SMALL-TEAM COMPUTER SECURITY POLICY — EDITABLE TEMPLATE Adoption instructions Replace every bracketed field. Delete inapplicable choices. The owner must confirm each requirement can be implemented and checked. Review contractual, sector and legal obligations separately. This is an original planning template, not a certification or a substitute for organization-specific procedures. Organization: [name] Approver: [name/role] Policy owner: [name/role] Effective date: [date] Review date: [date] Scope: [workers, contractors, devices, services, data, locations] Personally owned device rule: [approved conditions or approved alternative] 1. Accounts and access Use individual accounts for human users. System owners approve roles before access is granted. Use [approved password manager] for unique passwords and [approved MFA/passkey methods] for [covered account types]. Administrative access is limited to approved tasks. Recovery follows [verification procedure]. Evidence owner: [name] Record: [access request/review location] 2. Devices and updates Use supported devices and software. IT maintains [inventory location], checks updates on [schedule], prioritizes urgent exposures through [process], and records unresolved exceptions. Staff report lost devices to [contact route]. Evidence owner: [name] Record: [update and device report] 3. Data and recovery Store [data types] in [approved locations]. Apply [access and retention rules]. Back up [systems/data] using [method, frequency, separate protection]. Test restoration of [sample scope] on [schedule]; record success and gaps. Recovery priorities and acceptable interruption: [business-approved values]. Evidence owner: [name] Record: [backup and restore log] 4. Remote work and software Use [approved remote-access path]. Install software through [approval route]. Report unexpected sign-ins, suspicious programs or security changes to [incident contact]. Staff must not approve unexpected authentication prompts. Evidence owner: [name] Procedure: [location] 5. Incidents Report promptly through [primary route] or [backup route]. Record observed symptoms and time. Follow the incident lead's instructions for isolation, evidence, cleanup and restoration. Do not erase a work device independently. Incident lead: [name/role] Alternate: [name/role] External responder/provider: [verified contact and contract reference] 6. Role changes and departures The manager approves effective times. IT and application owners grant/remove roles, revoke sessions as supported, handle retained data, retrieve devices and verify the result in each service. Use [lifecycle checklist location]. Coordinator: [name/role] Completion record: [location] 7. Exceptions Record: [asset; requirement; reason; exposure; interim safeguards] Approved by: [name/role] Expires/reviewed: [date] Closure evidence: [result and date] Adoption and operating checks [ ] All fields completed; scope and owners approved. [ ] Account setup and departure tested with a test account. [ ] Sample restore completed and readable files checked. [ ] Incident contact routes checked without triggering an emergency. [ ] Staff instructions distributed and accessible. [ ] Evidence review schedule and exception expiry tracking assigned. Source context: NIST CSF 2.0 Small Business Quick-Start Guides https://www.nist.gov/itl/smallbusinesscyber/quick-start-guides Authentication requirements require contextual review: https://pages.nist.gov/800-63-4/sp800-63b.html Never put passwords, private keys or recovery codes in this policy. Yenra | Updated September 9, 2026 Guide: https://yenra.com/computer-security-policies/