About Us Contact Blog
Governance DocsGovernance Docs
Which Toolkit?SoA GeneratorFree TemplatesGap AssessmentsBusiness Impact AnalysisAboutBlogContactMy AccountCart
FOX v.2.4.9
Browse Toolkits
Governance Docs
  • Browse All Toolkits
  • Information Security & Cybersecurity
  • Data Privacy & Protection
  • Governance, Risk & Compliance
  • Quality Management
  • Health, Safety & Environment
  • AI Governance

My Account

CART

No products in the cart.

Tag: Topic: Information Security

Derived from the related-toolkit resolver (WPCode 12925). Used to scope MailPoet post-notification digests. Archives noindexed.

FTC Safeguards Rule breach notification explained

FTC Safeguards Rule Breach Notification: The 30-Day WISP Rule

Governance Docs18th September 2026

FTC Safeguards Rule breach notification under 314.4(j): the notification-event definition, deemed discovery, 500 consumers, 30 days, the 6…
Read More
FTC Safeguards Rule penalties explained

FTC Safeguards Rule Penalties: The Complete WISP Enforcement Guide

Governance Docs18th September 2026

FTC Safeguards Rule penalties: no fine in the Rule, section 5 orders with 20-year obligations, $53,088 per violation…
Read More
Qualified Individual explained

Qualified Individual: The Complete WISP and Safeguards Rule Guide

Governance Docs18th September 2026

The Qualified Individual under 16 CFR 314.4(a): what the Rule requires, what qualified means, 3 ways to fill…
Read More
NIST CSF vs ISO 27001 explained

NIST CSF vs ISO 27001: 5 Clear Differences Explained (2026)

Governance Docs18th September 2026

NIST CSF vs ISO 27001 on 5 differences: outcome framework vs certifiable system, Profiles vs certificate, scope, prescription,…
Read More
SAMA Business Continuity Management Framework explained

SAMA Business Continuity Management Framework: 9 Principles (2026)

Governance Docs18th September 2026

The SAMA Business Continuity Management Framework (2017): 9 principles, the control considerations that decide findings, annual BCP and…
Read More
CIS Controls ISO 27001 mapping explained

CIS Controls ISO 27001 Mapping: All 18 Controls to Annex A (2026)

Governance Docs18th September 2026

CIS Controls ISO 27001 mapping: all 18 Controls to the 93 Annex A controls of ISO 27001:2022, where…
Read More
NIST 800-53 Rev 5 vs Rev 4 explained

NIST 800-53 Rev 5 vs Rev 4: The 7 Clear Changes (2026)

Governance Docs18th September 2026

NIST 800-53 Rev 5 vs Rev 4: the 7 changes NIST lists, the new PT and SR families,…
Read More
NIST 800-53A explained

NIST 800-53A: The Clear Guide to Assessment Procedures

Governance Docs18th September 2026

NIST 800-53A Rev 5 explained: determination statements, the 3 methods (examine, interview, test), 4 object types, depth and…
Read More
NIST 800-53 overlays explained

NIST 800-53 Overlays: The 7 Categories Explained (2026)

Governance Docs18th September 2026

NIST 800-53 overlays: the 800-53B definition, the 7 categories, baseline vs overlay vs tailoring, published overlays (SP 800-82,…
Read More
NIST 800-53 vs ISO 27001 explained

NIST 800-53 vs ISO 27001: 5 Clear Differences Explained

Governance Docs18th September 2026

NIST 800-53 vs ISO 27001 on 5 differences: catalogue vs certifiable system, baseline vs risk assessment, granularity, assessment…
Read More
Cyber Essentials requirements explained

Cyber Essentials Requirements: The 5 Controls Explained (2026)

Governance Docs18th September 2026

Cyber Essentials requirements v3.3: the 5 controls with numbers — 14-day patching, MFA on cloud, 12-character passwords, 10-attempt…
Read More
Cyber Essentials scope explained

Cyber Essentials Scope: 12 Essential In-or-Out Rules (2026)

Governance Docs18th September 2026

Cyber Essentials scope under v3.3: whole organisation vs sub-set, 12 device rules, the role-based BYOD table, cloud never…
Read More
    ←
  • 1
  • 2
  • 3
  • 4
  • 5
  • …
  • 19
  • →

Recent Posts

Business Impact Analysis questionnaire with 30 essential questions for governance and risk.
Business Impact Analysis Questionnaire: 30 Essential Questions (2026)

September 26, 2026

Comparison of BIA and Risk Assessment for governance and business continuity planning.
BIA vs Risk Assessment: The Definitive 2026 Comparison

September 25, 2026

Business Impact Analysis example from Governance Docs website.
Business Impact Analysis Example: A Complete Worked BIA (2026)

September 25, 2026

Infographic answering is ISO 13485 worth it in 2026 with audit days, QMSR date and MDSAP regulators
Is ISO 13485 Worth It? The Complete 2026 Cost-Benefit Case

September 25, 2026

Is ISO 42001 worth it in 2026 — audit days, first-year cost and Annex A controls at a glance
Is ISO 42001 Worth It? The Complete 2026 Cost-Benefit Case

September 25, 2026

Categories

  • Articles
  • DORA
  • GDPR
  • HIPAA
  • ISO 27001
  • ISO 42001 & AI governance
  • ISO 9001
  • Management systems
  • NIS2
  • Security frameworks
  • SOC 2
Governance DocsGovernance Docs

Reliable ISO & compliance documentation toolkits that help your business meet regulatory standards with ease.

Governance Docs LLC
1209 Mountain Road Pl NE, Suite R
Albuquerque, NM 87110, USA
info@governancedocs.com
+1 812 227 5662

Toolkits

  • ISO 27001:2022
  • GDPR
  • SOC 2
  • PCI-DSS v4.0
  • HIPAA
  • ISO 42001
  • All toolkits →

Company

  • About Us
  • Blog
  • Contact
  • FAQ
  • Which toolkit do I need?
  • Free templates
  • SoA generator
  • Gap assessments
  • Business impact analysis
  • RSS feeds

Policies

  • Privacy Policy
  • Terms & Conditions
  • Refund & Return Policy
  • Delivery Policy
  • Manage cookies
Browse by topicISO 27001ISO 42001 & AI governanceGDPRSOC 2HIPAANIS2DORAISO 9001Management systemsSecurity frameworks
© 2026 Governance Docs LLC. All rights reserved.
Secure checkoutstripeVISA