Information security policies and procedures, written for your company
Policies aren't a checklist. They're the rules that let your people know what they're allowed to do, what they're not allowed to do, and what to do when something goes wrong.

A company can have a firewall, backup, and antivirus and still lose data because someone gave out the password over the phone. Technology covers part of the risk; policies and procedures covers the rest: people, access, providers, incidents.
GreenSoft drafts sets of policies adapted to the size of the company: access control, passwords and authentication, equipment use, remote work, backup, incident management, supplier relations. We do not deliver generic templates, but documents that you can apply on Monday morning.
For NIS2 entities and for companies seeking ISO/IEC 27001 certification, the policy set is built directly on the requirements of the standard.
What does the service include?
- Analysis of current practices and applicable requirements
- Policy set: access, passwords, equipment, remote work, backup
- Incident response and continuity procedures
- Registers: assets, accesses, suppliers, incidents
- Presentation session for management and managers
Why GreenSoft
We apply these policies daily in our own organization, certified ISO/IEC 27001 and audited annually. We know what works in a 20-person company and what is unnecessary bureaucracy.
How the project is progressing
- Interview with management and identification of critical processes
- Writing policies and procedures in plain language
- Review with the company and adjust
- Approval, communication to employees and review schedule
For what types of goals
- Companies with 10-250 employees
- offices and clinics
- accounting and law firms
- public institutions
- NIS2 entities
- companies that want ISO 27001
Tell us what requirement is pushing you (NIS2, a client, an incident) and you will receive a proposal with a list of documents and an offer within 3-5 days.
Where we work
We cover the entire county of Constanta — the municipality of Constanta, Mamaia, Năvodari, Ovidiu, Agigea, Eforie, Techirghiol, Mangalia, Medgidia and Cernavodă — including the port perimeter, based on the license to work in the Port of Constanta. For larger works, we travel throughout Dobrogea.
Useful resources
Frequently asked questions
How many documents does "policies and procedures" mean?
For a small company, 6-8 policies and 3-4 procedures are enough. We prefer short, actionable documents over a manual that no one reads.
Do employees need to be trained?
Yes, otherwise the policy remains on paper. We offer staff training sessions, see the dedicated page.
Are the policies valid for ISO 27001?
They are written in the structure of the standard, so they can be used directly in the certification process. The actual certification is done by an accredited body.
How often are they reviewed?
Annually or at any major change: new system, new supplier, incident. We establish a review calendar and can maintain it under an IT services contract.
Shall we discuss your project?
Free initial technical consultation and quote within 3–5 business days.









































