About Us Contact Blog
Governance DocsGovernance Docs
Which Toolkit?SoA GeneratorFree TemplatesAboutBlogContactMy AccountCart
FOX v.2.4.9
Browse Toolkits
Governance Docs
  • Browse All Toolkits
  • Information Security & Cybersecurity
  • Data Privacy & Protection
  • Governance, Risk & Compliance
  • Quality Management
  • Health, Safety & Environment
  • AI Governance

My Account
CART

No products in the cart.

ISO 27001

What DORA Article 12 and NIS2 require of a backup policy

Backup Policy: 6 Proven Rules DORA Article 12 Sets

Governance Docs16th August 2026

Scope, frequency derived from classification, segregation from the source system, RTOs that hold in extreme scenarios, and reconciliation after the restore.
Read More
What DORA Articles 26 and 27 require for threat-led penetration testing

Threat-Led Penetration Testing: Who DORA Actually Requires It From

Governance Docs16th August 2026

DORA TLPT applies only to entities their regulator identifies. Live production systems, a scope the authority validates, and an attestation that travels.
Read More
What addressable means in the HIPAA safeguards under 45 CFR 164.306

HIPAA Safeguards: Addressable Does Not Mean Optional

Governance Docs16th August 2026

The HIPAA Security Rule labels specifications Required or Addressable. Addressable means assess, then implement or document why not and put an alternative in place.
Read More
The NIS2 management liability duties under Articles 20 and 32

NIS2 Management Liability: Three Duties on Named People

Governance Docs16th August 2026

NIS2 Article 20 makes management approve, oversee and be liable for cybersecurity measures — and Article 32(5) can bar a CEO from managerial functions.
Read More
The three control populations in a SOC 2 report including complementary user entity controls

Complementary User Entity Controls: The Half You Must Do

Governance Docs16th August 2026

A SOC 2 report lists controls the provider assumes you operate. Nobody tests them. How to extract, own and evidence complementary user entity controls.
Read More
What DORA Article 28(3) requires in the register of information

Register of Information: What DORA Article 28(3) Requires

Governance Docs16th August 2026

DORA's register of information carries four obligations, and the forward-looking ones get missed. All arrangements, prescribed templates, and the criticality trigger.
Read More
GDPR breach notification thresholds, audiences and timing

Breach Notification: Two Thresholds, Two Clocks

Governance Docs16th August 2026

GDPR breach notification is not one 72-hour rule. Two thresholds, two audiences, phased notification, and the log you must keep even when you do not notify.
Read More
TISAX Exchange steps and the active and passive participant roles

TISAX Exchange: The Half of TISAX Suppliers Never Use

Governance Docs15th August 2026

TISAX is an exchange mechanism, not a certificate. The four steps, why scope decides what customers receive, and the passive role most suppliers never use.
Read More
The SWIFT CSCF customer security controls framework and assessment routes

SWIFT CSCF: Your Independent Assessment Can Be Internal

Governance Docs15th August 2026

The SWIFT CSCF independent assessment can be performed by your own second or third line of defence, not only an external firm. The five-step journey explained.
Read More
SOX 404 filer status and the auditor attestation requirement

SOX 404: Who Needs the Auditor Attestation

Governance Docs15th August 2026

SOX 404(a) applies to every issuer; 404(b) only to some. The public float and revenue tests that decide it, read from the SEC's own compliance guide.
Read More
    ←
  • 1
  • …
  • 24
  • 25
  • 26
  • 27
  • 28
  • …
  • 33
  • →

Recent Posts

ISO 9001 certification timeline 2026: six stages from gap analysis to certificate, with the ISO 9001:2026 transition dates
ISO 9001 Certification Timeline: The Complete 2026 Guide

September 21, 2026

ISO 13485 certification timeline infographic: 6–18 months from kickoff to certificate, phase by phase
ISO 13485 Certification Timeline: The Complete 2026 Guide

September 20, 2026

ISO 27001 vs HIPAA infographic comparing the voluntary ISO/IEC 27001:2022 standard with the HIPAA federal law on scope, controls, proof and consequences
ISO 27001 vs HIPAA: 7 Essential Differences Explained (2026)

September 20, 2026

HITRUST vs ISO 27001 comparison: issuer, controls, scoring, validity and recognition side by side
HITRUST vs ISO 27001: 7 Essential Differences Explained (2026)

September 19, 2026

compliance consultant certifications explained
Compliance Consultant Certifications: 6 Essential Credentials

September 19, 2026

Categories

  • Articles
  • DORA
  • GDPR
  • HIPAA
  • ISO 27001
  • ISO 42001 & AI governance
  • ISO 9001
  • Management systems
  • NIS2
  • Security frameworks
  • SOC 2
Governance DocsGovernance Docs

Reliable ISO & compliance documentation toolkits that help your business meet regulatory standards with ease.

Governance Docs LLC
1209 Mountain Road Pl NE, Suite R
Albuquerque, NM 87110, USA
info@governancedocs.com
+1 812 227 5662

Toolkits

  • ISO 27001:2022
  • GDPR
  • SOC 2
  • PCI-DSS v4.0
  • HIPAA
  • ISO 42001
  • All toolkits →

Company

  • About Us
  • Blog
  • Contact
  • FAQ
  • Which toolkit do I need?
  • Free templates
  • SoA generator
  • RSS feeds

Policies

  • Privacy Policy
  • Terms & Conditions
  • Refund & Return Policy
  • Delivery Policy
  • Manage cookies
Browse by topicISO 27001ISO 42001 & AI governanceGDPRSOC 2HIPAANIS2DORAISO 9001Management systemsSecurity frameworks
© 2026 Governance Docs LLC. All rights reserved.
Secure checkoutstripeVISA