$ ls resources/cheat-sheets/
Back to Resources

Security Field Reference Library

17 terminal-styled reference cards for practitioners — built from primary sources, no AI-summary filler. Free to view and download.

csf-field-reference.html
Field Reference

NIST CSF 2.0 Field Reference

Core Functions, Categories, Subcategories, Tiers, and Profiles — with a structured audit loop for assessments. Sourced from NIST CSF 2.0.

csf-small-business.html
Quick-Start Guide

CSF 2.0 Small Business Quick-Start

Plain-language NIST SP 1300 guidance for SMBs. Practical steps, no compliance jargon — a working leave-behind for security conversations.

incident-response-field-reference.html
Operational Checklist

Incident Response Field Reference

SANS PICERL operational checklist — Preparation through Lessons Learned. What to do, in order, when something breaks.

vendor-risk-field-reference.html
Field Reference

Vendor Risk Field Reference

TPRM quick reference with criticality tiering, BAA/DPA red flags, and due diligence checkpoints for third-party assessments.

iso-27001-field-reference.html
Field Reference

ISO/IEC 27001:2022 Field Reference

Structural mapping of the ISMS standard — Annexes, controls, and alignment to common compliance frameworks.

ai-rmf-field-reference.html
Field Reference

NIST AI RMF Field Reference

Govern, Map, Measure, and Manage core functions for AI risk management. Sourced directly from NIST AI RMF 1.0.

audit-fieldwork-field-reference.html
Field Reference

Audit Fieldwork Field Reference

Framework-agnostic trust-but-verify methodology for security audits — evidence collection, finding classification, and reporting structure.

stride-ai-threat-reference.html
Threat Modeling

STRIDE + AI Threat Reference

Six STRIDE categories mapped alongside AI-specific extensions — prompt injection, model exfiltration, and LLM-specific attack surfaces.

asvs-field-reference.html
Field Reference

OWASP ASVS 5.0 Field Reference

Per-chapter verification index for the Application Security Verification Standard. Fastest-payoff chapters highlighted for practical application.

cis-controls-field-reference.html
Quick Map

CIS Controls v8 Quick Map

Implementation Groups IG1, IG2, and IG3 mapped across all 18 controls — actionable starting points for any organization size.

dlp-detection-patterns.html
Pattern Reference

DLP Detection Patterns

PII, PHI, PCI, and secrets pattern reference with false-positive tuning guidance. Built for policy review and DLP tool configuration.

privacy-law-quick-diff.html
Compliance Reference

Privacy Law Quick-Diff

HIPAA, CCPA/CPRA, and GDPR side-by-side — key obligations, breach timelines, and jurisdictional triggers. Accurate as of September 2026.

hipaa-security-rule-reference.html
Compliance Reference

HIPAA Security Rule Quick Reference

Required vs. addressable safeguards across Administrative, Physical, and Technical categories — plus OCR Risk Analysis steps and Breach Notification timelines.

cmmc-2-practice-areas.html
Compliance Reference

CMMC 2.0 Practice Areas

All 14 CMMC domains with practice counts per level, NIST SP 800-171 §3.x section references, and assessment path comparison (self / C3PAO / DIBCAC).

cloud-security-hardening-reference.html
Hardening Reference

Cloud Security Hardening Reference

IAM, logging, network, and encryption hardening controls mapped side-by-side for AWS, Azure, and GCP. Sourced from CIS Benchmarks v2/v3 and vendor Well-Architected Frameworks.

bec-prevention-checklist.html
Prevention Checklist

BEC Prevention Checklist

Wire transfer controls, SPF/DKIM/DMARC configuration, and social engineering red flags for business email compromise prevention. Sourced from FBI IC3 and FinCEN advisories.

ir-plan-structure-reference.html
Field Reference

IR Plan Structure Reference

NIST SP 800-61 Rev 2 four-phase lifecycle, required plan sections with framework attribution, and tabletop scenario types for incident response plan development.

$ anchor --contact

Need help applying these frameworks?

Reference cards show you the structure. A consultation shows you where your organization actually sits within it.

Schedule a Free Consultation