Lab

    Where GRCIDE builds.

    Working products, not slideware — the same methods published here, shipped as software.

    01 — Products

    Two products, both in use.

    Each one is a published method taken far enough to run. The status line on every card says exactly where it stands today.

    ISM Security Handbook

    On the App StoreiOS & iPadOS

    An offline reference handbook for information security managers.

    An offline reference for information security managers. The whole knowledge base ships with the app: 478 topic cards across five parts, wired together by typed cross-links and a glossary built from the topics themselves.

    • 478 topic cards across governance, risk, program development, security operations and AI security management.
    • 1,372 typed cross-links and a 1,324-term glossary, both built from the topics themselves.
    • Five surfaces — Browse, Search, Connect, Saved and Glossary — plus Spotlight indexing.
    • No account, no tracking, no third-party SDKs, and the content works with the network off.

    Free to install. Part 1 is complete at no cost; Parts 2 to 5 are one-time purchases and nothing renews.

    BISO Guide

    Running privatelyWeb app

    A working BISO operating system, running privately. Early access on request.

    A single-operator workspace that runs the business information security officer function end to end. Charter and service catalogue, risk register and control library, strategy, assurance, incidents and continuity. A governed AI agent proposes changes; a person reviews them before anything is applied.

    • A BISO operating layer: profile, charter with a publish flow, service catalogue, decision rights and a health monitor.
    • A risk stack: ISO 27005 risk register, control library with verification and validation, risk profile heatmap, threat modelling and exceptions.
    • A strategy and assurance stack: risk appetite, objectives, a versioned strategy map, Statement of Applicability, evidence vault and registers.
    • A security-operations stack: incidents, response plans and playbooks, post-incident reviews, drills, and business continuity planning.
    • A reference library of 45+ standards on a seven-level clause taxonomy, with cross-standard mappings and gap analysis.

    Single-operator today. There is no public instance and no demo mode.

    02 — Ethos

    Why we build.

    A method that has never been built is still an opinion.

    Both products started as working files behind published methods: a control library, a risk register, a set of topic notes that had to hold together under daily use. Software was the only honest way to find out whether they did.

    Building a method forces the decisions a document lets you postpone. What the register has to store. What an exception is allowed to change. Which link between two ideas is real and which one only sounded good in an outline. Every answer goes back into what is published here.

    Neither product is a sales instrument. They exist because the methods are used, and the fastest way to find the weak clause in a method is to run it.

    All content in this app is original, written for ISM. An independent, unofficial professional reference. Not affiliated with, authorized, sponsored, or otherwise endorsed by ISACA, NIST, ISO, or any other standards body. CISM® and AAISM™ are trademarks of ISACA.

    Let's make compliance an asset, not a tax.