<-- Back To Resources

Governance Frameworks Portal

Policy & Guidance

Foundational documents, global compliance architectures, identity baselines, software supply-chain guidance, and legislative reference material organized into operational buckets.

Authoritative Frameworks

DoD Cybersecurity Reference Architecture (CSRA)

Department of Defense reference architecture for cybersecurity alignment.

Download PDF
NIST SP 800-53 r5 Security and Privacy Controls

Security and privacy control catalog for information systems and organizations.

Download PDF
NIST SP 800-37 r2 Risk Management Framework

Risk management framework for system authorization and continuous monitoring.

Download PDF
Cybersecurity Framework v1.0

Original NIST cybersecurity framework reference baseline.

Download PDF
NIST CSF 2.0

Current NIST cybersecurity framework with governance as a core function.

Download PDF
CISA Cross-Sector Cybersecurity Performance Goals

Cross-sector cyber performance goals for baseline resilience.

Download PDF
NIST SP 800-60 Mapping Guides

Information type and system categorization references, volumes 1 and 2 plus interagency working draft.

ISO 27001 Official ISO Hub

Commercial standard reference. Source-only to avoid unauthorized redistribution.

Access Source ↗

Zero-Trust Architecture

NIST SP 800-207 Zero Trust Architecture

Canonical zero-trust architecture reference.

Download PDF
CISA Zero Trust Maturity Model v2.0

Federal maturity model for zero-trust capability planning.

Download PDF
NCCoE Implementing Zero Trust Architecture

Applied zero-trust implementation reference from NCCoE.

Download PDF

Cloud & Identity Baselines

NSA CISA Cloud Top-10 IAM

Cloud identity and access management baseline risks.

Download PDF
NIST SP 800-63b Digital Identity Guidelines

Authentication and digital identity assurance guidance.

Download PDF

Statutory Regulatory Text

HIPAA Administrative Simplification

Administrative simplification reference for healthcare data handling.

Download PDF
HIPAA Security Standards Matrix

Appendix A security standards matrix.

Download PDF
NIST SP 800-66r2 HIPAA Security Rule

Implementation guidance for the HIPAA Security Rule.

Download PDF
PCI DSS v4.0.1 Official Document Portal

Commercial payment-card standard portal. Source-only access.

Access Source ↗

Organizational Templates

NIST SP 1299 CSF Resources & Overview Guide

Resource overview for applying the Cybersecurity Framework.

Download PDF
Adopt the NIST

Use CSF and NIST overview resources as organizational adoption templates.

Download PDF

Supply Chain & Infrastructure

NIST SP 800-171r3 Protecting CUI

Security requirements for controlled unclassified information in nonfederal systems.

Download PDF
NIST SP 800-218 Secure Software Development Framework

Secure software development framework for modern delivery pipelines.

Download PDF