Packs
Documents for running a security function
Each pack is a set of ready-made documents for one job, with a guide that says where to start.
Vulnerability & Exposure Management
Vulnerability & Exposure Management
Your scanner reports hundreds or thousands of issues. Nobody agrees which ones matter, who should fix them, or by when. This pack gives you ready-made documents to settle those three questions and keep them settled.
9 documents
Security Governance & Management
Security Exception, Waiver & Segregation of Duties
Every organisation has gaps it cannot close today: a server that cannot be patched, a supplier that cannot use multi-factor sign-in, an administrator who both makes changes and approves them. The danger is the gap nobody wrote down, nobody owns and nobody revisits. This pack gives you the documents to record each gap, decide who may accept it, and make sure it ends.
9 documents
Security Policy Management
Most organisations have security policies; few have policies anyone reads. They were copied from a template years ago and name people who have left. When an auditor asks who has read them, nobody can show it. This pack helps you build a smaller set of documents that people follow, keep it current, and prove it has been read.
9 documents
Security Metrics, Reporting & Executive Communication
Board Cybersecurity Reporting
Most security reports to a board list what the team did last quarter and colour each line red, amber or green. The board nods and moves on. Nothing is decided, because nothing was put to it. This pack helps you turn a technical status update into a governance conversation.
8 documents
Cybersecurity Risk Management
Information Security Risk Management
Most risk registers are a list of vague worries such as “cyber attack”, owned by IT and scored once in a workshop. Nothing is decided, so nothing changes before the next audit. This pack helps you run a process that produces decisions: who owns each risk, whether it is acceptable, and what happens next.
9 documents
Third-Party & Supply Chain Security
Third-Party Security Risk Management
Every supplier gets the same 200-question audit, whether it runs payments or delivers office plants. Nobody reads the answers, certificates are filed without checking what they cover, and the review stalls after a dozen vendors. This pack helps you assess suppliers in proportion to the harm they could do, so the process scales to all.
9 documents
Identity & Access Management
User Access Review
A manager receives a list of 200 accounts, half of them named after roles nobody recognises. The deadline is Friday, so everything is approved in four minutes. Nobody checks the few removals requested. This pack helps you run an access review that produces genuine decisions, not bulk approvals under time pressure.
8 documents
Regulatory & Framework Implementation
ISO 27001 Implementation & Certification Readiness
A customer asks for a certificate, so someone buys a toolkit, writes forty policies and books an audit. At Stage 1 the auditor finds a scope nobody can explain, controls copied from Annex A instead of chosen from risk, and no records. This pack sets realistic expectations for a first certification: what it costs, how long it takes, and which decisions determine whether it goes well.
9 documents