Search alphaZ documents
Products meeting the search criteria
Some processing is risky enough that the UK GDPR expects you to assess it before you start - large-scale profiling, special-category data, new technology. This assessment works through the need for a ..
Article 30 of the UK GDPR expects most organisations to keep a record of what personal data they process and why. This form documents each processing activity, its lawful basis, any sharing or transfe..
When I audit data protection I work down the same list every time - is there a record of processing, are retention and deletion controlled, are the policies and privacy notices in place, is training d..
Blank Training Certificate for use when issuing certs to workers upon completion of training.Training listed on this certificate;The ISO StandardsIntegrated Management Systems – IMS1Risk Based Approac..
Blank Training Certificate for use when issuing certs to workers upon completion of training.Training listed on this certificate;The ISO StandardsIntegrated Management Systems – IMS1Preparing Audit Sc..
Relying on a cloud provider is fine until you need to leave one - or it leaves you. This planner rates the provider, maps the data and applications you depend on, and works through a migration and exi..
Blank Training Certificate for use when issuing certs to workers upon completion of training.Training listed on this certificate;The ISO 27001:2013 StandardIntegrated Management Systems – IMS1Protecti..
Blank Training Certificate for use when issuing certs to workers upon completion of training.Training listed on this certificate;The ISO 27001:2022 StandardIntegrated Management Systems – IMS1Protecti..
When a security incident hits - a malware infection, a lost device, an intrusion - the first record matters. This form captures the incident, what was contained and corrected, any personal data involv..
ISO 27001 Information Security Policy
Policy Template for ISO 27001 Requirements
This policy outlines the company’s commitment to maintain an
information security management system that ..
This policy communicates the company’s use of IT equipment
and covers staff use of company equipment, software management, physical security
of IT equipment and the disposal of IT equipment.
The ..
This policy covers employees’ use of company provided IT and
communications equipment. It emphasises the requirement to use these facilities
sensibly, professionally, lawfully and with respect for t..
This policy template outlines the need for employees to
maintain the security of physical and electronic documents. It emphasises the
importance of locking away paper documents when not in use and e..
This policy template communicates the company’s commitment to
information security and outlines the systems it has in place to control access
to controlled information and information security equip..
The Data Protection Policy states the company’s commitment to comply with Data Protection regulations including the General Data Protection Regulation (GDPR). It details the measures it has implemente..
This privacy policy template is a privacy notice that can be
used to provide an overview of how personal data is collected and managed.The policy includes: - The App..
The Password Policy details how
passwords must be managed to ensure that they are protected and secure. The
policy provides guidance on password management which includes: -· ..
The Teleworking Policy template states the requirement for employees working or accessing information remotely to adhere to all company policies, procedures and controls that have been set in place in..
This policy outlines the standards, procedures and restrictions in place that govern the use of mobile devices – either company supplied or personally owned – for work purposes or when connected to th..
The Cryptographic Policy outlines the company’s commitment to encrypt confidential data whenever it is transferred on portable media, transferred across networks, accessed remotely, or taken for use o..
The Information Protection Policy details the measures the company has in place to protect the confidentiality, integrity, and availability of its information assets.The policy also provides a general..
The Own Device Policy covers the use of handheld and mobile devices that are personally owned by workers while on company premises or working remotely.The Policy details rules that employees must foll..
The Internet and Email Policy covers the acceptable use of
the internet when using company provided or employee-owned equipment during the
working day. The policy also covers all email communication..
The Business Continuity Policy Statement outlines the arrangements the company has in place to maintain its operations in the even of unplanned incidents.The policy provides guidance on the continuity..
The Information Security Awareness Policy provides guidance to employees on good practice and company policy and procedures with regards to information security.The policy covers: - Information Securi..
The Software Installation Policy covers the control of software installations including the management of software licenses, updates and patches.The policy outlines the rules and authorities governing..
The Information Transfer Policy outlines the company's commitment to ensure the security and protection of information when it is transferred internally or externally. The policy outlines procedures a..