The ten projects every security program runs
MFA, EDR, IAM/PAM, SIEM/SOC, vulnerability management, incident response, zero trust segmentation, DLP, vendor risk and security awareness โ each one built out into a complete PMO pack: a business case, a phased plan with exit criteria, governance and decision rights, baselined success criteria, a status-report skeleton, and a pre-seeded RAID log. Download an artefact, a project pack, or the whole library, then make it yours.
What it gives you
Ten canonical projects
MFA, EDR, IAM/PAM, SIEM/SOC, vulnerability management, incident response, zero trust segmentation, DLP, vendor risk, and security awareness โ the projects every security program eventually runs.
Phased plan with exit criteria
Each project is broken into phases with a duration, tasks and an exit criterion, so you know what "done with this phase" actually means.
Pre-seeded RAID log
Risks, assumptions, issues and dependencies specific to that project, ready to paste into your own tracker as a CSV.
Full downloadable packs
Business case, governance doc, success criteria with baseline/target KPIs, and a status-report skeleton โ per project, or all ten as one Markdown file.
Personalised recommendations
Signed-in members can see a project or two surfaced from their own scorecard weak spot or a rough War Room grade, instead of scanning all ten.
How it works
- 1Pick a project from the grid of ten โ each shows its typical duration and cost band up front.
- 2Review its problem statement, why-now case, phased plan and KPI table with baseline and target.
- 3Preview or download any single artefact โ business case, plan, governance, success criteria, status report, RAID log โ or the full pack.
- 4Grab all ten packs as one Markdown file, or come back project by project as your program moves.
Honest about what this is
- A complete starting pack per project โ business case, plan, governance, KPIs, status report and RAID log โ you fill in and own.
- Useful for a security leader who needs to stand up (or justify) a project fast, without writing PMO paperwork from a blank page.
- โ Not a scan, assessment, or benchmark of your environment โ nothing connects to your systems, and the baselines/dates in each template are placeholders for you to fill in.
FAQ
What does the Cyber PMO Library give me?
Ten canonical security projects โ MFA, EDR, IAM/PAM, SIEM/SOC, vulnerability management, incident response, zero trust segmentation, DLP, vendor risk, and security awareness โ each expanded into a complete pack: a business case, a phased project plan with exit criteria, a governance and decision-rights doc, baselined success criteria, a status-report skeleton, and a pre-seeded RAID log.
Is this generated from my environment?
No. Each pack is a pre-built template for a named, common security project. You download it and fill in your own numbers, owners and dates โ nothing connects to your systems or scans anything.
What can I export?
Any single artefact (business case, project plan, governance, success criteria, status report, or RAID log as CSV) for one project, a full pack per project, or all ten packs together as one Markdown file.
What are the recommendations at the top?
If you are signed in and have taken the security scorecard or played a War Room incident, the library can surface one or two projects tied to your weakest area or a poor incident grade. Everyone else sees the full set of ten.
Is it free?
The interactive library is part of a paid plan. Any PlayCISO plan unlocks it, along with the other security-architect studios.