Resources worth opening.
Methods for understanding risk, practical third-party guidance, and tools for building with evidence. Start with the question you are trying to answer.
Original tools
-
Third-party assessment summary report →
risk.engineer · Ahmed Mohamed
Open a completed fictional example showing how an assessment report communicates scope, evidence, conclusion, implementation conditions, provider actions, and documentation reviewed.
Risk methods
-
Open FAIR body of knowledge →
The Open Group
Understand the factors behind loss frequency and loss magnitude, then use a shared vocabulary for quantitative risk analysis.
-
Guide for conducting risk assessments →
NIST · SP 800-30 Rev. 1
Structure an assessment around threats, vulnerabilities, likelihood, and impact. Useful background beyond Lab 01’s identification-only scope.
-
Cybersecurity Framework 2.0 →
NIST
Connect cybersecurity outcomes to organizational priorities through current and target profiles. A profile is not a risk score.
Bayesian reasoning & uncertainty
-
Think Bayes, second edition →
Allen B. Downey
Learn to update probabilities as evidence arrives using Python and executable notebooks. A practical foundation, not a ready-made cyber risk model.
Third-party & supply-chain risk
-
Supply-chain risk management: quick-start guide →
NIST · SP 1305
Start with supplier requirements and a repeatable cybersecurity supply-chain capability. A shorter entry point before the full guidance.
-
Cybersecurity supply-chain risk management practices →
NIST · SP 800-161 Rev. 1, Update 1
Go deeper on supplier risk across acquisition, operation, and monitoring. Covers cybersecurity supply-chain risk, not every financial or legal dimension of TPRM.
Engineering & evidence
-
OCSF schema browser →
Open Cybersecurity Schema Framework
Inspect common event classes and fields for mapping telemetry across tools. Event normalization still needs business context.
-
OSCAL →
NIST
Explore machine-readable control catalogs, implementation information, and assessment results. Distinct from OCSF event data.
-
Building a GRC evidence pipeline →
GRC Engineering Club
Build evidence collection with GitHub Actions, policy checks, and infrastructure scans. Review its prerequisite labs and AWS setup first.
-
What is GRC engineering? →
Ayoub Fandi · The GRC Engineer
Explore the practice, principles, and implementation examples behind engineering GRC work.
-
GRC Engineering Learning Hub →
GRC Engineering community
Browse community-curated books, courses, labs, and talks. Access terms vary by resource.
-
GRC 20/20 research and commentary →
Michael Rasmussen · GRC 20/20
Explore GRC strategy, architecture, and the extended enterprise. Distinguish public commentary from paid or sponsored research.
Curated September 9, 2026. Original downloadable tools are published by risk.engineer and attributed to their practitioner source. External resources belong to their authors; inclusion does not imply endorsement. Check each publisher’s access and licensing terms.