DDailyWF

External Guidelines and Control References

Known public resources that inform DailyWF guidance, including NIST, CISA, CIS, OWASP, ISO, and Google Search Central.

Purpose

This reference note explains external guidelines and control references in practical operating language. Use it to align vocabulary before turning the concept into a workflow, policy, or checklist.

Reference set

DailyWF uses public guidance as orientation, then translates it into smaller operating pages. These links are not a claim that every DailyWF page implements every requirement in the referenced standards.

ResourceUseDailyWF fit
NIST Cybersecurity Framework 2.0General cybersecurity risk management structure: govern, identify, protect, detect, respond, recover.Risk vocabulary, governance rhythm, cybersecurity lifecycle thinking.
NIST SP 800-53 Rev. 5 control catalogSecurity and privacy control language useful when translating operating work into controls.Control mapping, evidence expectations, policy-to-workflow translation.
CISA Cybersecurity Incident and Vulnerability Response PlaybooksPractical incident and vulnerability response sequencing for structured response work.Incident response sequence, vulnerability response, coordination checkpoints.
CIS Critical Security Controls v8Prioritized safeguards for common enterprise security risks.Prioritized safeguards for small and mid-size security programs.
OWASP Application Security Verification StandardVerification requirements for web application security controls.Application security verification language for software-facing workflows.
NIST SP 800-63-4 Digital Identity GuidelinesIdentity proofing, authentication, and federation guidance.Authentication, identity, and account lifecycle pages.
NIST AI Risk Management FrameworkAI risk governance structure for mapping, measuring, managing, and governing AI risk.AI-assisted work boundaries, risk mapping, and review practices.
ISO quality management principlesProcess approach, evidence-based decisions, improvement, and relationship management.Process approach, improvement, evidence-based decisions.
NIST SP 800-34 Rev. 1 Contingency Planning GuideContingency planning concepts useful for recovery and continuity workflows.Backup, restore, recovery, continuity, and contingency planning pages.
CISA Secure by DesignSecure-by-design principles for software and technology evaluation.Vendor review, software adoption, and secure delivery thinking.
Google Search Central SEO Starter GuideGuidance for crawlable, understandable, user-centered site structure.Site structure, crawlability, useful navigation, and search hygiene.

When to use

  • When the work repeats often enough that memory is no longer reliable.
  • When more than one person may request, perform, review, or inherit the work.
  • When risk, approval, evidence, or handoff needs to be visible later.

Common failure modes

  • Ownership is implied rather than named.
  • Inputs are accepted before they are complete.
  • The output is not easy to verify later.

Review guidance

Review this page after a material incident, after a role or system change, and on a normal cadence appropriate to its risk. During review, check whether the owner is still correct, whether inputs are still complete, whether the output is still useful, and whether related pages need updates.