NIST CSF 2.0
Outcome-based framework organized around Govern, Identify, Protect, Detect, Respond, Recover.
The frameworks security teams actually use — from risk management and control catalogs to threat modeling and offensive testing.
Outcome-based framework organized around Govern, Identify, Protect, Detect, Respond, Recover.
Comprehensive catalog of security and privacy controls used across US federal systems.
Awareness document on the most critical security risks to web applications.
Verification requirements for designing, building, and testing modern web apps and services.
Measurable framework for analyzing and improving a software security posture.
Peer-reviewed methodology for operational security testing.
Common language and scope for delivering and procuring penetration tests.
Community-developed list of software and hardware weakness types.
Mnemonic-based threat modeling categories used for system decomposition.
Globally accessible knowledge base of adversary tactics and techniques.
Prioritized set of safeguards to mitigate the most common attacks.
Reference set of controls supporting an ISO/IEC 27001 ISMS.