Security policies, risk registers, access reviews, vendor assessments and DPIAs.
Information Security Policy
Mandatory rules with named owners, written so people can actually comply with them.
Risk Register
Standing organisational risks with owners, treatment decisions, and dated reviews.
Access Review
Periodic recertification of who has access to what — and the evidence that someone actually looked.
Vendor Security Assessment
Due diligence on a third party, scaled to what they will actually hold and do.
Data Protection Impact Assessment
Structured analysis of privacy risk before processing starts — necessity, proportionality, and what you will do about the risks.