Artefacts from other books
This audit is a frozen example calculated at development time.
Office files are not copied into demo/audit/. Links on in-pack cards
open source/ in this ZIP. Named artefacts that belong to another
book open an acquire page instead of a missing file.
This archive is Volume 1. Unpack the other book's
Office SKU under source/volume-N/{basic,premium}/ so
MANIFEST.json is in that folder.
- ISO 27003 / 27004 Conformance Matrix (27003-27004-MAP) — Volume 2 — Implementation & Certification
- Access Control Matrix (ACM) — Volume 2 — Implementation & Certification, Volume 3 — Secure Engineering
- AI System Governance File (AISGF) — Volume 5 — Dual Compliance
- Asset Owner Asset Validation Checklist (AOAVC) — Volume 2 — Implementation & Certification, Volume 3 — Secure Engineering
- Asset Owner Risk Validation Checklist (AORVC) — Volume 2 — Implementation & Certification
- Access Request and Approval (ARA) — Volume 3 — Secure Engineering
- Access Rights Register (ARR) — Volume 2 — Implementation & Certification, Volume 3 — Secure Engineering
- Application Security Testing Register (ASTR) — Volume 3 — Secure Engineering
- Auditor Evidence Request Log (AUD-ER) — Volume 2 — Implementation & Certification
- Business Continuity Plan (BCP) (BCP) — Volume 4 — Secure Operations
- Business Continuity Policy (BCPOL) — Volume 4 — Secure Operations
- Business Impact Analysis (BIA) Statement (BIA) — Volume 4 — Secure Operations
- Backup & Recovery Policy (BRP) — Volume 3 — Secure Engineering, Volume 4 — Secure Operations
- Backup & Recovery Procedure (BRPROC) — Volume 3 — Secure Engineering, Volume 4 — Secure Operations
- Backup Restore Test Record (BRT-R) — Volume 4 — Secure Operations
- BSI C5 Criteria Mapping (C5-CM) — Volume 5 — Dual Compliance
- Certification Body Selection and Evaluation (CB-SEL) — Volume 2 — Implementation & Certification
- UK Cyber Essentials Self-Assessment (CE-SA) — Volume 5 — Dual Compliance
- Certification Audit Dry-Run Workbook (CERT-DR) — Volume 2 — Implementation & Certification
- Certification Project Plan (CERT-P) — Volume 2 — Implementation & Certification
- Cross-Framework Evidence Crosswalk (CFE-X) — Volume 5 — Dual Compliance
- CI/CD Security Hardening Checklist (CICD-H) — Volume 3 — Secure Engineering
- Continual Improvement Log (CIL) — Volume 2 — Implementation & Certification
- Cryptography & Key Management Policy (CKMP) — Volume 3 — Secure Engineering, Volume 4 — Secure Operations
- Cloud Security Baseline Checklist (CLD-BL) — Volume 4 — Secure Operations
- Change Management Policy & Procedure (CMP) — Volume 3 — Secure Engineering
- Competence Matrix and Training Plan (CMTP) — Volume 2 — Implementation & Certification
- ISMS Communication Plan (COMM-P) — Volume 2 — Implementation & Certification
- Cryptography Policy (CP) — Volume 3 — Secure Engineering, Volume 4 — Secure Operations
- CRA Product Security File (CRA-PSF) — Volume 5 — Dual Compliance
- Cloud Security Policy (CSP) — Volume 3 — Secure Engineering, Volume 4 — Secure Operations
- Critical Services Register (CSR) — Volume 5 — Dual Compliance
- Cloud Shared Responsibility Matrix (CSRM) — Volume 3 — Secure Engineering
- Contract Security Schedule (CSS) — Volume 2 — Implementation & Certification
- Document Control Procedure (DCP) — Volume 2 — Implementation & Certification
- Dependency Risk Assessment (DEP-RISK) — Volume 3 — Secure Engineering
- Documented Operating Procedure Template (DOP) — Volume 2 — Implementation & Certification
- Data Processing Activities Register (GDPR) (DPAR) — Volume 3 — Secure Engineering, Volume 5 — Dual Compliance
- Data Protection Impact Assessment (DPIA) — Volume 5 — Dual Compliance
- Data Processors Register (GDPR) (DPR) — Volume 3 — Secure Engineering, Volume 5 — Dual Compliance
- Disaster Recovery Plan (DRP) (DRP) — Volume 4 — Secure Operations
- Data Subject Request Case File (DSAR) — Volume 5 — Dual Compliance
- Evidence Log / Audit Pack Index (ELAI) — Volume 2 — Implementation & Certification
- ENS Categorization Decision Record (ENS-CAT) — Volume 5 — Dual Compliance
- ENS Measure-to-Evidence Index (ENS-MI) — Volume 5 — Dual Compliance
- Environmental Monitoring and Alert Log (ENV-LOG) — Volume 4 — Secure Operations
- Evacuation Plan (EP) — Volume 4 — Secure Operations
- Evacuation Drill Record (EVAC-DR) — Volume 4 — Secure Operations
- Exceptions Register (EXR) — Volume 2 — Implementation & Certification
- Facility Access Review Checklist (FAC-RV) — Volume 4 — Secure Operations
- Framework Delta Backlog (FDB) — Volume 5 — Dual Compliance
- Framework Mapping Index (FMI) — Volume 5 — Dual Compliance
- GDPR Breach Decision Record (GBDR) — Volume 5 — Dual Compliance
- Incident Log (IL) — Volume 3 — Secure Engineering, Volume 4 — Secure Operations
- Incident Management Policy (IMP) — Volume 2 — Implementation & Certification, Volume 3 — Secure Engineering, Volume 4 — Secure Operations
- Phased ISMS Implementation Plan (IMPL-P) — Volume 2 — Implementation & Certification
- Incident Response Runbooks (IR-RB) — Volume 4 — Secure Operations
- Incident Response Policy (IRP) — Volume 3 — Secure Engineering, Volume 4 — Secure Operations
- Incident Response Procedure (IRPROC) — Volume 3 — Secure Engineering, Volume 4 — Secure Operations
- Incident Register and Reporting Template (IRRT) — Volume 3 — Secure Engineering, Volume 4 — Secure Operations
- ISMS Change Log (ISMS-CL) — Volume 2 — Implementation & Certification
- BSI IT-Grundschutz Module Mapping (ITG-MM) — Volume 5 — Dual Compliance
- Cryptographic Key Register (KEY-R) — Volume 4 — Secure Operations
- Logging and Monitoring Policy (LMP) — Volume 3 — Secure Engineering, Volume 4 — Secure Operations
- Legal, Regulatory and Contractual Requirements Register (LRR) — Volume 2 — Implementation & Certification
- Mandatory Documents and Records Register (MDR) — Volume 2 — Implementation & Certification
- Multi-Framework Assurance Report (MFAR) — Volume 5 — Dual Compliance
- Nonconformity Response and Corrective Action Pack (NC-RP) — Volume 2 — Implementation & Certification
- Network Firewall Rule Review Register (NFR-R) — Volume 4 — Secure Operations
- NIS2 First-Hours Reporting Drill (NIS2-RD) — Volume 5 — Dual Compliance
- Network Security Policy (NSP) — Volume 3 — Secure Engineering, Volume 4 — Secure Operations
- Compliance Obligations Calendar (OBL-CAL) — Volume 5 — Dual Compliance
- Operations Evidence Register (OER) — Volume 4 — Secure Operations
- Operational Procedures Index (OPI) — Volume 4 — Secure Operations
- Password & Authentication Policy (PAP) — Volume 3 — Secure Engineering
- Physical Access Register (PAR) — Volume 4 — Secure Operations
- Process Owner Business Impact Validation Checklist (PBIVC) — Volume 2 — Implementation & Certification
- PCI DSS CDE Scope and Control Matrix (PCI-CDE) — Volume 5 — Dual Compliance
- Physical and Environmental Security Policy (PESP) — Volume 4 — Secure Operations
- Regulatory Change Impact Assessment (RCIA) — Volume 5 — Dual Compliance
- Security Release Gate Record (REL-GATE) — Volume 3 — Secure Engineering
- ISO 27001 Clauses 4-10 Requirements Tracker (REQT) — Volume 2 — Implementation & Certification
- ISMS Risks and Opportunities Register (ROAR) — Volume 2 — Implementation & Certification
- Response Procedure by Incident Type (RPIT) — Volume 3 — Secure Engineering, Volume 4 — Secure Operations
- Records Retention Schedule (RRS) — Volume 2 — Implementation & Certification
- Stage 1 Readiness Assessment (S1-RDY) — Volume 2 — Implementation & Certification
- Stage 2 Readiness and Sampling Assessment (S2-RDY) — Volume 2 — Implementation & Certification
- SBOM and Component Inventory Register (SBOM-R) — Volume 3 — Secure Engineering
- Secure Code Review Checklist (SCR-C) — Volume 3 — Secure Engineering
- Security Requirements Register (SEC-REQ) — Volume 3 — Secure Engineering
- Secrets Management Register (SECR) — Volume 3 — Secure Engineering
- Software Inventory (SI) — Volume 3 — Secure Engineering, Volume 4 — Secure Operations
- Security Incident Communication Template (SICT) — Volume 3 — Secure Engineering, Volume 4 — Secure Operations
- Security Incident Register (SIR) — Volume 3 — Secure Engineering, Volume 4 — Secure Operations
- SOC 2 Evidence Calendar (SOC2-EC) — Volume 5 — Dual Compliance
- SOC 2 System Description (SOC2-SD) — Volume 5 — Dual Compliance
- S-SDLC Implementation Requirements Checklist (SSDLC) — Volume 3 — Secure Engineering
- Secure Software Development Policy (SSDP) — Volume 3 — Secure Engineering
- Current Standard Supplement (STD-SUP) — Volume 2 — Implementation & Certification
- TISAX Assessment Scope and ISA Mapping (TISAX-AS) — Volume 5 — Dual Compliance
- Threat Modeling Worksheet (TMM) — Volume 3 — Secure Engineering
- Users and Access Inventory (UAI) — Volume 2 — Implementation & Certification, Volume 3 — Secure Engineering
- Vulnerability Remediation SLA Matrix (VULN-SLA) — Volume 3 — Secure Engineering
- Weekly Report (WIR-S1) — Volume 2 — Implementation & Certification, Volume 5 — Dual Compliance
- Cross-Framework Applicability Register (XFA-R) — Volume 5 — Dual Compliance
