
Over the years we have published a range of free security resources on this blog: checklists, templates, self-assessment tools and guides. This page collects them in one place. Everything here is free to download and use. Some older items reference superseded standards – they remain available because the underlying approach is still useful, but check currency before relying on them for compliance work.
Frameworks and Compliance
- NIST SP 800-53 self-assessment checklist – benchmark your controls against Rev 5.
- ISO 27001 compliance checklist – gap analysis against the standard.
- SPF – ISO 27001 control mapping tool – map HMG Security Policy Framework requirements onto ISO 27001 controls.
- Security Policy Framework compliance tool and the accompanying SPF compliance checklist.
- Information Protection Policy template – a starting point for your own policy set.
- Information Security Classification Guide – practical data classification.
Business Security Checklists
- Office security checklist – physical and procedural security for office environments.
- Business Security Guide – a broad introduction for smaller organisations.
- Rapid Security and Safety Review checklist – a fast, structured walk-through.
- Physical Security Assessment form – for site surveys and reviews.
- Supplier Security Self-Assessment Questionnaire – due diligence on third parties.
Guides and Handouts
- Business Guide to Penetration Testing – what to expect and how to buy well.
- Passwords and IT Security – guidance for staff.
- Preventing Identity Theft – a handout for awareness campaigns.
More Resources
The main Halkyn site hosts additional material, including the security downloads index and a curated list of Linux incident response and forensics tools. For guided reading of the blog itself, see the Start Here page.