Organizations use information security policies (ISP) to guide the use of their information assets. Previous literature has presented ways to develop ISPs from suggested content to development methods; however, these approaches encounter problems when they are applied in organizations without adequate support. This paper introduces the development of a meta-methodology to support organization-specific ISP development. The approach is developed via action research with four Finnish companies. The results of the first two research cycles produced a list of 11 critical considerations, which were used to design ISP development methods. The critical considerations proved to be useful in designing different methods for different organization settings. However, they are only the first step towards a meta-methodology for designing ISP development methods.