Checklists

Our working checklists, handed over to you.

None of these sheets started life as marketing. They are working documents: web and API test cases, AD attack phases, OT questionnaires, a privacy crosswalk. The same checklists our consultants work through on paid engagements, exported as XLSX for your team to run without us
Featured Checklist
Web Application Security

Web Application and API Security Self-Assessment Checklist: OWASP-Mapped Test Cases

Over 200 web test cases mapped to the OWASP Top 10 2021, plus API checklists for the 2019 and 2023 OWASP API Security Top 10, so you test against a standard, not an ad-hoc list.
View Checklist
White arrow pointing diagonally upward to the right on a black square background.Dark gray arrow pointing to the right on a transparent background.
Category
Black circular refresh icon with arrow pointing counterclockwise, symbolizing reset or reload.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Web Application Security

Web Application and API Security Self-Assessment Checklist: OWASP-Mapped Test Cases

Over 200 web test cases mapped to the OWASP Top 10 2021, plus API checklists for the 2019 and 2023 OWASP API Security Top 10, so you test against a standard, not an ad-hoc list.
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.
Web Application Security

DevSecOps Pipeline Integration Checklist: Controls Across the CI/CD Lifecycle

Security controls across the ten stages of a CI/CD pipeline, each with its objective, tools, and owner, plus a four-quarter rollout roadmap.
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.
Critical Infrastructure

ICS/SCADA (OT) Cybersecurity Self-Assessment Checklist: 154 Questions Mapped to NIST 800-82

150+ self-assessment questions for ICS and SCADA environments, organized by the five NIST CSF functions and mapped to NIST 800-82, so an OT operator can baseline site security without waiting for a formal audit.
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.
DevSecOps

Privacy Control Crosswalk: ISO 27701:2025 to GDPR and DPDP

All 82 ISO/IEC 27701:2025 subclauses mapped to the GDPR article and the DPDP Act section or 2025 Rule that covers them, so your team runs one control set against two regulators instead of two.
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.
Compliance / GRC

C-Suite Red Team Engagement Checklist: A Full Kill-Chain Methodology

More than 330 red team tasks across 13 stages, from signed Rules of Engagement to post-report quality assurance, so a security leader knows exactly what an adversary simulation involves.
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.
Web Application Security

Active Directory Attack Test Cases: MITRE ATT&CK-Mapped Checks for On-Prem AD

40 on-prem Active Directory attack test cases, each mapped to its MITRE ATT&CK technique, with the exact tools, commands, and indicators of compromise to run the attack and catch it.
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.