Zero Security Theatre
Evidence library
These sources support or challenge the work. Each note says what the source can establish, and contrary evidence stays in the library.
Standard
NIST SP 800-53 revision 5, security and privacy controls
A large control catalogue, useful for mapping requirements to testable statements.
Used by Compliant Insecurity, GRC engineering
Standard
NIST AI Risk Management Framework
Used when assessing AI components in defensive workflows, where the same evidence standard applies.
Used by AI-native defensive security
Standard
NIST Privacy Framework
A structure for privacy outcomes that can be mapped to engineered tests.
Used by The dangers of data privacy theatre, GRC engineering
Reference
Compliant Insecurity
Collected material on organisations that satisfy their frameworks while remaining unable to detect, contain, or recover.
Used by Compliant Insecurity, GRC engineering
Reference
Operational Truth
The intended, reported, recorded, inferred, observed, and verified distinction used throughout this area.
Used by GRC engineering, Attack-and-recovery engineering, Compliant Insecurity
