Complete Build Series
All ten volumes in reading order — a security department built out of open source, with control mappings, validation harnesses and honest buy lines throughout. 29% off buying separately.
Ten volumes, closed at ten. The open-source companion to the compliance workbooks: every compliance workbook identifies requirements, every build volume makes them real.
The volumes are numbered by subject and read in a different order — 02 → 01 → 06 → 05 → 03 → 10 → 04 → 07 → 09 → 08.
Inventory first, because every other volume scopes from it. Detection second, because its agents and network sensor pay dividends into volumes 02, 03, 07 and 09 at no marginal cost. Identity third, because in a remote-first estate that is where incidents actually begin. Backup next, because half of ransomware outcomes are decided by whether the restore works. Vulnerability management once you have inventory and detection to prioritise against. Email here, earlier than its number — locking down non-sending domains is an afternoon of work that closes a real spoofing gap and is the volume most likely to produce a visible early win, which matters when a programme needs internal support to keep going. Then response capability, hardening, cloud posture, and segmentation last, because it depends on both the inventory and the identity work being real.
What every volume contains that a blog post does not. The exact SOC 2, ISO 27001:2022, NIST CSF 2.0, CIS v8.1, CMMC, PCI DSS v4.0.1 and HIPAA clauses the build satisfies, printed first. A validation harness for proving the control works and catching it failing silently. And dated currency notes, in a field full of confidently wrong guidance.
Every volume runs the same nine sections: prerequisites, control mapping, the decisions that matter, three sized architectures, a build runbook, a validation harness, an evidence pack, an operating cadence with honest hour counts, failure modes and the buy line, and an AI prompt pack.
Twelve months of updates included — when a tracked fact moves, a rule finalises, a certificate expires or a licence changes, the volume is revised and you get the new edition.
Ships without support. These are documents, not a service contract. That is deliberate: the failure mode for a technical DIY line is a support queue nobody priced for, and every volume tells you plainly where the buy line is.
What's in this bundle
Build Series Vol. 02 — Asset Inventory & Discovery
Discovery tells you what is out there. The source of truth holds what you have decided about it. The control lives in the reconciliation between them, not in either list.
Build Series Vol. 01 — Detection & Monitoring
Wazuh, Suricata and Zeek assembled into a stack one person can operate, with the tuning and detection validation that almost every deployment skips.
Build Series Vol. 06 — Identity & Access
One front door, authenticators that survive phishing, privileged identities separated from daily work, and access that genuinely ends when people do.
Build Series Vol. 05 — Backup & Recovery
Copies an attacker holding domain admin cannot reach, and restores you have actually performed and timed — including the full-estate rebuild nobody plans for.
Build Series Vol. 03 — Vulnerability Management
Finding what is exploitable, fixing what matters, and proving both — with a prioritisation model that still works when the severity score is missing.
Build Series Vol. 10 — Email & Domain Defense
Domain authentication all the way to enforcement, transport security, portfolio hygiene, and the monitoring that tells you when someone is impersonating you.
Build Series Vol. 04 — Incident Response Lab
The capability to investigate, contain and report — built before you need it, including the reporting clocks measured in hours rather than days.
Build Series Vol. 07 — Endpoint Hardening & Configuration
Baselines per system class, enforced continuously and measured for drift, across a fleet that includes machines you do not manage and cannot reach on a network.
Build Series Vol. 09 — Cloud & SaaS Security Posture
The control plane where the estate actually lives — misconfiguration, privilege graphs, public exposure, and the SaaS tenants nobody has ever baselined.
Build Series Vol. 08 — Network Segmentation & Zero Trust
The containment substrate the rest of the series assumes: isolating a host, keeping a compromised endpoint away from the backups, restricting an unmanaged device to a narrow slice.
What's included
- PDF — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
Complete your toolkit
More from the CISO Marketplace ecosystem
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee