← Book contents
25 · FURTHER READING AND SOURCES Book · edition v1.2

Further Reading and Sources

The works and standards this framework draws on, grouped by the part of the lifecycle they inform.

These mappings are the author’s operational crosswalk for UTIOM. They are not official NIST, ISO or regulatory mappings, do not establish conformity or compliance by themselves, and are not legal advice. Validate them against the organisation’s applicable profile, ISO Statement of Applicability, regulatory classification, national transposition and competent-authority guidance.

25.1 Standards and regulation#

NIST — Cybersecurity Framework 2.0; SP 800-61 Rev. 3 (2025) Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile; IR 8183 Rev. 2 Cybersecurity Framework 2.0 Manufacturing Profile (Initial Public Draft); SP 800-137 Information Security Continuous Monitoring.

ISO/IEC — ISO/IEC 27001:2022 + Amd 1:2024 Information security management systems; 27035-1:2023 Principles and process; 27035-2:2023 Guidelines to plan and prepare for incident response; 27035-3:2020 Guidelines for ICT incident response operations; 27035-4:2024 Coordination.

European Union — Directive (EU) 2022/2555 (NIS2); Commission Implementing Regulation (EU) 2024/2690; Regulation (EU) 2022/2554 (DORA); Commission Delegated Regulation (EU) 2025/1190; Regulation (EU) 2016/679 (GDPR); TIBER-EU 2025 framework for threat intelligence-based ethical red teaming.

Other — COBIT 2019 governance objectives; TOGAF Standard, 10th Edition Architecture Development Method; CIS Critical Security Controls v8.1; FIRST CSIRT Services Framework v2.1.

25.2 Threat-informed defence#

MITRE — ATT&CK Enterprise v19.2 knowledge base; Engage adversary engagement framework; D3FEND countermeasure knowledge graph.

Community — DeTT&CT by Marcus Bakker and Ruben Bouman; Sigma detection rule format; Atomic Red Team; Caldera.

Maturity models — SOC-CMM by Rob van Os; DML by Ryan Stillions; the Pyramid of Pain by David Bianco.

25.3 Management and engineering thinking#

Peter Drucker — The Practice of Management; Management by Objectives; the concept of the knowledge worker and systematic abandonment.

Henry Mintzberg — Strategy as a pattern in a stream of decisions, rather than a document.

W. Edwards Deming — The Plan-Do-Check-Act improvement cycle.

Toyota Production System — Kaizen as small, consistent, compounding improvement.

John Boyd — The OODA loop as a model for decision tempo under adversarial pressure.

Hunt and Thomas — The Pragmatic Programmer, and the DRY principle applied here to detection content.

Dieter Rams — Principles of good design, applied to alert output and cognitive load.

Sun Tzu — The Art of War, for the principle that self-knowledge precedes effective defence.

25.4 The framework family#

UTIOM — utiom.de. Framework book, assessment instruments and supporting material.

TID-CMM — tid-cmm.com. Threat-Informed Detection Capability Maturity Model.

TIR-CMM — tir-cmm.com. Threat-Informed Response Capability Maturity Model.

STRATA and RSMM — Published through the author's writing. See utiom.de for current links.

Cite this chapter: Adineh, R. (2026). Further Reading and Sources. UTIOM Framework Book, edition 1.2. utiom.de/book/sources/
← Back to book contents

Join the UTIOM community. Discuss, contribute evidence and share implementation experience. About the community →