Enterprise AI, cybersecurity, cloud and software for organizations worldwide.
Cybersecurity

Governance and policies a board can actually use.

F Creative Studio 360 sets who decides on cyber risk, and writes the policies organisations in any country can enforce.

A policy no one can follow is not governance.

The frame is chosen for the organisation in front of you. That may be COBIT from ISACA, ISO/IEC 27001 with the control guidance in ISO/IEC 27002, or the NIST Cybersecurity Framework. Alignment with a framework is not a certification.

F Creative Studio 360 does not change systems during this work, and does not replace your counsel.

Governance is who decides
A control only works if someone owns it. The work sets who approves a risk, who writes the rule, and who is told when it is broken.
A policy has to be usable
A document nobody can follow is not a control. Policies are written for the way the organisation already works, in language staff can apply.
The framework follows the organisation
COBIT, ISO/IEC 27001 and the NIST Cybersecurity Framework are options. F Creative Studio 360 uses the one that fits where you operate. Choosing a framework is not a certification.
This is not a legal opinion
The advisory names the obligations that apply and turns them into policies and roles. Your counsel interprets the statute. F Creative Studio 360 does not file reports for you.

What the advisory covers

The scope is the entities and the decisions in front of you. The same method works in any country. The rules inside it change with where you are governed.

How security is governed
The committee, the charter, and the line from the board to the people who run the systems. A steering group is set up only when the organisation wants one.
Roles and accountability
Who accepts a risk, who approves an exception, and who is accountable when a supplier or a remote worker is involved.
The policy set
Acceptable use, access control, data security, remote work, incident response, third parties, personal devices, and backup and recovery, where each one is in scope.
Procedures people can follow
The steps behind a policy: who does what, with which record, and when it is reviewed.
A roadmap the business can fund
What to write or change first, tied to the risk the organisation has already accepted. It is a plan, not a claim that the risk is gone.
A record of the decision
The charter, the policies, and who approved them. F Creative Studio 360 does not certify the programme.

How an advisory runs

The same shape works in any country. It can be done on site or remotely, including when directors and operators are in more than one place.

  1. 1

    Confirm who decides

    Which entities, which countries, and which rules those entities are actually subject to.

  2. 2

    Read what exists

    The current policies, committees and roles. Gaps are noted against the framework in scope. Systems are not attacked.

  3. 3

    Choose the frame

    COBIT, ISO/IEC 27001, ISO/IEC 27002 or the NIST Cybersecurity Framework, matched to how the organisation already works.

  4. 4

    Draft what people will use

    Policies and the procedures that sit under them. Your team owns the documents after the engagement.

  5. 5

    Hand back the structure

    Roles, a charter when one was in scope, and a roadmap. Counsel owns any reading of the law.

What you receive

  • A view of how security decisions are made today.
  • A recommended framework, without a claim that you are certified to it.
  • Roles from the board to the operational teams.
  • Policies and procedures for the topics in scope.
  • A charter for a security committee, when one was in scope.
  • A roadmap of what to write or change next.

Rules the advisory can use

F Creative Studio 360 uses the references that apply where you are governed. Control language can follow NIST SP 800-53 when that is the catalogue management already uses. Examples of obligations include GDPR, the HIPAA Security Rule and NIS2.

For an organisation that is actually subject to them, the policies can use CPS 234 and the Essential Eight. Naming a rule is not a statement that you comply with it.

Common questions

What is included in governance and policy advisory?+

A view of how security is governed today, a recommended framework, defined roles, and the policies and procedures in scope. F Creative Studio 360 does not certify the programme, and does not replace your counsel.

How is this different from compliance consulting?+

Compliance consulting prepares a programme so an external auditor can assess a named standard. This advisory sets who decides, and writes the policies the organisation will live with. They can be scoped together, and they are not the same engagement.

Where do you deliver this?+

For organisations in any country, on site or online. The policies follow the rules that apply where you are governed. A local rule, such as CPS 234 or the Essential Eight, is used only when that organisation is actually subject to it.

Will you write our legal obligations for us?+

The work names the obligations that apply and turns them into policies a board and a team can use. Interpretation of the statute, and any filing, stays with your counsel. F Creative Studio 360 does not file reports for you.

Is this a penetration test?+

No. The engagement reads policies, roles and the framework in scope. F Creative Studio 360 does not attack systems, send phishing mail, or change the environment as part of this work.

How much does it cost, and how long does it take?+

It depends on how many entities are in scope and how many policies need to be written. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.

Start with who is allowed to decide.

F Creative Studio 360 will look at the entities, the current policies and the rules that apply, then say what a sensible advisory includes.