Policies, Standards & Procedures

A complete, approved document set — written to be used, not just filed.

We develop or update your cybersecurity policies, standards and procedures, mapped to the frameworks you must meet and written in Arabic and English.

Typical duration
6–12 weeks
Engagement
Fixed-scope project
Deliverables
5
Frameworks
3

Reviewers ask for the policy, then for the procedure that implements it, then for evidence that people follow it. We write all three layers so they connect, and so each document has a clear owner and review date.

Every document is mapped control by control to SAMA CSF, NCA ECC and the other frameworks that apply, so you can show coverage at a glance.

Why it matters

Policy hierarchy and document control
Framework-mapped policies
Technical standards and baselines
Operational procedures and forms
Bilingual drafting

How the engagement runs

  1. 1InventoryExisting documents, gaps and overlaps
  2. 2DraftPolicies, standards and procedures in both languages
  3. 3ValidateWorkshops with owners to make sure each document can be followed
  4. 4ApproveApproval support and document-control setup

What you receive

  1. Policy set (typically 15–25 policies)
  2. Standards and secure baselines
  3. Procedures with workflows
  4. Control mapping matrix
  5. Document control register

Questions

Can you update our existing documents instead of starting again?
Yes. We keep what works, close the gaps against the frameworks, and harmonize the style and structure.
Readiness self-check

How ready are you? Find out in two minutes

Answer a few questions for your framework. You get a score, your biggest gaps and — if you want it — a detailed assessment from our team.

Ready to talk about your compliance?

Tell us where you stand. We will show you the shortest path to what your regulator expects.

Regulatory updates in your inbox

SAMA, NCA and SDAIA changes and what they mean for your institution — once a month.

We confirm by e-mail; unsubscribe any time.

Schedule a Free Assessment