The 2026 InfoSec Playbook · Daniel Ramos

#Appendix A — The Master Checklist

Every testable control from every chapter of this book, in one place, with a status you can set and share.

This appendix is assembled automatically from the checklist at the end of each chapter, so it can never drift out of sync with the book. Each control is written to be answerable true or false by someone who is not you.

Tiers follow CIS Implementation Group semantics. IG1 is essential cyber hygiene that every organization needs regardless of size. IG2 assumes people whose job is security. IG3 is for organizations facing adversaries who will spend real money to get in. Work down the tiers, not across the chapters — an organization with every IG1 control implemented is in better shape than one with half of Chapter 4 done to IG3.

Set a status on anything below. If the shared store is available to your account, everyone opening this page sees and edits the same board, which is the entire difference between a checklist and a program.

Program readiness

Saved on this device
Coverage
0%
Implemented
0
Open
0
Controls
489
Set a status on any control below. With the shared store available, your team sees the same board.

AI 25 controls · Using and Securing AI

CLD 26 controls · Cloud, Container and Kubernetes Security

COMM 22 controls · Communications, Legal and Regulatory Notification

CRAFT 25 controls · Plan, Playbook, Runbook

DATA 25 controls · Data, Cryptography and the Post-Quantum Clock

DEPT 25 controls · Departmental Playbooks

DET 25 controls · Detection and Monitoring

EX 25 controls · Exercising the Playbook

GOV 25 controls · Governance, Frameworks and Metrics

IAM 26 controls · Identity and Access: The New Perimeter

IR 26 controls · The Incident Response Lifecycle

LAND 15 controls · Why 2026 Broke the Old Playbook

MAP 25 controls · The Coverage Model

RES 24 controls · Resilience, Backup and Recovery

ROAD 27 controls · The First 180 Days

SOAR 25 controls · Automation and Orchestration

TPRM 25 controls · Third-Party and Supply Chain Risk

VULN 25 controls · Vulnerability and Exposure Management

ZT 23 controls · Zero Trust Architecture

This page is one chapter of The 2026 InfoSec Playbook, a free field manual by Daniel Ramos. Checklist statuses and the live coverage model are in the full manual. Free, in full, no email wall.