20 editable cybersecurity and privacy policies, each mapped to the specific gaps found in your PostureCheck report. Ready to customise, sign and file — no policy writing required.
Answer 33 guided questions about your current controls. Takes 12 minutes. No IT team needed.
Your AUD 149 executive report identifies gaps by severity and maps them to Essential Eight controls and Privacy Act obligations.
Add the pack after your report. Each policy arrives pre-mapped to your gaps — customise names, dates and ownership fields, then file.
Governs who can access what systems, under what conditions, and how access is reviewed and revoked.
Defines MFA requirements across remote access, email, cloud services and privileged accounts.
Specifies which applications may execute on workstations and servers, and the process for approvals.
Sets timelines for patching critical, high and medium vulnerabilities across operating systems and applications.
Defines permitted use of company devices, networks and data including personal use, social media and removable media.
Covers conditions under which personal devices may access company systems, and the security controls required.
Defines backup frequency, retention, storage requirements, restoration testing and RTO/RPO targets.
Documents roles, communication protocols and recovery steps for system outages, ransomware and data loss events.
Establishes roles, escalation paths and response steps for security incidents from detection through to post-incident review.
Covers NDB Scheme notification obligations, OAIC reporting timelines and affected-individual communication requirements.
Internal governance document covering data collection, use, disclosure, retention and destruction aligned to the APPs.
Sets retention schedules by data type and governs secure destruction of physical and digital records.
Governs how vendors may access, process or store company data, including overseas disclosure controls and DPA requirements.
Defines the process for handling access, correction and deletion requests from individuals within the 30-day APP requirement.
Defines minimum training requirements, frequency and content for all staff including privileged users and contractors.
Sets minimum password requirements, credential rotation schedules, shared account controls and password manager usage.
Covers firewall requirements, network segmentation, remote access controls and wireless security standards.
Governs approved cloud services, shadow IT controls, data residency requirements and shared responsibility expectations.
Top-level governance document that establishes the security framework, ownership, scope and compliance obligations across all other policies.
Defines how risks are logged, rated, owned and accepted or escalated — with a template register pre-populated from your report findings.