ISMS_REFERENCE_GUIDE.md

January 12, 2026 Β· View on GitHub

Hack23 AB Logo

πŸ” Hack23 AB β€” ISMS Reference Guide

πŸ“˜ Quick Reference: Homepage Blog β†’ ISMS Policy Mapping

Transparency through precise documentation

Document owner: James Pether SΓΆrling Version 1.0 Effective date: 2025-11-10 Review cycle: Quarterly

πŸ“„ Document | πŸ” Security Policy | 🌐 Public | ⚑ Living Document


🎯 Purpose Statement

"This reference guide maps Hack23's public-facing blog content to our Information Security Management System (ISMS) policies in the ISMS-PUBLIC repository. It ensures accurate, verifiable references from marketing content to operational security documentationβ€”demonstrating that our cybersecurity consulting expertise is backed by auditable implementation, not marketing claims."

β€” James Pether SΓΆrling, CEO / Cybersecurity Expert, Hack23 AB


πŸ“‹ Blog Post to ISMS Policy Mapping

This guide documents the precise mapping between blog posts on hack23.com and the corresponding ISMS policies in our public ISMS-PUBLIC repository.

πŸ“§ Email Security

Blog Page: discordian-email-security.html

TopicPrimary PolicySection/AnchorStatusNotes
Email Authentication (SPF/DKIM/DMARC)Network_Security_Policy.mdΒ§ Email Security Architectureβœ… VerifiedComprehensive email security controls including SPF, DKIM, DMARC, MTA-STS, TLS-RPT
General Security FrameworkInformation_Security_Policy.mdFull documentβœ… VerifiedOverarching security policy
ISMS Repository RootISMS-PUBLICRepository homeβœ… VerifiedPublic ISMS documentation

Coverage Summary: Email security is comprehensively documented in the Network Security Policy's dedicated email section, covering all aspects of email authentication, transport security, and monitoring.


☁️ Cloud Security

Blog Page: discordian-cloud-security.html

TopicPrimary PolicySection/AnchorStatusNotes
AWS Cloud ArchitectureNetwork_Security_Policy.mdFull documentβœ… VerifiedVPC architecture, security groups, CloudFront, WAF
Cloud Access ControlAccess_Control_Policy.mdFull documentβœ… VerifiedIAM, MFA, least privilege
AWS Supplier DetailsSUPPLIER.mdΒ§ AWS Sectionβœ… VerifiedAWS supplier risk assessment and controls
General Security FrameworkInformation_Security_Policy.mdFull documentβœ… VerifiedOverarching security policy

Coverage Summary: Cloud security is distributed across Network Security Policy (technical controls), Access Control Policy (identity and permissions), and SUPPLIER.md (third-party risk management for AWS).


🏒 Physical Security

Blog Page: discordian-physical-security.html

TopicPrimary PolicySection/AnchorStatusNotes
Physical Security ControlsPhysical_Security_Policy.mdFull documentβœ… VerifiedStandalone policy covering office access, device protection, home office security
Device EncryptionCryptography_Policy.mdΒ§ Full Disk Encryptionβœ… VerifiedAES-256 FDE requirements
General Security FrameworkInformation_Security_Policy.mdFull documentβœ… VerifiedOverarching security policy

Coverage Summary: Physical security has a dedicated standalone policy, with device encryption requirements cross-referenced in the Cryptography Policy.


πŸ“œ Acceptable Use

Blog Page: discordian-acceptable-use.html

TopicPrimary PolicySection/AnchorStatusNotes
Acceptable Use PolicyAcceptable_Use_Policy.mdFull documentβœ… VerifiedStandalone policy covering resource usage, prohibited activities, enforcement
General Security FrameworkInformation_Security_Policy.mdFull documentβœ… VerifiedOverarching security policy

Coverage Summary: Acceptable Use has a comprehensive standalone policy document.


πŸ“Š Monitoring and Logging

Blog Page: discordian-monitoring-logging.html

TopicPrimary PolicySection/AnchorStatusNotes
Development LoggingSecure_Development_Policy.mdΒ§ Security Monitoringβœ… VerifiedApplication-level security logging, audit trails
Network MonitoringNetwork_Security_Policy.mdΒ§ Monitoring sectionsβœ… VerifiedCloudWatch, GuardDuty, Security Hub
Security MetricsSecurity_Metrics.mdFull documentβœ… VerifiedMonitoring dashboards, KPIs, metrics framework
Incident ResponseIncident_Response_Plan.mdΒ§ Detection & Monitoringβœ… VerifiedIncident detection and response procedures
General Security FrameworkInformation_Security_Policy.mdFull documentβœ… VerifiedOverarching security policy

Coverage Summary: Monitoring and logging coverage is distributed across multiple policies: Secure Development Policy (application logging), Network Security Policy (infrastructure monitoring), Security Metrics (measurement framework), and Incident Response Plan (detection procedures).


πŸ” Remote Access

Blog Page: discordian-remote-access.html

TopicPrimary PolicySection/AnchorStatusNotes
Remote Access ControlsAccess_Control_Policy.mdFull documentβœ… VerifiedRemote access integrated into general access control (MFA, session management, least privilege)
Mobile Device ManagementMobile_Device_Management_Policy.mdFull documentβœ… VerifiedBYOD policy, mobile device security, remote work endpoints
Data Classification for Remote AccessCLASSIFICATION.mdΒ§ CIA Classificationβœ… VerifiedData classification framework guiding remote access controls
General Security FrameworkInformation_Security_Policy.mdFull documentβœ… VerifiedOverarching security policy

Coverage Summary: Remote access is treated as a subset of general access control rather than having a standalone policy. Coverage spans Access Control Policy (authentication, authorization), Mobile Device Management Policy (endpoint security), and CLASSIFICATION.md (data handling requirements).


πŸŽ“ Security Training

Blog Page: discordian-security-training.html

TopicPrimary PolicySection/AnchorStatusNotes
Security Awareness TrainingInformation_Security_Policy.mdΒ§ Training & Awarenessβœ… VerifiedTraining requirements integrated into main security policy
Classification TrainingCLASSIFICATION.mdFull documentβœ… VerifiedData classification framework training requirements
Incident Response TrainingIncident_Response_Plan.mdΒ§ Training & Exercisesβœ… VerifiedIncident response drills and training

Coverage Summary: Security training is documented within the Information Security Policy rather than as a standalone document, with specialized training requirements in Classification and Incident Response documents.


πŸ”’ Data Protection

Blog Page: discordian-data-protection.html

TopicPrimary PolicySection/AnchorStatusNotes
Privacy PolicyPrivacy_Policy.mdFull documentβœ… VerifiedGDPR compliance, data subject rights, retention policies
Data ClassificationData_Classification_Policy.mdFull documentβœ… VerifiedClassification framework for data protection requirements
Privacy LevelsCLASSIFICATION.mdΒ§ Privacy Levelsβœ… VerifiedPrivacy classification tiers
Encryption ControlsCryptography_Policy.mdFull documentβœ… VerifiedEncryption requirements for data protection
Access ControlsAccess_Control_Policy.mdFull documentβœ… VerifiedData access control requirements
Backup & RecoveryBackup_Recovery_Policy.mdFull documentβœ… VerifiedData backup and retention
Third-Party Data HandlingThird_Party_Management.mdΒ§ Data Processingβœ… VerifiedSupplier data protection requirements
Incident ResponseIncident_Response_Plan.mdΒ§ Data Breach Responseβœ… VerifiedData breach notification procedures
General Security FrameworkInformation_Security_Policy.mdFull documentβœ… VerifiedOverarching security policy

Coverage Summary: Data protection has comprehensive coverage split between Privacy Policy (legal/regulatory requirements) and Data Classification Policy (technical controls), with supporting controls across multiple policies.


πŸ—οΈ ISMS Policy Architecture

Policy Organization Philosophy

Hack23's ISMS follows a modular, topic-focused architecture rather than creating redundant standalone policies for every blog topic. This approach:

βœ… Reduces Redundancy: Avoids duplicating common controls across multiple documents
βœ… Maintains Single Source of Truth: Each control defined once, referenced everywhere
βœ… Improves Maintainability: Changes propagate automatically through cross-references
βœ… Demonstrates Real Implementation: Structure reflects actual operational integration

Primary Policy Categories

πŸ“œ Policies (Requirements & Standards)

  • πŸ” Information_Security_Policy.md (master policy)
  • πŸ” Acceptable_Use_Policy.md
  • πŸ” Access_Control_Policy.md
  • πŸ” Network_Security_Policy.md
  • πŸ” Physical_Security_Policy.md
  • πŸ” Privacy_Policy.md
  • πŸ” Cryptography_Policy.md
  • πŸ” Data_Classification_Policy.md
  • πŸ” Mobile_Device_Management_Policy.md
  • πŸ” Secure_Development_Policy.md
  • πŸ” AI_Policy.md
  • πŸ” OWASP_LLM_Security_Policy.md
  • πŸ” Open_Source_Policy.md

πŸ“‹ Plans (Procedures & Responses)

  • πŸ“‹ Incident_Response_Plan.md
  • πŸ“‹ Business_Continuity_Plan.md
  • πŸ“‹ Disaster_Recovery_Plan.md
  • πŸ“‹ Backup_Recovery_Policy.md

πŸ“Š Registers (Asset & Risk Management)

  • πŸ“Š Asset_Register.md
  • πŸ“Š Risk_Register.md
  • πŸ“Š External_Stakeholder_Registry.md

🏷️ Frameworks (Standards & Methodologies)

  • 🏷️ CLASSIFICATION.md
  • 🏷️ Security_Metrics.md
  • 🏷️ Risk_Assessment_Methodology.md
  • 🏷️ Threat_Modeling.md

πŸ“„ Supporting Documents

  • πŸ“„ SUPPLIER.md (third-party risk assessment)
  • πŸ“„ Third_Party_Management.md
  • πŸ“„ Change_Management.md
  • πŸ“„ Vulnerability_Management.md
  • πŸ“„ CRA_Conformity_Assessment_Process.md
  • πŸ“„ Compliance_Checklist.md
  • πŸ“„ ISMS_Transparency_Plan.md
  • πŸ“„ STYLE_GUIDE.md

πŸ” Verification & Testing

All ISMS policy links are verified through:

Automated Verification

  • βœ… GitHub Actions link checker (weekly)
  • βœ… Pre-deployment link validation
  • βœ… Broken link detection in CI/CD

Manual Verification

  • βœ… Quarterly ISMS review (per review cycle)
  • βœ… Blog content audit during ISMS updates
  • βœ… Cross-reference validation during policy changes

Testing Commands

# Verify all ISMS-PUBLIC links in blog files
grep -r "github.com/Hack23/ISMS-PUBLIC" *.html | wc -l

# Check for anchor existence by searching for the heading in the raw Markdown file
curl -s "https://raw.githubusercontent.com/Hack23/ISMS-PUBLIC/main/Network_Security_Policy.md" | grep -i "^##.*Email Security Architecture"

# Validate policy file existence
curl -I "https://raw.githubusercontent.com/Hack23/ISMS-PUBLIC/main/Acceptable_Use_Policy.md"

DocumentPurposeLink
πŸ” ISMS-PUBLIC RepositoryComplete ISMS documentationGitHub
πŸ“˜ ISMS Style GuideDocumentation standardsSTYLE_GUIDE.md
🏷️ Classification FrameworkCIA classification levelsCLASSIFICATION.md
πŸ“‹ Compliance ChecklistISO 27001, NIST CSF, CIS ControlsCompliance_Checklist.md
🌐 Homepage RepositoryWebsite source codeGitHub

πŸ”„ Maintenance Procedures

When Adding New Blog Posts

  1. Identify Topic Coverage: Determine which ISMS policies cover the blog topic
  2. Check for Existing Sections: Review policies for relevant section anchors
  3. Update This Guide: Add new blog post mapping to this reference guide
  4. Verify Links: Test all links before publication
  5. Cross-Reference: Ensure bidirectional references (blog ↔ ISMS)

When Updating ISMS Policies

  1. Check Blog References: Search homepage repository for references to updated policy
  2. Update Section Anchors: If section headings change, update blog anchor links
  3. Update This Guide: Reflect any policy reorganization
  4. Communication: Notify stakeholders of significant policy changes
  5. Version Control: Update policy version badges and dates

When Reorganizing ISMS Structure

  1. Impact Assessment: Identify all homepage references affected
  2. Redirect Strategy: Plan for deprecated policy redirects/mergers
  3. Batch Update: Update all homepage references simultaneously
  4. This Guide Update: Complete revision of mapping table
  5. Verification: Full link validation across entire homepage

πŸ“Š Current Status Summary

Last Verified: 2025-11-10
Total Blog Posts Mapped: 8 primary discordian-* blog posts
Total ISMS Policies Referenced: 30+ policies, plans, and frameworks
Broken Links: 0 βœ…
Verification Status: All links verified and working

Blog PostISMS LinksStatusLast Verified
discordian-email-security.html3 referencesβœ… Verified2025-11-10
discordian-cloud-security.html3 policiesβœ… Verified2025-11-10
discordian-physical-security.html3 policiesβœ… Verified2025-11-10
discordian-acceptable-use.html2 policiesβœ… Verified2025-11-10
discordian-monitoring-logging.html5 policiesβœ… Verified2025-11-10
discordian-remote-access.html3 policiesβœ… Verified2025-11-10
discordian-security-training.html3 policiesβœ… Verified2025-11-10
discordian-data-protection.html9 policiesβœ… Verified2025-11-10

πŸ“‹ Document Control

βœ… Approved by: James Pether SΓΆrling, CEO
πŸ“€ Distribution: Public
🏷️ Classification: Confidentiality: Public

πŸ“… Effective Date: 2025-11-10
⏰ Next Review: 2026-02-10 (Quarterly)

🎯 Framework Compliance:
ISO 27001 NIST CSF 2.0 CIS Controls

πŸ”— Related Documents: ISMS Transparency Plan, Information Security Policy, Style Guide


Living documentation maintained through continuous improvement. Report discrepancies via GitHub Issues.