Toolkit

    Method, carried.

    Three shelves. Playbooks set out a method end to end. Templates carry it as a file you can open on Monday. The Lab ships it as software.

    01 — Playbooks

    Playbooks

    Each one covers a responsibility end to end, with the failure mode it prevents, the steps, the deliverables and what the auditor will ask.

    BCM under ISO 22301: BIA, strategy, exercise

    Turning a continuity document into a management system: impact analysis, disruption risk, costed strategies, exercised plans and evaluation evidence.

    Risk5 Sept 202622 min read

    The BISO operating model

    A method for designing the business information security officer role: mandate, decision rights, placement, operating rhythm, interfaces, measures and pitfalls.

    Governance5 Sept 202622 min read

    Board and management reporting for security

    A method for putting security in front of a board and getting a decision: five to seven risks, measured controls, and an outcome that is written down.

    Governance5 Sept 202621 min read

    Control ownership and the control catalogue

    A method for building one list of the controls that actually run, each with an owner, an evidence record and a test result, mapped to the frameworks they serve.

    Governance5 Sept 202622 min read

    Control testing and ITGC

    A method for proving controls operated over a period: the ITGC map, complete populations, risk-based samples, workpapers a second person can re-perform.

    Compliance5 Sept 202622 min read

    Choosing the CRA conformity route

    Which Article 32 procedure applies to each product, who signs the declaration, and what the chosen route must produce before 11 December 2027.

    Governance5 Sept 202622 min read

    Product & OT

    02 — Templates

    Templates

    The artefacts the playbooks produce, as downloadable files under an open licence.

    AI system register

    A three-sheet register: every AI system with its two roles and its owner, one impact assessment per system, and the Annex A statement of applicability.

    Compliance5 Sept 20263 min read

    AI governance

    AI use-case triage form

    A twenty-two column form that runs the AI Act decision test over one AI use case per row and closes each row with proceed, conditions or stop.

    Compliance5 Sept 20263 min read

    AI governance

    Control catalogue

    A sixteen-column register of the controls that actually run: owner, evidence producer, approver, reference controls served, evidence record and last test.

    Governance5 Sept 20263 min read

    Control test workpaper

    A twenty-one-column record of one control test: the population, its completeness check, the sample, the procedure, the evidence and a conclusion two roles sign.

    Compliance5 Sept 20263 min read

    CRA technical documentation index

    Four sheets that map the Annex VII file: one row per element per product, the declaration's Annex V items, and a retention schedule with derived end dates.

    Compliance5 Sept 20263 min read

    Product & OT

    Findings-to-closure tracker template

    A sixteen-column register that carries every external audit finding from the auditor's wording to a verification date, with correction and cause kept apart.

    Compliance5 Sept 20263 min read

    03 — Lab

    Lab

    Working products, not slideware — the same methods published here, shipped as software.

    ISM Security Handbook

    On the App StoreiOS & iPadOS

    An offline reference handbook for information security managers.

    An offline reference for information security managers. The whole knowledge base ships with the app: 478 topic cards across five parts, wired together by typed cross-links and a glossary built from the topics themselves.

    BISO Guide

    Running privatelyWeb app

    A working BISO operating system, running privately. Early access on request.

    A single-operator workspace that runs the business information security officer function end to end. Charter and service catalogue, risk register and control library, strategy, assurance, incidents and continuity. A governed AI agent proposes changes; a person reviews them before anything is applied.