GLOBAL ENTERPRISE SECURITY
Integrating Cyber, Physical, Personnel, and Operational Protection

Links

Curated primary-source references for global enterprise security operators. Downloadable materials from the book are available on the Resources page.

Standards & frameworks

CIS Critical Security Controls

Prioritized safeguards that help operators sequence cyber defense work.

COSO Enterprise Risk Management (ERM)

Integrated framework for enterprise risk management.

ISO (standards catalog)

ISO standards referenced for management systems and security practices.

ISO 22301 (business continuity)

Business continuity management system requirements for disruption planning and recovery.

ISO 31000 (risk management)

Principles and process for enterprise risk management across security disciplines.

ISO/IEC 27001 (information security management)

ISMS requirements used to structure enterprise information security programs.

ISO/IEC 27002 (information security controls)

Control guidance that implements ISO/IEC 27001 across people, physical, and technology domains.

NIST AI Risk Management Framework

Trustworthy AI risk management for security, privacy, and governance of AI systems.

NIST CSRC Publications

Primary source for NIST security and privacy publications.

NIST Cybersecurity Framework (CSF)

Primary source for NIST's Cybersecurity Framework program.

NIST Privacy Framework

Risk-based privacy outcomes that sit alongside CSF for data protection programs.

NIST Risk Management Framework (RMF)

Primary source for NIST's Risk Management Framework.

NIST SP 800-171 (protecting CUI)

CUI protection requirements commonly flowed to contractors and suppliers.

NIST SP 800-181 (NICE Workforce Framework)

Workforce framework for building security roles, skills, and staffing models.

NIST SP 800-30 (guide for conducting risk assessments)

Risk assessment methodology used to identify and communicate security risk.

NIST SP 800-37 (Risk Management Framework)

RMF life cycle for selecting, implementing, assessing, and monitoring controls.

NIST SP 800-53 (security and privacy controls)

Security and privacy control catalog mapped into most enterprise control programs.

PCI Security Standards Council

Payment card security standards and supporting documents for environments that handle card data.

Secure Controls Framework (SCF)

A metaframework of controls made up of over 100 cybersecurity and data privacy laws, regulations and frameworks.

Security operations

CISA Cross-Sector Cybersecurity Performance Goals

Baseline cybersecurity performance goals for critical infrastructure operators.

CISA Cyber Security Evaluation Tool (CSET)

Free CISA assessment tool for evaluating IT and ICS security posture against recognized standards.

CISA Known Exploited Vulnerabilities (KEV) Catalog

Authoritative catalog of vulnerabilities known to be exploited in the wild.

FEMA (incident management resources)

Incident management concepts and reference material (NIMS).

FIRST (Forum of Incident Response and Security Teams)

Global CSIRT community, standards, and coordination practices for incident responders.

MITRE ATT&CK

Adversary tactics and techniques reference useful for SOC and threat programs.

MITRE D3FEND

Defensive countermeasure knowledge base that complements ATT&CK with detection and denial techniques.

MITRE ENGAGE

Adversary engagement model for planning intelligence-driven defense and deception.

NIST SP 800-83 (malware incident prevention and handling)

Malware incident prevention and handling guidance for enterprise endpoints.

NIST SP 800-88 (media sanitization)

Media sanitization guidance for decommissioning devices and destroying sensitive data.

Identity & access

CISA Zero Trust Maturity Model

CISA maturity model for sequencing zero trust implementation across pillars.

Federal ICAM (FICAM) Program

Federal identity, credential, and access architecture and playbooks.

NIST FIPS 201-3 (Personal Identity Verification)

PIV standard for employee and contractor identity credentials used in physical and logical access.

NIST SP 800-207 (zero trust architecture)

Zero trust architecture model for identity-centric enterprise access.

NIST SP 800-63-4 (digital identity guidelines)

Digital identity guidelines for proofing, authentication, and federation assurance levels.

Physical security & personnel

ASIS International

Primary professional body for physical and enterprise security risk management practice.

CERT SEI Common Sense Guide to Mitigating Insider Threats

Evidence-based practices for mitigating insider threats, mapped to security standards.

CISA Insider Threat Mitigation Guide

CISA guide for building a multidisciplinary insider threat mitigation program.

International Association of Professional Security Consultants (IAPSC)

Independent physical security consulting practice standards and practitioner community.

International CPTED Association

Crime prevention through environmental design principles for sites and facilities.

ISC Standard: Risk Management Process (CISA)

Facility security level and countermeasure process used for federal and comparable sites.

Overseas Security Advisory Council (OSAC)

State Department public-private forum for overseas security information used by global operators.

UK National Protective Security Authority (NPSA)

UK protective security guidance covering physical security, personnel security, and site protection.

Supply chain

CBP CTPAT (Customs Trade Partnership Against Terrorism)

CBP trusted trader program with minimum security criteria covering physical, personnel, and cargo security.

CISA ICT Supply Chain Security

CISA ICT supply chain security programs, task force products, and operator resources.

CISA Software Bill of Materials (SBOM)

CISA SBOM program page for software transparency and supplier attestation work.

NIST SP 800-161 (cybersecurity supply chain risk management)

Cybersecurity supply chain risk management practices for systems and organizations.

NTIA Software Bill of Materials

NTIA SBOM initiative framing minimum elements and transparency for software supply chains.

Incident & crisis

CDC Crisis and Emergency Risk Communication (CERC)

CDC crisis and emergency risk communication manual and training for public information work.

CISA #StopRansomware Guide

Joint federal ransomware prevention and response checklist for operators.

CISA Federal Cybersecurity Incident and Vulnerability Response Playbooks

Standard incident and vulnerability response procedures operators can adapt from FCEB practice.

CISA Tabletop Exercise Packages

CISA tabletop scenarios for exercising cyber and operational incident response.

FEMA ICS Resource Center

Incident Command System doctrine, forms, and job aids for unified command during incidents.

FEMA National Response Framework

National Response Framework for multi-agency incident coordination and community lifelines.

FIRST CSIRT Services Framework

FIRST service catalog for structuring CSIRT capabilities and intake.

NIST SP 800-34 (contingency planning)

Contingency planning guide for information system backup, failover, and reconstitution.

NIST SP 800-61 (incident response)

Incident response recommendations aligned to CSF 2.0 for prepare, detect, respond, and recover.

OT & industrial control

CISA Industrial Control Systems

CISA ICS and OT cybersecurity resources for asset owners and operators.

DOE CESER

DOE office for energy sector cybersecurity, physical security, and emergency response.

ISA/IEC 62443 Series

Industrial automation and control system security standards used by OT programs.

MITRE ATT&CK for ICS

Adversary tactics and techniques observed against industrial control systems.

NERC CIP Standards

North American electric reliability CIP standards for bulk electric system cyber security.

NIST SP 800-82 (OT and ICS security)

Guide to OT and ICS security, including network architecture and control overlays.

Application security

OWASP API Security Top 10

OWASP API Security Top 10 for protecting enterprise APIs and integrations.

OWASP Application Security Verification Standard (ASVS)

Application security verification standard for scoping and assessing software controls.

OWASP Software Assurance Maturity Model (SAMM)

Software assurance maturity model for building a secure development program.

OWASP Top 10

Highest-priority web application risks used to brief development and security leaders.

National authorities

ENISA (EU Agency for Cybersecurity)

EU Agency for Cybersecurity publications, threat analysis, and good practice for operators.

FBI Internet Crime Complaint Center (IC3)

FBI Internet Crime Complaint Center for reporting cyber-enabled crime and reviewing public alerts.

UK National Cyber Security Centre (NCSC)

UK National Cyber Security Centre guidance for organizations and technical operators.

UK NCSC Cyber Assessment Framework

Outcome-based cyber assessment framework used to gauge organizational cyber resilience.