Curated primary-source references for global enterprise security operators. Downloadable materials from the book are available on the Resources page.
Prioritized safeguards that help operators sequence cyber defense work.
Integrated framework for enterprise risk management.
ISO standards referenced for management systems and security practices.
Business continuity management system requirements for disruption planning and recovery.
Principles and process for enterprise risk management across security disciplines.
ISMS requirements used to structure enterprise information security programs.
Control guidance that implements ISO/IEC 27001 across people, physical, and technology domains.
Trustworthy AI risk management for security, privacy, and governance of AI systems.
Primary source for NIST security and privacy publications.
Primary source for NIST's Cybersecurity Framework program.
Risk-based privacy outcomes that sit alongside CSF for data protection programs.
Primary source for NIST's Risk Management Framework.
CUI protection requirements commonly flowed to contractors and suppliers.
Workforce framework for building security roles, skills, and staffing models.
Risk assessment methodology used to identify and communicate security risk.
RMF life cycle for selecting, implementing, assessing, and monitoring controls.
Security and privacy control catalog mapped into most enterprise control programs.
Payment card security standards and supporting documents for environments that handle card data.
A metaframework of controls made up of over 100 cybersecurity and data privacy laws, regulations and frameworks.
Baseline cybersecurity performance goals for critical infrastructure operators.
Free CISA assessment tool for evaluating IT and ICS security posture against recognized standards.
Authoritative catalog of vulnerabilities known to be exploited in the wild.
Incident management concepts and reference material (NIMS).
Global CSIRT community, standards, and coordination practices for incident responders.
Adversary tactics and techniques reference useful for SOC and threat programs.
Defensive countermeasure knowledge base that complements ATT&CK with detection and denial techniques.
Adversary engagement model for planning intelligence-driven defense and deception.
Malware incident prevention and handling guidance for enterprise endpoints.
Media sanitization guidance for decommissioning devices and destroying sensitive data.
CISA maturity model for sequencing zero trust implementation across pillars.
Federal identity, credential, and access architecture and playbooks.
PIV standard for employee and contractor identity credentials used in physical and logical access.
Zero trust architecture model for identity-centric enterprise access.
Digital identity guidelines for proofing, authentication, and federation assurance levels.
Primary professional body for physical and enterprise security risk management practice.
Evidence-based practices for mitigating insider threats, mapped to security standards.
CISA guide for building a multidisciplinary insider threat mitigation program.
Independent physical security consulting practice standards and practitioner community.
Crime prevention through environmental design principles for sites and facilities.
Facility security level and countermeasure process used for federal and comparable sites.
State Department public-private forum for overseas security information used by global operators.
UK protective security guidance covering physical security, personnel security, and site protection.
CBP trusted trader program with minimum security criteria covering physical, personnel, and cargo security.
CISA ICT supply chain security programs, task force products, and operator resources.
CISA SBOM program page for software transparency and supplier attestation work.
Cybersecurity supply chain risk management practices for systems and organizations.
NTIA SBOM initiative framing minimum elements and transparency for software supply chains.
CDC crisis and emergency risk communication manual and training for public information work.
Joint federal ransomware prevention and response checklist for operators.
Standard incident and vulnerability response procedures operators can adapt from FCEB practice.
CISA tabletop scenarios for exercising cyber and operational incident response.
Incident Command System doctrine, forms, and job aids for unified command during incidents.
National Response Framework for multi-agency incident coordination and community lifelines.
FIRST service catalog for structuring CSIRT capabilities and intake.
Contingency planning guide for information system backup, failover, and reconstitution.
Incident response recommendations aligned to CSF 2.0 for prepare, detect, respond, and recover.
CISA ICS and OT cybersecurity resources for asset owners and operators.
DOE office for energy sector cybersecurity, physical security, and emergency response.
Industrial automation and control system security standards used by OT programs.
Adversary tactics and techniques observed against industrial control systems.
North American electric reliability CIP standards for bulk electric system cyber security.
Guide to OT and ICS security, including network architecture and control overlays.
OWASP API Security Top 10 for protecting enterprise APIs and integrations.
Application security verification standard for scoping and assessing software controls.
Software assurance maturity model for building a secure development program.
Highest-priority web application risks used to brief development and security leaders.
EU Agency for Cybersecurity publications, threat analysis, and good practice for operators.
FBI Internet Crime Complaint Center for reporting cyber-enabled crime and reviewing public alerts.
UK National Cyber Security Centre guidance for organizations and technical operators.
Outcome-based cyber assessment framework used to gauge organizational cyber resilience.