Skip to product information
1 of 1

Apex Global Solutions AGS

Information Security Policy & ISMS Package

Information Security Policy & ISMS Package

Regular price $790.00 USD
Regular price Sale price $790.00 USD
Taxes included.
Secure checkout Visa Mastercard American Express Google Pay Apple Pay
View full details
About this toolkitAGS-01-031

The difference between a set of policies and a working ISMS is what the team does in the first hour of an incident.

Overview

Most security documentation stops at the statement of intent. This information security management system takes password management, access control, encryption and key management, backup, incident response, email security, mobile devices and clean desk practice down to the step a technician actually performs. It is aligned to ISO/IEC 27001 and informed by NIST SP 800-53 control families, with a master document index (AGS-ISMS-000) holding the numbering and the annual review cycle together.

The situations it covers are the ones that arrive without warning: the first hour after a suspected ransomware infection, a user-reported phishing email waiting to be triaged, a device reported lost or stolen, a monthly restore test that has to prove the backup is real. Each domain carries its own measures, so a control can be shown operating rather than declared.

What this system covers
  • Identity and access — password standards, granting and removing user access, and reviews of who still holds what
  • Cryptography and key management — encryption requirements, the key lifecycle, and issuing and installing a TLS certificate
  • Backup and recovery — what is backed up and protected, proven by a monthly restore test
  • Incident response — detection, triage and containment, with a defined first hour for suspected ransomware and a closing record
  • Email security — mail protection and acceptable use, and triage of a phishing message a user reports
  • Mobile and endpoint — device enrolment and configuration, and the response to a lost or stolen device
  • Physical and desk security — clean desk expectations and the after-hours sweep that verifies them
  • Measurement and risk — access reviews completed, restore tests passed and phishing reports handled, with risk scored the same way everywhere
Who it's for

Built for CISOs, IT managers and security or GRC leads in SMEs pursuing ISO/IEC 27001 certification, and for teams whose enterprise customers send vendor security questionnaires faster than documentation can be written. Once the domains are mapped to your own infrastructure and tooling, one set of documents serves the certification audit, the customer questionnaire and the engineer on call, with consistent numbering, an annual review point and evidence behind each control.

65 ready-to-use documents 65 Word · plus the AGS license

By document type

Policies 8
Procedures & SOPs 8
Forms & Records 16
Checklists & Audit Tools 8
Registers, Logs & Matrices 9
Guides & Work Instructions 8
Tools & Workbooks 8
Total 65

Key documents

AGS-ISP-01Password_PolicyWord
AGS-ISP-02Access_Control_PolicyWord
AGS-ISP-05Incident_Response_PolicyWord
AGS-ISP-03Encryption_PolicyWord
AGS-PRC-05Incident_Response_ProcedureWord
AGS-WI-05First-Hour_Response_to_a_Suspected_Ransomware_InfectionWord

Need the complete document list for this toolkit? Request it — sent the same day.

What's included

Everything you get

Every toolkit gives you a full set of working documents for your standard, ready to edit and use.

Editable Word and Excel

Native Microsoft files. Add your logo and adapt every document to how you work.

Instant download

Your full toolkit arrives as a ZIP the moment payment clears.

Unlimited users

One purchase covers everyone in your organisation. No per-seat fees.

Written by auditors

Built by people who run real audits, so the content matches what assessors check.

Yours to keep

Buy once and own it. No subscription and no renewals.

Refund guarantee

If the toolkit is not right for you, tell us within 14 days for a full refund.

Simple process

From purchase to audit-ready

1

Buy & download instantly

Pay securely by card. Your ZIP download link appears immediately on the confirmation page and in your email.

2

Edit & brand as your own

Open the native Word & Excel files, add your logo and details, and adapt everything to your organisation.

3

Implement & get audit-ready

Roll out the manuals, procedures, forms and checklists to build a working, certification-ready system.

Frequently asked questions

What exactly do I receive?

A downloadable ZIP containing the full set of ready-to-use documents for this toolkit — manuals, procedures, forms, records, checklists, guidance and training material, all in editable Word and Excel format. The exact document count is shown at the top of this page.

Are the documents really editable?

Yes. Every file is native Microsoft Word or Excel — no locked PDFs. Add your logo, change wording, and tailor the content to your organisation. The toolkit is yours to keep and reuse.

Does this certify my organisation?

No. These are documentation toolkits aligned to the relevant standard to help you prepare. Certification itself is issued by an accredited certification body after their audit. Our toolkits give you a strong, audit-ready starting point.

How is it delivered?

Instantly and digitally. There's no physical shipment — you download the files right after payment and receive a backup link by email.

Do I get updates?

Yes. If we revise this toolkit, you're entitled to the updated version at no extra cost — just contact us with your order details.

What is your refund policy?

Because these are digital products delivered instantly, all sales are final once downloaded. If you have any issue with your files, contact us and we'll make it right. See our Refund Policy for full details.

Cannot find your standard?

Tell us which scheme you work to. We will point you to the right toolkit.

Request a toolkit