dates
  • Control library with owners, frequencies, and framework mappings
  • Evidence plan and recurring collection calendar
  • Evidence repository structure with naming conventions
  • Control-owner training materials

How the engagement runs

Every engagement begins with a written scope and proposal.

  1. Baseline

    We review your current policies, controls, and evidence, and identify which frameworks and customer requirements apply.

  2. Design

    We draft policies and controls with the people who'll own them, so they reflect how work actually gets done.

  3. Map

    We map each control to your frameworks and define the evidence it should produce.

  4. Put it into practice

    We set up the evidence calendar and repository and train control owners.

  5. Test the routine

    We run a practice evidence-collection cycle and close gaps before any real review.

Standards and methods

  • NIST CSF 2.0 and the CIS Critical Security Controls v8.1 as a baseline control set
  • AICPA Trust Services Criteria, for organizations preparing for SOC 2
  • ISO/IEC 27001 requirements and Annex A controls, for organizations pursuing certification
  • HIPAA Security Rule safeguards, PCI DSS requirements, and CMMC requirements where they apply

One control set, many frameworks

Security frameworks often ask for overlapping safeguards in different words and structures. Recording each control once and mapping it to every framework you answer to avoids testing and documenting the same safeguard several times over. The structures differ, which is why the mapping takes care:

  • SOC 2 uses the AICPA Trust Services Criteria: the common criteria CC1 through CC9, plus additional criteria for availability, processing integrity, confidentiality, or privacy when those categories are in scope, with points of focus as guidance.
  • ISO/IEC 27001:2022 sets management system requirements in clauses 4 to 10, and its Annex A lists 93 reference controls in four themes: organizational, people, physical, and technological.
  • The HIPAA Security Rule sets administrative, physical, and technical safeguard standards, with implementation specifications marked required or addressable.
  • NIST CSF 2.0 describes outcomes, organized into six Functions and then into Categories and Subcategories.

Sources: AICPA & CIMA: 2017 Trust Services Criteria (With Revised Points of Focus – 2022); ISO/IEC 27001:2022 (publisher-authorized preview); IAF MD 26: transition requirements for ISO/IEC 27001:2022; ISO/IEC 27002:2022 table of contents, as adopted by SIST (publisher-authorized preview); eCFR: 45 CFR Part 164, Subpart C (HIPAA Security Rule); NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0 (February 26, 2024)

Prerequisites and your responsibilities

  • A sponsor who can approve policies and assign control owners
  • Named control owners with time to review drafts and attend training
  • Access to existing policies, procedures, and any prior audit or customer-review findings
  • A decision on where evidence will be stored

Pricing

There's no published starting price for this service. Pricing is set in your proposal after scoping.

What affects the final price

Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.

Compare published prices for every service

Preparation, not the audit itself

When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.

Security Inspect is not a law firm, a CPA firm, or an ISO/IEC 27001 certification body. We don't give legal opinions, issue SOC 2 reports or ISO/IEC 27001 certificates, or guarantee that a client will pass an assessment.

Guides

Frequently asked questions

Can you just give us policy templates?

Templates are a reasonable starting point, but the value is in tailoring. A policy that says you review access quarterly, when you actually do it once a year, creates a finding. We write policies around what you do today and what you can realistically sustain.

How does this relate to compliance readiness?

Readiness work shows where you stand against a specific framework. This service builds the policies, controls, and evidence routine that close those gaps and keep them closed. Many clients need both, and we scope them together so nothing is done twice.

Will an auditor accept our evidence?

We design evidence around what each framework asks for and run a practice collection cycle before any formal review. The assessor decides what they accept, so we recommend confirming their evidence expectations early.

Do we need compliance automation software?

Not necessarily. Some organizations benefit from a platform; others do well with a shared drive and a calendar. We'll recommend what fits your size and frameworks, and design the evidence plan so it works either way.

Primary sources

Talk to a practitioner about policies, controls, and evidence

Share what’s prompting the work and what you need to decide, and we’ll help you judge whether this service is the right fit.

What happens next

  1. Tell us about your environment and what's driving the request.
  2. Talk through goals, constraints, and options with a practitioner.
  3. Review the proposal and decide whether to go ahead.