CIS Controls (opens in a new tab)
Why: Prioritised, actionable safeguards that help teams sequence hardening work by impact.
Recognised frameworks and control sets to structure a programme without reinventing the wheel.
13 current resources
Highest starting-point strength resources in this category.
Why: Prioritised, actionable safeguards that help teams sequence hardening work by impact.
Why: Global ISMS requirements and control guidance underpinning certification and supplier assurance.
Why: Living knowledge base of adversary tactics and techniques for threat-informed detection and defence.
Showing 13 resources
Why: Prioritised, actionable safeguards that help teams sequence hardening work by impact.
Why: Global ISMS requirements and control guidance underpinning certification and supplier assurance.
Why: Living knowledge base of adversary tactics and techniques for threat-informed detection and defence.
Why: Widely adopted risk-based framework for organising cyber capability across Identify–Protect–Detect–Respond–Recover.
Why: Authoritative catalogue of security and privacy controls used to design and assess system safeguards.
Why: Practical application security verification standard that turns secure-design expectations into testable requirements for builders, reviewers and assurance teams.
Why: Canonical web application risk ranking — the shared language practitioners and boards use for the biggest app risks.
Why: The Cyber Security Body of Knowledge — structured academic and practitioner reference covering the core knowledge areas of the discipline.
Why: Countermeasure knowledge graph that maps defensive techniques against attacker behaviours.
Why: MITRE active-defence framework for denial, deception and adversary engagement, mapped to ATT&CK for defender planning.
Why: Mandatory UK health and care self-assessment of data security and information governance practice.
Why: Cross-maps many regulatory and security frameworks into one controls set for multi-obligation programmes.
Why: International criteria for evaluating IT product security claims in procurement and assurance.