I will write iso 27001, nist csf, and pci dss policies and procedures
I Will be Your Senior Information Security GRC Consultant
About this Gig
Need ISO 27001:2022, NIST CSF 2.0, or PCI DSS v4.0.1 policies that will pass an external audit on the first attempt?
I am a VP of Information Security with 15+ years of regulator-facing GRC experience at a State Bank of Pakistan-regulated financial institution. I hold CISSP, CISM, and ISO 27001 Lead Auditor certifications, and I write the same policy artifacts I use day-to-day at a bank under continuous regulatory scrutiny.
What you get:
Audit ready policies mapped to exact control IDs (Annex A.5 to A.8, NIST CSF Functions and Subcategories, PCI DSS Requirements 1 to 12).
A control-mapping table you can hand directly to your external auditor or assessor.
Document version control and approval block.
Tailored to your industry, size, and risk profile.
Frameworks I cover:
ISO 27001:2022, ISO 27002:2022, NIST CSF 2.0, NIST SP 800-53 Rev. 5, PCI DSS v4.0.1, GDPR, HIPAA, SOC 2 Trust Services Criteria.
My process:
30-minute scoping call to understand your environment and target framework.
Draft delivered against the agreed scope and timeline.
Up to 3 revision cycles included on the Standard package.

