The following sources provide reference points for terminology, risk management and good practice. Their inclusion does not mean they endorse this site, and not every source applies to every organisation.
Core sources
- NIST Cybersecurity Framework
- NIST SP 800-207: Zero Trust Architecture
- NIST Digital Identity Guidelines
- NIST AI Risk Management Framework
- NIST Definition of Cloud Computing
- NIST Privacy Framework
- CISA Secure by Design
- OWASP Top 10
- OWASP API Security Project
- W3C Web Content Accessibility Guidelines 2.2
How sources are used
Frameworks are translated into planning questions rather than copied as universal prescriptions. Readers remain responsible for determining the laws, contractual obligations, standards and professional practices that apply to their location and environment.