Where Do I Start?

The library of Rules/Policy documents is provided to you and your organization as a starting point or maturity checkpoint for existing rules/policies. It is brought to you on behalf of Jim McConnell, Principal Owner, and Ask McConnell, LLC — A Converged Security Services Provider. The content is not meant to cover every circumstance, industry, law, regulation, contractual requirement, threat, environment, or risk, but it provides an easy, defendable, highly accountable starting point for any organization. Please consult with your legal counsel and insurance provider about added requirements. If you know of peers who you think would find value in these resources, please have them contact us. These will be updated on our website regularly. We are not legally protecting these documents; we just ask for credit, shout-outs, and referrals if you find them helpful. If you have recommended updates, we are all ears. And if you need Converged Security Consulting and Training, please reach out, we would be honored to serve you and your organization.

Jim McConnell  |  info@askmcconnell.com  |  askmcconnell.com

Where Do I Start?

Below is a GUIDE for when someone asks, “Where should I/we start”? This won’t fit every situation, organization, legal requirements, or culture, but use it to start the conversation internally. My perspective is people protection policies first, critical infrastructure policies second, information/services security third, governance support, and other items.

Updated: 09 May 2025 (converted to HTML 05 July 2026)

  1. Personnel Security
  2. Child and Youth Protection
  3. Weapons and Security
  4. Reporting Security Incidents, Vulnerabilities, Threats
  5. Investigations
  6. Crisis Management and Communications
  7. Onsite/Offsite Events Security
  8. Partnerships with Law Enforcement
  9. Termination / Offboarding Personnel
  10. Protecting VIPs (Physical)
  11. Insider Threat Management
  12. Visitor (Invited / Non-Invited) Management
  13. Vulnerability Management
  14. Physical Security
  15. Basic Safety
  16. Emergency Evaluation/Shelter-In-Place
  17. Use of Our Facilities
  18. Recruiting and Onboarding
  19. Security Personnel Training
  20. Warehouse Security (Worker Edition)
  21. Construction Site Security (Worker Edition)
  22. Fraud Management
  23. Supplier / Customer Care Diligence
  24. Asset Inventory Management
  25. Cyber Security – Center for Internet Security 18 Critical Controls
  26. User IDs / Login IDs – Cyber / Information Security
  27. Technology Software Updates
  28. Supply Chain Security
  29. Non-Public Information Security (Including PII)
  30. Social Media Usage
  31. Email Security
  32. Laptop/Desktop/Mobile Security
  33. Secure Software Development
  34. Retail Loss Prevention
  35. Handling of Cash or Checks
  36. Engaging Security for New Projects / New Events
  37. Records Retention/Destruction
  38. Drone Management Policy
  39. Security Metrics
  40. Safety Metrics

← Return to the One-Pager Library


🖶 To save or print this document, use your browser’s Print function (Ctrl+P / Cmd+P) and select “Save as PDF” if needed.