PRACTICAL GUIDE · VERSION 1.0.0

Write a policy your firm can follow

Turn structured prompts into an actual operating procedure.

Content and source check: October 1, 2026 · Operational suggestions

01

Choose the policy

Create separate written information security, continuity, incident response or AI use drafts. Each starts with the relevant sections; it is not an adopted policy.

02

Replace the prompts

Write the actual process, accountable roles, records and exceptions. Use references to protected directories rather than embedding credentials or sensitive contacts.

03

Compare with practice

For every section, record whether it matches practice, needs a change or is inapplicable, with a rationale. Assign operational gaps instead of implying that policy text fixes them.

04

Review before adoption

Export editable text for professional review. Confirm applicability, approval authority, effective date and records. A workspace approval preserves a review snapshot; it does not prove implementation or replace the firm's adoption process.

Source & applicability

NIST-1300 — Cybersecurity Framework 2.0: Small Business Quick-Start Guide

Provides a starting point for small organizations to organize cybersecurity risk management. Voluntary guidance; no RIA-specific frequency or legal deadline is derived here.

SEC-registered and state-registered firms may have different obligations. Have the appropriate professionals review what applies to your firm. No regulatory determination is made here.

Draft a policy →