Nashville, serving organizations nationwide
(615) 829-6802 Client login

Resources

Where to start, by situation.

Everything Tectori publishes is free to read and free to use. This page points to the right starting place depending on the problem in front of you, and defines the terms the rest of the site uses.

Reading paths

Three common starting points.

Templates and tools

Seven published tools, no form in front of them.

Tectori publishes working tools rather than descriptions of them. Automation for Active Directory, Azure, and Microsoft 365, security program templates, evidence tooling, and reference material are all on GitHub under open licenses.

The list, with what each one does, is on free tools.

Glossary

The terms this site uses, in plain language.

Audit readiness

The state where the records an examiner asks for already exist, because operating the system produced them.

Control

Something you do, or something a system enforces, that reduces a risk. A control has an owner or it is a statement.

Evidence

The record that proves a control operated. A log, an approval, a review sign off, a test result.

Framework mapping

The link between a requirement in a framework, such as FFIEC or HIPAA, and the control that satisfies it.

Gap analysis

A check of what is missing, what is partial, and what is already satisfied, measured against a named framework.

Risk register

A living list of risks with owners, ratings, treatment decisions, and review dates.

Exception

A recorded decision to accept a control not being met, with a reason, an owner, and an end date.

Third party risk

The risk carried by vendors and service providers, reviewed before signing and again on a cycle.

Business continuity

The plan for continuing to operate through a failure, tested rather than assumed.

Least privilege

Giving an account only the access its work requires, and removing what it no longer needs.

Access review

A periodic check of who has access to what, why, and whether it should continue.

Decision record

A short written note of what was decided, by whom, on what basis, and how to reverse it.

Runbook

A written procedure for work that repeats, detailed enough for someone else to follow.

Agentic AI

AI that takes actions rather than only producing text. It needs approval gates, monitoring, and a stop path.

Want this run in your environment?

Start a conversation