Skip to main content

Policy & Procedure Framework

cimply builds policy and procedure frameworks that hold up to audit and hold up in practice. The documents are short, current and used, not filed away to gather dust.

The Business Challenge

Most policy libraries were written once, by someone no longer here, for an audit that ended years ago.

Long, generic policies are the easiest thing to write and the hardest thing to operate against. cimply builds frameworks that work in the business as it is today.

What’s included

  • Framework design

    A policy hierarchy that fits the business, no longer than it needs to be, so nothing gets written that nobody reads.

  • Policy development

    Information security, acceptable use, access control and incident management policies, all in plain English.

  • Procedure documentation

    How the work actually gets done, captured at the level of detail the team needs to follow it.

  • Mapping to obligations

    Each policy mapped to the obligations it satisfies, including the Essential Eight, ISO 27001 and the Privacy Act.

  • Adoption and communication

    Briefings and short-form summaries so the framework is understood, not just published.

  • Attestation and acknowledgement

    Staff formally accept the policies that apply to them, with acceptance tracked and evidenced, not just assumed.

  • Review cadence and ownership

    Every document has an owner, a review cadence and an audit trail. Currency stops being a question.

  • Exception management

    A clean process for documented, time-limited exceptions, so reality and policy stay close.

  • Continuous improvement

    Policies evolve with the business and the threat landscape. The framework stays useful, not just compliant.

Why it matters

  • Acceptance is on the record. You can show exactly who accepted which policy and when, the question an auditor always asks.”
  • Policies are followable. Short, clear and tied to the way the business actually works. The team can read them and act on them.
  • Audits get faster. Mapping to obligations and clean evidence trails mean auditors find what they need quickly. The conversation moves on.
  • Ownership is clear. Every document has a named owner. Currency, accuracy and exceptions stop being everyone’s job and no one’s job.
  • Exceptions are visible. Documented, time-limited exceptions mean leadership sees where reality and policy differ, and chooses what to do about it.
  • The framework keeps up. Reviews are scheduled, changes are tracked, the framework reflects the business as it is now, not as it was three years ago.

Frequently asked questions

We’ve compiled the most important information to help you get the most out of your experience.

Can't find what you're looking for?

Contact us
  • Yes. Where existing documents are useful, they are kept and updated. Where they are not, replacement is recommended openly.

    Find out more

Talk to someone who already cares.

You won’t be triaged, ticketed, or handed off. When you contact cimply, you speak directly to someone who knows your environment and has the authority to act.

This is where it starts.

Start the conversation

Rated 4.9 out of 5 by Australian businesses who made the switch.

Managed ITExplore all Managed IT
Cyber SecurityExplore all Cyber Security
IndustriesExplore all Industries
Why cimplyHow are we different
AboutFind out more about cimply
Insights