68 free IT templates, checklists and policy documents
Every document below is the real thing — the template itself, not a landing page describing one. Nothing is gated. There is no signup, no email wall and no download form; each opens as a page you can read, copy or print.
They are written for the person who has been asked to produce a document and does not want to start from an empty file: a disaster recovery plan before an audit, an access review before a renewal, a Microsoft 365 baseline before a migration.
Find the document, not the category
Templates you fill in (15)
Start from a structure rather than a blank page. Each one is the document itself, not a description of one.
Document
What it covers
Topic area
A structured template for documenting critical business functions, recovery priorities, roles, and communication procedures during a disruption.
Business Continuity & Disaster Recovery
A technical DR plan document structure covering systems inventory, RPO/RTO, failover procedures, recovery infrastructure, and post-recovery validation.
Business Continuity & Disaster Recovery
A step-by-step disaster recovery runbook structure for recovering a specific system, from pre-recovery checks through verification and rollback.
Business Continuity & Disaster Recovery
A structured workbook for organizing scope, evidence, and internal review ahead of a compliance or security audit.
Compliance & Governance
A workbook for scoping the ISMS, running the risk assessment, and preparing for Stage 1 and Stage 2 certification audits.
Compliance & Governance
A workbook for mapping controls to evidence types, building a continuous collection cadence, and tracking evidence quality.
Compliance & Governance
A reusable template structure for writing compliance and security policy documents, with version control guidance.
Compliance & Governance
A workbook for planning Microsoft 365 workload-specific Conditional Access policies — Exchange, SharePoint, Teams, and admin portals.
Microsoft 365 Security
A workbook for tracking Secure Score improvement actions by architectural layer, to spot imbalanced coverage.
Microsoft 365 Security
A fill-in-the-blank template for documenting the joiner mover leaver process — your organization's onboarding, role-change, and offboarding procedures — as a repeatable policy rather than institutional memory.
Identity & Access Management
A multi-phase rollout workbook for planning a Conditional Access implementation from baseline to advanced policy sets.
Identity & Access Management
A structured template for documenting network topology, addressing, device inventory, and core services so the network is understandable to more than one person. Copy it straight into your own IT infrastructure documentation, download it, or print it to PDF.
Infrastructure & Networking
A change request document structure covering description, risk classification, impact assessment, rollback planning, approval, implementation, and post-implementation review.
IT Operations & Service Management
A structured template for documenting approved AI tools, data classification rules, ownership, and monitoring provisions that govern AI use across the organization.
AI Governance
A policy structure defining permitted and prohibited AI use, data handling rules, disclosure requirements, and consequences for violations.
AI Governance
A structured template for documenting critical business functions, recovery priorities, roles, and communication procedures during a disruption.
Topic area
Business Continuity & Disaster Recovery
A technical DR plan document structure covering systems inventory, RPO/RTO, failover procedures, recovery infrastructure, and post-recovery validation.
Topic area
Business Continuity & Disaster Recovery
A step-by-step disaster recovery runbook structure for recovering a specific system, from pre-recovery checks through verification and rollback.
Topic area
Business Continuity & Disaster Recovery
A structured workbook for organizing scope, evidence, and internal review ahead of a compliance or security audit.
Topic area
Compliance & Governance
A workbook for scoping the ISMS, running the risk assessment, and preparing for Stage 1 and Stage 2 certification audits.
Topic area
Compliance & Governance
A workbook for mapping controls to evidence types, building a continuous collection cadence, and tracking evidence quality.
Topic area
Compliance & Governance
A reusable template structure for writing compliance and security policy documents, with version control guidance.
Topic area
Compliance & Governance
A workbook for planning Microsoft 365 workload-specific Conditional Access policies — Exchange, SharePoint, Teams, and admin portals.
Topic area
Microsoft 365 Security
A workbook for tracking Secure Score improvement actions by architectural layer, to spot imbalanced coverage.
Topic area
Microsoft 365 Security
A fill-in-the-blank template for documenting the joiner mover leaver process — your organization's onboarding, role-change, and offboarding procedures — as a repeatable policy rather than institutional memory.
Topic area
Identity & Access Management
A multi-phase rollout workbook for planning a Conditional Access implementation from baseline to advanced policy sets.
Topic area
Identity & Access Management
A structured template for documenting network topology, addressing, device inventory, and core services so the network is understandable to more than one person. Copy it straight into your own IT infrastructure documentation, download it, or print it to PDF.
Topic area
Infrastructure & Networking
A change request document structure covering description, risk classification, impact assessment, rollback planning, approval, implementation, and post-implementation review.
Topic area
IT Operations & Service Management
A structured template for documenting approved AI tools, data classification rules, ownership, and monitoring provisions that govern AI use across the organization.
Topic area
AI Governance
A policy structure defining permitted and prohibited AI use, data handling rules, disclosure requirements, and consequences for violations.
Topic area
AI Governance
Checklists you work through (30)
Sequenced checks for a specific job — a rollout, an audit, a review.
Document
What it covers
Topic area
A checklist for scheduling, executing, and documenting backup restoration tests to confirm backups are actually recoverable.
Business Continuity & Disaster Recovery
A checklist organized by incident response phase — Detection, Containment, Eradication, Recovery, and Post-Incident Review.
Business Continuity & Disaster Recovery
A worksheet for planning backup strategy by data criticality tier, applying the 3-2-1 rule, and setting retention periods.
Business Continuity & Disaster Recovery
A cross-framework checklist covering the core governance and compliance controls most audits and frameworks expect to see in place.
Compliance & Governance
A practical starter checklist of representative CIS Controls Implementation Group 1 (IG1) safeguards across several of the 18 controls.
Compliance & Governance
A checklist organized by the three HIPAA Security Rule safeguard categories — Administrative, Physical, and Technical.
Compliance & Governance
A checklist of representative implementation items organized by NIST SP 800-171 control family, for organizations protecting CUI.
Compliance & Governance
A representative vendor security questionnaire covering data handling, certifications, access controls, incident history, and audit rights.
Compliance & Governance
A practical, printable checklist covering the full Microsoft 365 Security Baseline across identity, email, device, and data.
Microsoft 365 Security
A recurring administration checklist for keeping an Entra ID tenant healthy over time.
Microsoft 365 Security
A checklist for rolling out and maintaining Intune security baselines across a device fleet.
Microsoft 365 Security
A consolidated hardening checklist spanning identity, email, endpoint, device, and data protection across the full cluster.
Microsoft 365 Security
A step-by-step checklist for rolling out multi-factor authentication without a support-desk avalanche.
Identity & Access Management
A planning worksheet for designing Conditional Access policies before building them in the identity platform.
Identity & Access Management
A checklist covering provisioning, access reviews, and deprovisioning discipline across the identity lifecycle.
Identity & Access Management
A structured worksheet for conducting a periodic identity access review, with fields for findings and remediation.
Identity & Access Management
A practical, printable checklist covering the core credential-security controls every organization should have in place.
Password & Credential Security
A structured checklist for auditing an organization's current password posture before or during a security assessment.
Password & Credential Security
A structured worksheet for comparing password manager vendors before a business-wide deployment decision.
Password & Credential Security
Immediate steps to take when a password compromise is suspected or confirmed.
Password & Credential Security
A cross-framework checklist for confirming password practices align with HIPAA, PCI DSS, and general NIST-based expectations.
Password & Credential Security
A checklist for auditing physical infrastructure, network configuration, virtualization, storage, and monitoring coverage across the environment.
Infrastructure & Networking
A worksheet for planning VLAN segmentation by traffic type, assigning IDs and subnets, and defining inter-VLAN policy and broadcast domain sizing.
Infrastructure & Networking
A checklist organized by monitoring domain — compute, network, storage, and alerting discipline — for confirming monitoring coverage is complete and actionable.
Infrastructure & Networking
A checklist for provisioning a new server consistently — from pre-build planning through OS build, post-build configuration, and validation.
Infrastructure & Networking
A cross-functional checklist covering documentation, change management, incident and problem management, asset management, monitoring, and continuous improvement.
IT Operations & Service Management
A self-assessment worksheet structured around the five maturity stages, with indicator questions across documentation, change management, incident/problem management, monitoring, and asset management.
IT Operations & Service Management
A checklist covering coverage, alert configuration, escalation, and ongoing review for an effective IT monitoring implementation.
IT Operations & Service Management
A worksheet for scoring the risk of a specific AI use case by data sensitivity, tool trust level, and risk category before approval.
AI Governance
A checklist covering pre-deployment permissions review, pilot phase setup, rollout, and post-deployment monitoring for a Microsoft 365 Copilot deployment.
AI Governance
A checklist for scheduling, executing, and documenting backup restoration tests to confirm backups are actually recoverable.
Topic area
Business Continuity & Disaster Recovery
A checklist organized by incident response phase — Detection, Containment, Eradication, Recovery, and Post-Incident Review.
Topic area
Business Continuity & Disaster Recovery
A worksheet for planning backup strategy by data criticality tier, applying the 3-2-1 rule, and setting retention periods.
Topic area
Business Continuity & Disaster Recovery
A cross-framework checklist covering the core governance and compliance controls most audits and frameworks expect to see in place.
Topic area
Compliance & Governance
A practical starter checklist of representative CIS Controls Implementation Group 1 (IG1) safeguards across several of the 18 controls.
Topic area
Compliance & Governance
A checklist organized by the three HIPAA Security Rule safeguard categories — Administrative, Physical, and Technical.
Topic area
Compliance & Governance
A checklist of representative implementation items organized by NIST SP 800-171 control family, for organizations protecting CUI.
Topic area
Compliance & Governance
A representative vendor security questionnaire covering data handling, certifications, access controls, incident history, and audit rights.
Topic area
Compliance & Governance
A practical, printable checklist covering the full Microsoft 365 Security Baseline across identity, email, device, and data.
Topic area
Microsoft 365 Security
A recurring administration checklist for keeping an Entra ID tenant healthy over time.
Topic area
Microsoft 365 Security
A checklist for rolling out and maintaining Intune security baselines across a device fleet.
Topic area
Microsoft 365 Security
A consolidated hardening checklist spanning identity, email, endpoint, device, and data protection across the full cluster.
Topic area
Microsoft 365 Security
A step-by-step checklist for rolling out multi-factor authentication without a support-desk avalanche.
Topic area
Identity & Access Management
A planning worksheet for designing Conditional Access policies before building them in the identity platform.
Topic area
Identity & Access Management
A checklist covering provisioning, access reviews, and deprovisioning discipline across the identity lifecycle.
Topic area
Identity & Access Management
A structured worksheet for conducting a periodic identity access review, with fields for findings and remediation.
Topic area
Identity & Access Management
A practical, printable checklist covering the core credential-security controls every organization should have in place.
Topic area
Password & Credential Security
A structured checklist for auditing an organization's current password posture before or during a security assessment.
Topic area
Password & Credential Security
A structured worksheet for comparing password manager vendors before a business-wide deployment decision.
Topic area
Password & Credential Security
Immediate steps to take when a password compromise is suspected or confirmed.
Topic area
Password & Credential Security
A cross-framework checklist for confirming password practices align with HIPAA, PCI DSS, and general NIST-based expectations.
Topic area
Password & Credential Security
A checklist for auditing physical infrastructure, network configuration, virtualization, storage, and monitoring coverage across the environment.
Topic area
Infrastructure & Networking
A worksheet for planning VLAN segmentation by traffic type, assigning IDs and subnets, and defining inter-VLAN policy and broadcast domain sizing.
Topic area
Infrastructure & Networking
A checklist organized by monitoring domain — compute, network, storage, and alerting discipline — for confirming monitoring coverage is complete and actionable.
Topic area
Infrastructure & Networking
A checklist for provisioning a new server consistently — from pre-build planning through OS build, post-build configuration, and validation.
Topic area
Infrastructure & Networking
A cross-functional checklist covering documentation, change management, incident and problem management, asset management, monitoring, and continuous improvement.
Topic area
IT Operations & Service Management
A self-assessment worksheet structured around the five maturity stages, with indicator questions across documentation, change management, incident/problem management, monitoring, and asset management.
Topic area
IT Operations & Service Management
A checklist covering coverage, alert configuration, escalation, and ongoing review for an effective IT monitoring implementation.
Topic area
IT Operations & Service Management
A worksheet for scoring the risk of a specific AI use case by data sensitivity, tool trust level, and risk category before approval.
Topic area
AI Governance
A checklist covering pre-deployment permissions review, pilot phase setup, rollout, and post-deployment monitoring for a Microsoft 365 Copilot deployment.
Topic area
AI Governance
Procedures and playbooks (3)
What to do, in order, when something is already happening.
Document
What it covers
Topic area
A playbook of specific response actions for common Microsoft 365 security incident scenarios.
Microsoft 365 Security
A runbook structure for handling an IT incident from severity classification through resolution, verification, and post-incident documentation.
IT Operations & Service Management
A staged roadmap for moving from initial AI policy and pilot through controlled rollout, organization-wide adoption, and continuous governance.
AI Governance
A playbook of specific response actions for common Microsoft 365 security incident scenarios.
Topic area
Microsoft 365 Security
A runbook structure for handling an IT incident from severity classification through resolution, verification, and post-incident documentation.
Topic area
IT Operations & Service Management
A staged roadmap for moving from initial AI policy and pilot through controlled rollout, organization-wide adoption, and continuous governance.
Topic area
AI Governance
Reference material (20)
Background you read once and come back to.
Document
What it covers
Topic area
A one-page-style reference to the six NIST Cybersecurity Framework 2.0 functions and representative activities for each.
Compliance & Governance
A practical guide to preparing for PCI DSS 4.0 covering scope reduction, the six control goals, and reducing audit burden.
Compliance & Governance
A practical guide to determining your CMMC level, mapping practices to NIST SP 800-171, and preparing for a C3PAO assessment.
Compliance & Governance
A prioritized template for planning and tracking Microsoft Secure Score improvement actions over time.
Microsoft 365 Security
A phased implementation guide for adopting Zero Trust principles across a Microsoft 365 environment.
Microsoft 365 Security
A guide to ongoing security operations across the Microsoft 365 security stack — monitoring, review cadences, and incident response touchpoints.
Microsoft 365 Security
A phased deployment guide for rolling out Defender for Office 365 and Defender for Endpoint across a tenant.
Microsoft 365 Security
A planning guide for evaluating whether and how to adopt Microsoft Sentinel.
Microsoft 365 Security
A reference matrix mapping this cluster's security capabilities to the Entra ID and Microsoft 365 licensing tiers that unlock them.
Microsoft 365 Security
A guide for reducing standing administrative privilege through just-in-time activation, break-glass accounts, and periodic review.
Identity & Access Management
A phased guide for rolling out passkeys and FIDO2/WebAuthn authentication across an organization.
Identity & Access Management
A consolidated reference covering the full set of current identity and authentication best practices in one document.
Identity & Access Management
A reference architecture guide covering how authentication, SSO, Conditional Access, and privileged access fit together as one system.
Identity & Access Management
A step-by-step technical guide for IT administrators implementing a modern password policy across an identity platform.
Password & Credential Security
A concise, non-technical briefing for leadership on why modern password governance matters and what to expect from the program.
Password & Credential Security
A plain-language guide for general staff — not administrators — on what changed in password guidance and what to actually do.
Password & Credential Security
A consolidated reference covering the full set of current password best practices in one document.
Password & Credential Security
A guide for matching storage architecture to workload, planning capacity and performance, and applying appropriate redundancy.
Infrastructure & Networking
A guide covering what should be documented, documentation quality standards, where documentation should live, and review cadence.
IT Operations & Service Management
An executive-level guide to why AI governance matters now, the business case for a governed approach, and the specific decisions leadership needs to make.
AI Governance
A one-page-style reference to the six NIST Cybersecurity Framework 2.0 functions and representative activities for each.
Topic area
Compliance & Governance
A practical guide to preparing for PCI DSS 4.0 covering scope reduction, the six control goals, and reducing audit burden.
Topic area
Compliance & Governance
A practical guide to determining your CMMC level, mapping practices to NIST SP 800-171, and preparing for a C3PAO assessment.
Topic area
Compliance & Governance
A prioritized template for planning and tracking Microsoft Secure Score improvement actions over time.
Topic area
Microsoft 365 Security
A phased implementation guide for adopting Zero Trust principles across a Microsoft 365 environment.
Topic area
Microsoft 365 Security
A guide to ongoing security operations across the Microsoft 365 security stack — monitoring, review cadences, and incident response touchpoints.
Topic area
Microsoft 365 Security
A phased deployment guide for rolling out Defender for Office 365 and Defender for Endpoint across a tenant.
Topic area
Microsoft 365 Security
A planning guide for evaluating whether and how to adopt Microsoft Sentinel.
Topic area
Microsoft 365 Security
A reference matrix mapping this cluster's security capabilities to the Entra ID and Microsoft 365 licensing tiers that unlock them.
Topic area
Microsoft 365 Security
A guide for reducing standing administrative privilege through just-in-time activation, break-glass accounts, and periodic review.
Topic area
Identity & Access Management
A phased guide for rolling out passkeys and FIDO2/WebAuthn authentication across an organization.
Topic area
Identity & Access Management
A consolidated reference covering the full set of current identity and authentication best practices in one document.
Topic area
Identity & Access Management
A reference architecture guide covering how authentication, SSO, Conditional Access, and privileged access fit together as one system.
Topic area
Identity & Access Management
A step-by-step technical guide for IT administrators implementing a modern password policy across an identity platform.
Topic area
Password & Credential Security
A concise, non-technical briefing for leadership on why modern password governance matters and what to expect from the program.
Topic area
Password & Credential Security
A plain-language guide for general staff — not administrators — on what changed in password guidance and what to actually do.
Topic area
Password & Credential Security
A consolidated reference covering the full set of current password best practices in one document.
Topic area
Password & Credential Security
A guide for matching storage architecture to workload, planning capacity and performance, and applying appropriate redundancy.
Topic area
Infrastructure & Networking
A guide covering what should be documented, documentation quality standards, where documentation should live, and review cadence.
Topic area
IT Operations & Service Management
An executive-level guide to why AI governance matters now, the business case for a governed approach, and the specific decisions leadership needs to make.
Topic area
AI Governance
Each set sits inside a wider body of guidance
A template answers “what should this document contain”. The cluster it belongs to answers “why, and what happens next”.
Business Continuity & Disaster Recovery (6)
Read the Business Continuity & Disaster Recoveryguidance →IT directors and operations leads who have been asked to produce a plan, or to prove one works.
Compliance & Governance (12)
Read the Compliance & Governanceguidance →Compliance leads and quality managers assembling evidence against a framework.
- Compliance Readiness Checklist
- Audit Preparation Workbook
- NIST CSF 2.0 Quick Reference
- CIS Controls IG1 Starter Checklist
- HIPAA Compliance Checklist
- PCI DSS Preparation Guide
- CMMC Preparation Guide
- NIST SP 800-171 Control Family Checklist
- ISO 27001 Readiness Workbook
- Vendor Security Risk Questionnaire
- Audit Evidence Collection Workbook
- Compliance Policy Documentation Template
Microsoft 365 Security (13)
Read the Microsoft 365 Securityguidance →Microsoft 365 administrators hardening a tenant or preparing a review.
- Microsoft 365 Security Checklist
- Secure Score Improvement Plan
- Conditional Access Baseline Workbook
- Zero Trust Implementation Guide
- Entra ID Administration Checklist
- Microsoft Security Operations Guide
- Defender Deployment Guide
- Intune Security Baseline Checklist
- Microsoft Sentinel Planning Guide
- Secure Score Optimization Workbook
- Microsoft Security Operations Playbook
- Microsoft Licensing Matrix
- Microsoft 365 Hardening Checklist
Identity & Access Management (10)
Read the Identity & Access Managementguidance →Security and identity administrators running access reviews or an MFA rollout.
- MFA Rollout Checklist
- Conditional Access Policy Worksheet
- Privileged Access Governance Guide
- Passwordless Adoption Guide
- Identity Governance Checklist
- Joiner-Mover-Leaver Template
- Identity Security Best Practices
- Authentication Architecture Guide
- Conditional Access Planning Workbook
- Identity Governance Review Worksheet
Password & Credential Security (9)
Read the Password & Credential Securityguidance →IT administrators writing or auditing a credential policy.
Infrastructure & Networking (6)
Read the Infrastructure & Networkingguidance →Network and infrastructure administrators documenting or rebuilding an environment.
IT Operations & Service Management (6)
Read the IT Operations & Service Managementguidance →IT and service managers formalising how operations actually run.
AI Governance (6)
Read the AI Governanceguidance →CIOs and compliance leads putting guardrails around AI adoption.
68 documents across 8 topic areas and 14 formats. All free, none gated.
Operational Support
Using one of these and want a second opinion on what you produced?
The Independent IT Environment Review is read-only, scoped by you, and returns written findings against a published baseline. A completed template is a good starting point for it.
No commitment required — we respond within one business day.