The following primary sources support the concepts discussed in this documentation. Choose the publication and edition applicable to your programme. Guidance, technical standards and legislation have different purposes; listing a source does not mean that every requirement is implemented by the app or applies to every organisation.
NIST risk management and assurance
| Reference | Use |
|---|---|
| FIPS 199 | Security categorisation of federal information and systems; February 2004. |
| FIPS 200 | Minimum security requirements for federal information and systems; March 2006. |
| SP 800-12 Rev. 1 | Introduction to information security. |
| SP 800-18 Rev. 2 | Developing security, privacy and supply-chain risk management plans; June 2026, replacing the 2006 revision. |
| SP 800-30 Rev. 1 | Conducting risk assessments; September 2012. |
| SP 800-37 Rev. 2 | The system life-cycle Risk Management Framework. |
| SP 800-39 | Organisation, mission/business-process and information-system views of risk. |
| SP 800-53 Rev. 5 | Security and privacy control catalogue. Check its current control release and update notices as well as the revision number. |
| SP 800-53A Rev. 5 | Assessment procedures for security and privacy controls. |
| SP 800-53B | Control baselines. |
| SP 800-161 Rev. 1, updated November 2024 | Cybersecurity supply-chain risk management practices. |
| SP 800-171 Rev. 3 | Protecting controlled unclassified information in nonfederal systems and organisations. |
| SP 800-171A Rev. 3 | Assessing the corresponding CUI security requirements. |
| SP 800-221 | Connecting ICT risk programmes to an enterprise risk portfolio. |
NIST issued a 5.2.0 control and assessment release in August 2025. A control release and a document revision are not interchangeable identifiers. Record the version actually used by your assessment.
Cybersecurity and enterprise risk
The IR 8286 Rev. 1 series connects cybersecurity risk information with enterprise risk management. Its supporting publications cover risk identification and estimation, IR 8286A Rev. 1, prioritisation, IR 8286B, governance reporting, IR 8286C Rev. 1, and business impact analysis, IR 8286D.
Use the final publications and their update notices when maintaining a methodology. Earlier public drafts can be useful historical references, but should be identified as drafts.
ISO and IEC
| Reference | Scope |
|---|---|
| ISO 31000:2018 | Risk management guidelines. |
| IEC 31010:2019 | Risk assessment techniques. |
| ISO/IEC 27001 | Information security management system requirements; consult the applicable edition and amendments. |
| ISO/IEC 27002:2022 | Information security control guidance. |
| ISO/IEC 27005:2022 | Guidance for managing information security risks. |
ISO 31000 is not titled ISO/IEC 31000. Its risk-management guidance should not be confused with the ISMS requirements of ISO/IEC 27001.
European Union legislation
Consult the official texts for NIS2, Directive (EU) 2022/2555, DORA, Regulation (EU) 2022/2554, GDPR, Regulation (EU) 2016/679, and the Cyber Resilience Act, Regulation (EU) 2024/2847.
Determine the obligations relevant to your organisation using the applicable legal texts, national measures where relevant, and competent-authority guidance. A framework selection in CSFaaS does not establish legal applicability or fulfilment.
Further reference material
The concepts chapter also draws on COSO enterprise risk management guidance. Specialist frameworks, control catalogues and incident vocabularies should be attributed to their publishers and identified by edition wherever they are used. Retain those references with the relevant framework, policy or assessment so reviewers can distinguish source requirements from workspace adaptations.