Good Security Policy Names Names
TL;DR I wrote the security policies and procedures for a company against NIST CSF and NIST 800-53, and these days I ghostwrite books for the security leaders who live this
No single person should control a whole sensitive process, because that is how fraud and mistakes happen. These articles cover separation of duties as a real control: splitting steps across roles so no one owns the full chain.
TL;DR I wrote the security policies and procedures for a company against NIST CSF and NIST 800-53, and these days I ghostwrite books for the security leaders who live this
If this sparked something, let's talk about turning your expertise into a finished book.