Guides

Short primers that anchor a framework to a working scenario.

Plain-English reads — the language first, then the one function each beginner brief should open first. Pair them with the matching course for the full control map, or with a lab to score a real environment against it.

Framework

Cross-industry frameworks

Framework
Beginner
NIST CSF 2.0 Quick-Start

A beginner-friendly walk of NIST CSF 2.0 — the six functions, the four-tier maturity model, three real analyst briefs to anchor each function to a working scenario, and where to go next once you have read it.

Read primer →
Framework
Advanced
NIST RMF Quick-Start

A beginner-friendly walk of the NIST Risk Management Framework — the seven lifecycle steps, how RMF and NIST CSF 2.0 fit together (and where they overlap), and two real analyst briefs that show the gates firing in practice.

Read primer →

Standard

Standards

Standard
Advanced
ISO 27001 Quick-Start

A beginner-friendly walk of ISO 27001 — the Annex A control domains, the Plan-Do-Check-Act cycle that runs the ISMS, the Statement of Applicability that ties it together, and two real analyst briefs (gap assessment and audit prep) that show the certification clock firing in practice.

Read primer →
Standard
Intermediate
PCI DSS Quick-Start

A beginner-friendly walk of PCI DSS — the six goal families that organize the twelve requirements, the four SAQ levels and merchant-vs-service-provider tiering that decide which report you actually file, v4.0 in 2024–2025 with the future-dated controls now mandatory, scope-reduction patterns (segmentation, processor tokenization, the CDE-on-a-VLAN shape), and two real analyst briefs that show the AOC firing in a vendor intake and a redirect-to-tokenized-checkout migration.

Read primer →

Regulation

Regulations

Regulation
Intermediate
HIPAA Quick-Start

A beginner-friendly walk of HIPAA — the 1996 Health Insurance Portability and Accountability Act, enforced by the HHS Office for Civil Rights (OCR), applicable US-wide to Covered Entities and Business Associates handling Protected Health Information (PHI). The primer names the law, the regulator, and the scope before it opens the Privacy Rule (§164.500–§164.534), the Security Rule (§164.302–§164.318), and the Breach Notification Rule (§164.400–§164.414) subpart by subpart, and pairs each citation with the concrete artifact the audit asks for.

Read primer →
Regulation
Intermediate
GDPR Quick-Start

A beginner-friendly walk of the EU General Data Protection Regulation — the EU's data-protection law since May 2018, enforced by each Member State's independent data protection authority and by the European Data Protection Board for cross-border cases, applicable to any controller or processor that handles the personal data of people in the EU. The primer drops the Article-pin wall into plain English: what GDPR is, who is on the hook, the seven principles that govern every processing activity, and how it differs from US frameworks like HIPAA and SOC 2 in the language the audit and the procurement team actually read.

Read primer →

Audit

Audit frameworks

Audit
Intermediate
SOC 2 Quick-Start

A beginner-friendly walk of SOC 2 — the five Trust Service Criteria, the audit lifecycle (readiness → Type 1 → Type 2), the difference between a Type I and Type II report, and two real analyst briefs that show the report firing in a vendor intake and a customer questionnaire.

Read primer →