Security Field Reference Library
17 terminal-styled reference cards for practitioners — built from primary sources, no AI-summary filler. Free to view and download.
NIST CSF 2.0 Field Reference
Core Functions, Categories, Subcategories, Tiers, and Profiles — with a structured audit loop for assessments. Sourced from NIST CSF 2.0.
CSF 2.0 Small Business Quick-Start
Plain-language NIST SP 1300 guidance for SMBs. Practical steps, no compliance jargon — a working leave-behind for security conversations.
Incident Response Field Reference
SANS PICERL operational checklist — Preparation through Lessons Learned. What to do, in order, when something breaks.
Vendor Risk Field Reference
TPRM quick reference with criticality tiering, BAA/DPA red flags, and due diligence checkpoints for third-party assessments.
ISO/IEC 27001:2022 Field Reference
Structural mapping of the ISMS standard — Annexes, controls, and alignment to common compliance frameworks.
NIST AI RMF Field Reference
Govern, Map, Measure, and Manage core functions for AI risk management. Sourced directly from NIST AI RMF 1.0.
Audit Fieldwork Field Reference
Framework-agnostic trust-but-verify methodology for security audits — evidence collection, finding classification, and reporting structure.
STRIDE + AI Threat Reference
Six STRIDE categories mapped alongside AI-specific extensions — prompt injection, model exfiltration, and LLM-specific attack surfaces.
OWASP ASVS 5.0 Field Reference
Per-chapter verification index for the Application Security Verification Standard. Fastest-payoff chapters highlighted for practical application.
CIS Controls v8 Quick Map
Implementation Groups IG1, IG2, and IG3 mapped across all 18 controls — actionable starting points for any organization size.
DLP Detection Patterns
PII, PHI, PCI, and secrets pattern reference with false-positive tuning guidance. Built for policy review and DLP tool configuration.
Privacy Law Quick-Diff
HIPAA, CCPA/CPRA, and GDPR side-by-side — key obligations, breach timelines, and jurisdictional triggers. Accurate as of September 2026.
HIPAA Security Rule Quick Reference
Required vs. addressable safeguards across Administrative, Physical, and Technical categories — plus OCR Risk Analysis steps and Breach Notification timelines.
CMMC 2.0 Practice Areas
All 14 CMMC domains with practice counts per level, NIST SP 800-171 §3.x section references, and assessment path comparison (self / C3PAO / DIBCAC).
Cloud Security Hardening Reference
IAM, logging, network, and encryption hardening controls mapped side-by-side for AWS, Azure, and GCP. Sourced from CIS Benchmarks v2/v3 and vendor Well-Architected Frameworks.
BEC Prevention Checklist
Wire transfer controls, SPF/DKIM/DMARC configuration, and social engineering red flags for business email compromise prevention. Sourced from FBI IC3 and FinCEN advisories.
IR Plan Structure Reference
NIST SP 800-61 Rev 2 four-phase lifecycle, required plan sections with framework attribution, and tabletop scenario types for incident response plan development.
$ anchor --contact
Need help applying these frameworks?
Reference cards show you the structure. A consultation shows you where your organization actually sits within it.
Schedule a Free Consultation