This is for the purchase of an organizational license for internal use or as a training handbook for commercial training courses. Individual copies of the book, as a paperback or Kindle version, are available from Amazon.
The whole handbook, downloadable now, searchable and ready to circulate internally.
The complete handbook as an A4 PDF, available for download with purchase. Fully bookmarked and internally linked, so you can jump from the Sharing Decision to the policy language to the violation playbook without hunting. The edition to buy if you want to search it, quote it, and get the toolkit into your own templates this week.
Same book as on Amazon, no waiting. This is the full A4 edition: 319 pages as a searchable, full-color PDF you can download the moment you buy it.
If you have ever marked something AMBER because it felt safer, you already know the problem this handbook is about. TLP is a set of labels that answers exactly one question: how far may the recipient pass this on? Sensitivity, access and handling are three different questions, and the trouble starts when an organization collapses all four into a color.
The handbook treats controlled information sharing as a security risk problem. It is candid about where the evidence for a widely repeated claim does not hold, and it says so rather than repeating it. It tests TLP against the hierarchy of controls and bow tie barrier criteria and reports what it finds: a marking is an administrative control that depends entirely on continued correct human action.
For a practitioner working digitally, this edition earns its keep in Part VIII. The 12-card toolkit — decision card, implementation checklist, sample policy language, roles and escalation, channel guidance for email, documents, decks, chat, meetings and verbal briefings, third-party clauses, workshop designs, a maturity ladder and a review register — is all built to be lifted and adapted. Copy it straight into your own policy set.
Chapter 22 works as a checklist for diagnosing your own organization. Chapter 23 works as a casebook. Mark each failure mode present, absent, or unknown, and the unknowns are the finding.
- Digital download, no shipping, no wait
- Full colour A4, 321 pages including covers
- Searchable text with 56 bookmarks and 282 working internal links
- The complete 12-card toolkit, ready to copy into your own policy and training material
- Chapter 22 as a self-diagnostic checklist, Chapter 23 as a casebook of 19 documented failures
- Half-day and full-day workshop designs, with facilitator answers at the back
- Reads correctly in greyscale and for a reader with a colour vision deficiency — every part, box and marker is named in words as well as coloured
Who it's for
Security managers and CISOs. Threat intelligence and incident response teams. Investigators and consultants. Critical infrastructure operators. Emergency and crisis managers. NGO security advisers. Supply chain risk teams. And the legal, HR and communications colleagues who get drawn in at the worst possible moment.
If you have ever marked something AMBER because it felt safer, or watched a warning sit unread in the wrong inbox because nobody could work out who was allowed to see it, this book is aimed at you.
About the author
Julian Talbot is co-author of the Security Risk Management Body of Knowledge (Wiley) and writes on risk, security and decision-making. SRMBOK publishes guides and templates for practitioners at srmbok.com.
















