secria.eu

What belongs in an information security policy for an installation company?

An overview of what an information security policy for the installation sector should contain, precisely because technicians work on-site at customer locations and have access to buildings and systems.

What belongs in an information security policy for an installation company?

An information security policy for an installation company describes, in short, who within the organisation is responsible for information security, what agreements apply to access to buildings and systems, how incidents are handled and how that is documented. The document need not be a technical manual. It is primarily a readable overview that demonstrates that risks have been considered, and that there is someone accountable for them.

For installation companies, a specific point applies that is often missing from example policies: technicians physically enter customer premises and frequently gain access to systems, keys, badges or networks there. A policy that covers only the own office thereby misses part of where the real risk lies. Whoever receives a question from a client, an insurer or — at a larger installation company — a competent authority is almost always questioned on this point.

Why it is being asked for now

The due care obligation from the NIS2 Directive requires essential and important entities to assess their suppliers. An installation company working for an energy company, a hospital or a water company thus often faces no statutory obligation itself, but does receive a questionnaire asking for an information security policy. Even without this supply chain pressure, a documented policy is useful: it makes clear who checks which agreement, and it prevents knowledge from residing only in someone's head.

Whether an organisation itself is subject to the law, is affected via the supply chain, or neither, can be determined with a few questions. in a few questions see whether and how your company is affected provides an initial, cost-free indication there, with an explanation for each outcome.

The sections that almost always appear

An information security policy for the installation sector typically contains a brief introduction about the purpose and scope: does it cover the office, the workshop, the vehicles, the systems on-site at customer locations, or everything at once. This is usually followed by a section on roles: who is ultimately responsible, who manages access rights, and to whom does a technician report a lost badge or a suspected incident.

A next section addresses access: how is it determined who may access which systems and keys, how is this documented when someone leaves, and what agreements apply specifically to work on-site at a customer location. This is often followed by a section on equipment: laptops, tablets and mobile phones that technicians carry, and what happens if such a device is lost.

The policy further describes how an incident is identified and reported, even if that is brief and refers to a separate incident register. And it usually concludes with a section on maintenance: when is the policy reviewed, and who is responsible for that. That final section is often as important to a client or competent authority as the content itself — a policy that has not been updated since the organisation's founding raises more questions than it answers.

How detailed should it be

There is no prescribed length or fixed format. Competent authorities and clients look at whether the policy fits the size and risks of the organisation, not at the number of pages. An installation company with twenty technicians working at multiple locations has different concerns than an office organisation without customer visits. What the national laws and competent authorities precisely expect from essential and important entities, moreover, varies by country — the secria.eu knowledge base tracks this by subject, with the date the source was consulted.

It is also worth knowing that a policy document itself is rarely the endpoint. It describes agreements that must also be reflected somewhere: in an access overview, in an incident register, in a supplier overview. Without these underlying documents, a policy remains an intention on paper. Frequently asked questions about what is precisely being asked and why can be found in the frequently asked questions about the dossier and the questionnaires.

Drawing up yourself or having it prepared

An information security policy can be written by an installation company itself, using knowledge of its own working methods as a starting point. For those who prefer to use a worked-out structure as a basis, the cyber-dossier of secria.eu offers prepared texts per section, linked to the status and supporting document that goes with it. This does not replace legal advice on your own situation, but does save the legwork of starting from scratch. More about the structure of the dossier and the associated subscriptions can be found on the page with the subscriptions and what they include.

Anyone who first wants to get an overview of which topics are relevant before anything is recorded will find an ordered overview on the page with all topics, sorted by situation. For most installation companies, that is a pleasant first step: first see what it is really about, then start writing.

This article is general information and not legal advice.