IT Security Policy Generator
Generate Acceptable Use, Password & Authentication, Incident Response, Backup & Recovery and Remote Access policies from your answers.
How to use this tool
Choose a policy, fill in your company details and key parameters (password length, MFA scope, backup frequency, recovery objectives, incident contacts), and copy the generated Markdown text into your document system. Policies are built from templates in your browser. They are a starting point: adapt them to your environment, get management approval, publish them to staff and review them at least yearly.
Worked example
An Incident Response policy for "Acme Ltd" with a 24/7 contact and GDPR and NIS2 ticked includes the 72-hour authority notification and the 24-hour NIS2 early warning steps, plus roles and escalation.
Frequently asked questions
Are these policies legally sufficient?
No. They are practical templates. A policy only counts if it matches what you really do, is approved by management and is communicated to staff.
Which policies does NIS2 expect?
Article 21(2) requires, among others, policies on risk analysis and information system security, incident handling, business continuity and backup, access control, cryptography and authentication. These templates cover the common core.
What password rules do the templates use?
They favour length, a block-list of known-breached passwords and MFA over forced complexity and routine expiry, in line with NIST SP 800-63B guidance.
How often should policies be reviewed?
At least annually and after significant changes or incidents is common practice.