CIS Critical Security Controls
Unknown
Center for Internet Security's prioritized set of defensive safeguards, grouped into implementation groups so smaller organizations know which controls to adopt first. Free download, with mappings to NIST CSF, ISO 27001 and other frameworks.
More resources on Cybersecurity Policies
SANS Institute Free Resources
Library of free, customizable information security policy templates maintained by SANS with the Cybersecurity Risk Foundation, spanning acceptable use, passwords, encryption, email and incident response. Gives a starting draft rather than a finished policy.
ISO 27001 Official Site
ISO catalogue entry for ISO/IEC 27001:2022, the certifiable standard for information security management systems. Sets out risk assessment and treatment requirements plus the 93 Annex A controls; the abstract and scope are readable free.
NIST SP 800-53
Revision 5 of the federal catalog of security and privacy controls, organized into twenty families spanning access control, incident response, supply chain and more. Practitioners use it to select, tailor and document the safeguards a system or organization must implement.
The Cyberlaw Podcast
Weekly interview and roundup podcast hosted by former NSA general counsel Stewart Baker. Episodes debate current developments in cybersecurity regulation, surveillance, privacy law, AI governance and national security, helping listeners follow how technology policy is argued and made.
Information Security Governance
Brotby sets out how to build a security program that answers to business objectives rather than to IT, covering strategy development, governance structures, roles, policy hierarchies and metrics. Aimed at managers defining an organization's security posture rather than at engineers.
Schneier on Security
Long-running blog and essay archive of security technologist Bruce Schneier, covering cryptography, surveillance, privacy, security economics and technology policy. Readers follow expert analysis of current breaches and legislation and develop a critical view of how security decisions are made in practice.