# Authoritative Readings and Resources

These resources extend the supplied learning chapters in **AINS6302 AI for Risk Assessment**. They were selected because they are primary standards, official documentation, open textbooks, or authoritative institutional guidance—not unsourced link lists.

## How to Read Them

For each module, read the supplied chapter first. Then use the two linked resources at the end of that chapter to test terminology, compare the course's worked example with an authoritative treatment, and identify one point that should change or qualify your recommendation. Students are not expected to read every linked document cover to cover.

### 1. [NIST Cybersecurity Framework 2.0](https://www.nist.gov/cyberframework)

Governance and cybersecurity risk outcomes.

**Use with:** Cyber risk concepts and assets, Scenario analysis and stress testing, Controls and residual risk, Cyber risk assessment portfolio.
### 2. [NIST Risk Management Framework](https://csrc.nist.gov/projects/risk-management)

System-level risk categorization and controls.

**Use with:** Cyber risk concepts and assets, Threat likelihood and impact modeling, Controls and residual risk, Executive reporting and risk communication.
### 3. [NIST SP 800-30 Risk Assessments](https://csrc.nist.gov/pubs/sp/800/30/r1/final)

Threat, vulnerability, likelihood, impact, and uncertainty.

**Use with:** Threat likelihood and impact modeling, Vulnerability prioritization, Executive reporting and risk communication, Governance, compliance, and audit.
### 4. [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)

Evidence for vulnerability prioritization.

**Use with:** Vulnerability prioritization, Scenario analysis and stress testing, Governance, compliance, and audit, Cyber risk assessment portfolio.

## Source-Use Standard

Assignments should distinguish among measured notebook evidence, course-provided synthetic evidence, claims supported by these sources, and the student's own professional judgment. Cite the specific page, section, control, or documentation topic used; a bare homepage link is not adequate evidence.
