Independent security assurance and editable documentation to keep organizations secure, compliant and resilient Questions? contact@rootguardsecurity.com

Pack add-on · Priced on the pack

A policy suite written for the estate you actually run

Your policies, standards and procedures rewritten against the systems you run and the obligations you carry, with every interval, threshold and owner set to a real number and a real name. One intake form. You own the files, and there is no assessment: that is a separate engagement and we say so on the documents.

Basis
Added to a pack
Intake
One form, 30 to 45 minutes
Turnaround
7 to 10 business days
Revisions
One round

What changes

What we change in every document

This is the difference between a customized document and a template with your name dropped into it. Which of these apply depends on the tier.

Industry context

Generic clauses rewritten to name your sector, its terminology and the way you actually operate. A policy that could describe any organization describes none.

Regulatory mapping

Which obligations apply, decided from your industry, geography, data types and customer base. Controls that do not apply are marked so, with the reason recorded rather than left blank.

Control applicability

Each control marked in scope or out, with the justification written down. An assessor asks for this before anything else.

Risk pre-population

The register arrives with risks already entered for your industry and environment, each with a rated likelihood and impact, rather than as an empty grid.

Parameter calibration

Every interval, threshold and retention period set to a number appropriate to your size, in place of the bracketed field you would otherwise have to guess at.

Technology references

Your systems named in the documents that govern them, so a reader can tell the policy was written for your estate.

Framework cross-referencing

Each requirement mapped to the framework a customer or an auditor is asking about, so one document answers more than one question.

Ownership and hierarchy

Policy ownership mapped to your actual titles and reporting lines, including a fractional CISO or an MSP where that is who holds it, and the set arranged into your governance hierarchy so a policy, a standard and a procedure are not all called policy.

Threshold feasibility

Remediation windows, access review cadence and retention periods set to what your team can actually sustain. A fourteen-day critical patch window you will miss every month is worse than a thirty-day one you meet, because the first is a documented breach of your own policy.

Exceptions workflow

How an exception is logged, who accepts the risk and when it expires, calibrated before publication. Without it a policy set goes live already in breach of itself the first time somebody cannot meet a control.

Escalation grounding

Incident escalation paths, severities and notification lists carrying your legal counsel, your insurer's notification number, your retained responder and your executive tree, rather than bracketed placeholders nobody fills in.

How it works

One form, then five steps

Step 01

Purchase

Choose a pack and a customization tier. Either can be bought on its own.

Step 02

Intake

One online form: company details, named owners, industry, technology, obligations, team size, approval chains, target framework. Thirty to forty-five minutes, once.

Step 03

Customize

Every action in your tier applied to every document in the pack.

Step 04

Review

You receive editable files and read them at your pace. Revision notes back within ten business days.

Step 05

Delivery

The final revision within five business days of your notes. The files are yours.

Tiers

Two tiers, both priced on the pack

 FoundationCompliance
ScopeOne packOne pack, aligned to a target framework
Industry contextIncludedIncluded
Regulatory mappingIncludedIncluded
Control applicabilityIncludedIncluded
Risk pre-populationIncludedIncluded, broader coverage
Parameter calibrationIncludedIncluded
Technology referencesNot includedIncluded
Framework cross-referencingNot includedIncluded
Ownership and hierarchyTitles and reporting linesTitles, reporting lines and hierarchy
Threshold feasibilitySet to your sizeAgreed with your team in a review session
Exceptions workflowNot includedIncluded
Escalation groundingNot includedIncluded
Intake30-minute form45-minute form, a technology questionnaire and one review session
Turnaround7 business days10 business days
RevisionsOne roundOne round
FeeQuoted on the pack you chooseQuoted on the pack you choose

Boundaries

What this does not include

Stated plainly so you can decide quickly rather than discovering it after the intake form.

Outside every tier

  • We do not assess your controls. This work makes the documents describe your organization. Establishing whether the controls they describe are actually operating is a separate engagement, and no customized document claims otherwise. That is also why there is no third tier: a customization that validated controls against your live environment would be an assessment sold under another name, and you would be paying documentation rates for work that needs evidence.
  • We do not run a gap analysis. We do not compare your current posture against your target framework. That is assessment work.
  • We do not conduct a risk assessment. Risks are pre-populated from your industry and environment. A formal assessment of your organization is not included.
  • We do not advise on strategy. We write what you tell us your environment is. What your security strategy ought to be is not our call here.
  • We do not select or configure tools. We name the tools you tell us you use. We do not recommend them or set them up.
  • We do not prepare you for audit. We customize documents for your target framework. We do not rehearse you, attend, or represent you.
  • We do not implement or maintain. No deployment, no training, no ongoing upkeep. Those are the deployment and support engagements.

What you end up with

  • Every document in the pack rewritten to reference your organization.
  • Editable files, yours to keep, with updates included.
  • A register that arrives populated rather than empty.
  • Bracketed fields resolved to numbers appropriate to your size.
  • One round of revisions after you have read them.

Before you add this

If you need to prove the controls work, buy the assessment instead

Customized documents state what your organization intends to do, correctly and in your own terms. They do not establish that it is happening. If a customer, an insurer or your board is asking for proof rather than policy, the engagement you want is Cybersecurity Program Assessment, and we would rather tell you that now than after the intake form.