About Us Contact Blog
Governance DocsGovernance Docs
Which Toolkit?SoA GeneratorFree TemplatesGap AssessmentsBusiness Impact AnalysisAboutBlogContactMy AccountCart
FOX v.2.4.9
Browse Toolkits
Governance Docs
  • Browse All Toolkits
  • Information Security & Cybersecurity
  • Data Privacy & Protection
  • Governance, Risk & Compliance
  • Quality Management
  • Health, Safety & Environment
  • AI Governance

My Account

CART

No products in the cart.

Tag: Topic: Information Security

Derived from the related-toolkit resolver (WPCode 12925). Used to scope MailPoet post-notification digests. Archives noindexed.

NCA ECC implementation step by step

NCA ECC Implementation: A Clear Guide in 6 Steps

Governance Docs02nd September 2026

NCA ECC implementation in 6 steps: scope, gap assessment, governance, remediation, internal review and assessment - plus the…
Read More
Threat intelligence and ISO 27001 control 5.7

Threat Intelligence: A Clear Guide to ISO 27001 Control 5.7

Governance Docs02nd September 2026

Threat intelligence under ISO 27001 control 5.7: the 3 levels, the 5 artefacts that make it auditable, and…
Read More
The plan of action and milestones explained

Plan of Action and Milestones: A Clear POA&M Guide for 2026

Governance Docs02nd September 2026

A plan of action and milestones in 9 fields, where the POA&M is still required in 2026, where…
Read More
The cloud shared responsibility matrix

Shared Responsibility Matrix: A Clear Guide for ISO 27017

Governance Docs02nd September 2026

A shared responsibility matrix decides who patches, configures and restores. What goes in it across IaaS, PaaS and…
Read More
The CSA Cloud Controls Matrix and CAIQ

Cloud Controls Matrix: A Clear Guide to CCM v4.1 and the CAIQ

Governance Docs02nd September 2026

The Cloud Controls Matrix explained: 17 domains, how the CAIQ turns it into a STAR submission, what CCM…
Read More
The three HITRUST assessment types

HITRUST Assessments: A Clear Guide to e1, i1 and r2

Governance Docs02nd September 2026

The 3 HITRUST assessments compared: 43 controls at e1, 182 at i1, a tailored set at r2 -…
Read More
TX-RAMP certification levels explained

TX-RAMP: A Clear Guide to the 2 Texas Certification Levels

Governance Docs02nd September 2026

TX-RAMP explained: who must comply, the 2 certification levels, the 18-month provisional route, and which FedRAMP and GovRAMP…
Read More
SAMA CSF compared with the NCA ECC

SAMA CSF vs NCA ECC: A Clear Guide for Saudi Firms in 2026

Governance Docs02nd September 2026

SAMA CSF vs NCA ECC: who each binds, why one scores maturity 0-5 and the other tests compliance,…
Read More
The twenty NIST 800-53 control families

NIST 800-53 Control Families: A Clear Guide to All 20

Governance Docs02nd September 2026

All 20 NIST 800-53 control families with their two-letter IDs, base controls versus enhancements, and the 3 families…
Read More
The cybersecurity risk register template elements

Cybersecurity Risk Register: A Clear Guide to the 10 Elements

Governance Docs02nd September 2026

A cybersecurity risk register in 10 elements, from NIST IR 8286 Revision 1 - what each field is…
Read More
The seven steps of the NIST RMF

NIST RMF: A Clear Guide to the 7 Steps of SP 800-37

Governance Docs02nd September 2026

The NIST RMF in 7 steps, from Prepare to Monitor, with the publication behind each - and how…
Read More
CIS Benchmarks compared with the CIS Controls

CIS Benchmarks vs CIS Controls: A Clear Guide for 2026

Governance Docs02nd September 2026

CIS Benchmarks are configuration guides; CIS Controls are a prioritized program. What each covers, the 3 profile levels,…
Read More
    ←
  • 1
  • …
  • 7
  • 8
  • 9
  • 10
  • 11
  • …
  • 19
  • →

Recent Posts

Business Impact Analysis questionnaire with 30 essential questions for governance and risk.
Business Impact Analysis Questionnaire: 30 Essential Questions (2026)

September 26, 2026

Comparison of BIA and Risk Assessment for governance and business continuity planning.
BIA vs Risk Assessment: The Definitive 2026 Comparison

September 25, 2026

Business Impact Analysis example from Governance Docs website.
Business Impact Analysis Example: A Complete Worked BIA (2026)

September 25, 2026

Infographic answering is ISO 13485 worth it in 2026 with audit days, QMSR date and MDSAP regulators
Is ISO 13485 Worth It? The Complete 2026 Cost-Benefit Case

September 25, 2026

Is ISO 42001 worth it in 2026 — audit days, first-year cost and Annex A controls at a glance
Is ISO 42001 Worth It? The Complete 2026 Cost-Benefit Case

September 25, 2026

Categories

  • Articles
  • DORA
  • GDPR
  • HIPAA
  • ISO 27001
  • ISO 42001 & AI governance
  • ISO 9001
  • Management systems
  • NIS2
  • Security frameworks
  • SOC 2
Governance DocsGovernance Docs

Reliable ISO & compliance documentation toolkits that help your business meet regulatory standards with ease.

Governance Docs LLC
1209 Mountain Road Pl NE, Suite R
Albuquerque, NM 87110, USA
info@governancedocs.com
+1 812 227 5662

Toolkits

  • ISO 27001:2022
  • GDPR
  • SOC 2
  • PCI-DSS v4.0
  • HIPAA
  • ISO 42001
  • All toolkits →

Company

  • About Us
  • Blog
  • Contact
  • FAQ
  • Which toolkit do I need?
  • Free templates
  • SoA generator
  • Gap assessments
  • Business impact analysis
  • RSS feeds

Policies

  • Privacy Policy
  • Terms & Conditions
  • Refund & Return Policy
  • Delivery Policy
  • Manage cookies
Browse by topicISO 27001ISO 42001 & AI governanceGDPRSOC 2HIPAANIS2DORAISO 9001Management systemsSecurity frameworks
© 2026 Governance Docs LLC. All rights reserved.
Secure checkoutstripeVISA