Reference
Resources
IT Atlas summarises and connects; it does not replace primary sources. These are the references worth going to directly when a decision needs to be defensible.
Standards and specifications
The authoritative text, where a definition needs settling rather than paraphrasing.
IETF RFC Editor
The actual protocol specifications, TCP, DNS, HTTP, TLS, OAuth, DHCP.
NIST Computer Security Resource Center
SP 800 series publications, including 800-53, 800-63 identity, 800-207 Zero Trust and 800-61 incident handling.
ISO/IEC 27000 family
Information security management system requirements and control guidance.
OASIS SAML specifications
The SAML 2.0 assertions and protocol documents.
OpenID Connect specifications
Core, discovery and session management specifications.
Vulnerability and exposure data
For prioritisation decisions, use exploitation evidence rather than severity score alone.
CISA Known Exploited Vulnerabilities catalogue
Vulnerabilities with confirmed exploitation, the strongest prioritisation signal available.
NIST National Vulnerability Database
CVE records enriched with CVSS scores, CPE data and references.
FIRST EPSS
Probability that a vulnerability will be exploited in the next 30 days.
CVE Program
The identifier registry itself, and the assigning authorities behind it.
Threat behaviour and advisories
Adversary technique references and government advisories with technical detail.
MITRE ATT&CK
Tactics, techniques, mitigations and data sources for detection coverage work.
CISA advisories
Joint advisories with indicators and mitigations, usually the fastest authoritative source during an active campaign.
UK NCSC guidance
Clear, practitioner focused guidance on architecture, cloud and incident management.
MITRE D3FEND
A countermeasure knowledge graph that pairs with ATT&CK.
Hardening and configuration baselines
Start from a published baseline and document deviations, rather than inventing one.
CIS Benchmarks
Consensus configuration baselines for operating systems, cloud platforms and applications.
Microsoft security baselines
Group Policy and Intune baselines for Windows and Microsoft 365 Apps.
DISA STIGs
Stricter US Department of Defense configuration standards, useful as a reference ceiling.
OWASP Cheat Sheet Series
Concise, practical application security guidance by topic.
Vendor documentation
For product behaviour, the vendor's own current documentation is the only reliable source.
Microsoft Learn
Entra ID, Intune, Microsoft 365, Azure, Windows Server and Defender documentation.
AWS Documentation
Service references, IAM policy evaluation logic and the well architected guidance.
Google Cloud Documentation
Service documentation and architecture centre patterns.
Kubernetes Documentation
Concepts, API reference and production hardening guidance.
Operational data and reporting
Useful for calibrating expectations and supporting risk conversations with evidence.
Verizon Data Breach Investigations Report
Annual analysis of incident patterns by industry and attack type.
IETF Datatracker
Draft standards in progress, when you need to know where a protocol is heading.
Internet Assigned Numbers Authority registries
The authoritative port number, protocol and parameter registries.
News and continuous monitoring
Publishers worth following daily, all of which feed the IT Atlas news page directly.
CISA cybersecurity advisories
Alerts and joint advisories, usually the first authoritative detail on an active campaign.
SANS Internet Storm Center
Daily practitioner analysis of scanning, exploitation attempts and malware samples.
Microsoft Security blog
Threat intelligence and product direction across Entra, Defender and Microsoft 365.
Cloudflare blog
Internet scale traffic data, outage analysis and protocol adoption reporting.
Google Online Security blog
Chrome, Android and cryptography changes that reach every managed estate eventually.
Kubernetes blog
Releases, deprecations and security posture changes for Kubernetes itself.
Certification and structured learning
Official certification programmes, listed by the body that awards them, with no affiliate arrangements of any kind.
CompTIA certifications
A+, Network+, Security+, Cloud+ and Linux+, the common vendor neutral entry route.
Microsoft Credentials
Azure, Microsoft 365, Entra, Intune and security operations role based certifications.
AWS Certification
Solutions architect, sysops, networking and security specialty tracks.
Cisco certifications
CCNA through CCIE for routing, switching, data centre and security.
ISC2 certifications
CISSP, CCSP and SSCP, with experience requirements for the senior credentials.
ISACA certifications
CISA, CISM and CRISC for audit, security management and risk work.
GIAC certifications
Hands on security operations, forensics and incident response credentials.
Linux Foundation certifications
CKA, CKAD, CKS and Linux administration, all performance based exams.
Red Hat certifications
RHCSA and RHCE, examined on a live system rather than by multiple choice.
