Skip to content

Review Process

Document status

As of October 2026, every document in this portfolio is a Draft. None has been marked Reviewed or Published.

Status Meaning
Draft Written and internally consistent, but not every command, step, and control reference has been checked against primary sources yet
Reviewed Every factual claim, command, and control reference checked by the author against primary sources: NIST SP 800-53 Rev 5, ISO/IEC 27001:2022, AICPA Trust Services Criteria, vendor documentation, and the relevant standard
Published Reviewed, given version 1.0 or later, and featured on the landing pages

A document moves up a status through a pull request that records what was checked and against which source. The pull request history is the audit trail for each review.

Use of AI

First drafts are produced with AI assistance, using a local model and Claude Code. AI output is treated as a draft from a junior writer: every command is checked against vendor documentation or run in the lab, every control reference is checked against the framework text, and anything that cannot be verified is removed or marked for verification. The status field shows how far that checking has gone.

Real and illustrative content

SOP-001, SOP-002, and SOP-003 document systems the author built and faults the author diagnosed. Identifying details are omitted. SOP-004, SOP-005, and SOP-006 are written for a generic small office and do not describe any client environment.

None of these documents contain client data, and none are client deliverables.

Limits

These documents are portfolio samples. They are not legal advice, an audit opinion, or a certification. Control mappings record the author's intent and should be confirmed by a qualified assessor for any real environment.