Free reference library
67 authoritative sources for the frameworks, policies, and procedures behind the exams — NIST, ISO 27001, COBIT, CIS, MITRE ATT&CK, OT/ICS standards, and government sources. Every link goes straight to the primary source.
The control catalogues and governance frameworks most exams and audits map back to.
NIST Cybersecurity Framework (CSF 2.0)
Govern, Identify, Protect, Detect, Respond, Recover — the outcome-based framework for managing cyber risk.
NIST Risk Management Framework (RMF)
The seven-step process for categorizing, selecting, implementing, assessing, authorizing, and monitoring controls.
NIST SP 800-53 Rev. 5
The master catalogue of security and privacy controls for information systems and organizations.
ISO/IEC 27001
The international standard for an Information Security Management System (ISMS) and its Annex A controls.
COBIT 2019
The governance and management framework for enterprise IT, widely used to align IT with business goals.
CIS Critical Security Controls v8
A prioritized set of 18 safeguards that stop the most common and damaging attacks.
MITRE ATT&CK
A globally accessible knowledge base of adversary tactics and techniques based on real-world observation.
MITRE D3FEND
A knowledge graph of defensive countermeasures, mapped to the ATT&CK techniques they mitigate.
Enterprise and security-architecture methods you meet in CISSP-ISSAP and architecture roles.
SABSA
A business-driven framework and methodology for enterprise security architecture and service management.
TOGAF Standard
The enterprise-architecture framework and Architecture Development Method (ADM) referenced across security design.
OWASP ASVS
The Application Security Verification Standard — a testable baseline of application security requirements.
AWS Security Reference Architecture
A holistic reference for deploying AWS security services across a multi-account environment.
Azure Well-Architected — Security
Design principles and reference guidance for securing workloads on Azure.
Authoritative guidance to base your own password, identity, and hardening policies on.
NIST SP 800-63B — Password & Authentication
The modern digital-identity guidelines: memorized-secret (password) rules, MFA, and authenticator assurance levels.
SANS Security Policy Templates
Free, ready-to-adapt templates for acceptable use, password, remote access, and dozens of other policies.
CIS Benchmarks
Consensus-developed secure-configuration baselines for operating systems, cloud, and applications.
NIST SP 800-88 — Media Sanitization
The authoritative guidance for clearing, purging, and destroying data on storage media.
Reference architectures and cheat sheets for logging, detection, and incident-response procedures.
NIST SP 800-92 — Log Management
The Guide to Computer Security Log Management: what to log, how to store it, and how to review it.
OWASP Logging Cheat Sheet
Practical guidance on what application events to log and how to log them securely.
NIST SP 800-61 — Incident Handling
The Computer Security Incident Handling Guide — the reference IR lifecycle and procedures.
MITRE Engenuity — Detection guidance
Analytics and data-source guidance for building detections mapped to ATT&CK.
Standards and advisories for operational technology and industrial control systems.
NIST SP 800-82 Rev. 3 — OT Security
The Guide to Operational Technology (OT) Security, covering SCADA, DCS, and PLC environments.
IEC 62443
The series of standards for security of industrial automation and control systems (IACS).
CISA — Industrial Control Systems
ICS advisories, alerts, and recommended practices for critical-infrastructure defenders.
Primary sources for vulnerabilities, advisories, and national guidance.
CISA.gov
The US Cybersecurity and Infrastructure Security Agency — advisories, guidance, and free tools.
CISA Known Exploited Vulnerabilities (KEV)
The authoritative catalogue of vulnerabilities known to be exploited in the wild.
National Vulnerability Database (NVD)
The US government repository of standards-based vulnerability data (CVEs, CVSS scores).
ENISA
The EU Agency for Cybersecurity — threat landscape reports and guidance.
UK NCSC
The UK National Cyber Security Centre — practical guidance and standards.
The regulations and standards that drive so many control requirements.
PCI DSS
The Payment Card Industry Data Security Standard for anyone handling cardholder data.
FedRAMP
The US government program for standardized security assessment of cloud services.
GDPR (full text)
The General Data Protection Regulation: the EU law governing how personal data of EU residents is collected, processed, and transferred — including consent, breach notification, and the right to erasure.
India DPDP Act, 2023
The Digital Personal Data Protection Act: India's data-protection law setting consent-based rules, data-fiduciary duties, data-principal rights, and penalties for processing digital personal data.
EU Cyber Resilience Act (CRA)
A horizontal EU regulation setting mandatory cybersecurity requirements for products with digital elements — secure-by-design, vulnerability handling, and updates across the product lifecycle.
EU NIS2 Directive
Raises the baseline of cybersecurity and incident-reporting obligations for 'essential' and 'important' entities across critical sectors in the EU.
EU DORA
The Digital Operational Resilience Act: ICT risk-management, incident-reporting, and third-party oversight requirements for the EU financial sector.
HIPAA
The Health Insurance Portability and Accountability Act: US privacy and security rules protecting patients' health information (PHI/ePHI).
SOC 2 (Trust Services Criteria)
The Trust Services Criteria behind SOC 2 audit reports, covering security, availability, processing integrity, confidentiality, and privacy.
First-party security guidance and platform docs from major security and cloud vendors.
Microsoft Security Documentation
Docs for Microsoft Defender, Sentinel, Entra ID, and the Security Development Lifecycle (SDL).
Microsoft Zero Trust Guidance
Reference architecture and deployment guidance for a Zero Trust security model.
CrowdStrike Falcon Documentation
Platform docs and the annual Global Threat Report on adversary tradecraft.
SentinelOne Resources
Singularity platform docs, Labs research, and threat-actor analyses.
Cisco Security Documentation
Docs for Secure Firewall, ISE, Umbrella, and Cisco's Zero Trust guidance.
Splunk Security Docs
Docs for Splunk Enterprise Security, SPL search, and detection content.
Palo Alto Networks TechDocs
PAN-OS, Prisma, and Cortex documentation for next-gen firewall and XDR.
Fortinet Document Library
FortiGate, FortiAnalyzer, and the Fortinet Security Fabric documentation.
Elastic Security Docs
Docs for the Elastic Stack SIEM, detection rules, and EQL.
Okta Developer & Security Docs
Identity, SSO, and adaptive MFA implementation guidance.
Vendor and community threat-research feeds worth following.
Microsoft Threat Intelligence (MSTIC)
Threat-actor tracking, blog research, and the annual Digital Defense Report.
Cisco Talos Intelligence
One of the largest commercial threat-intelligence teams: research, IOCs, and reputation lookups.
Mandiant / Google TI
Incident-driven threat research, APT naming, and frontline intelligence.
Unit 42
Threat research, ransomware analysis, and an ATT&CK-mapped playbook library.
Recorded Future Blog
Analyst research across cyber, geopolitical, and criminal threat activity.
The DFIR Report
Detailed, timeline-driven walkthroughs of real intrusions, mapped to ATT&CK.
AlienVault OTX
An open threat-exchange community for sharing indicators of compromise.
First-party security baselines and benchmarks for the major cloud platforms.
AWS Security Documentation
Security, identity, and compliance docs, plus the AWS Well-Architected security pillar.
Microsoft Cloud Security Benchmark
Prescriptive security controls and baselines for Azure and multi-cloud.
Google Cloud Security Best Practices
Security foundations blueprint and best-practice guidance for GCP.
CSA Cloud Controls Matrix
A cloud-specific control framework mapped to major standards and regulations.
CNCF / Kubernetes Security
Kubernetes hardening guidance and the cloud-native security whitepaper.
Reference material for the tools and detection languages that show up on exams and on the job.
Nmap Reference Guide
The definitive documentation for the network scanner, including NSE scripts.
Metasploit Documentation
Docs for the Metasploit Framework, modules, and Meterpreter.
Wireshark User's Guide
Packet capture and analysis, display filters, and protocol dissection.
Burp Suite Documentation
Web application security testing, plus the free Web Security Academy.
Sigma Rules
The generic, vendor-agnostic signature format for SIEM detection rules.
YARA Documentation
The pattern-matching language for identifying and classifying malware.
Atomic Red Team
Small, portable tests mapped to ATT&CK for validating detections.