Zero Security Theatre
Evidence library
These sources support or challenge the work. Each note says what the source can establish, and contrary evidence stays in the library.
Standard
NIST Cybersecurity Framework 2.0
Organises outcomes across govern, identify, protect, detect, respond, and recover. Used here as a requirement source, not as evidence of effect.
Used by Attack-and-recovery engineering, Compliant Insecurity
Standard
NIST SP 800-61, computer security incident handling guide
The reference model behind the detection, containment, and recovery intervals this area measures.
Used by Attack-and-recovery engineering
Standard
NIST SP 800-34, contingency planning guide
Establishes recovery objectives as planning targets. This area asks for the demonstrated result beside the target.
Standard
NIST SP 800-53 revision 5, security and privacy controls
A large control catalogue, useful for mapping requirements to testable statements.
Used by Compliant Insecurity, GRC engineering
Standard
NIST SP 800-161 revision 1, supply chain risk management
Third-party practice guidance. The gap this area studies is between its practices and the tested escalation path.
Standard
NIST SP 800-63, digital identity guidelines
Authenticator assurance levels, including the properties that make a credential resistant to phishing.
Used by Human error without human blame
Advisory
CISA Known Exploited Vulnerabilities catalogue
A public record of what is actually being exploited, useful for separating theoretical from observed risk.
Used by The dangers of security theatre
Advisory
CISA guidance on phishing-resistant multifactor authentication
Shows how the credential itself can block phishing even when a message fools the user.
Used by Human error without human blame
Advisory
CISA Stop Ransomware guidance
Practical recovery material, including isolated backup guidance used in the restore experiments.
Advisory
CISA Secure by Design
Places responsibility for safe defaults with the supplier, which is the vendor-side form of this area's design argument.
Used by Vendor and supply-chain resilience, Human error without human blame
Reference
MITRE ATT&CK
The behaviour catalogue used to select techniques for detection and containment measurement.
Used by The dangers of security theatre, Attack-and-recovery engineering
Reference
MITRE ATLAS, adversarial threat landscape for AI systems
Relevant as AI components enter both the defensive stack and the attack surface.
Used by AI-native defensive security
Standard
NIST AI Risk Management Framework
Used when assessing AI components in defensive workflows, where the same evidence standard applies.
Used by AI-native defensive security
Regulatory guidance
HHS, HIPAA Security Rule
A frequent source of the compliant insecurity pattern, because many requirements ask whether a process exists.
Used by Compliant Insecurity
Regulatory guidance
HHS, HIPAA Privacy Rule
The documentary baseline against which observed data handling is compared in healthcare settings.
Regulatory guidance
European Data Protection Board guidelines
Interpretation of purpose limitation, minimisation, and erasure, which the privacy experiments test against systems.
Standard
NIST Privacy Framework
A structure for privacy outcomes that can be mapped to engineered tests.
Used by The dangers of data privacy theatre, GRC engineering
Public report
Verizon Data Breach Investigations Report
Annual incident pattern data. Useful for base rates, with the usual caution that the sample is not a population.
Used by The dangers of security theatre, Vendor and supply-chain resilience
Reference
Compliant Insecurity
Collected material on organisations that satisfy their frameworks while remaining unable to detect, contain, or recover.
Used by Compliant Insecurity, GRC engineering
Reference
Operational Truth
The intended, reported, recorded, inferred, observed, and verified distinction used throughout this area.
Used by GRC engineering, Attack-and-recovery engineering, Compliant Insecurity
