Smarter and more secure, together.
Policies, register templates, control guidance, threat and regulation briefings — freely available, multilingual, ready to use. Written in practice, maintained by the Cenedril team.
What you'll find here
ISO 27001 Starter Kit
Ready-made policies, register templates, and documents for building an ISO 27001-compliant ISMS. Copy-to-clipboard for Notion, Confluence, Obsidian.
33+ documents Section 02Controls
Every Annex A control from ISO/IEC 27001:2022 explained — with practical implementation guidance, typical audit evidence, and real-world examples.
93 controls Section 03Threats
Ransomware, phishing, BEC, DDoS, supply chain attacks: how they work, which controls help, and what to do when an incident occurs.
Threat catalogue Section 04Laws & Standards
ISO 27001, NIS2, GDPR, CRA, BSI IT-Grundschutz — paraphrased article by article, with implementation guidance for SMBs and links to the official sources.
7 frameworksWhy this wiki exists
Free and without barrier
We believe that knowledge about information security belongs in the open. Everything here is published under Creative Commons Attribution 4.0 — copy, adapt, even use commercially, as long as attribution remains. No registration, no paywall, no tracking via forms.
Open source — better together
All policies, registers, and templates are available as an open-source repo on GitHub. Found a mistake, want to make a template more practical, or extend a register? Open a pull request — we review and merge. The documents improve with every use.
Multilingual and up to date
Every article exists in German and English. We revise content quarterly and mark every update transparently with date and author. More languages? The repo is open — we welcome community translations and list them as community-maintained versions.
Cenedril turns these into a living ISMS.
This wiki is the open part of our work. If you want to manage these documents in an online management system software — with versioning, workflow integration, automatic PDF generation, audit trails and a bunch more bells and whistles — take a look at Cenedril.
Go to Cenedril →