ISMS_REFERENCE_GUIDE.md
January 12, 2026 Β· View on GitHub
π Hack23 AB β ISMS Reference Guide
π Quick Reference: Homepage Blog β ISMS Policy Mapping
Transparency through precise documentation
π Document | π Security Policy | π Public | β‘ Living Document
π― Purpose Statement
"This reference guide maps Hack23's public-facing blog content to our Information Security Management System (ISMS) policies in the ISMS-PUBLIC repository. It ensures accurate, verifiable references from marketing content to operational security documentationβdemonstrating that our cybersecurity consulting expertise is backed by auditable implementation, not marketing claims."
β James Pether SΓΆrling, CEO / Cybersecurity Expert, Hack23 AB
π Blog Post to ISMS Policy Mapping
This guide documents the precise mapping between blog posts on hack23.com and the corresponding ISMS policies in our public ISMS-PUBLIC repository.
π§ Email Security
Blog Page: discordian-email-security.html
| Topic | Primary Policy | Section/Anchor | Status | Notes |
|---|---|---|---|---|
| Email Authentication (SPF/DKIM/DMARC) | Network_Security_Policy.md | Β§ Email Security Architecture | β Verified | Comprehensive email security controls including SPF, DKIM, DMARC, MTA-STS, TLS-RPT |
| General Security Framework | Information_Security_Policy.md | Full document | β Verified | Overarching security policy |
| ISMS Repository Root | ISMS-PUBLIC | Repository home | β Verified | Public ISMS documentation |
Coverage Summary: Email security is comprehensively documented in the Network Security Policy's dedicated email section, covering all aspects of email authentication, transport security, and monitoring.
βοΈ Cloud Security
Blog Page: discordian-cloud-security.html
| Topic | Primary Policy | Section/Anchor | Status | Notes |
|---|---|---|---|---|
| AWS Cloud Architecture | Network_Security_Policy.md | Full document | β Verified | VPC architecture, security groups, CloudFront, WAF |
| Cloud Access Control | Access_Control_Policy.md | Full document | β Verified | IAM, MFA, least privilege |
| AWS Supplier Details | SUPPLIER.md | Β§ AWS Section | β Verified | AWS supplier risk assessment and controls |
| General Security Framework | Information_Security_Policy.md | Full document | β Verified | Overarching security policy |
Coverage Summary: Cloud security is distributed across Network Security Policy (technical controls), Access Control Policy (identity and permissions), and SUPPLIER.md (third-party risk management for AWS).
π’ Physical Security
Blog Page: discordian-physical-security.html
| Topic | Primary Policy | Section/Anchor | Status | Notes |
|---|---|---|---|---|
| Physical Security Controls | Physical_Security_Policy.md | Full document | β Verified | Standalone policy covering office access, device protection, home office security |
| Device Encryption | Cryptography_Policy.md | Β§ Full Disk Encryption | β Verified | AES-256 FDE requirements |
| General Security Framework | Information_Security_Policy.md | Full document | β Verified | Overarching security policy |
Coverage Summary: Physical security has a dedicated standalone policy, with device encryption requirements cross-referenced in the Cryptography Policy.
π Acceptable Use
Blog Page: discordian-acceptable-use.html
| Topic | Primary Policy | Section/Anchor | Status | Notes |
|---|---|---|---|---|
| Acceptable Use Policy | Acceptable_Use_Policy.md | Full document | β Verified | Standalone policy covering resource usage, prohibited activities, enforcement |
| General Security Framework | Information_Security_Policy.md | Full document | β Verified | Overarching security policy |
Coverage Summary: Acceptable Use has a comprehensive standalone policy document.
π Monitoring and Logging
Blog Page: discordian-monitoring-logging.html
| Topic | Primary Policy | Section/Anchor | Status | Notes |
|---|---|---|---|---|
| Development Logging | Secure_Development_Policy.md | Β§ Security Monitoring | β Verified | Application-level security logging, audit trails |
| Network Monitoring | Network_Security_Policy.md | Β§ Monitoring sections | β Verified | CloudWatch, GuardDuty, Security Hub |
| Security Metrics | Security_Metrics.md | Full document | β Verified | Monitoring dashboards, KPIs, metrics framework |
| Incident Response | Incident_Response_Plan.md | Β§ Detection & Monitoring | β Verified | Incident detection and response procedures |
| General Security Framework | Information_Security_Policy.md | Full document | β Verified | Overarching security policy |
Coverage Summary: Monitoring and logging coverage is distributed across multiple policies: Secure Development Policy (application logging), Network Security Policy (infrastructure monitoring), Security Metrics (measurement framework), and Incident Response Plan (detection procedures).
π Remote Access
Blog Page: discordian-remote-access.html
| Topic | Primary Policy | Section/Anchor | Status | Notes |
|---|---|---|---|---|
| Remote Access Controls | Access_Control_Policy.md | Full document | β Verified | Remote access integrated into general access control (MFA, session management, least privilege) |
| Mobile Device Management | Mobile_Device_Management_Policy.md | Full document | β Verified | BYOD policy, mobile device security, remote work endpoints |
| Data Classification for Remote Access | CLASSIFICATION.md | Β§ CIA Classification | β Verified | Data classification framework guiding remote access controls |
| General Security Framework | Information_Security_Policy.md | Full document | β Verified | Overarching security policy |
Coverage Summary: Remote access is treated as a subset of general access control rather than having a standalone policy. Coverage spans Access Control Policy (authentication, authorization), Mobile Device Management Policy (endpoint security), and CLASSIFICATION.md (data handling requirements).
π Security Training
Blog Page: discordian-security-training.html
| Topic | Primary Policy | Section/Anchor | Status | Notes |
|---|---|---|---|---|
| Security Awareness Training | Information_Security_Policy.md | Β§ Training & Awareness | β Verified | Training requirements integrated into main security policy |
| Classification Training | CLASSIFICATION.md | Full document | β Verified | Data classification framework training requirements |
| Incident Response Training | Incident_Response_Plan.md | Β§ Training & Exercises | β Verified | Incident response drills and training |
Coverage Summary: Security training is documented within the Information Security Policy rather than as a standalone document, with specialized training requirements in Classification and Incident Response documents.
π Data Protection
Blog Page: discordian-data-protection.html
| Topic | Primary Policy | Section/Anchor | Status | Notes |
|---|---|---|---|---|
| Privacy Policy | Privacy_Policy.md | Full document | β Verified | GDPR compliance, data subject rights, retention policies |
| Data Classification | Data_Classification_Policy.md | Full document | β Verified | Classification framework for data protection requirements |
| Privacy Levels | CLASSIFICATION.md | Β§ Privacy Levels | β Verified | Privacy classification tiers |
| Encryption Controls | Cryptography_Policy.md | Full document | β Verified | Encryption requirements for data protection |
| Access Controls | Access_Control_Policy.md | Full document | β Verified | Data access control requirements |
| Backup & Recovery | Backup_Recovery_Policy.md | Full document | β Verified | Data backup and retention |
| Third-Party Data Handling | Third_Party_Management.md | Β§ Data Processing | β Verified | Supplier data protection requirements |
| Incident Response | Incident_Response_Plan.md | Β§ Data Breach Response | β Verified | Data breach notification procedures |
| General Security Framework | Information_Security_Policy.md | Full document | β Verified | Overarching security policy |
Coverage Summary: Data protection has comprehensive coverage split between Privacy Policy (legal/regulatory requirements) and Data Classification Policy (technical controls), with supporting controls across multiple policies.
ποΈ ISMS Policy Architecture
Policy Organization Philosophy
Hack23's ISMS follows a modular, topic-focused architecture rather than creating redundant standalone policies for every blog topic. This approach:
β
Reduces Redundancy: Avoids duplicating common controls across multiple documents
β
Maintains Single Source of Truth: Each control defined once, referenced everywhere
β
Improves Maintainability: Changes propagate automatically through cross-references
β
Demonstrates Real Implementation: Structure reflects actual operational integration
Primary Policy Categories
π Policies (Requirements & Standards)
- π Information_Security_Policy.md (master policy)
- π Acceptable_Use_Policy.md
- π Access_Control_Policy.md
- π Network_Security_Policy.md
- π Physical_Security_Policy.md
- π Privacy_Policy.md
- π Cryptography_Policy.md
- π Data_Classification_Policy.md
- π Mobile_Device_Management_Policy.md
- π Secure_Development_Policy.md
- π AI_Policy.md
- π OWASP_LLM_Security_Policy.md
- π Open_Source_Policy.md
π Plans (Procedures & Responses)
- π Incident_Response_Plan.md
- π Business_Continuity_Plan.md
- π Disaster_Recovery_Plan.md
- π Backup_Recovery_Policy.md
π Registers (Asset & Risk Management)
- π Asset_Register.md
- π Risk_Register.md
- π External_Stakeholder_Registry.md
π·οΈ Frameworks (Standards & Methodologies)
- π·οΈ CLASSIFICATION.md
- π·οΈ Security_Metrics.md
- π·οΈ Risk_Assessment_Methodology.md
- π·οΈ Threat_Modeling.md
π Supporting Documents
- π SUPPLIER.md (third-party risk assessment)
- π Third_Party_Management.md
- π Change_Management.md
- π Vulnerability_Management.md
- π CRA_Conformity_Assessment_Process.md
- π Compliance_Checklist.md
- π ISMS_Transparency_Plan.md
- π STYLE_GUIDE.md
π Verification & Testing
All ISMS policy links are verified through:
Automated Verification
- β GitHub Actions link checker (weekly)
- β Pre-deployment link validation
- β Broken link detection in CI/CD
Manual Verification
- β Quarterly ISMS review (per review cycle)
- β Blog content audit during ISMS updates
- β Cross-reference validation during policy changes
Testing Commands
# Verify all ISMS-PUBLIC links in blog files
grep -r "github.com/Hack23/ISMS-PUBLIC" *.html | wc -l
# Check for anchor existence by searching for the heading in the raw Markdown file
curl -s "https://raw.githubusercontent.com/Hack23/ISMS-PUBLIC/main/Network_Security_Policy.md" | grep -i "^##.*Email Security Architecture"
# Validate policy file existence
curl -I "https://raw.githubusercontent.com/Hack23/ISMS-PUBLIC/main/Acceptable_Use_Policy.md"
π Related Documents
| Document | Purpose | Link |
|---|---|---|
| π ISMS-PUBLIC Repository | Complete ISMS documentation | GitHub |
| π ISMS Style Guide | Documentation standards | STYLE_GUIDE.md |
| π·οΈ Classification Framework | CIA classification levels | CLASSIFICATION.md |
| π Compliance Checklist | ISO 27001, NIST CSF, CIS Controls | Compliance_Checklist.md |
| π Homepage Repository | Website source code | GitHub |
π Maintenance Procedures
When Adding New Blog Posts
- Identify Topic Coverage: Determine which ISMS policies cover the blog topic
- Check for Existing Sections: Review policies for relevant section anchors
- Update This Guide: Add new blog post mapping to this reference guide
- Verify Links: Test all links before publication
- Cross-Reference: Ensure bidirectional references (blog β ISMS)
When Updating ISMS Policies
- Check Blog References: Search homepage repository for references to updated policy
- Update Section Anchors: If section headings change, update blog anchor links
- Update This Guide: Reflect any policy reorganization
- Communication: Notify stakeholders of significant policy changes
- Version Control: Update policy version badges and dates
When Reorganizing ISMS Structure
- Impact Assessment: Identify all homepage references affected
- Redirect Strategy: Plan for deprecated policy redirects/mergers
- Batch Update: Update all homepage references simultaneously
- This Guide Update: Complete revision of mapping table
- Verification: Full link validation across entire homepage
π Current Status Summary
Last Verified: 2025-11-10
Total Blog Posts Mapped: 8 primary discordian-* blog posts
Total ISMS Policies Referenced: 30+ policies, plans, and frameworks
Broken Links: 0 β
Verification Status: All links verified and working
Link Health Dashboard
| Blog Post | ISMS Links | Status | Last Verified |
|---|---|---|---|
| discordian-email-security.html | 3 references | β Verified | 2025-11-10 |
| discordian-cloud-security.html | 3 policies | β Verified | 2025-11-10 |
| discordian-physical-security.html | 3 policies | β Verified | 2025-11-10 |
| discordian-acceptable-use.html | 2 policies | β Verified | 2025-11-10 |
| discordian-monitoring-logging.html | 5 policies | β Verified | 2025-11-10 |
| discordian-remote-access.html | 3 policies | β Verified | 2025-11-10 |
| discordian-security-training.html | 3 policies | β Verified | 2025-11-10 |
| discordian-data-protection.html | 9 policies | β Verified | 2025-11-10 |
π Document Control
β
Approved by: James Pether SΓΆrling, CEO
π€ Distribution: Public
π·οΈ Classification:
π
Effective Date: 2025-11-10
β° Next Review: 2026-02-10 (Quarterly)
π Related Documents: ISMS Transparency Plan, Information Security Policy, Style Guide
Living documentation maintained through continuous improvement. Report discrepancies via GitHub Issues.