Resources
IT guides and security policy templates
A library of guides, templates, checklists, cheat sheets, whitepapers, case studies, and datasheets, written in plain language. They cover cloud setup and cost governance, networking, identity, platform configuration, and information security.
Everything here is free to adapt for your organization. Treat the templates and everything else as general-purpose starting points. Adapt them to how your organization actually works before relying on them, and where a topic touches law, regulation, or insurance, involve a qualified advisor. None of it is legal advice.
The policy templates map to ISO/IEC 27001:2022 Annex A and NIST CSF 2.0. Where one follows a further or different standard, its card says so.
If you want help applying any of this, from a cloud project to a full security program, get in touch.
No resources match. Clear the search or filter, or try a different term.
-
Case study
Replacing per-store AWS Site-to-Site VPN with Tailscale subnet routers
How a specialty food and beverage retailer replaced 10 AWS Site-to-Site VPN connections that carried monitoring traffic with one Raspberry Pi per store running Tailscale as a subnet router.
Open the PDF -
Checklist
Cloud landing zone and account baseline across AWS, Azure, GCP, and OCI
Sixteen things to settle before any workload goes live in the cloud, from account structure and identity to logging and backup, with the matching service named for AWS, Azure, GCP, and OCI.
Open the PDF -
Datasheet
Identity standards, demystified
How apps and services prove who they are and reach an API, covering SAML, OpenID Connect, OAuth, passkeys, and SCIM, with the integration patterns and the mistakes that cause outages.
Open the PDF -
How-to guide
Cloud tagging and cost governance across AWS, Azure, GCP, and OCI
One tagging standard that works the same on AWS, Azure, GCP, and OCI, how each cloud enforces it, and the cost tools to reach for, with a one-week plan to get started.
Open the PDF -
How-to guide
nginx as a TLS reverse proxy on AWS
A hardened front door for a private backend on AWS: VPC segmentation, security groups, a Let's Encrypt certificate, modern TLS, and automated renewal. For Ubuntu 24.04 and Amazon Linux 2023.
Open the PDF -
How-to guide
Establish a secure server baseline on Linux
A new server setup blueprint: an admin account, automatic security updates, logging and auditing, SELinux or AppArmor, and the disk and encryption choices. For Debian, Ubuntu, and RHEL.
Open the PDF -
How-to guide
Harden Linux against CIS Benchmarks with OpenSCAP
Measure a running server against a CIS Benchmark with OpenSCAP, fix only the rules that failed, and keep the before-and-after evidence. For Fedora, RHEL, and Ubuntu.
Open the PDF -
How-to guide
Set up and secure a new GitHub account and organization
How to configure GitHub securely for a small team: account and commit signing, organization policies, third-party and token access, branch rulesets, and security scanning.
Open the PDF -
How-to guide
Move a GitHub repository to an organization without breaking Cloudflare Pages
How to move a repository into a GitHub organization when Cloudflare Pages deploys it: what the transfer carries, what to record first, and rebuilding the project and its domain.
Open the PDF -
How-to guide
Set up and secure a new Microsoft 365 tenant
A security baseline for a small business on Microsoft 365 Business Premium: admin accounts, MFA and Conditional Access, email protection, sharing, and audit logging.
Open the PDF -
How-to guide
Set up and secure a new Google Workspace organization
A security baseline for a small business on Google Workspace: super admin accounts, 2-Step Verification, app and API access, Gmail safety, sharing, and the alerts worth turning on.
Open the PDF -
How-to guide
Secure and harden SSH access on Linux
Key-only authentication, a CIS-aligned hardening drop-in, the brute-force defenses sshd now has built in, and when fail2ban still earns its place. For Fedora, RHEL, Ubuntu, and Arch.
Open the PDF -
How-to guide
Configure and harden a host firewall on Linux
Set up a default-deny inbound firewall with firewalld, ufw, or nftables without locking yourself out, and verify it from another machine. For Fedora, RHEL, Ubuntu, and Arch.
Open the PDF -
How-to guide
Set up a self-hosted WireGuard VPN on Linux
An encrypted tunnel between machines you control, for remote access to your own network or a full-tunnel VPN off untrusted Wi-Fi. Server and client setup, routing, NAT, and DNS.
Open the PDF -
How-to guide
Set up encrypted, validated DNS on Linux with Quad9
Encrypt your DNS lookups with Quad9 over DNS-over-TLS and validate the answers with DNSSEC, including how to stop your router's resolver taking over. For Fedora, RHEL, Ubuntu, and CachyOS.
Open the PDF -
How-to guide
Configure local VM and backup storage in Proxmox VE
Give each disk in a Proxmox VE node a job: an NVMe LVM-thin pool for VM disks, an ext4 directory for backups, and one held spare, then prove it with a full restore. Validated on Proxmox VE 9.2.10.
Open the PDF -
How-to guide
Configure a trusted Let's Encrypt certificate for Proxmox VE with Cloudflare DNS
Replace the cluster-signed Proxmox VE certificate with a trusted Let's Encrypt one through the ACME DNS-01 challenge on Cloudflare, with no port opened. Validated on Proxmox VE 9.2.10.
Open the PDF -
How-to guide
Configure Proxmox VE no-subscription updates for a homelab
Point a Proxmox VE homelab at the official no-subscription repository, keep the Debian base and security streams, and update safely. Validated on Proxmox VE 9.2.10 on Debian 13.
Open the PDF -
How-to guide
Configure AMD GPU passthrough to a Windows 11 VM in Proxmox VE
Hand a Windows 11 VM direct use of an AMD Radeon in Proxmox VE: IOMMU and isolation checks, VFIO binding, and a staged switch-over that keeps a recovery console. Validated on Proxmox VE 9.2.10.
Open the PDF -
How-to guide
Deploy Ubuntu 26.04 LTS Server on Proxmox VE
Build and validate an Ubuntu 26.04 LTS Server VM on Proxmox VE, with Secure Boot checked inside and outside the guest, VirtIO storage, and a restore-tested backup. Validated on Proxmox VE 9.2.10.
Open the PDF -
Cheatsheet
Docker Swarm cheat sheet
The Docker Swarm commands with what each one does: setting up and locking the cluster, rolling updates and rollback, stacks, secrets, overlay networks, and quorum recovery.
Open the PDF -
Cheatsheet
DevSecOps cheat sheet
What to check at each stage of software delivery and the tools that do it: secrets, code, dependency, container, and IaC scanning, SBOMs with signing, and DAST on staging.
Open the PDF -
Cheatsheet
DNS security records cheat sheet
The DNS records that protect a domain: SPF, DKIM, and DMARC to stop forged mail, MTA-STS to keep delivery encrypted, DNSSEC to stop forged answers, and CAA to control certificate issuance.
Open the PDF -
Whitepaper
Shadow IT: the silent threat inside your ISMS
What Shadow IT is, why it undermines an ISMS without anyone noticing, and how to find, assess, and govern it. Mapped to ISO/IEC 27001, NIST CSF 2.0, and the CIS Controls.
Open the PDF -
Whitepaper
A practical ISMS documentation structure for ISO 27001
A folder tree for your ISO/IEC 27001:2022 documents, arranged the way the standard is, so every mandatory record has a place and each policy folder names the free template that fills it.
Open the PDF -
Template
Information Security Policy template
The top-level policy the rest of the set hangs off: who owns security, how risk is judged and accepted, and the basics everyone signs up to when they join.
Download the template -
Template
Acceptable Use Policy template
The everyday rules for your staff, covering passwords, phishing, AI tools, and personal devices. Everyone reads and acknowledges this one and the Information Security Policy.
Download the template -
Template
AI Acceptable Use Policy template
Rules for staff using generative AI at work, from which tools are approved to what may be typed into one and who checks the output, aligned to the NIST AI Risk Management Framework.
Download the template -
Template
Access Control Policy template
Who gets access to what: joiners, movers, and leavers, least privilege, multi-factor authentication, and privileged access, with password rules that meet NIST SP 800-63B-4.
Download the template -
Template
Incident Response Policy template
How your team handles a security incident: severity levels and response targets, containment and recovery, ransomware and fraudulent payments, and breach notification. Follows NIST SP 800-61r3.
Download the template -
Template
Incident Response Plan Worksheet
The fill-in companion to the Incident Response Policy: who responds, the help arranged in advance, the first-hour steps, and an incident log, on five pages you print and keep offline.
Download the template -
Template
Data Handling Policy template
Three classification levels with handling rules for each, retention with legal holds, and secure disposal, so everyone knows what a document's label actually requires.
Download the template -
Template
Vendor Risk Management Policy template
How to vet and manage third parties: tiered assessments sized to the risk, the contract terms to insist on, monitoring with re-assessment triggers, and clean exits.
Download the template -
Checklist
Vendor Security Assessment Checklist
The fill-in companion to the Vendor Risk Management Policy: profile the vendor, set its risk tier, run the review that tier calls for, and record the gaps and the outcome.
Download the checklist -
Template
Vendor Security Questionnaire template
The questions to send a vendor when their published documentation leaves gaps: data handling, access, subprocessors, incidents, continuity, physical access, and any software they supply.
Download the template -
Template
Business Continuity & Disaster Recovery Plan template
Who takes charge when the business stops, what comes back first, how backups get tested, and runbooks for ransomware, site loss, and losing the person who knows how it works.
Download the template -
Template
Remote Work & Mobile Device Policy template
Working away from the office: what a device must meet, how a personal one gets approved, what changes when travelling, and what happens when one is lost.
Download the template -
Template
Vulnerability Management Policy template
Scan schedules, priorities set by real risk rather than by score alone, deadlines to fix by, and automated patching with a snapshot to roll back to when one breaks something.
Download the template -
Template
Change Management Policy template
How a change gets requested, reviewed, and released, including who approves one that weakens a protection and what happens when an emergency fix goes in first.
Download the template -
Template
Encryption Policy template
What to encrypt in transit and at rest, which methods are approved, how keys are made, stored, and retired, and disposal by destroying the key rather than the disk.
Download the template -
Template
Secure Development Policy template
Threat modeling at design, secure coding and review, components and SBOMs, security testing, and building AI features, following NIST's SSDF and OWASP ASVS 5.0.0.
Download the template -
Template
Physical and Environmental Security Policy template
Secure areas and who may enter them, monitoring and the notice it requires, protection from fire, water, and power loss, equipment handling, and secure disposal.
Download the template -
Template
Logging and Monitoring Policy template
What gets logged, where the logs live, how long they are kept, who reviews them, and how to prove the coverage is real. Aligned to CIS Control 8, Audit Log Management.
Download the template -
Template
Email Security Policy template
The organization's side of email security: SPF, DKIM, and DMARC on your domains, provider filtering, the mailbox rules that catch business email compromise, and what to watch.
Download the template -
Template
Risk Register template
A ready-to-use register that scores likelihood and impact, colors each risk by level, and records who owns it, how it is treated, and who accepted it. Aligned to ISO/IEC 27001:2022.
Download the template -
Template
Asset Inventory template
A ready-to-use inventory of hardware, software, cloud services, and information, with owners, classification, and criticality, plus tabs for keys, certificates, and approved channels.
Download the template -
Template
Exception Register template
Record approved policy deviations with the safeguards that make each one tolerable, who approved it, when it expires, and how often it has been renewed.
Download the template -
Template
Vendor / Supplier Register template
Keep every third party in one register, with risk tiers, assessment dates, the contract terms agreed, and reminders when a re-assessment falls due.
Download the template