Resources

IT guides and security policy templates

A library of guides, templates, checklists, cheat sheets, whitepapers, case studies, and datasheets, written in plain language. They cover cloud setup and cost governance, networking, identity, platform configuration, and information security.

Everything here is free to adapt for your organization. Treat the templates and everything else as general-purpose starting points. Adapt them to how your organization actually works before relying on them, and where a topic touches law, regulation, or insurance, involve a qualified advisor. None of it is legal advice.

The policy templates map to ISO/IEC 27001:2022 Annex A and NIST CSF 2.0. Where one follows a further or different standard, its card says so.

If you want help applying any of this, from a cloud project to a full security program, get in touch.

  • Case study

    Replacing per-store AWS Site-to-Site VPN with Tailscale subnet routers

    How a specialty food and beverage retailer replaced 10 AWS Site-to-Site VPN connections that carried monitoring traffic with one Raspberry Pi per store running Tailscale as a subnet router.

    PDF · 10 pages · Published

    Open the PDF
  • Checklist

    Cloud landing zone and account baseline across AWS, Azure, GCP, and OCI

    Sixteen things to settle before any workload goes live in the cloud, from account structure and identity to logging and backup, with the matching service named for AWS, Azure, GCP, and OCI.

    PDF · 18 pages · Published

    Open the PDF
  • Datasheet

    Identity standards, demystified

    How apps and services prove who they are and reach an API, covering SAML, OpenID Connect, OAuth, passkeys, and SCIM, with the integration patterns and the mistakes that cause outages.

    PDF · 8 pages · Published

    Open the PDF
  • How-to guide

    Cloud tagging and cost governance across AWS, Azure, GCP, and OCI

    One tagging standard that works the same on AWS, Azure, GCP, and OCI, how each cloud enforces it, and the cost tools to reach for, with a one-week plan to get started.

    PDF · 7 pages · Published

    Open the PDF
  • How-to guide

    nginx as a TLS reverse proxy on AWS

    A hardened front door for a private backend on AWS: VPC segmentation, security groups, a Let's Encrypt certificate, modern TLS, and automated renewal. For Ubuntu 24.04 and Amazon Linux 2023.

    PDF · 16 pages · Published

    Open the PDF
  • How-to guide

    Establish a secure server baseline on Linux

    A new server setup blueprint: an admin account, automatic security updates, logging and auditing, SELinux or AppArmor, and the disk and encryption choices. For Debian, Ubuntu, and RHEL.

    PDF · 17 pages · Published

    Open the PDF
  • How-to guide

    Harden Linux against CIS Benchmarks with OpenSCAP

    Measure a running server against a CIS Benchmark with OpenSCAP, fix only the rules that failed, and keep the before-and-after evidence. For Fedora, RHEL, and Ubuntu.

    PDF · 11 pages · Published

    Open the PDF
  • How-to guide

    Set up and secure a new GitHub account and organization

    How to configure GitHub securely for a small team: account and commit signing, organization policies, third-party and token access, branch rulesets, and security scanning.

    PDF · 23 pages · Published

    Open the PDF
  • How-to guide

    Move a GitHub repository to an organization without breaking Cloudflare Pages

    How to move a repository into a GitHub organization when Cloudflare Pages deploys it: what the transfer carries, what to record first, and rebuilding the project and its domain.

    PDF · 14 pages · Published

    Open the PDF
  • How-to guide

    Set up and secure a new Microsoft 365 tenant

    A security baseline for a small business on Microsoft 365 Business Premium: admin accounts, MFA and Conditional Access, email protection, sharing, and audit logging.

    PDF · 25 pages · Published

    Open the PDF
  • How-to guide

    Set up and secure a new Google Workspace organization

    A security baseline for a small business on Google Workspace: super admin accounts, 2-Step Verification, app and API access, Gmail safety, sharing, and the alerts worth turning on.

    PDF · 21 pages · Published

    Open the PDF
  • How-to guide

    Secure and harden SSH access on Linux

    Key-only authentication, a CIS-aligned hardening drop-in, the brute-force defenses sshd now has built in, and when fail2ban still earns its place. For Fedora, RHEL, Ubuntu, and Arch.

    PDF · 24 pages · Published

    Open the PDF
  • How-to guide

    Configure and harden a host firewall on Linux

    Set up a default-deny inbound firewall with firewalld, ufw, or nftables without locking yourself out, and verify it from another machine. For Fedora, RHEL, Ubuntu, and Arch.

    PDF · 14 pages · Published

    Open the PDF
  • How-to guide

    Set up a self-hosted WireGuard VPN on Linux

    An encrypted tunnel between machines you control, for remote access to your own network or a full-tunnel VPN off untrusted Wi-Fi. Server and client setup, routing, NAT, and DNS.

    PDF · 15 pages · Published

    Open the PDF
  • How-to guide

    Set up encrypted, validated DNS on Linux with Quad9

    Encrypt your DNS lookups with Quad9 over DNS-over-TLS and validate the answers with DNSSEC, including how to stop your router's resolver taking over. For Fedora, RHEL, Ubuntu, and CachyOS.

    PDF · 15 pages · Published

    Open the PDF
  • How-to guide

    Configure local VM and backup storage in Proxmox VE

    Give each disk in a Proxmox VE node a job: an NVMe LVM-thin pool for VM disks, an ext4 directory for backups, and one held spare, then prove it with a full restore. Validated on Proxmox VE 9.2.10.

    PDF · 10 pages · Published

    Open the PDF
  • How-to guide

    Configure a trusted Let's Encrypt certificate for Proxmox VE with Cloudflare DNS

    Replace the cluster-signed Proxmox VE certificate with a trusted Let's Encrypt one through the ACME DNS-01 challenge on Cloudflare, with no port opened. Validated on Proxmox VE 9.2.10.

    PDF · 8 pages · Published

    Open the PDF
  • How-to guide

    Configure Proxmox VE no-subscription updates for a homelab

    Point a Proxmox VE homelab at the official no-subscription repository, keep the Debian base and security streams, and update safely. Validated on Proxmox VE 9.2.10 on Debian 13.

    PDF · 9 pages · Published

    Open the PDF
  • How-to guide

    Configure AMD GPU passthrough to a Windows 11 VM in Proxmox VE

    Hand a Windows 11 VM direct use of an AMD Radeon in Proxmox VE: IOMMU and isolation checks, VFIO binding, and a staged switch-over that keeps a recovery console. Validated on Proxmox VE 9.2.10.

    PDF · 11 pages · Published

    Open the PDF
  • How-to guide

    Deploy Ubuntu 26.04 LTS Server on Proxmox VE

    Build and validate an Ubuntu 26.04 LTS Server VM on Proxmox VE, with Secure Boot checked inside and outside the guest, VirtIO storage, and a restore-tested backup. Validated on Proxmox VE 9.2.10.

    PDF · 11 pages · Published

    Open the PDF
  • Cheatsheet

    Docker Swarm cheat sheet

    The Docker Swarm commands with what each one does: setting up and locking the cluster, rolling updates and rollback, stacks, secrets, overlay networks, and quorum recovery.

    PDF · 6 pages · Published

    Open the PDF
  • Cheatsheet

    DevSecOps cheat sheet

    What to check at each stage of software delivery and the tools that do it: secrets, code, dependency, container, and IaC scanning, SBOMs with signing, and DAST on staging.

    PDF · 5 pages · Published

    Open the PDF
  • Cheatsheet

    DNS security records cheat sheet

    The DNS records that protect a domain: SPF, DKIM, and DMARC to stop forged mail, MTA-STS to keep delivery encrypted, DNSSEC to stop forged answers, and CAA to control certificate issuance.

    PDF · 5 pages · Published

    Open the PDF
  • Whitepaper

    Shadow IT: the silent threat inside your ISMS

    What Shadow IT is, why it undermines an ISMS without anyone noticing, and how to find, assess, and govern it. Mapped to ISO/IEC 27001, NIST CSF 2.0, and the CIS Controls.

    PDF · 7 pages · Published

    Open the PDF
  • Whitepaper

    A practical ISMS documentation structure for ISO 27001

    A folder tree for your ISO/IEC 27001:2022 documents, arranged the way the standard is, so every mandatory record has a place and each policy folder names the free template that fills it.

    PDF · 6 pages · Published

    Open the PDF
  • Template

    Information Security Policy template

    The top-level policy the rest of the set hangs off: who owns security, how risk is judged and accepted, and the basics everyone signs up to when they join.

    DOCX · 8 pages · Published

    Download the template
  • Template

    Acceptable Use Policy template

    The everyday rules for your staff, covering passwords, phishing, AI tools, and personal devices. Everyone reads and acknowledges this one and the Information Security Policy.

    DOCX · 8 pages · Published

    Download the template
  • Template

    AI Acceptable Use Policy template

    Rules for staff using generative AI at work, from which tools are approved to what may be typed into one and who checks the output, aligned to the NIST AI Risk Management Framework.

    DOCX · 10 pages · Published

    Download the template
  • Template

    Access Control Policy template

    Who gets access to what: joiners, movers, and leavers, least privilege, multi-factor authentication, and privileged access, with password rules that meet NIST SP 800-63B-4.

    DOCX · 8 pages · Published

    Download the template
  • Template

    Incident Response Policy template

    How your team handles a security incident: severity levels and response targets, containment and recovery, ransomware and fraudulent payments, and breach notification. Follows NIST SP 800-61r3.

    DOCX · 10 pages · Published

    Download the template
  • Template

    Incident Response Plan Worksheet

    The fill-in companion to the Incident Response Policy: who responds, the help arranged in advance, the first-hour steps, and an incident log, on five pages you print and keep offline.

    DOCX · 5 pages · Published

    Download the template
  • Template

    Data Handling Policy template

    Three classification levels with handling rules for each, retention with legal holds, and secure disposal, so everyone knows what a document's label actually requires.

    DOCX · 8 pages · Published

    Download the template
  • Template

    Vendor Risk Management Policy template

    How to vet and manage third parties: tiered assessments sized to the risk, the contract terms to insist on, monitoring with re-assessment triggers, and clean exits.

    DOCX · 8 pages · Published

    Download the template
  • Checklist

    Vendor Security Assessment Checklist

    The fill-in companion to the Vendor Risk Management Policy: profile the vendor, set its risk tier, run the review that tier calls for, and record the gaps and the outcome.

    DOCX · 6 pages · Published

    Download the checklist
  • Template

    Vendor Security Questionnaire template

    The questions to send a vendor when their published documentation leaves gaps: data handling, access, subprocessors, incidents, continuity, physical access, and any software they supply.

    DOCX · 5 pages · Published

    Download the template
  • Template

    Business Continuity & Disaster Recovery Plan template

    Who takes charge when the business stops, what comes back first, how backups get tested, and runbooks for ransomware, site loss, and losing the person who knows how it works.

    DOCX · 9 pages · Published

    Download the template
  • Template

    Remote Work & Mobile Device Policy template

    Working away from the office: what a device must meet, how a personal one gets approved, what changes when travelling, and what happens when one is lost.

    DOCX · 11 pages · Published

    Download the template
  • Template

    Vulnerability Management Policy template

    Scan schedules, priorities set by real risk rather than by score alone, deadlines to fix by, and automated patching with a snapshot to roll back to when one breaks something.

    DOCX · 7 pages · Published

    Download the template
  • Template

    Change Management Policy template

    How a change gets requested, reviewed, and released, including who approves one that weakens a protection and what happens when an emergency fix goes in first.

    DOCX · 6 pages · Published

    Download the template
  • Template

    Encryption Policy template

    What to encrypt in transit and at rest, which methods are approved, how keys are made, stored, and retired, and disposal by destroying the key rather than the disk.

    DOCX · 7 pages · Published

    Download the template
  • Template

    Secure Development Policy template

    Threat modeling at design, secure coding and review, components and SBOMs, security testing, and building AI features, following NIST's SSDF and OWASP ASVS 5.0.0.

    DOCX · 13 pages · Published

    Download the template
  • Template

    Physical and Environmental Security Policy template

    Secure areas and who may enter them, monitoring and the notice it requires, protection from fire, water, and power loss, equipment handling, and secure disposal.

    DOCX · 7 pages · Published

    Download the template
  • Template

    Logging and Monitoring Policy template

    What gets logged, where the logs live, how long they are kept, who reviews them, and how to prove the coverage is real. Aligned to CIS Control 8, Audit Log Management.

    DOCX · 6 pages · Published

    Download the template
  • Template

    Email Security Policy template

    The organization's side of email security: SPF, DKIM, and DMARC on your domains, provider filtering, the mailbox rules that catch business email compromise, and what to watch.

    DOCX · 5 pages · Published

    Download the template
  • Template

    Risk Register template

    A ready-to-use register that scores likelihood and impact, colors each risk by level, and records who owns it, how it is treated, and who accepted it. Aligned to ISO/IEC 27001:2022.

    XLSX · 3 sheets · Published

    Download the template
  • Template

    Asset Inventory template

    A ready-to-use inventory of hardware, software, cloud services, and information, with owners, classification, and criticality, plus tabs for keys, certificates, and approved channels.

    XLSX · 5 sheets · Published

    Download the template
  • Template

    Exception Register template

    Record approved policy deviations with the safeguards that make each one tolerable, who approved it, when it expires, and how often it has been renewed.

    XLSX · 2 sheets · Published

    Download the template
  • Template

    Vendor / Supplier Register template

    Keep every third party in one register, with risk tiers, assessment dates, the contract terms agreed, and reminders when a re-assessment falls due.

    XLSX · 2 sheets · Published

    Download the template