External Guidelines and Control References
Known public resources that inform DailyWF guidance, including NIST, CISA, CIS, OWASP, ISO, and Google Search Central.
Purpose
This reference note explains external guidelines and control references in practical operating language. Use it to align vocabulary before turning the concept into a workflow, policy, or checklist.
Reference set
DailyWF uses public guidance as orientation, then translates it into smaller operating pages. These links are not a claim that every DailyWF page implements every requirement in the referenced standards.
| Resource | Use | DailyWF fit |
|---|---|---|
| NIST Cybersecurity Framework 2.0 | General cybersecurity risk management structure: govern, identify, protect, detect, respond, recover. | Risk vocabulary, governance rhythm, cybersecurity lifecycle thinking. |
| NIST SP 800-53 Rev. 5 control catalog | Security and privacy control language useful when translating operating work into controls. | Control mapping, evidence expectations, policy-to-workflow translation. |
| CISA Cybersecurity Incident and Vulnerability Response Playbooks | Practical incident and vulnerability response sequencing for structured response work. | Incident response sequence, vulnerability response, coordination checkpoints. |
| CIS Critical Security Controls v8 | Prioritized safeguards for common enterprise security risks. | Prioritized safeguards for small and mid-size security programs. |
| OWASP Application Security Verification Standard | Verification requirements for web application security controls. | Application security verification language for software-facing workflows. |
| NIST SP 800-63-4 Digital Identity Guidelines | Identity proofing, authentication, and federation guidance. | Authentication, identity, and account lifecycle pages. |
| NIST AI Risk Management Framework | AI risk governance structure for mapping, measuring, managing, and governing AI risk. | AI-assisted work boundaries, risk mapping, and review practices. |
| ISO quality management principles | Process approach, evidence-based decisions, improvement, and relationship management. | Process approach, improvement, evidence-based decisions. |
| NIST SP 800-34 Rev. 1 Contingency Planning Guide | Contingency planning concepts useful for recovery and continuity workflows. | Backup, restore, recovery, continuity, and contingency planning pages. |
| CISA Secure by Design | Secure-by-design principles for software and technology evaluation. | Vendor review, software adoption, and secure delivery thinking. |
| Google Search Central SEO Starter Guide | Guidance for crawlable, understandable, user-centered site structure. | Site structure, crawlability, useful navigation, and search hygiene. |
When to use
- When the work repeats often enough that memory is no longer reliable.
- When more than one person may request, perform, review, or inherit the work.
- When risk, approval, evidence, or handoff needs to be visible later.
Common failure modes
- Ownership is implied rather than named.
- Inputs are accepted before they are complete.
- The output is not easy to verify later.
Review guidance
Review this page after a material incident, after a role or system change, and on a normal cadence appropriate to its risk. During review, check whether the owner is still correct, whether inputs are still complete, whether the output is still useful, and whether related pages need updates.