Security notebook
Making complex ideas usable.
Practical explanations of the frameworks, models, and vocabulary I return to while studying cybersecurity.
NIST SP 800-37
The Risk Management Framework and its role in integrating security and privacy into the system development life cycle.
Read the note →NIST SP 800-53
A catalog of security and privacy controls for protecting systems, organizations, and missions.
Read the note →CVE / CVSS
How vulnerabilities are identified, scored, prioritized, remediated, and verified.
Read the note →MITRE ATT&CK
A common knowledge base for adversary tactics, techniques, and procedures observed in real attacks.
Read the note →OWASP Top 10
A widely used awareness guide to the most significant categories of web application security risk.
Read the note →