Zero Security Theatre
Evidence library
These sources support or challenge the work. Each note says what the source can establish, and contrary evidence stays in the library.
Standard
NIST Cybersecurity Framework 2.0
Organises outcomes across govern, identify, protect, detect, respond, and recover. Used here as a requirement source, not as evidence of effect.
Used by Attack-and-recovery engineering, Compliant Insecurity
Standard
NIST SP 800-53 revision 5, security and privacy controls
A large control catalogue, useful for mapping requirements to testable statements.
Used by Compliant Insecurity, GRC engineering
Regulatory guidance
HHS, HIPAA Security Rule
A frequent source of the compliant insecurity pattern, because many requirements ask whether a process exists.
Used by Compliant Insecurity
Regulatory guidance
HHS, HIPAA Privacy Rule
The documentary baseline against which observed data handling is compared in healthcare settings.
Reference
Compliant Insecurity
Collected material on organisations that satisfy their frameworks while remaining unable to detect, contain, or recover.
Used by Compliant Insecurity, GRC engineering
