I will create iso 27001 security policies and risk assessment documents
Will create ISO 27001 security policies, risk assessments and GRC documentation
About this Gig
I help individuals, startups, and small businesses build clear, audit-ready security documentation without the cost of a full consulting firm.
As an Information Security professional working in a government security role, I have hands-on experience with ISO 27001-aligned policy development, Threat Risk Assessments (TRAs), Business Impact Analyses (BIAs), and vendor/third-party risk reviews. I bring that same rigor to every project I take on here.
What I can help with:
- ISO 27001-aligned security policies (Access Control, Incident Response, Data Classification, Acceptable Use, and more)
- Threat Risk Assessment (TRA) and Business Impact Analysis (BIA) templates
- Vendor and third-party security risk assessment frameworks
- Basic security documentation for startups getting audit-ready
Every deliverable is customized to your organization, not a generic template with your name pasted in. I'll ask a few quick questions upfront to make sure the documentation actually fits how your business operates.
Message me before ordering if you're not sure which package fits your needs, or if you have specific compliance requirements (SOC 2, PCI-DSS, etc.) I should know about.

