Resources

A curated set of the standards, advisories, and reference material used day-to-day across GRC, cloud security, and CNI/OT engagements.

Showing all 22 resources

All resources

Government & National Bodies

NCSC — National Cyber Security Centre

UK government authority for cyber security guidance, advisories, and the Cyber Assessment Framework (CAF).
US federal agency publishing advisories, known exploited vulnerabilities (KEV) catalogue, and CNI guidance.
Government & National Bodies

ONR — Office for Nuclear Regulation

UK nuclear regulator; source for SyAPS (Security Assessment Principles) guidance for CNI operators.
Government & National Bodies

IASME Consortium

Cyber Essentials and Cyber Essentials Plus certification body; scheme guidance and assessor resources.
Frameworks & Standards

ISO/IEC 27001

International standard for information security management systems (ISMS).
US NIST framework for managing and reducing cybersecurity risk, widely used as a cross-sector baseline.
Frameworks & Standards

CIS Controls

Center for Internet Security's prioritised set of safeguards for defending against common attacks.
Frameworks & Standards

MITRE ATT&CK

Globally accessible knowledge base of adversary tactics and techniques based on real-world observations.
Frameworks & Standards

MITRE ATT&CK Navigator

Interactive tool for annotating and visualising ATT&CK matrices — detection coverage, threat actor mapping, and gap analysis.
Frameworks & Standards

IEC 62443

Series of standards for security of industrial automation and control systems (IACS) / OT environments.
Frameworks & Standards

Cyber Essentials

UK government-backed scheme (and Cyber Essentials Plus) defining five technical controls against common cyber attacks.
Threat Intelligence & Advisories

Microsoft Security Response Center (MSRC)

Microsoft's security advisories, vulnerability disclosures, and update guide.
Authoritative, actively maintained list of vulnerabilities known to be exploited in the wild.
Threat Intelligence & Advisories

NVD — National Vulnerability Database

US government repository of standards-based vulnerability management data, built on CVE.
Threat Intelligence & Advisories

SANS Internet Storm Center

Community-driven early-warning system and daily analysis of emerging threats.
Training & Research

SANS Institute

Training, certification (GIAC), and research across offensive and defensive security disciplines.
Training & Research

OWASP

Open community producing application security tools, standards, and the OWASP Top 10.
Training & Research

SABSA Institute

Home of the SABSA enterprise security architecture methodology and certification framework.
Vendor Documentation

Microsoft Learn — Security

Official Microsoft documentation for Defender, Sentinel, Entra ID, and the broader security stack.
Vendor Documentation

Azure Security Documentation

Azure-specific security architecture, benchmark, and best-practice documentation.
Vendor Documentation

AWS Security Documentation

Official AWS documentation covering IAM, security services, and the Well-Architected security pillar.
Google Cloud's security product documentation, best practices, and architecture guidance.
Kent Wildlife Trust logo
ACCOR HOTELS logo
KURT GEIGER logo
Kobalt Music logo
INEOS Oil & Gas logo
Sizewell C logo
Northern Powergrid logo
Brian Stephens

© 2026 Brian Stephens. All rights reserved.

Privacy Policy