River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

Information Security Policy Set Template

Six documents and five sheets, including a register that traces every sentence in your policy set to the document actually requiring it.

Free download  ·  No account needed

Commitment Register, one row

One sentence, the document behind it, and what the record says

Quoted verbatim from the policy  ·  Traced before it is judged  ·  One verdict, never two

“Security event logs shall be reviewed daily by the security team.”
Logging and Monitoring Policy, clause 2.1

Requiring Source

None found. Not in the signed contracts, not in the insurance answers, not in the criteria in scope, not in statute.

Evidence System

Log platform search history. Named before anyone guesses, because the plausible source is usually the wrong one.

What the record shows Seventeen searches in twelve months. Every one of them after an alert had already fired.

Evidence load Daily means 365 dated artifacts a year that an assessor can sample from. This clause alone carries 365 of the set’s 1,317.

Verdict Remove. Keep as written, keep and fix the evidence, amend to actual practice, or remove. Nothing else, and provenance decides which.

Why it matters

Read as a control, alerting is what finds things and this is fine. Read as a policy sentence, it is 348 documented failures a year against a promise nobody asked the company to make.

What survives

Every sentence left in the set is one that a statute, a signed contract, an insurance answer or a criterion in scope actually requires. That is the only test for whether a policy sentence should exist.

A downloaded policy set is not a document. It is several hundred separate assertions about a company the template author never met, and every one of them is something an auditor, a customer or an insurer can hold you to. NIST says this plainly in its own control catalogue, where the discussion under AC-1 notes that simply restating controls does not constitute an organizational policy. Restating controls is exactly what a template pack does.

So the first pass here is arithmetic rather than editorial. Every modal sentence becomes a register row, quoted verbatim, and Calderhall's nineteen downloaded policies produced 437 of them against a room that had guessed somewhere between forty and eighty. Then each row is traced to the document that requires it: a statute, a clause in a signed customer contract, an answer given on the cyber insurance application, or a control in the framework actually being assessed. Two hundred and twelve had no such document.

Those 212 are not harmless. Forty-seven of them were already contradicted by the observable record, which makes them exceptions Calderhall wrote against itself. Ninety-day password rotation sat in the set while the identity provider had rotation switched off in 2024, following NIST's own advice that verifiers should not require memorized secrets to be changed arbitrarily. Deleting the sentence closed the finding. The SOC 2 narratives written afterwards had half as much to defend.

Four hundred and thirty-seven commitments, and the 212 nobody required

The register, the roll-up per policy, and the annual evidence load before and after tracing.

Commitment Register

Twelve of the 437 rows at Calderhall, a scheduling software company with thirty-four employees and no office.

Commitment as writtenRequiring sourceWhat the record showsVerdict
Visitors shall sign a visitor log held at reception.None foundNo office, the company is fully remoteRemove
Passwords shall be changed every 90 days.None foundRotation disabled in 2024 on NIST guidanceRemove
The Change Advisory Board shall meet weekly.None foundNo board exists, changes ship on mergeRemove
Encryption keys shall be rotated annually.None foundRotation not enabled on 3 of 5 keysRemove
Audit logs shall be retained for a minimum of 12 months.Criterion CC7.2Retention set to 30 days on the ingest tierFix evidence
All code changes shall be peer reviewed before merge.Criterion CC8.1Enforced on 6 of 8 repositoriesFix evidence
Vendor SOC 2 reports shall be reviewed annually.Criterion CC9.2Reports collected, no review recordedFix evidence
User access rights shall be reviewed at least quarterly.Northbank MSA sch. 3Two reviews completed in 2026Amend
Critical vulnerabilities shall be remediated within 7 days.Northbank MSA sch. 3Median 11 days, 4 of 19 inside 7Amend
A tabletop exercise shall be conducted twice per year.Peverell DPA annex 2One exercise in 18 monthsAmend
Infrastructure shall be scanned for vulnerabilities weekly.Criterion CC7.1Weekly, uninterrupted, 52 of 52Keep
Multi-factor authentication shall be enforced for remote access.Insurance Q8Enforced, no exclusionsKeep

The trace is disjoint. A commitment required by both a contract and a criterion counts once, against the contract, because that is the source with no negotiating room.

Policy Register

Nineteen policies, 437 commitments, four verdicts. Six rows of the roll-up plus the total.

PolicyCommitmentsKeepFix evidenceAmendRemoveTraced
Access Control38121031366%
Acceptable Use314322229%
Physical Security201211620%
Secure Development24871867%
Vulnerability Management20491670%
Change Management19831763%
All nineteen policies43796993021252%

Ninety-six of 437 were true, required and evidenced. That is 22% of the document Calderhall was about to hand an auditor. The 212 removals took 47 self-inflicted contradictions out with them.

Evidence Load

Sixty-three commitments carry a cadence word. Multiplied over a year, that is the population an assessor samples from.

CadenceInstances eachAs downloadedInstancesWith a sourceInstances
Daily365273000
Weekly526312152
Monthly1214168560
Quarterly42288936
Annually1191999
Total631,31724157

One thousand one hundred and sixty dated artifacts a year that no customer, criterion, insurer or statute had asked for. Two daily clauses carried 730 of the total between them, and neither had a source. This is the number that gets permission to delete text.

What is in the pack

01

Commitment Register

One row per testable sentence, quoted verbatim, carrying its requiring source, its evidence system, the observable record and one of four verdicts.

02

Policy Register

The roll-up per policy: commitments, the four verdict counts, the traced share, the owner, and the review dates that actually get met.

03

Evidence Load

Every cadence word multiplied out over a year, summed before and after tracing, so the cost of a word somebody skim-read is visible.

04

Exception Log

Time-boxed departures with a scope, a compensating control, an expiry date and an approver chosen by requiring source rather than by seniority.

05

Acknowledgment Tracker

Signatures against a version number, with refusals and absences kept apart because they are different findings needing different people.

06

How Commitments Are Counted

What counts as a commitment, the four columns behind each one, and why the four verdicts are the only permitted values.

07

The Policy Set by Domain

Nineteen domains, the shape every policy shares, and which ones attract unsourced text so heavily that they are worth writing last.

08

Amending a Commitment

Which end of a contradiction to move, how much room each requiring source leaves you, and the three phrases that only look like precision.

09

Exception Procedure

What an exception record carries, how approval routes by source, and why a standing exception is an amendment wearing a costume.

How it works

  1. 1

    Open it in River, or download it

    Edit with AI opens the pack as a private Space with the agent ready to run the extraction and the trace. Download hands you six Word documents and five CSV sheets, no account required.

  2. 2

    Send the paperwork, not just the policies

    The set you have in any state, plus the security schedules from executed customer contracts, the completed cyber insurance application, and the criteria you are in scope for. The last three are where sentences live or die.

  3. 3

    Get the count before the argument

    Every modal sentence becomes a register row with the policy, the clause number and the wording quoted. The total is normally several times what anybody in the room expected, and it reframes the whole conversation.

  4. 4

    Trace first, judge second

    Provenance is filled in before any verdict is assigned, so removals are derived rather than argued. Where the search finds nothing, the row reads none found and stays that way.

Frequently asked questions

Is this template free?

Yes, and the download needs no account, card or email. Edit with AI is the optional half and the one that does the work: it extracts every commitment from the set you already have, traces each one, and checks it against your systems. The rest of the template library works the same way.

What format are the downloaded files?

Six documents as .docx and five sheets as .csv, in one zip. Word, Pages, Google Docs, Excel, Numbers and Sheets open them with nothing to convert. The sheets arrive carrying the worked Calderhall example, so you can read a filled register before replacing it with your own.

We already downloaded a policy pack. Is this a replacement?

No, it is the pass you run over the one you have. The set you downloaded is the input. Nineteen policies at Calderhall carried 437 commitments and 212 of them had no requiring source, which is a finding you can only get by counting what you already own.

Why does deleting policy text make an audit go better?

Because every sentence is something fieldwork can test. Calderhall's 212 removals took 47 contradictions out with them, each of which would have become an exception in a report. Removing an unrequired sentence removes the exception at no cost to the actual control.

How is this different from a SOC 2 evidence pack?

Different question, one step earlier. The evidence pack asks whether the evidence a narrative names still exists. This asks whether the sentence should exist at all, and it runs on contracts and insurance answers rather than only on criteria.

What if we have no policies at all yet?

Then run it backwards, from the requiring sources. Read the signed contracts, the insurance application and the criteria in scope, and write one commitment per obligation. The result is shorter than any downloaded set and every line has a document behind it, which is the position NIST's framework describes.

Where do the specific controls behind the policies live?

In their own spaces, because a policy commits and a control operates. The access commitments are evidenced by the access review, the remediation deadlines by the vulnerability register, and the review clause by a supply chain review.

Count the commitments before somebody else does

Edit with AI