Marketplace
Ready-to-deploy Information Security documentation.
Policies, standards, controls, procedures and assurance metrics, written by practising security professionals, mapped to NIST CSF 2.0 and ISO 27001 together, and delivered as editable files you own outright.
Free samples on every package, no email address required.
At a glance
2
Documentation packages
2
Frameworks, mapped side by side
€1,795
Starting price, one-time
1 yr
Framework updates included
The packages
Two packages, built from the same library
The smaller package is the governance layer: the policy and the standards that make it enforceable. The larger one is the full documentation stack, through to procedures and assurance metrics. If you are unsure which applies, contact us and we will advise, including when the smaller package is the right answer.
Governance and requirements
Information Security Policies and Standards Package
An information security policy and the full standards library that makes it enforceable, mapped to NIST CSF 2.0 and ISO 27001.
Information Security Framework Package
Policies, standards, control library, procedures, and assurance metrics, aligned to NIST CSF 2.0 and ISO 27001 together.
Side by side
What's in each package
Both start from the same policy and standards library, and both carry the dual framework mapping throughout. The framework package adds the layers an auditor tests a programme against.
| Policies and standards | Framework package | |
|---|---|---|
| Policy | ||
| Standards library | ||
| Control library | ||
| Procedures | ||
| Assurance metrics | ||
| Supporting templates | ||
| NIST CSF 2.0 + ISO 27001 | ||
| Price | €1,795 | €4,995 |
Why buy ours
Written to hold up in an audit
Four things that separate these from generic template packs.
Written by practitioners
Every clause was drafted by a working security professional who has implemented the control, produced the evidence, and had the scoping challenged by an assessor. Clauses are written to be tested and scope language to be challenged.
Both frameworks, every document
NIST CSF 2.0 and ISO 27001 mappings run side by side through the whole set, so a request for the other framework does not mean starting again.
Editable files you own
Plain Word and Excel under a single-organisation licence. There is no platform, no seat licence, and nothing that lapses. Tailor it, rebrand it, and keep it in your own systems.
Clear about the limits
No document set makes you compliant. What these packages save is the hundreds of hours of research, structuring and drafting. Tailoring and operating the programme are still your work.
How it works
Samples, checkout, download
There are no sales calls, onboarding sessions or platform accounts.
Read the samples
Free extracts from every package show the structure, tone and level of detail. No email address is required.
Buy and download
Checkout runs through Stripe and the files are yours within minutes, with a year of framework updates included.
Make it yours
Name owners, set thresholds and review cadences, delete what doesn't apply. Small organisations usually need days; complex ones, longer.
Put it to work
Publish it, operate against it, and provide it when a questionnaire or auditor asks.
Written and maintained by information security practitioners. Editable files, licensed to your organisation, no platform.
Read the samples before you decide.
Free extracts are available on both package pages. If they do not read as if they were written by someone who has done the work, do not buy the package.