Reference / Frameworks & standards

Different maps.
Different jobs.

A risk framework, a certifiable management standard, and a threat knowledge base solve different problems. Understand their purpose before mapping them together.

Outcome taxonomy and program communication tool

NIST Cybersecurity Framework

CSF 2.0

NIST CSF 2.0 organizes cybersecurity outcomes into six Functions: Govern, Identify, Protect, Detect, Respond, and Recover. The Framework Core holds those outcomes, Organizational Profiles describe current and target states, and Tiers describe how rigorously an organization discusses and manages risk. It is written so organizations of many sizes can communicate priorities without prescribing a single architecture or product list.

Read the field guide ↗

Prioritized safeguard set with implementation groups

CIS Controls

CIS Controls v8.1

CIS Controls v8.1 is a prioritized list of Safeguards for defending organizations, grouped so teams can implement in a sensible order. Three Implementation Groups (IGs) scale effort: IG1 is essential cyber hygiene for organizations that need a foundational set, with IG2 and IG3 adding depth for more complex environments. The Controls are practical and opinionated compared with a pure outcome taxonomy.

Read the field guide ↗

Certifiable information security management system requirements

ISO/IEC 27001

ISO/IEC 27001:2022 (Edition 3) with ISO/IEC 27001:2022/Amd 1:2024

ISO/IEC 27001:2022 is Edition 3 of the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). The 2024 amendment (Amd 1) adds climate-action related changes. Certification, when pursued, is scoped: it covers a defined ISMS, not “the whole company is safe.” The standard is copyrighted; this card explains its nature rather than reprinting Annex A controls.

Read the field guide ↗

Security and privacy control catalog

NIST SP 800-53

Revision 5, Release 5.2.0 (27 August 2025)

NIST Special Publication 800-53 Revision 5 is a broad catalog of security and privacy controls for information systems and organizations. Release 5.2.0, noted by NIST on 27 August 2025, updates the catalog, including software update and patch reliability related controls. Companion publications SP 800-53A (assessment procedures) and SP 800-53B (control baselines) are how selection and assessment are typically discussed. It is a catalog to select and tailor from, not a single mandatory list for every private company.

Read the field guide ↗

Knowledge base of observed adversary behavior

MITRE ATT&CK

ATT&CK v19.2 (6 August 2026)

MITRE ATT&CK is a knowledge base of adversary tactics and techniques observed in the world, used to describe how attacks unfold. Version 19.2 was released on 6 August 2026. Version 19 split the former Defense Evasion tactic into Stealth and Defense Impairment; do not reuse older tactic counts as if they were current. ATT&CK is a language for behaviors and evidence, not a scoring system that proves defensive coverage.

Read the field guide ↗

Web application security risk awareness document

OWASP Top 10

OWASP Top 10:2025 (final)

The OWASP Top 10:2025 is a final awareness document describing widely seen web application security risks. It is meant to educate and to start conversations about application security, not to be a complete testing standard. It is distinct from the OWASP Top 10 for Large Language Model Applications; mixing the two leads people to treat prompt injection as just another XSS row or to ignore it entirely.

Read the field guide ↗

Find your next idea.

Tip: press / to open search. Escape closes this window.