Independent security assurance and editable documentation to keep organizations secure, compliant and resilient Questions? contact@rootguardsecurity.com

Pack add-on · Priced on the pack

Documents that name your organization, not a placeholder

Pick a pack and we rewrite every document in it to reference your industry, your obligations and your systems. One intake form. You own the files either way, and there is no assessment: that is a separate engagement and we say so on the documents.

Basis
Added to a pack
Intake
One form, 30 to 45 minutes
Turnaround
7 to 10 business days
Revisions
One round

What changes

Seven things we do to every document

This is the difference between a customized document and a template with your name dropped into it. Which of the seven apply depends on the tier.

Industry context

Generic clauses rewritten to name your sector, its terminology and the way you actually operate. A policy that could describe any organization describes none.

Regulatory mapping

Which obligations apply, decided from your industry, geography, data types and customer base. Controls that do not apply are marked so, with the reason recorded rather than left blank.

Control applicability

Each control marked in scope or out, with the justification written down. An assessor asks for this before anything else.

Risk pre-population

The register arrives with risks already entered for your industry and environment, each with a rated likelihood and impact, rather than as an empty grid.

Parameter calibration

Every interval, threshold and retention period set to a number appropriate to your size, in place of the bracketed field you would otherwise have to guess at.

Technology references

Your systems named in the documents that govern them, so a reader can tell the policy was written for your estate.

Framework cross-referencing

Each requirement mapped to the framework a customer or an auditor is asking about, so one document answers more than one question.

How it works

One form, then five steps

Step 01

Purchase

Choose a pack and a customization tier. Either can be bought on its own.

Step 02

Intake

One online form: company details, named owners, industry, technology, obligations, team size, approval chains, target framework. Thirty to forty-five minutes, once.

Step 03

Customize

Every action in your tier applied to every document in the pack.

Step 04

Review

You receive editable files and read them at your pace. Revision notes back within ten business days.

Step 05

Delivery

The final revision within five business days of your notes. The files are yours.

Tiers

Two tiers, both priced on the pack

 FoundationCompliance
ScopeOne packOne pack, aligned to a target framework
Industry contextIncludedIncluded
Regulatory mappingIncludedIncluded
Control applicabilityIncludedIncluded
Risk pre-population15 risks20 risks
Parameter calibrationIncludedIncluded
Technology referencesNot includedIncluded
Framework cross-referencingNot includedIncluded
Intake30-minute form45-minute form and a technology questionnaire
Turnaround7 business days10 business days
RevisionsOne roundOne round
FeeQuoted on the pack you chooseQuoted on the pack you choose

Boundaries

What this does not include

Stated plainly so you can decide quickly rather than discovering it after the intake form.

Outside every tier

  • We do not assess your controls. This work makes the documents describe your organization. Establishing whether the controls they describe are actually operating is a separate engagement, and no customized document claims otherwise.
  • We do not run a gap analysis. We do not compare your current posture against your target framework. That is assessment work.
  • We do not conduct a risk assessment. Risks are pre-populated from your industry and environment. A formal assessment of your organization is not included.
  • We do not advise on strategy. We write what you tell us your environment is. What your security strategy ought to be is not our call here.
  • We do not select or configure tools. We name the tools you tell us you use. We do not recommend them or set them up.
  • We do not prepare you for audit. We customize documents for your target framework. We do not rehearse you, attend, or represent you.
  • We do not implement or maintain. No deployment, no training, no ongoing upkeep. Those are the deployment and support engagements.

What you end up with

  • Every document in the pack rewritten to reference your organization.
  • Editable files, yours to keep, with updates included.
  • A register that arrives populated rather than empty.
  • Bracketed fields resolved to numbers appropriate to your size.
  • One round of revisions after you have read them.

Before you add this

If you need to prove the controls work, buy the assessment instead

Customized documents state what your organization intends to do, correctly and in your own terms. They do not establish that it is happening. If a customer, an insurer or your board is asking for proof rather than policy, the engagement you want is Security Program Assessment, and we would rather tell you that now than after the intake form.