Resources
Resources
Guides and templates we use on engagements: framework mapping, regulatory evidence, and the checklists that survive an auditor’s follow-up.
Compliance guides
Practical walkthroughs for finance and healthcare teams who have to show their work.
GDPR Compliance & Article 28 Security Measures
GDPR Article 28 security measures and data protection consulting for controllers, processors, and organizations navigating EU personal data requirements.
FINRA & SEC Technology Compliance
FINRA and SEC cybersecurity compliance consulting for broker-dealers and advisers—Rule 30, Regulation S-P, and SEC cybersecurity rules covered.
HIPAA Security & Privacy Compliance
HIPAA Security Rule and Privacy Rule compliance consulting, risk assessment, and audit preparation for healthcare and life sciences organizations.
Cybersecurity frameworks
How we implement the frameworks we actually map to, not a brochure version.
CIS Critical Security Controls Implementation
CIS Controls consulting for Implementation Groups 1–3. Prioritized control roadmaps, evidence libraries, and audit-ready documentation for CIS CSC compliance.
ISO 27001 Compliance & Audit Readiness
ISO 27001 implementation, Statement of Applicability development, and audit-ready evidence for organizations pursuing information security certification.
NIST Cybersecurity Framework Alignment
NIST CSF consulting and implementation. Map controls to CSF functions, produce audit-ready evidence, and demonstrate compliance to auditors and regulators.
SOC 2 Compliance Consulting & Trust Services Criteria Implementation
SOC 2 compliance consulting with Trust Services Criteria mapping and audit-ready Type I and Type II evidence packages built for auditor acceptance.
Templates and tools
Starting points for evidence libraries, tabletops, and vendor reviews.
ISO 27001 Statement of Applicability Examples
Practical Statement of Applicability examples, SoA rationale templates, and inclusion exclusion criteria for ISO 27001 certification audits.
NIST CSF Control Mapping Template
Free NIST CSF control mapping template and worksheet. Map your existing security controls to the NIST Cybersecurity Framework and identify gaps quickly.
Regulatory Compliance Crosswalk: NIST CSF to HIPAA, FINRA/SEC & GDPR Mapping
Practical reference showing how NIST Cybersecurity Framework maps to HIPAA Security Rule, FINRA/SEC requirements, and GDPR Article 32 for unified compliance.
BCDR Tabletop AAR Template
Free BCDR tabletop after-action report template to document lessons learned, remediation owners, and audit-ready evidence for compliance teams.
Platform Security Clarifications — Examples
Sample clarifications for Meta, Microsoft SSPA, and Google Workspace security reviews. Tight, evidence-based responses that reviewers accept.
SOC 2 Evidence Library Template
Organize SOC 2 evidence by Trust Services Criteria with ownership, refresh cadences, and bridge letters. Downloadable template for continuous compliance.
Microsoft SSPA Reassessment Guide
Navigate Microsoft SSPA reassessment with this guide covering common failure points, preparation steps, evidence requirements, and the review process timeline.
Vendor Review Evidence Checklist
Map Meta, Microsoft SSPA, and Google Workspace security review requirements to SOC 2, ISO 27001, NIST CSF, and CIS Controls with this evidence checklist.
Let's Talk
These pages are a starting point. If you need the mapping, the evidence, or the infrastructure work done—that's what we do.
Contact Us