Technical control policies and standards that close the gap between documented and defensible: access control, cryptography, vulnerability management, logging, network security and secure development - each mapped to ISO 27001:2022 Annex A and Cyber Essentials.