Service
Virtual CISO
Security leadership without a full-time hire
Service
We help you write policies people follow, define controls that fit how you operate, and set up an evidence routine so proof is ready when a customer, auditor, or assessor asks for it.
What we deliver
Policy, control, and evidence design to help clients build repeatable security programs.
Every engagement begins with a written scope and proposal.
We review your current policies, controls, and evidence, and identify which frameworks and customer requirements apply.
We draft policies and controls with the people who'll own them, so they reflect how work actually gets done.
We map each control to your frameworks and define the evidence it should produce.
We set up the evidence calendar and repository and train control owners.
We run a practice evidence-collection cycle and close gaps before any real review.
Security frameworks often ask for overlapping safeguards in different words and structures. Recording each control once and mapping it to every framework you answer to avoids testing and documenting the same safeguard several times over. The structures differ, which is why the mapping takes care:
Sources: AICPA & CIMA: 2017 Trust Services Criteria (With Revised Points of Focus – 2022); ISO/IEC 27001:2022 (publisher-authorized preview); IAF MD 26: transition requirements for ISO/IEC 27001:2022; ISO/IEC 27002:2022 table of contents, as adopted by SIST (publisher-authorized preview); eCFR: 45 CFR Part 164, Subpart C (HIPAA Security Rule); NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0 (February 26, 2024)
Read the full guide: SOC 2 Trust Services Criteria explained, CC1 to CC9
There's no published starting price for this service. Pricing is set in your proposal after scoping.
Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.
When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.
Security Inspect is not a law firm, a CPA firm, or an ISO/IEC 27001 certification body. We don't give legal opinions, issue SOC 2 reports or ISO/IEC 27001 certificates, or guarantee that a client will pass an assessment.
Templates are a reasonable starting point, but the value is in tailoring. A policy that says you review access quarterly, when you actually do it once a year, creates a finding. We write policies around what you do today and what you can realistically sustain.
Readiness work shows where you stand against a specific framework. This service builds the policies, controls, and evidence routine that close those gaps and keep them closed. Many clients need both, and we scope them together so nothing is done twice.
We design evidence around what each framework asks for and run a practice collection cycle before any formal review. The assessor decides what they accept, so we recommend confirming their evidence expectations early.
Not necessarily. Some organizations benefit from a platform; others do well with a shared drive and a calendar. We'll recommend what fits your size and frameworks, and design the evidence plan so it works either way.
Share what’s prompting the work and what you need to decide, and we’ll help you judge whether this service is the right fit.