GRC Advisory & Audit

Information Security Policies

Practical, right-sized information security policies developed by senior consultants and tailored to how your organisation actually works.

We hold the standards we help you meet.
Australian-owned &
operating since 2017.

Information security policies are the documented rules that define how your organisation manages security, including how staff use systems, how data is handled, how incidents are reported, and how third parties are managed. Done well, they formalise how the organisation actually works and give customers, auditors, and regulators something concrete to point to. Done badly, they sit unread in a shared drive.

Your policy set is developed by senior consultants who spend time understanding how you actually operate, so the policies reflect your organisation rather than a generic template. Policies are aligned with ISO 27001 where certification is a driver, and structured so they can be extended into a full Information Security Management System (ISMS) later if you go that way.

Where a policy set is what you need, this is what you get. Where something else would serve you better, we'll tell you so during scoping.

Why choose us for your policy development

Right-sized to your organisation

A 20-person SaaS company shouldn't get the same policy set as a 500-person regulated business. Your policies reflect your size, risk profile, and how your team actually works, so they're followed rather than filed.

Written to be read

Policies that people don't understand aren't followed. Yours are written in clear language, structured so relevant sections are easy to find, and pitched at the readers who need to act on them.

Aligned with ISO 27001, whether or not you certify

Your policy set is developed against ISO 27001, so it holds up as evidence for customer questionnaires, insurer requirements, and audit scrutiny, and provides a foundation for a full ISMS implementation later if you go that way.

Senior consultants who know when policies aren't the answer

Not every organisation searching for policies actually needs a standalone policy set. Where full ISO 27001 implementation, a broader assessment, or a different service would serve you better, we'll say so during scoping.

Senior consultants, based in Australia

Scoped and delivered by senior consultants based in Brisbane and surrounds, working with clients across Australia. On-shore data handling, local context, and clear accountability.

How your policy engagement runs

Discovery

You and your lead consultant work through your organisation, systems, existing practices, compliance drivers, and the specific gaps or requirements the policies need to address. Where you have existing policies, they're reviewed as a starting point rather than replaced by default.

Policy development

Your consultant develops a right-sized set of core information security policies covering acceptable use, access control, data handling, incident response, third-party management, and related areas, tailored to your context and aligned with ISO 27001. Policies are drafted in your template or ours, depending on what fits.

Review and refinement

The draft policies are reviewed with you, refined based on feedback, and finalised. Where policies touch specific teams (engineering, HR, operations), those teams have the chance to weigh in before the policies are locked.

Walkthrough and rollout support

Your consultant walks the relevant stakeholders through the finalised policies, answers questions, and supports rollout to the wider team. Where staff awareness training is helpful, it can be scoped as an add-on.

Most engagements run between two and six weeks, depending on the size of the policy set and your review cycle.

Frequently asked questions.

Straight answers to the questions we hear most. Can't find yours? We're happy to help.

Will these policies satisfy our customer or compliance requirement?

It depends on what your specific contractual or regulatory requirements are. Customer security questionnaires, contract clauses, APRA CPS 234, and DISP requirements commonly specify a management system rather than policies alone. If a stakeholder has asked for "security policies" without specifying, it's worth checking what they actually need before scoping the engagement.

Can we extend these into a full ISO 27001 implementation later?

Yes. Policies developed in this engagement are aligned with ISO 27001 and structured so they can carry into a full ISO 27001 implementation later. It doesn't constitute an ISMS on its own: an implementation includes risk assessment, Statement of Applicability, internal audit, management review, and other requirements the policy set doesn't deliver.

Can you work with our existing tools and templates?

Yes. Policies can be drafted in your existing template, in a template we provide, or into a platform like Vanta, Drata, or Notion where you're already using one.

Where is your team based?

Our consultants are based in Australia, including a core group of Brisbane penetration testers, with engagements delivered both nationally and internationally. Testing, reporting, and walkthroughs are handled by the same senior consultant from start to finish. You get clear accountability, on-shore data handling, and the local context that comes from working with Australian organisations every day.

Case Studies

Proof in practice.

A snapshot of how we've helped Australian organisations strengthen security, meet stakeholder expectations, and move forward with confidence.

Two Askable team members working at a screen in their Brisbane office
"There’s being secure, and there’s appearing to be secure, and Acumenis has really achieved both of those things for us."
scott-goleby
Scott Goleby
Co-founder and Director
Acumenis

Let's talk about where you are and where you need to be.

Whether you're preparing for certification, validating your controls, or building security foundations for growth, we'll help you get there with clarity and confidence.

Contact Form

Acumenis is committed to protecting and respecting your privacy, and we'll only use your contact information to provide services and information to you. For more details, please review our Privacy Policy.

Success
Thanks for getting in touch.
Your message has come through and one of our senior consultants will respond within one business day.
If it's urgent, you're welcome to call us on 1300 450 970.
Follow the team, join the conversation, and see what we’re working on across Australian cyber security.
Oops! Something went wrong while submitting the form.