About Us Contact Blog
Governance DocsGovernance Docs
Which Toolkit?SoA GeneratorFree TemplatesAboutBlogContactMy AccountCart
FOX v.2.4.9
Browse Toolkits
Governance Docs
  • Browse All Toolkits
  • Information Security & Cybersecurity
  • Data Privacy & Protection
  • Governance, Risk & Compliance
  • Quality Management
  • Health, Safety & Environment
  • AI Governance

My Account

CART

No products in the cart.

Category: Articles

HIPAA risk assessment steps from mapping ePHI to risk management and remediation

How to Conduct a HIPAA Risk Assessment

Governance Docs17th July 2026

The HIPAA risk assessment is the foundation of the Security Rule. Here is what it is, why it…
Read More
HIPAA Security Rule vs Privacy Rule - protecting electronic PHI versus governing use and disclosure

HIPAA Security Rule vs Privacy Rule Explained

Governance Docs17th July 2026

HIPAA Security Rule vs Privacy Rule: one protects electronic health data, the other governs its use and disclosure.…
Read More
HIPAA policies checklist including privacy, security, risk assessment and breach notification

HIPAA Required Policies & Documentation Checklist

Governance Docs17th July 2026

HIPAA requires documented policies and procedures. Here are the essential HIPAA policies, the records you must keep, and…
Read More
SOC 2 cost and timeline factors including scope, report type, size and readiness

SOC 2 Cost & Timeline: What to Expect

Governance Docs17th July 2026

What does SOC 2 cost and how long does it take? Here are the main cost factors, the…
Read More
SOC 2 audit preparation covering scoping, readiness assessment, controls and evidence

How to Prepare for a SOC 2 Audit

Governance Docs17th July 2026

The SOC 2 audit tests your controls independently. Here is what it involves, the process, how to prepare,…
Read More
SOC 2 documentation checklist of policies and evidence mapped to the Trust Services Criteria

SOC 2 Policies & Documentation Checklist

Governance Docs17th July 2026

SOC 2 documentation turns security practice into an auditable report. Here are the essential policies, the evidence you…
Read More
SOC 2 Type 1 vs Type 2 comparison of control design at a point in time versus operating effectiveness

SOC 2 Type 1 vs Type 2: What’s the Difference?

Governance Docs17th July 2026

SOC 2 Type 1 vs Type 2: one tests control design at a point in time, the other…
Read More
SOC 2 Trust Services Criteria explained - security, availability, processing integrity, confidentiality and privacy

SOC 2 Trust Services Criteria Explained

Governance Docs17th July 2026

The SOC 2 Trust Services Criteria define what your auditor evaluates. Here are all five - security, availability,…
Read More
GDPR gap analysis steps from mapping data to building a prioritised remediation plan

How to Run a GDPR Gap Analysis

Governance Docs17th July 2026

A GDPR gap analysis shows exactly where you stand against the regulation. Here is a step-by-step method to…
Read More
GDPR data subject rights explained including access, rectification, erasure and portability

GDPR Data Subject Rights Explained

Governance Docs17th July 2026

The GDPR data subject rights put individuals in control of their data. Here are all eight rights, how…
Read More
GDPR DPA guide - what a data processing agreement is and the Article 28 requirements

GDPR Data Processing Agreement (DPA): A Complete Guide

Governance Docs17th July 2026

A GDPR DPA is required whenever a third party processes personal data for you. Here is what a…
Read More
The 7 GDPR principles explained from lawfulness and minimisation to accountability

The 7 GDPR Principles Explained

Governance Docs17th July 2026

The seven GDPR principles are the foundation of the whole regulation. Here is what each one requires in…
Read More
    ←
  • 1
  • …
  • 14
  • 15
  • 16
  • 17
  • 18
  • …
  • 21
  • →

Recent Posts

ISO 27001 risk treatment plan diagram showing the six steps of clause 6.1.3
ISO 27001 Risk Treatment Plan: The Complete 2026 Guide

August 23, 2026

ISO 27001 nonconformity classification chart comparing major and minor audit findings
ISO 27001 Nonconformity: The Complete 2026 Guide to Major vs Minor Findings

August 22, 2026

ISO 27001 recertification audit timeline showing the three-year certification cycle from Stage 1 and Stage 2 through surveillance audits to year three reassessment
ISO 27001 Recertification Audit: The Complete 2026 Guide

August 21, 2026

Phishing-resistant MFA methods compared against NIST SP 800-63B-4 assurance levels
Phishing-Resistant MFA: The Complete 2026 Guide

August 20, 2026

Cybersecurity governance obligations under NIS2, DORA, ISO 27001 and NIST CSF 2.0
Cybersecurity Governance: The Definitive 2026 Board Guide

August 20, 2026

Categories

  • Articles
  • DORA
  • GDPR
  • HIPAA
  • ISO 27001
  • ISO 42001 & AI governance
  • ISO 9001
  • Management systems
  • NIS2
  • Security frameworks
  • SOC 2
Governance DocsGovernance Docs

Reliable ISO & compliance documentation toolkits that help your business meet regulatory standards with ease.

Governance Docs LLC
1209 Mountain Road Pl NE, Suite R
Albuquerque, NM 87110, USA
info@governancedocs.com
+1 812 227 5662

Toolkits

  • ISO 27001:2022
  • GDPR
  • SOC 2
  • PCI-DSS v4.0
  • HIPAA
  • ISO 42001
  • All toolkits →

Company

  • About Us
  • Blog
  • Contact
  • FAQ
  • Which toolkit do I need?
  • Free templates
  • SoA generator
  • RSS feeds

Policies

  • Privacy Policy
  • Terms & Conditions
  • Refund & Return Policy
  • Delivery Policy
Browse by topicISO 27001ISO 42001 & AI governanceGDPRSOC 2HIPAANIS2DORAISO 9001Management systemsSecurity frameworks
© 2026 Governance Docs LLC. All rights reserved.
Secure checkoutstripeVISA