Information Technology PolicyPro®

From policy to sign-off

Co-marketed with

Information Technology PolicyPro is co-marketed by CPA Canada and First Reference Inc.
Meet your systems and data management, security and disaster planning obligations with dwonloadable model polices

The leading source for up-to-date model policies based on Canadian compliance and best practice.

Choose the classic print manual or the comprehensive online platform that automates policy management.

Choose which PolicyPro is right for you

Do you require only IT policies and prefer a print manual with downloadable Microsoft Word® versions of each policy? Select PolicyPro Classic

In addition to IT policies, do you require policy templates for finance, accessibility, HR and non-profits and an automated method to distribute policies and ensure employee sign-off? Select PolicyProPlus®

Check out the features
available with each PolicyPro

PolicyPro Classic

Information Technology PolicyPro:
Online policy templates and print manuals

Try it free for 30 days


From policy to sign-off:
The complete policy management service

Try it free for 30 days

$ 995 /year

$ 2,495 /year



Two-volume print manual with IT model policies updated regularly

Online versions of all policies, forms, checklists and commentary regularly updated for changes in compliance and best practice

Add policies for finance, accessibility, non-profits and HR for each province (Note: no print manual)

Commentary by subject-matter experts outlines needs and considerations for each policy

Information Technology PolicyPro policies cross-referenced to leading control frameworks: ITCG and CobiT

Ask the Editor for queries about content or to suggest new policies

Bi-weekly newsletter informs you of revised and new policies and why they're important

Use or revise existing quizzes or create new ones to ensure employees read and understand each policy

Draft, update and archive policies and forms with professional document management functionality

Use multiple manuals and distribution lists for different departments and employee groups

Track employees' completion of assigned policies for internal and external audits using easy management reports

In-context help and technical support

Each employee has their own online account for reading policies, completing quizzes and a report to track progress

Secure and centralized document storage with access from any location or device

Try it for free today!

Get PolicyPro Classic

Best offer:
Platform and content

* The PolicyProPlus Platform is also available without policy databases for $1,495 per year.

Information Technology PolicyPro Model Policies


  • Strategic Planning
  • Tactical Planning
  • Implementation Planning
  • Site Planning
  • Risk Assessment
  • Risk Management

Systems Acquisition, Maintenance and Disposal

  • Accountability for Systems
  • Systems Acquisition
  • Recording IT Assets
  • System Setup
  • Warranties and Support
  • Maintenance
  • Disposal of Hardware

Software Acquisition, Implementation and Maintenance

  • Standard Applications
  • Application Development and Implementation
  • Non-standard Software
  • Standard Application Fixes
  • Licenses
  • Software Downloading

Systems Management

  • Computer Naming System Conventions
  • Role-based User Management
  • Internet Access
  • Downloading

Data Management

  • Data Processing Integrity and Validation
  • Data Backup and Storage
  • Management of Third-Party Services
  • Database Management
  • Customer Relationship Management Data
  • Records Retention

Computing Operations and Support

  • Configuration and Systems Management
  • Access Administration
  • System Availability
  • Service Levels
  • Operations and Scheduling
  • Performance and Capacity Management
  • Corporate Website
  • Company Intranet
  • Cost Allocation
  • Problems and Incident Management

Monitoring and Evaluation

  • IT Effectiveness Reviews
  • Logging Controls
  • Internal Audits
  • Performance and Capacity Reviews
  • Security Reviews
  • Software Audit

Physical and Systems Security

  • Physical and Infrastructure Security
  • Systems Security
  • User Identification and Passwords
  • Confidentiality and Privacy
  • Controls for Viruses, Worms and Malware

Data Security

  • Data Ownership
  • Data Classification
  • Data Access Controls
  • Application Security Controls
  • Data Disposal
  • Data Encryption

Network Security

  • Network Hardware Connection
  • Firewall Protection
  • Remote Access
  • Wireless Network
  • Network Intrusion Detection
  • File Transfer Protocol
  • Email Security
  • Instant Messaging
  • Electronic Commerce

Backup and Disaster Planning

  • Disaster Planning Team
  • Disaster Notification
  • Identification of Critical Processes
  • Backup Schedule
  • Backup Files Stored Onsite
  • Backup Files Stored Offsite
  • Offsite Processing Agreements
  • Disaster Recovery Plan Testing
  • Disaster Recovery Plan Review
  • Disaster Recovery Team
  • End-user Restrictions

Training and Support

  • IT Staff Training
  • End-user Training
  • Customer Support

User Responsibilities

  • System Access and Acceptable Use
  • Data Access and Data Protection
  • Passwords
  • Email Acceptable Use
  • Internet Access and Acceptable Use
  • Clear and Locked Screen
  • Removable Media
  • Portable Computers
  • Remote Acesss - Users

Mobile Device Management: BYOD

  • BYOD: Acceptable Devices and Operating Systems
  • BYOD: Systems Access and Acceptable Use
  • Security for BYOD Devices
  • Maintenance and Support for BYOD Devices Email Acceptable Use
  • Employee Agreements for BYOD Participation
  • Compensation for BYOD

Print ISSN 1911-5873  |  Online ISSN 1923-8916

Authors and Editors


Jeffrey D. Sherman, Bcomm, MBA, CIM, FCPA, FCA, has had over 20 years of executive management experience. He is a former director or CFO of several public companies. His extensive knowledge and experience includes corporate governance, risk management, accounting and finance, restructuring and start-up enterprises.

Mr. Sherman has lectured and conducted seminars for many organizations and was an adjunct professor at York University for 15 years. He is a popular course director and course author for many organizations, including The Chartered Professional Accountants of Canada (CPA Canada) and other provincial institutes of chartered professional accountants and law societies, and has written many books and articles on finance and accounting.

Co-marketed with

Informatiopn Technology PolicyPro is co-marketed by CPA Canada and First Reference

Content Editor

Apolone Gentles, JD, CPA, CGA, FCCA, is an Ontario lawyer and editor with over 20 years of business experience.

Ms. Gentles has held senior leadership roles in non-profit organizations, leading finance, human resources, information technology and facilities teams. She has also held senior roles in audit and assurance at a "Big Four" audit firm. Apolone has also lectured in auditing, economics and business at post-secondary schools.

Managing Editor

Yosie Saint-Cyr, LLB, was called to the Quebec bar in 1988 and is a member in good standing. She practised business, employment and labour law until 1999 before becoming Managing Editor at First Reference.

Yosie is responsible for the high-quality, up-to-date content for employment law services and the Internal Controls Library. She is currently enrolled in the Osgoode Professional LLM degree program.