The policy starter set: short enough to be followed
Three policies — Acceptable Use, Access Control, Incident Response — each under two pages, written in language a non-technical employee can read in one sitting. These three cover what insurers, customer questionnaires, and baseline assessments most often ask for first.
Why it's built this way
- Length is where policies go to die. Nobody reads page seven of an acceptable use policy, and what nobody reads, nobody follows. Every statement in these policies survived a simple test: would a reasonable employee understand it, and could you actually enforce it?
- Never write a policy that documents fiction. The most dangerous policy is the one describing controls you don't run — it converts an honest gap into documented negligence. The template's instructions are blunt about this: if a statement doesn't match how you operate, change the statement or change the operation.
- Reporting is framed as praised, not punished. The acceptable use and incident response policies both make false alarms explicitly welcome. At a small organization, your detection speed is mostly the speed of someone willing to say "this looks weird" — a blame-free reporting culture is a security control, and it costs nothing.
- Each policy carries a version table with an executive approver. A policy without leadership's signature is IT's opinion. The version table doubles as audit evidence that annual review actually happens.
What's deliberately missing
No 40-page omnibus "Information Security Policy," no policies for situations you don't have. Add remote work, vendor management, or data retention policies when something specific demands them — a new regulation, a customer contract, an actual incident. Policies written speculatively age into fiction.
How to use it
Replace every bracket, get an executive to approve each policy by name and date, share them where people will actually see them, and set the annual review reminder now. The incident response policy needs one more thing: print the contact list and verify your cyber insurer's notification deadline — it's usually hours, and it's usually required to be the first call.
SMB Policy Starter Set
Word document · Acceptable Use, Access Control, and Incident Response policies with usage instructions
Download the setBackground reading: Start here for the controls these policies should describe, and the multiple hats problem for making the review cadence survivable.