Governance

Procedures written for the person holding the laptop at 3am.

A policy says what the organisation intends. A procedure says what you do next, in order, with the switch in front of you. We write both, and we test the second one on the people who will use it. If practice and policy disagree, one of them is wrong, and we find out which.

Why it matters

A binder nobody reads, copied from a template that describes a different organisation, is the usual output and the usual waste. A procedure that cannot be followed at 3am on a service desk or a plant floor is the same waste in a different font.

The auditor's finding that hurts is the one where the policy says one thing and practice does another. We write the policy to the framework and the procedure to the site, and we check that they agree.

What it covers

The policy set
Security policies, standards, procedures and work instructions, with the difference between them kept clear. Access control and remote access, change and configuration management, patch and vulnerability management adapted for OT, removable media, supplier and vendor access, and acceptable use.
Procedures people actually use
Granting and revoking vendor and administrator access, joiner, mover and leaver account changes, a lost laptop or a phished account, and on a plant floor, taking a controller in and out of program mode and running a booked maintenance window.
Incident response
An incident response plan with a contact tree and playbooks, a tabletop exercise to test it, and the after-action notes that improve it. Written to NIST SP 800-61r3.
Awareness and competence
A programme that teaches your own people the procedures and records that they have understood them, so an attestation is evidence rather than a signature.

How it runs

  1. Choose the framework

    The one you report against: IEC 62443-2-1, NIST CSF 2.0, CIS Controls v8.1, ISO/IEC 27001:2022, or the Ontario framework for an LDC. We map to it, we do not sell a certificate in it.

  2. Write to the site

    Policies mapped to the framework with the mapping shown, and procedures written as steps a technician can follow with the equipment in front of them.

  3. Test the procedure

    We run the second thing, the procedure, on the people who will use it, in a tabletop or a walk-through, and fix the steps that do not survive contact.

  4. Set the review cycle

    A review calendar and document control, so the set stays true instead of ageing in a drawer. Policy you can prove is working.

A page of what you are handed

ARTA CYBER Representative deliverable — client and site redacted.

Procedure page — sample

Procedure AC-07 — Grant vendor remote access

Maps to: IEC 62443-2-1 (SP.05.02) · NIST CSF 2.0 PR.AA · CIS Controls v8.1 6.7. Review annually or on change of broker.

  1. Confirm a signed work order exists and names the vendor engineer. No name, no access.
  2. Open a time-boxed account on the brokered jump host, scoped to the target zone only. Default expiry: end of the booked window.
  3. Enable the conduit rule for the session (firewall object vendor-rdp-temporary). It is disabled by default; do not make it permanent.
  4. Notify the service owner, or the on-shift operator on a plant, that a vendor session is live and on which asset.
  5. Watch the session, or record it, per the work order.
  6. At the end of the window: disable the conduit rule, expire the account, and note the session in the site file.

If any step cannot be completed, stop and call the on-call security lead. Do not grant standing access as a workaround.

What you are left holding

  • Policy set mapped to the chosen framework, with the mapping table included.
  • Procedures written as steps a technician can follow.
  • Incident response plan with a contact tree and playbooks.
  • Tabletop exercise pack and after-action notes.
  • Review calendar.
  • Awareness and competence programme with assessment.

Worked to

  • IEC 62443-2-1
  • NIST CSF 2.0
  • CIS Controls v8.1
  • ISO/IEC 27001:2022
  • ISO/IEC 27002
  • NIST SP 800-61r3
CertPilot

CertPilot is the awareness and competence layer. It is a certification-readiness platform that organisations also run as their own training and examination panel: your procedures become your course and exam, for your candidates, under your name. An attestation stops being a signature on a sheet and becomes a pass mark you can show an auditor. It is live at certpilot.ca.

CertPilot

Questions we are asked first

How is this not another binder nobody opens?

Because the procedures are written to your site and tested on your people before we hand them over, and the policy is mapped to the framework you report against. A procedure that fails the walk-through gets rewritten until it works.

Will the policies match a template or our actual operation?

Your operation. We start from how the site really runs and write the policy to fit it and the framework, so an auditor does not find the policy and the practice disagreeing.

Can you make training prove people understood, not just attended?

Yes. On CertPilot your organisation runs its own training and examination panel, so your procedures become your own course and timed exam, and attestation is a pass mark and a record rather than a signature on a sheet.

Tell us what is bothering you.

An email is enough to start with. A scoping call is free and there is nothing to commit to, and where we are not the right people we will say so and point you at someone who is.

Book a scoping call

A first call about one site. No charge, and nothing to commit to.

Ask about a Site Assessment

Our named next step: we come to one site and hand you an assessment you can act on.