Document your security program
Use this service when your organization needs a written program for customer requirements, insurance requests, or an applicable regulatory obligation.
A Written Information Security Program (WISP) and supporting policies tailored to your data, systems, and responsibilities. We draft the documents, review them with leadership and IT, and define how they will be adopted and maintained.
Use this service when your organization needs a written program for customer requirements, insurance requests, or an applicable regulatory obligation.
Policies should describe approved responsibilities and safeguards. We identify where existing documents do not match your operations and separate current practices from planned improvements.
A policy set needs approval, responsible owners, staff communication, and review dates. These are addressed during the drafting and adoption process.
Best fit: Organizations needing a new WISP, an update to outdated policies, or documentation for a customer, insurer, or applicable regulatory requirement.
Outside this service: A request for legal advice, certification, or implementation of every technical safeguard. A broader ISMS or implementation project requires a separate scope.
The WISP defines the information covered, program responsibilities, risk-management approach, and administrative, technical, and physical safeguards.
The agreed policy set covers topics such as access control, MFA, acceptable use, data handling, vendor oversight, and incident response.
Covered financial institutions under FTC jurisdiction must maintain a written information security program. Applicability depends on activities and jurisdiction, not simply a company's industry label.
The engagement covers drafting, stakeholder review, approval support, and document maintenance responsibilities.
Step 01
Review your current documents, data, operations, and requested requirements. Agree the policy list, review rounds, responsibilities, and fee in writing.
Step 02
Interview system and business owners, then prepare the WISP and agreed policies. Initial drafting typically takes one to two weeks, depending on scope and available information.
Step 03
Check responsibilities, control descriptions, and implementation needs. Planned safeguards are identified as actions rather than described as already operating.
Step 04
Deliver the final versions, document owners, approval record, and review schedule. Your organization approves the policies and implements the required safeguards.
A named, CISSP-certified advisor leads your engagement, with specialist support where needed. Responsibilities and the agreed deliverables are documented before work begins.
We do not receive referral commissions from auditors, testing firms, brokers, or software vendors. External services are identified separately so you can review their scope and fees.
You receive the agreed WISP, policy set, approval responsibilities, and review schedule. Technical implementation is distinguished from policy drafting.
MB2 Dental
The biggest win was getting a clearer standard, a practical first set of fixes, and a way for our IT team to move without waiting on endless internal debate.
PDS Health / Pacific Dental Services
We were not looking for a cookie-cutter security review. The consulting team at Hardenwell took time to understand how our technology environment supports the business, then gave us recommendations that were practical, sequenced, and specific enough to act on.
Grassi
The technical findings mattered, but the bigger value was how the Hardenwell advisor explained them. They translated security risk into business risk for our partners, then worked with IT on the details. Decisions moved faster because both sides understood the same issue.
Yes. A template can be a starting point, but it must be checked against your operations, applicable requirements, and responsibilities. We can review existing drafts instead of rewriting suitable material.
The Rule covers certain financial institutions under FTC jurisdiction, including tax preparation firms and mortgage brokers. Your activities and jurisdiction determine applicability. We identify questions for confirmation with qualified legal counsel; policy drafting is not a legal opinion.
The written scope lists the WISP and supporting policies. The usual topics are access control, passwords and MFA, acceptable use, data handling, vendor oversight, and incident response. Extra policies or technical implementation are agreed separately.
Your organization owns and approves the documents. We assign review responsibilities and dates during handover. Further updates can be separately scoped or included in an agreed advisory retainer.
We cover your organization, your deadline, and who is asking for what. You leave knowing the likely scope, the timeline, and your next step, with the price fixed in writing before any work starts.
Prefer phone or email?
(754) 216-9664 [email protected]
Do not include PHI or sensitive records in booking notes. See our Privacy Policy.