Tools
Policy scaffolds

The Skeleton

Guidance on writing the policy itself, kept deliberately out of the Navigator. Each scaffold sets out the decisions a policy has to make, the ways those decisions are usually got wrong, and one worked extract showing what a decision looks like once it has actually been made.

Why this is organised by policy and not by control. The corpus holds 597 controls. Nobody writes 597 policies. A working management system has fifteen to twenty-five, and each one answers a cluster of controls across every framework at once, because they are all asking the same question in different words. One access control policy satisfies the ISO clause, the CSF category, the CIS control and the PCI requirement together. So the scaffold sits at the level of the artefact you actually have to write, and each one lists the controls it answers underneath.

Written

10 policies, answering 423 of 597 controls
Information Security PolicyThe top-level statement of who is accountable for security, what the organisation is willing to risk, and the authority under which every other policy is issued.150 controls · 7 frameworksOpen →Logging and Monitoring PolicyDetermines what the organisation will be able to reconstruct after the fact, and how long it keeps the ability to do so.47 controls · 7 frameworksOpen →Security Incident Response PolicyEstablishes what counts as an incident, who is allowed to declare one, and what authority the responders have once it is declared.43 controls · 7 frameworksOpen →Access Control PolicySettles who may reach what, on whose authority, and what happens to that access when the reason for it ends.39 controls · 5 frameworksOpen →Third-Party and Supply Chain Security PolicySets what an organisation requires of the parties it depends on, and what happens when they cannot meet it.34 controls · 8 frameworksOpen →Data Protection and Classification PolicyDecides what the organisation's data is worth, who may see each kind, and what handling each kind requires.30 controls · 4 frameworksOpen →Secure Configuration and Change PolicyEstablishes what a system is supposed to look like, how that is enforced, and how it is allowed to change.25 controls · 6 frameworksOpen →Personnel Security PolicyCovers what is verified before someone is given access, what they are told, and what happens on the way out.21 controls · 5 frameworksOpen →Business Continuity and Disaster Recovery PolicySets how long the organisation can be without each service, how much data it can afford to lose, and who decides to invoke.20 controls · 5 frameworksOpen →Cryptography and Key Management PolicyStates what must be encrypted, with what, and who can reach the keys, which is the part that actually decides the strength.14 controls · 3 frameworksOpen →

Not yet written

12 remaining

These domains exist in the corpus and their scaffolds have not been written. They are listed rather than linked, because a link that leads to a promise is exactly what this tool was rebuilt to stop doing.

Application SecurityBuilding and maintaining secure systems and software through secure development lifecycle practices, code review, application testing, and change management. This domain also covers application hardening and restricting user-facing application features that can be exploited.26 controlsNot yet written
Asset ManagementIdentifying, inventorying, classifying, and managing information assets including hardware, software, data, and cloud services throughout their lifecycle. Proper asset management is foundational — you cannot protect what you do not know you have.25 controlsNot yet written
Security TestingValidating the effectiveness of security controls through penetration testing, red teaming, vulnerability assessments, and security audits. Regular testing provides assurance that controls work as intended and helps identify gaps before attackers do.23 controlsNot yet written
Compliance and AuditEnsuring ongoing conformance with legal, regulatory, and contractual obligations through internal audits, management reviews, and compliance monitoring. This domain supports accountability and provides evidence of security programme effectiveness to stakeholders and regulators.22 controlsNot yet written
Physical SecurityProtecting physical premises, equipment, and media from unauthorised access, damage, and interference. This includes facility access controls, environmental protections, equipment security, and physical monitoring such as CCTV.18 controlsNot yet written
Network SecurityProtecting network infrastructure through segmentation, firewalls, intrusion detection and prevention, and secure architecture design. This domain covers controls that restrict unauthorised network access and monitor network traffic for threats.17 controlsNot yet written
Malware DefencePreventing, detecting, and responding to malicious software including viruses, ransomware, and spyware. This domain encompasses anti-malware tools, application control (whitelisting), email and web filtering, and macro restrictions.13 controlsNot yet written
Vulnerability ManagementContinuously identifying, assessing, prioritising, and remediating vulnerabilities across systems and applications. This includes patch management for operating systems and applications, vulnerability scanning, and penetration testing.12 controlsNot yet written
Email and Web SecurityProtecting against threats delivered via email and web browsing including phishing, drive-by downloads, and malicious attachments. Controls include email filtering, URL reputation, browser hardening, DNS security, and restricting Office macros.8 controlsNot yet written
Cloud SecurityDefining and implementing security controls specific to cloud service usage including shared responsibility models, cloud configuration management, cloud identity controls, and monitoring of cloud environments. As organisations migrate to cloud, this domain addresses the unique risks of multi-tenant and distributed infrastructure.4 controlsNot yet written
Threat IntelligenceCollecting, analysing, and acting on information about current and emerging cyber threats to inform defensive decisions. This includes understanding threat actors, tactics, techniques, and procedures (TTPs), and integrating threat intelligence into security operations.4 controlsNot yet written
Privacy & Data RightsLawful handling of personal information and the rights of data subjects/individuals — collection limitation, purpose, use and disclosure, access and correction, data-subject rights, lawful basis, and cross-border transfers.2 controlsNot yet written