IT governance that protects your business

Policy & Documentation

IT policy and documentation services are the writing of the disaster recovery plans, incident response playbooks, AI usage policies and POPIA records your organisation needs to stay compliant. When things go wrong, you need a plan. When auditors come knocking, you need proof. We write the documentation that keeps your organisation compliant, secure, and prepared for anything, tailored to your business rather than pulled from a generic template.

Why does IT documentation matter?

IT documentation matters because it reduces mistakes, proves POPIA and ISO 27001 compliance, tells staff what is allowed, and is the difference between recovering from an incident in hours and in weeks.

How does documentation reduce risk?

Risk is reduced because documented procedures mean fewer mistakes; when everyone knows the process, human error drops and incident response times improve.

Is documentation required for compliance?

Yes, POPIA, ISO 27001 and industry audit standards all require formal IT governance documentation, and AMEA makes sure you can prove compliance at any time.

How do policies help staff?

Clear policies are how staff know what is allowed, what is not, and exactly what to do when problems crop up.

How does documentation protect continuity?

Business continuity is protected because organisations with documented recovery plans are back on their feet in hours, while those without can take weeks.

Documentation Suite

Which IT policies and plans does AMEA write?

AMEA writes disaster recovery plans, IT policy frameworks, incident response plans, AI acceptable use policies, POPIA compliance frameworks and password and access policies, each written around your organisation rather than a generic template.

What is a Disaster Recovery Plan (DRP)?

A DRP is the step-by-step guide to restoring IT systems after a major incident.

A step-by-step guide for recovering your IT systems after a major incident, whether that is ransomware, hardware failure, or a natural disaster. We document your critical systems, recovery priorities, RTO/RPO targets, and communication protocols.

  • Business impact analysis (BIA)
  • Recovery time & recovery point objectives
  • Vendor and supplier contact lists
  • System restoration runbooks
  • Tabletop exercise scenarios
  • Annual testing and review schedule

What is an IT Policy Framework?

An IT policy framework is the set of enforceable rules that govern how your organisation uses technology.

A comprehensive set of enforceable policies covering how your organisation uses technology. Clear, practical, and tailored to your size and industry, never generic templates.

  • Acceptable use policy (AUP)
  • Data classification and handling standards
  • Access control and privilege management
  • Password and authentication requirements
  • BYOD and remote work guidelines
  • Software and hardware procurement rules

What is an Incident Response Plan (IRP)?

An IRP is the procedure your team follows the moment a breach or IT incident is detected.

When a security breach or IT incident occurs, every minute counts. We create detailed response procedures so your team acts decisively, minimising damage, preserving evidence, and meeting your notification obligations.

  • Incident severity classification matrix
  • Escalation paths and responsibilities
  • Evidence preservation procedures
  • Regulatory notification timelines (POPIA)
  • Communication templates for stakeholders
  • Post-incident review and lessons learned

What is an AI Acceptable Use Policy?

An AI acceptable use policy is the rule set for which AI tools staff may use and what data may go into them.

As AI tools become standard in the workplace, clear guidelines are non-negotiable. We help you define which tools are approved, what data can be shared with them, and how to maintain quality and legal compliance.

  • Approved AI tools and platforms list
  • Data sensitivity and privacy rules
  • Intellectual property considerations
  • Quality control and review obligations
  • AI output disclosure requirements
  • Staff training and acknowledgement process

What is a POPIA Compliance Framework?

A POPIA compliance framework is the documentation package that evidences how personal information is collected, stored and protected.

The Protection of Personal Information Act (POPIA) requires organisations to formalise how they collect, store, and process personal data. We create the full documentation package your Information Officer needs.

  • PAIA/POPIA manual
  • Data processing register
  • Consent management procedures
  • Data breach notification protocol
  • Supplier and third-party data agreements
  • Annual compliance review checklist

What is a Password & Access Policy?

A password and access policy is the enforceable standard for credentials, MFA and privileged access.

Weak credentials are the number-one attack vector. We create enforceable password and access management policies aligned with NIST best practices and your specific technology environment.

  • Password complexity and rotation standards
  • Multi-factor authentication requirements
  • Privileged access management rules
  • Joiner / mover / leaver procedures
  • Service account governance
  • Third-party and contractor access rules

How does the documentation process work?

The process runs in five steps: discovery interviews, a gap analysis against compliance requirements, drafting, review with your team, and implementation with staff training and a review schedule.

01

What happens in discovery?

Discovery is where AMEA learns your systems, processes and business priorities through structured interviews and a technical environment review.

02

What is the gap analysis?

Gap analysis is a comparison of your current documentation against compliance requirements and security best practice to identify exactly what is missing.

03

How is drafting done?

Drafting is clear, practical, business-specific writing with no copy-paste templates; every document is tailored to your organisation and signed off by you.

04

How does the review work?

Review is where your team reads the drafts and AMEA refines them until the documentation is accurate, actionable and fits the way your business works.

05

What does implementation involve?

Implementation is the rollout: AMEA helps you publish policies, train staff and establish review schedules so documentation stays current.

Standards & Frameworks

Which standards are the policies aligned to?

All documentation is aligned to POPIA, ISO 27001, the CIS Controls and NIST guidance where relevant, so it holds up in audits and customer due diligence.

The core IT policy set: acceptable use, information security, data protection under POPIA, incident response and business continuity, each one an auditor asks for by nameThe documents you get asked forAcceptable useWhat staff may and may not doInformation securityAccess, passwords, devicesData protection (POPIA)Lawful basis, retention, requestsIncident responseWho to call, in what orderBusiness continuityBackups, recovery targetsWritten once, reviewed yearly, and actually followed
The core policy set an auditor, an insurer or the Information Regulator asks for by name.

Start with the free POPIA compliance guide, which covers what every policy set has to say about personal information.

POPIA

Protection of Personal Information Act

ISO 27001

Information Security Management

NIST CSF

Cybersecurity Framework

CIS Controls

Center for Internet Security

PAIA

Promotion of Access to Information

GDPR

EU Data Protection (where applicable)

Which IT policy covers what, and who requires it?

Six documents cover most of what a South African business is asked for by regulators, auditors, insurers and enterprise customers.

IT policies and plans: purpose and who asks for them
DocumentWhat it coversWho requires it
Disaster Recovery PlanRestoring systems after a major outage: priorities, RTO and RPO, runbooksAuditors, insurers, enterprise customers, boards
Incident Response PlanDetecting, containing and reporting a security incidentPOPIA (breach notification), cyber insurers, ISO 27001
IT Policy FrameworkAcceptable use, data handling, access, passwords, BYOD, procurementISO 27001, customer due diligence, HR
POPIA Compliance FrameworkPAIA manual, processing register, consent, breach protocol, supplier agreementsInformation Regulator, every organisation under POPIA
AI Acceptable Use PolicyApproved AI tools, permitted data, review and disclosure rulesBoards, clients, professional bodies, cyber insurers
Password and Access PolicyCredential standards, MFA, privileged access, joiner and leaver processCyber insurers, CIS Controls, ISO 27001
A first engagement usually produces the POPIA framework, the incident response plan and the password and access policy, because those three are asked for most.
FAQ

IT policy & documentation questions

Most South African businesses need seven core documents at a minimum. An acceptable use policy, a password and access control policy, a data classification and handling standard, an incident response plan, a disaster recovery plan, a POPIA compliance framework including a PAIA/POPIA manual, and, if staff use AI tools, an AI acceptable use policy. AMEA writes all of these as business-specific documents rather than generic templates.

A disaster recovery plan (DRP) describes how to restore IT systems after a major outage, with recovery priorities, recovery time and recovery point objectives and step-by-step restoration runbooks. An incident response plan (IRP) describes how to detect, contain and report a security incident such as a breach or ransomware attack, including POPIA notification timelines. Most businesses need both, and they reference each other.

Yes. POPIA requires responsible parties to take reasonable, documented measures to secure personal information, to appoint an Information Officer, to maintain a PAIA manual, and to be able to demonstrate compliance to the Information Regulator. Written policies, a data processing register and a breach notification protocol are how that compliance is evidenced.

A typical engagement runs four to eight weeks: discovery interviews and an environment review in week one, a gap analysis against POPIA and security best practice, drafting, one or two review rounds with your team, and then rollout with staff training and a review schedule.

Not sure what you're missing?

We'll run a free policy gap analysis to identify exactly what documentation your organisation needs to be compliant and protected.