Source library · 320 curated entries

Where every claim in SecProve comes from.

A dense reading catalog. Every claim is footnoted. Sort by source, filter by pillar, type, or recency. Built for analysts who want to see what we are standing on.

320SOURCES
143ORGS
50DOMAINS
320ADDED · 90 DAYS
Pillar · multi-selectall 4 selected
Domainsselect pillar(s) above
Browsing the full corpus. Pick pillars above to narrow to specific domains.
8 sources · matching filters · sorted by citation density
Sort
ACybersecurity8 sources
01

International standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).

FrameworkIntermediateA1 · Governance, Risk & ComplianceNEW · 1mo ago
Test your knowledge · A1
02
CIS Controls v8Center for Internet Security

18 prioritized security controls organized into Implementation Groups (IG1, IG2, IG3). Practical and prescriptive — good for questions about prioritization and which controls matter most for different organization sizes.

Test your knowledge · A1
03

Quantitative risk analysis framework. Provides a model for understanding, analyzing, and quantifying information risk in financial terms.

FrameworkAdvancedA1 · Governance, Risk & ComplianceNEW · 1mo ago
Test your knowledge · A1
04

Guide for applying the RMF to information systems and organizations. Covers categorization, control selection, implementation, assessment, authorization, and monitoring.

FrameworkIntermediateA1 · Governance, Risk & ComplianceNEW · 1mo ago
Test your knowledge · A1
05

Risk assessment methodology: threat sources, vulnerabilities, likelihood, impact. Complements 800-37. Good for questions comparing quantitative vs. qualitative risk assessment.

FrameworkIntermediateA1 · Governance, Risk & ComplianceNEW · 22d ago
Test your knowledge · A1
06

The 7-step RMF (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor). Questions should test understanding of step sequencing, roles (AO, ISSO, ISSM), and continuous monitoring vs. point-in-time assessment.

FrameworkIntermediateA1 · Governance, Risk & ComplianceNEW · 22d ago
Test your knowledge · A1
07
FAIR (Factor Analysis of Information Risk)The Open Group / FAIR Institute

Quantitative risk analysis framework. Decomposes risk into Loss Event Frequency and Loss Magnitude. Questions on translating risk into business terms and comparing to qualitative methods.

Test your knowledge · A1
08

Annual survey of cyber leaders on resilience, workforce, geopolitics, and emerging tech including AI. Excellent for leadership and strategy questions.

Test your knowledge · A1

Ready to test what you've learned?

Our questions are built directly from these resources. Take a quiz and see how your knowledge stacks up.