Cybersecurity GRC Docs Revamp -- 2
Publicada el 2026-07-26
Descripción de la oferta
I need an experienced Cybersecurity Governance / GRC consultant to overhaul our entire documentation set so it truly mirrors the way we operate today. We run our program primarily on the SAMA Cybersecurity Framework (CSF) and must also respect the Saudi PDPL, yet I want every policy, standard, and procedure you touch to map cleanly to ISO/IEC 27001 and recognised industry best practice as well. Your first task will be to read through the existing material, speak with the relevant stakeholders if clarification is needed, and mark anything that is outdated, redundant, or simply no longer implemented. Once the gaps are clear, rewrite the texts: tighten language, unify structure, eliminate conflicts, and—because I selected “Yes” to including new controls—recommend and weave in additional safeguards that strengthen our posture even if they are not yet live in production. The final language must remain practical and proportionate to our environment; I do not want theoretical controls that no one can maintain. Deliverables expected from you: • A fully updated set of cybersecurity policies, standards, and procedures, professionally formatted and ready for board approval. • A review log or comment matrix that shows what you changed, what you removed, and why. • A concise recommendations document highlighting any new controls you propose, mapped to SAMA CSF, ISO/IEC 27001, PDPL and, where helpful, NIST CSF for future reference. I will consider the engagement complete once every control listed in the documents can be traced back to an actual practice in our environment (or is marked as a recommended future control), and the formatting across the full suite is consistent. If you have successfully led similar governance clean-ups and can start soon, let’s talk.
Skills
Fuente original: freelancer