Guides
Short primers that anchor a framework to a working scenario.
Plain-English reads — the language first, then the one function each beginner brief should open first. Pair them with the matching course for the full control map, or with a lab to score a real environment against it.
Framework
Cross-industry frameworks
A beginner-friendly walk of NIST CSF 2.0 — the six functions, the four-tier maturity model, three real analyst briefs to anchor each function to a working scenario, and where to go next once you have read it.
Read primer →A beginner-friendly walk of the NIST Risk Management Framework — the seven lifecycle steps, how RMF and NIST CSF 2.0 fit together (and where they overlap), and two real analyst briefs that show the gates firing in practice.
Read primer →Standard
Standards
A beginner-friendly walk of ISO 27001 — the Annex A control domains, the Plan-Do-Check-Act cycle that runs the ISMS, the Statement of Applicability that ties it together, and two real analyst briefs (gap assessment and audit prep) that show the certification clock firing in practice.
Read primer →A beginner-friendly walk of PCI DSS — the six goal families that organize the twelve requirements, the four SAQ levels and merchant-vs-service-provider tiering that decide which report you actually file, v4.0 in 2024–2025 with the future-dated controls now mandatory, scope-reduction patterns (segmentation, processor tokenization, the CDE-on-a-VLAN shape), and two real analyst briefs that show the AOC firing in a vendor intake and a redirect-to-tokenized-checkout migration.
Read primer →Regulation
Regulations
A beginner-friendly walk of HIPAA — the 1996 Health Insurance Portability and Accountability Act, enforced by the HHS Office for Civil Rights (OCR), applicable US-wide to Covered Entities and Business Associates handling Protected Health Information (PHI). The primer names the law, the regulator, and the scope before it opens the Privacy Rule (§164.500–§164.534), the Security Rule (§164.302–§164.318), and the Breach Notification Rule (§164.400–§164.414) subpart by subpart, and pairs each citation with the concrete artifact the audit asks for.
Read primer →A beginner-friendly walk of the EU General Data Protection Regulation — the EU's data-protection law since May 2018, enforced by each Member State's independent data protection authority and by the European Data Protection Board for cross-border cases, applicable to any controller or processor that handles the personal data of people in the EU. The primer drops the Article-pin wall into plain English: what GDPR is, who is on the hook, the seven principles that govern every processing activity, and how it differs from US frameworks like HIPAA and SOC 2 in the language the audit and the procurement team actually read.
Read primer →Audit
Audit frameworks
A beginner-friendly walk of SOC 2 — the five Trust Service Criteria, the audit lifecycle (readiness → Type 1 → Type 2), the difference between a Type I and Type II report, and two real analyst briefs that show the report firing in a vendor intake and a customer questionnaire.
Read primer →