Zero Security Theatre
Evidence library
These sources support or challenge the work. Each note says what the source can establish, and contrary evidence stays in the library.
Standard
NIST Cybersecurity Framework 2.0
Organises outcomes across govern, identify, protect, detect, respond, and recover. Used here as a requirement source, not as evidence of effect.
Used by Attack-and-recovery engineering, Compliant Insecurity
Standard
NIST SP 800-61, computer security incident handling guide
The reference model behind the detection, containment, and recovery intervals this area measures.
Used by Attack-and-recovery engineering
Advisory
CISA Stop Ransomware guidance
Practical recovery material, including isolated backup guidance used in the restore experiments.
Public report
Verizon Data Breach Investigations Report
Annual incident pattern data. Useful for base rates, with the usual caution that the sample is not a population.
Used by The dangers of security theatre, Vendor and supply-chain resilience
Reference
Operational Truth
The intended, reported, recorded, inferred, observed, and verified distinction used throughout this area.
Used by GRC engineering, Attack-and-recovery engineering, Compliant Insecurity
