IT governance, cybersecurity and digital transformation in Belgiumcontact@itselect.be
Start IT diagnostic
CyberFundamentals Basic · CCB

Build your cybersecurity policies without starting from scratch.

The Center for Cybersecurity Belgium provides Belgian organisations with reference templates. ITSelect helps you turn them into adapted, validated and usable governance evidence.

Start the diagnosticGet supportOfficial CCB source

Why these templates matter

A policy document is not only about compliance. It clarifies responsibilities, provides governance evidence, structures controls and gives management a practical baseline to steer cyber risks.

01Start from a recognised baseline instead of a blank page.
02Adapt rules to the size, business and real risks of the organisation.
03Link policies to controls, suppliers and action plans.
04Prepare useful evidence for audits, NIS2, clients and management.

The 9 documents to structure

The cards below summarise the CCB CyberFundamentals Basic templates and their practical value for a Belgian SME or organisation. Official downloads remain available on Safeonweb@work.

Governance

Basic cybersecurity policy

Define minimum security requirements, responsibilities and common rules applicable across the organisation.

Prioritise this if cybersecurity rules are not yet formalised or are scattered across teams.
Inventory

Asset management policy

Identify and track devices, applications, data, accounts and critical resources throughout their lifecycle.

An essential baseline for managing risks, access rights, backups and ownership.
Identity

Access policy

Structure who accesses what, under which conditions, with which approvals and periodic reviews.

Priority when shared accounts, unmanaged leavers or legacy access rights remain in place.
Identity

Password policy

Clarify password, authentication and sensitive access protection requirements.

Ideally connected to MFA, Microsoft 365 and privileged administrator accounts.
Network

Network security policy

Frame network protection, segmentation, remote access, equipment and connection rules.

Useful to turn firewall and network controls into a governed, documented setup.
Operations

Vulnerability and patch management policy

Organise the detection, prioritisation and remediation of vulnerabilities and security updates.

Essential to avoid known unpatched weaknesses on servers, endpoints and applications.
Continuity

Backup and restore policy

Define backup scope, frequencies, responsibilities, restore tests and recovery objectives.

Priority when facing ransomware exposure, cloud dependency or critical business data.
Incident

Cyber incident response plan

Prepare roles, reflexes, communications, evidence and escalation paths for cybersecurity incidents.

Critical to reduce improvisation during phishing, ransomware or supplier-related incidents.
Awareness

10 Golden Rules for Cybersecurity

Use a simple support document to launch user awareness and promote practical behaviours.

A fast entry point to involve teams without overcomplicating the message.

CCB / Safeonweb@work source

The official templates are provided by the Center for Cybersecurity Belgium. They can be used as a working baseline and must be adapted to each organisation’s context. A version adapted by ITSelect does not constitute validation, certification or approval by the CCB.

View the official CCB source and downloads →

How ITSelect integrates them into your governance

The objective is not to accumulate documents. The objective is to turn templates into usable evidence connected to your diagnostic, risks, owners and roadmap.

1

Diagnostic

Identify missing or insufficient policies based on your maturity level.

2

Adaptation

Customise templates according to your assets, suppliers, tools and internal constraints.

3

Validation

Assign an owner, review date and management validation path.

4

Evidence

Link each document to controls, risks, action plans and follow-up reports.

Ready to turn these templates into real governance evidence?

Start with a simple diagnostic, then prioritise the documents to adapt based on your exposure, organisation and obligations.

Launch the diagnosticTalk to an expert