Bell Tower logo

Resources

Resources

Guides and templates we use on engagements: framework mapping, regulatory evidence, and the checklists that survive an auditor’s follow-up.

Compliance guides

Practical walkthroughs for finance and healthcare teams who have to show their work.

Cybersecurity frameworks

How we implement the frameworks we actually map to, not a brochure version.

Templates and tools

Starting points for evidence libraries, tabletops, and vendor reviews.

ISO 27001 Statement of Applicability Examples

Practical Statement of Applicability examples, SoA rationale templates, and inclusion exclusion criteria for ISO 27001 certification audits.

NIST CSF Control Mapping Template

Free NIST CSF control mapping template and worksheet. Map your existing security controls to the NIST Cybersecurity Framework and identify gaps quickly.

Regulatory Compliance Crosswalk: NIST CSF to HIPAA, FINRA/SEC & GDPR Mapping

Practical reference showing how NIST Cybersecurity Framework maps to HIPAA Security Rule, FINRA/SEC requirements, and GDPR Article 32 for unified compliance.

BCDR Tabletop AAR Template

Free BCDR tabletop after-action report template to document lessons learned, remediation owners, and audit-ready evidence for compliance teams.

Platform Security Clarifications — Examples

Sample clarifications for Meta, Microsoft SSPA, and Google Workspace security reviews. Tight, evidence-based responses that reviewers accept.

SOC 2 Evidence Library Template

Organize SOC 2 evidence by Trust Services Criteria with ownership, refresh cadences, and bridge letters. Downloadable template for continuous compliance.

Microsoft SSPA Reassessment Guide

Navigate Microsoft SSPA reassessment with this guide covering common failure points, preparation steps, evidence requirements, and the review process timeline.

Vendor Review Evidence Checklist

Map Meta, Microsoft SSPA, and Google Workspace security review requirements to SOC 2, ISO 27001, NIST CSF, and CIS Controls with this evidence checklist.

Let's Talk

These pages are a starting point. If you need the mapping, the evidence, or the infrastructure work done—that's what we do.

Contact Us