Requiring Source
None found. Not in the signed contracts, not in the insurance answers, not in the criteria in scope, not in statute.
Six documents and five sheets, including a register that traces every sentence in your policy set to the document actually requiring it.
Free download · No account needed
Commitment Register, one row
Quoted verbatim from the policy · Traced before it is judged · One verdict, never two
“Security event logs shall be reviewed daily by the security team.”
Logging and Monitoring Policy, clause 2.1
Requiring Source
None found. Not in the signed contracts, not in the insurance answers, not in the criteria in scope, not in statute.
Evidence System
Log platform search history. Named before anyone guesses, because the plausible source is usually the wrong one.
What the record shows Seventeen searches in twelve months. Every one of them after an alert had already fired.
Evidence load Daily means 365 dated artifacts a year that an assessor can sample from. This clause alone carries 365 of the set’s 1,317.
Verdict Remove. Keep as written, keep and fix the evidence, amend to actual practice, or remove. Nothing else, and provenance decides which.
Read as a control, alerting is what finds things and this is fine. Read as a policy sentence, it is 348 documented failures a year against a promise nobody asked the company to make.
Every sentence left in the set is one that a statute, a signed contract, an insurance answer or a criterion in scope actually requires. That is the only test for whether a policy sentence should exist.
A downloaded policy set is not a document. It is several hundred separate assertions about a company the template author never met, and every one of them is something an auditor, a customer or an insurer can hold you to. NIST says this plainly in its own control catalogue, where the discussion under AC-1 notes that simply restating controls does not constitute an organizational policy. Restating controls is exactly what a template pack does.
So the first pass here is arithmetic rather than editorial. Every modal sentence becomes a register row, quoted verbatim, and Calderhall's nineteen downloaded policies produced 437 of them against a room that had guessed somewhere between forty and eighty. Then each row is traced to the document that requires it: a statute, a clause in a signed customer contract, an answer given on the cyber insurance application, or a control in the framework actually being assessed. Two hundred and twelve had no such document.
Those 212 are not harmless. Forty-seven of them were already contradicted by the observable record, which makes them exceptions Calderhall wrote against itself. Ninety-day password rotation sat in the set while the identity provider had rotation switched off in 2024, following NIST's own advice that verifiers should not require memorized secrets to be changed arbitrarily. Deleting the sentence closed the finding. The SOC 2 narratives written afterwards had half as much to defend.
One row per testable sentence, quoted verbatim, carrying its requiring source, its evidence system, the observable record and one of four verdicts.
The roll-up per policy: commitments, the four verdict counts, the traced share, the owner, and the review dates that actually get met.
Every cadence word multiplied out over a year, summed before and after tracing, so the cost of a word somebody skim-read is visible.
Time-boxed departures with a scope, a compensating control, an expiry date and an approver chosen by requiring source rather than by seniority.
Signatures against a version number, with refusals and absences kept apart because they are different findings needing different people.
What counts as a commitment, the four columns behind each one, and why the four verdicts are the only permitted values.
Nineteen domains, the shape every policy shares, and which ones attract unsourced text so heavily that they are worth writing last.
Which end of a contradiction to move, how much room each requiring source leaves you, and the three phrases that only look like precision.
What an exception record carries, how approval routes by source, and why a standing exception is an amendment wearing a costume.
Edit with AI opens the pack as a private Space with the agent ready to run the extraction and the trace. Download hands you six Word documents and five CSV sheets, no account required.
The set you have in any state, plus the security schedules from executed customer contracts, the completed cyber insurance application, and the criteria you are in scope for. The last three are where sentences live or die.
Every modal sentence becomes a register row with the policy, the clause number and the wording quoted. The total is normally several times what anybody in the room expected, and it reframes the whole conversation.
Provenance is filled in before any verdict is assigned, so removals are derived rather than argued. Where the search finds nothing, the row reads none found and stays that way.
Yes, and the download needs no account, card or email. Edit with AI is the optional half and the one that does the work: it extracts every commitment from the set you already have, traces each one, and checks it against your systems. The rest of the template library works the same way.
Six documents as .docx and five sheets as .csv, in one zip. Word, Pages, Google Docs, Excel, Numbers and Sheets open them with nothing to convert. The sheets arrive carrying the worked Calderhall example, so you can read a filled register before replacing it with your own.
No, it is the pass you run over the one you have. The set you downloaded is the input. Nineteen policies at Calderhall carried 437 commitments and 212 of them had no requiring source, which is a finding you can only get by counting what you already own.
Because every sentence is something fieldwork can test. Calderhall's 212 removals took 47 contradictions out with them, each of which would have become an exception in a report. Removing an unrequired sentence removes the exception at no cost to the actual control.
Different question, one step earlier. The evidence pack asks whether the evidence a narrative names still exists. This asks whether the sentence should exist at all, and it runs on contracts and insurance answers rather than only on criteria.
Then run it backwards, from the requiring sources. Read the signed contracts, the insurance application and the criteria in scope, and write one commitment per obligation. The result is shorter than any downloaded set and every line has a document behind it, which is the position NIST's framework describes.
In their own spaces, because a policy commits and a control operates. The access commitments are evidenced by the access review, the remediation deadlines by the vulnerability register, and the review clause by a supply chain review.