Independent security assurance and editable documentation to keep organizations secure, compliant and resilient Questions? contact@rootguardsecurity.com

Resources

Free tools, plain-language guides and framework reference. Everything here is free, and none of it needs an account.

Downloads

Thirteen free tools

Thirteen self-scoring workbooks and complete production-ready documents, built to the same standard we deliver to paying clients. The four below are the most used; the rest are on the free tools page.

Security Readiness Assessment

Eighty questions across all six framework functions. Every control is asked twice: do you do this, and could you prove it today.

Download

Risk Register

Auto-scoring matrix, likelihood and impact before and after treatment, with a worked example and adaptable scales.

Download

Incident Response Plan

Eight pages. Severity definitions, roles, contact list, the six phases, incident log and after-action record.

Download

Information Security Policy

Fifteen sections, written to be cut down to your organization rather than adopted whole.

Download

Free guides

The questions buyers actually ask

Plain-language explainers, written for the person who has to answer a questionnaire rather than for a security team.

GuideWhat it answersStatus
Answering a customer security questionnaireWhat the forty questions are really asking, and how to answer each with evidence rather than a claimIn preparation
Policies vs standards vs procedures vs evidenceWhy documentation fails audits, and which layer is missing when it doesIn preparation
Which framework applies to youNIST CSF, ISO 27001, SOC 2 and CMMC, and how to tell which one your buyers meanIn preparation
What an insurer is really asking at renewalThe controls behind the application questions, and what evidence supports eachIn preparation

Guides are published as they are written. If one of these would be useful now, tell us and we will send a draft.

Framework reference

What maps to which standard

FrameworkWho asks for itWhat we provide
NIST CSF 2.0Boards, insurers, general customer due diligenceThe spine of our 242-control assessment, and the Security Program Pack
ISO 27001 / 27002Overseas customers, tender processesCrosswalked control set and mapped documentation
CIS Controls v8Technical reviewers, MSP contractsCrosswalked control set
SOC 2 Trust Services CriteriaUS customers of service providersSOC 2 Readiness Pack and evidence structure
CMMC / NIST SP 800-171US defense supply chainLevel 1 and Level 2 packs. We prepare; assessment is by an authorized body

Not sure which applies?

Tell us who is asking

The right framework is usually decided by whoever is asking you for proof. Tell us who that is and we will say which one matters, with the reasoning.