The following primary sources support the concepts discussed in this documentation. Choose the publication and edition applicable to your programme. Guidance, technical standards and legislation have different purposes; listing a source does not mean that every requirement is implemented by the app or applies to every organisation.

NIST risk management and assurance

ReferenceUse
FIPS 199Security categorisation of federal information and systems; February 2004.
FIPS 200Minimum security requirements for federal information and systems; March 2006.
SP 800-12 Rev. 1Introduction to information security.
SP 800-18 Rev. 2Developing security, privacy and supply-chain risk management plans; June 2026, replacing the 2006 revision.
SP 800-30 Rev. 1Conducting risk assessments; September 2012.
SP 800-37 Rev. 2The system life-cycle Risk Management Framework.
SP 800-39Organisation, mission/business-process and information-system views of risk.
SP 800-53 Rev. 5Security and privacy control catalogue. Check its current control release and update notices as well as the revision number.
SP 800-53A Rev. 5Assessment procedures for security and privacy controls.
SP 800-53BControl baselines.
SP 800-161 Rev. 1, updated November 2024Cybersecurity supply-chain risk management practices.
SP 800-171 Rev. 3Protecting controlled unclassified information in nonfederal systems and organisations.
SP 800-171A Rev. 3Assessing the corresponding CUI security requirements.
SP 800-221Connecting ICT risk programmes to an enterprise risk portfolio.

NIST issued a 5.2.0 control and assessment release in August 2025. A control release and a document revision are not interchangeable identifiers. Record the version actually used by your assessment.

Cybersecurity and enterprise risk

The IR 8286 Rev. 1 series connects cybersecurity risk information with enterprise risk management. Its supporting publications cover risk identification and estimation, IR 8286A Rev. 1, prioritisation, IR 8286B, governance reporting, IR 8286C Rev. 1, and business impact analysis, IR 8286D.

Use the final publications and their update notices when maintaining a methodology. Earlier public drafts can be useful historical references, but should be identified as drafts.

ISO and IEC

ReferenceScope
ISO 31000:2018Risk management guidelines.
IEC 31010:2019Risk assessment techniques.
ISO/IEC 27001Information security management system requirements; consult the applicable edition and amendments.
ISO/IEC 27002:2022Information security control guidance.
ISO/IEC 27005:2022Guidance for managing information security risks.

ISO 31000 is not titled ISO/IEC 31000. Its risk-management guidance should not be confused with the ISMS requirements of ISO/IEC 27001.

European Union legislation

Consult the official texts for NIS2, Directive (EU) 2022/2555, DORA, Regulation (EU) 2022/2554, GDPR, Regulation (EU) 2016/679, and the Cyber Resilience Act, Regulation (EU) 2024/2847.

Determine the obligations relevant to your organisation using the applicable legal texts, national measures where relevant, and competent-authority guidance. A framework selection in CSFaaS does not establish legal applicability or fulfilment.

Further reference material

The concepts chapter also draws on COSO enterprise risk management guidance. Specialist frameworks, control catalogues and incident vocabularies should be attributed to their publishers and identified by edition wherever they are used. Retain those references with the relevant framework, policy or assessment so reviewers can distinguish source requirements from workspace adaptations.