Resources
A curated set of the standards, advisories, and reference material used day-to-day across GRC, cloud security, and CNI/OT engagements.
Showing all 22 resources
All resources
Government & National Bodies
NCSC — National Cyber Security Centre
UK government authority for cyber security guidance, advisories, and the Cyber Assessment Framework (CAF).
Government & National Bodies
CISA — Cybersecurity and Infrastructure Security Agency
US federal agency publishing advisories, known exploited vulnerabilities (KEV) catalogue, and CNI guidance.
Government & National Bodies
ONR — Office for Nuclear Regulation
UK nuclear regulator; source for SyAPS (Security Assessment Principles) guidance for CNI operators.
Government & National Bodies
IASME Consortium
Cyber Essentials and Cyber Essentials Plus certification body; scheme guidance and assessor resources.
Frameworks & Standards
ISO/IEC 27001
International standard for information security management systems (ISMS).
Frameworks & Standards
NIST Cybersecurity Framework (CSF)
US NIST framework for managing and reducing cybersecurity risk, widely used as a cross-sector baseline.
Frameworks & Standards
CIS Controls
Center for Internet Security's prioritised set of safeguards for defending against common attacks.
Frameworks & Standards
MITRE ATT&CK
Globally accessible knowledge base of adversary tactics and techniques based on real-world observations.
Frameworks & Standards
MITRE ATT&CK Navigator
Interactive tool for annotating and visualising ATT&CK matrices — detection coverage, threat actor mapping, and gap analysis.
Frameworks & Standards
IEC 62443
Series of standards for security of industrial automation and control systems (IACS) / OT environments.
Frameworks & Standards
Cyber Essentials
UK government-backed scheme (and Cyber Essentials Plus) defining five technical controls against common cyber attacks.
Threat Intelligence & Advisories
Microsoft Security Response Center (MSRC)
Microsoft's security advisories, vulnerability disclosures, and update guide.
Threat Intelligence & Advisories
CISA Known Exploited Vulnerabilities (KEV) Catalog
Authoritative, actively maintained list of vulnerabilities known to be exploited in the wild.
Threat Intelligence & Advisories
NVD — National Vulnerability Database
US government repository of standards-based vulnerability management data, built on CVE.
Threat Intelligence & Advisories
SANS Internet Storm Center
Community-driven early-warning system and daily analysis of emerging threats.
Training & Research
SANS Institute
Training, certification (GIAC), and research across offensive and defensive security disciplines.
Training & Research
OWASP
Open community producing application security tools, standards, and the OWASP Top 10.
Training & Research
SABSA Institute
Home of the SABSA enterprise security architecture methodology and certification framework.
Vendor Documentation
Microsoft Learn — Security
Official Microsoft documentation for Defender, Sentinel, Entra ID, and the broader security stack.
Vendor Documentation
Azure Security Documentation
Azure-specific security architecture, benchmark, and best-practice documentation.
Vendor Documentation
AWS Security Documentation
Official AWS documentation covering IAM, security services, and the Well-Architected security pillar.
Vendor Documentation
Google Cloud Security Documentation
Google Cloud's security product documentation, best practices, and architecture guidance.