IT·Checklists
    • Web Application Security Review
    • Cloud Security Posture
    • Security Code Review
    • Secrets Management
    • Security Incident Response
    • Penetration Test Readiness
    • Production Readiness Review
    • CI/CD Pipeline Review
    • Container Image Hardening
    • Kubernetes Deployment
    • Infrastructure as Code Review
    • Release Day Runbook
    • Cloud Landing Zone Setup
    • Cloud Cost Optimisation
    • Cloud Migration Cutover
    • Serverless Readiness
    • Code Review
    • REST API Design
    • Database Schema Migration
    • New Service Bootstrap
    • Open Source Release
    • Frontend Performance
    • Web Accessibility (WCAG)
    • Observability
    • On-Call Handover
    • Incident Management
    • Postmortem
    • Backup and Recovery
    • Capacity Planning
    • Data Pipeline Review
    • Data Quality
    • ML Model Deployment
    • Data Warehouse Migration
    • Network Change
    • DNS Migration
    • TLS Certificate Management
    • Load Balancer Configuration
    • GDPR Readiness
    • ISO/IEC 27001 ISMS
    • SOC 2 Audit Readiness
    • Vendor Security Assessment
    • Employee IT Onboarding
    • Employee IT Offboarding
    • Change Management
    • Disaster Recovery Drill
    • IT Asset Management
    IT·Checklists
    • GitHub
  • to navigate
  • to select
  • to close
    • Home
    • Compliance & Governance
    On this page
    gavel

    Compliance & Governance

    Evidence-driven checklists for GDPR, ISO 27001, SOC 2, and third-party vendor risk.

    privacy_tip

    GDPR Readiness

    Verify that personal data processing has a lawful basis, working rights workflows, and evidence a regulator would …

    verified

    ISO/IEC 27001 ISMS

    Verify that an information security management system is complete, operating, and evidenced before the certification …

    assignment_turned_in

    SOC 2 Audit Readiness

    Verify that controls, narratives, and evidence will survive a SOC 2 examination before the observation window opens.

    handshake

    Vendor Security Assessment

    Verify that a third party handling your data or systems is assessed, contracted, monitored, and offboarded safely.


    © 2026 IT Checklists · Built with Hugo and Lotus Docs