About
About IT Atlas
IT Atlas is a structured knowledge platform for Information Technology practitioners. It exists because most IT information is either vendor documentation for one product or introductory material that stops before the part that matters in practice.

What it covers
Twelve layers, from fundamentals through infrastructure, cloud, networking, security, identity, endpoints, applications and data, operations, governance, vendor platforms and reference architecture. Each article explains what something is, how it works, why it matters, how it is secured, and how it commonly fails, then links to the topics it depends on.
IT Fundamentals
Start here
Infrastructure
Compute, storage, resilience
Cloud
Platforms and service models
Networking
How systems reach each other
Security
A layer, not a silo
Identity
The modern control plane
Endpoints
Devices and their lifecycle
Applications & Data
What the business actually uses
Operations
Keeping the environment healthy
Governance
Direction, policy and risk
Platforms
Ecosystems in context
Architecture
Reference designs
Editorial principles
- Vendor neutral. Products are described by function and positioning. No rankings, no scores, no sponsorship, no affiliate arrangements.
- Precise over simple. Where a simplification would mislead, Kerberos delegation, token validation, RAID versus backup, the article states the real behaviour.
- Structural, not encyclopaedic. Every topic states what it depends on and what depends on it, because that relationship is what makes an environment understandable.
- Failure aware. Common misconfigurations and failure points are treated as first class content, because that is where practitioner time actually goes.
- Primary sources cited. Standards, RFCs and vendor documentation are linked so any claim can be verified.
- IT only. Operational Technology is a different discipline with different priorities, and it is covered separately rather than blended in.
How content is structured
Content is held as structured data rather than free form pages: topics carry typed fields for overview, mechanics, security considerations, misconfigurations, protocols, ports, related topics and references. That is what allows a single search index across 163 articles, 66 glossary terms, 36 protocol entries and 46 technologies, and it is the reason the platform can later gain a CMS, an API or a knowledge graph without the content being rewritten.
Accuracy and limitations
- Vendor product behaviour changes frequently. For anything version specific, confirm against current vendor documentation before acting.
- Port numbers and defaults are conventions. Verify what is actually configured in your environment.
- Articles are reference material for practitioners, not a design authority for your environment and not legal, regulatory or professional advice.
- Corrections are treated as high priority; accuracy matters more than volume here.
Resources IT Atlas points to
Where to go for current information, vulnerability context and formal credentials. None of these links are sponsored or affiliated.
IT and security news
Primary publishers rather than aggregators, so a claim can be traced to its author.
- CISA cybersecurity advisories
Alerts and joint advisories with indicators and mitigations.
- NCSC UK reports and advisories
Threat reports and architecture guidance written for defenders.
- SANS Internet Storm Center
Daily analysis of what is actually being scanned and exploited.
- Microsoft Security blog
Threat intelligence and servicing context for the Microsoft estate.
- Cloudflare blog
Edge platform engineering, DDoS trends and protocol work.
- Google Online Security blog
Platform security research and ecosystem measurement.
- Kubernetes blog
Release notes and security announcements for the platform itself.
CVE and exposure context
A CVE identifier alone says nothing about risk. These sources supply the context that does.
- CVE Program
The identifier registry and the authorities that assign records.
- National Vulnerability Database
CVE records enriched with CVSS severity, affected product data and references.
- CISA Known Exploited Vulnerabilities catalogue
Confirmed exploitation in the wild, with remediation due dates. The strongest prioritisation signal available.
- FIRST EPSS
Probability that a given vulnerability is exploited in the next 30 days.
Certification bodies
Listed by awarding body so the syllabus, prerequisites and renewal rules come from the source.
- CompTIA certifications
Network+, Security+ and Cloud+, the common vendor neutral foundation.
- Microsoft Credentials
Role based Azure, Microsoft 365 and security operations certifications.
- AWS Certification
Cloud architecture, operations and security tiers.
- Cisco certifications
CCNA through CCIE, still the common networking ladder.
- ISC2 certifications
CISSP and CCSP, including the experience requirements.
- ISACA certifications
CISA, CISM and CRISC for audit, management and risk roles.
- GIAC certifications
Hands on detection, forensics and incident response credentials.
- Linux Foundation training
LFCS, CKA and CKS for Linux and Kubernetes operations.
- Red Hat training and certification
RHCSA and RHCE, performance based Linux exams.
Live headlines from most of these publishers are collected on the advisories and news page, and the wider reference list lives under resources.
IT Atlas and OT Atlas
IT Atlas and OT Atlas are separate platforms on purpose. Industrial control environments prioritise safety and availability, run equipment for decades, and cannot absorb IT practices such as automatic patching or active scanning. Keeping the two apart means neither audience has to filter out guidance that would be wrong or unsafe in their environment. Where the domains genuinely meet, IT Atlas says so explicitly. See IT vs OT.
Both platforms are published by RWP Ventures, which funds the editorial work and keeps it free of vendor influence: no sponsored placement, no affiliate links and no paid rankings on either site.
