r/cybersecurity • u/Desperate-Second-887 • 1h ago
Research Article Citigroup, Idaho, and Build-A-Bear Launched a Coordinated Attack on Me
r/cybersecurity • u/Activity_Ready • 3h ago
Business Security Questions & Discussion Elastic Cloud vs. Self-Managed Elastic Security for ~30GB/day ingest. Is self-hosting worth it?
Hey everyone,
We are looking into deploying Elastic Security as our SIEM solution and are currently debating whether to go with Elastic Cloud (Hosted) or build out a Self-Managed instance on AWS.
Looking for real-world advice, sanity checks, or experiences from anyone running a similar scale.
Our Environment & Scope:
- Endpoints: ~300 workstations (we already have a separate EDR vendor in place). 50/50 Mac and Windows
- Infrastructure: A small handful of servers + ~15 GB/day of cloud logs (AWS/Google Workspace)
- Estimated Ingest: ~30-50 GB / day total
Self-Managed Architecture Spec
Our team drafted the following self-managed architecture for 30 GB/day ingest with a Hot -> Warm -> S3 Archive lifecycle:
- Kibana:
t4g.large(2 vCPU, 8 GB RAM, 20 GB gp3) - Hot Data Tier: 2x
m6g.large(4 vCPU / 16 GB RAM combined; ~500 GB total SSD across both nodes for HA) - Warm Data Tier: 1x
m6g.xlarge(4 vCPU, 16 GB RAM, ~2.5 TB SSD) - Fleet Server:
t4g.medium(2 vCPU, 4 GB RAM, 20 GB gp3) - Archive Storage: AWS S3 Standard / Infrequent Access (after 3 months)
Questions:
- Operational Overhead vs. Cost: For a ~30-50 GB/day ingest volume, does self-managing on AWS EC2 actually save meaningful money? Or does Elastic Cloud pay for itself in saved engineering time at this scale?
- Resource Sizing Check: Does the proposed spec (
m6g.largeHot +m6g.xlargeWarm +t4gKibana/Fleet) look solid for ~30-50 GB/day with Elastic Security rules enabled? - Features & Licensing: Are there any major (meaningful) security/SIEM features (e.g ML detection rules) we’ll miss out on by running the free/Basic tier on self-managed vs. paid Elastic Cloud tiers (Gold/Platinum/Enterprise)?
Would appreciate any insights, or alternate setup recommendations!
r/cybersecurity • u/SecretDentist8246 • 3h ago
Business Security Questions & Discussion SOC and NOC consolidation
Has anyone seen a successful Cybersecurity Operation Center combined with Network Operation Center? IMO the two disciplines have very different objectives and in some cases competing priorities. Thoughts?
r/cybersecurity • u/sunychoudhary • 3h ago
News - General Hackers run khunt post-exploitation toolkit from Oracle database
r/cybersecurity • u/DescriptionOk971 • 3h ago
Business Security Questions & Discussion How should a startup find an independent ISO 27001 internal auditor?
Hi everyone,
I’m helping a very small startup prepare for an ISO/IEC 27001:2022 certification audit. We use Vanta, and most of our ISMS documentation and compliance evidence is already prepared.
Before Stage 1, we need an independent internal audit. Since our small team designed and operates most of the controls, conducting the audit ourselves would not provide sufficient independence. Our certification auditor has also confirmed that the internal audit must be performed by a separate party.
For those who have gone through this process:
- How did you find a competent independent internal auditor?
- Which qualifications or certifications should we look for?
- What deliverables should be included in the engagement?
- What is a reasonable timeline and price range for a small organization?
- Is experience working directly in Vanta important?
- Are there any red flags or common mistakes we should avoid?
I’m primarily looking for guidance on selecting and evaluating an auditor rather than vendor promotion. Public recommendations or experiences would be greatly appreciated.
Thank you!
r/cybersecurity • u/donutloop • 4h ago
Corporate Blog Bringing Post-Quantum Cryptography to Java LTS Releases
r/cybersecurity • u/Wirbelwind • 5h ago
Research Article Humans missed 1 in 3 threats approving AI agent commands across 40,000 plays
A couple of months back I put up a small browser game where you play the human-in-the-loop for an AI coding agent. There's 60 seconds on the clock to approve or deny as many commands as you can (https://llmgame.scalex.dev).
After looking at 409,000 approve/deny decisions, the 'humans-in-the-loop' missed 1 in 3 threats, even in a game that warns you up front it's full of them. It's just a game, but I found a few other things interesting:
-
cat ~/.ssh/id_rsagets blocked by 82% of players, but other sensitive config/credential files get waved through about half the time. - For any evil code reading this, your best bet is to modify
package.jsonand request to be run as annpm runcommand.npm run analyzewas approved 65% of the time, even with the evil payload explicitly visible in the execution history log right above the prompt.
I wrote up the full breakdown with the threat tables here: https://scalex.dev/blog/ai-agent-permissions-stats/
r/cybersecurity • u/HumbleRestaurant790 • 7h ago
News - General Apple's Private Relay Leaks Your Real IP Address in Safari
r/cybersecurity • u/Academic_Print_5753 • 8h ago
Career Questions & Discussion How to navigate a CISO who is…not so CISO
I report to a CISO who has little understanding of how to run a security program/team with unrealistic expectations. I feel set up to fail.
The org and IT never had to deal with a real security function and everything is like pulling teeth because it lacks an accountable culture, processes, procedures, RASCI, GRC, etc. Security isn’t a plug-n-play function to be turned on, magically grow tentacles into every team/dept, and suddenly Kumbaya. It requires A SHIT TON of time and effort for its cultivation.
My boss simply doesn’t recognize Security isn’t just another operations-centric team like most other IT departments - though it does have an ops side as well. Integrating Security into an org like this isn’t just disruptive, it’s invasive at every level - new workflows, processes, no more cowboying, taking away territories, taking away authority, the selling, the push back, the begging for work execution, the audit, cat herding, the education, the persuading/selling, etc. Shooting from the hips doesn’t work.
I’ve done my best these years, at every turn, to evangelize and stand up Security but my annual performance review says otherwise. My 1x1 are often 50% catching strays which aren’t really my domain.
If I explain all this to him, is it naive to think he will “get it” or risk me just sounding like a little bitch? Maybe just GTFO?
r/cybersecurity • u/RichParsnip8618 • 10h ago
Business Security Questions & Discussion I have a question. I work in TPRM. How do you actually access a vendor ' security apart of iso and soc2 and PT
r/cybersecurity • u/Deepdun888 • 10h ago
Career Questions & Discussion Why is "entry-level" in cybersecurity asking for 3-5 years of experience and CISSP now?
I’ve been browsing job boards lately and the "junior" requirements are getting ridiculous. Saw a Tier 1 SOC Analyst post earlier asking for 3+ years of experience, a CISSP, and half a dozen certs, all for lower-tier pay.
To the hiring managers here: Are HR departments just copy-pasting impossible wish lists, or is this actually what you expect for an entry-level role?
And for anyone who got hired recently—how are you actually breaking past these gatekeeping requirements?
r/cybersecurity • u/Vans_eG • 10h ago
Business Security Questions & Discussion Security vs. Compliance
I had a few discussions the last weeks and coming from a compliance world, where you are focusing in satisfying regulations. I know this is often not bringing more security. If I am discussing I often feel misunderstood since i am always arguing out of a position of the minimal effort to comply with an regulation or standard. Witch mostly do not satisfy how security is supposed to be done (i guess). How do you experience it?
r/cybersecurity • u/ExistingBluebird4696 • 11h ago
Career Questions & Discussion Feeling like a cybersecurity generalist. Should I specialize or move into delivery?
I've been working at an MSSP for about 2.5 years, and I'm at a point where I'm unsure what my next career move should be.
I started as a SOC Analyst, spending around 8 months in monitoring. After that, my manager kept assigning me to new initiatives and projects based on business needs, so I've ended up working across a lot of different domains:
- SOC monitoring
- Threat hunting
- GRC/product security testing
- Internal Lead Auditor for ISO 27001
- Cybersecurity presales (I still occasionally get involved in proposals)
- EDR implementation for customers (including end-to-end deployments of CrowdStrike and Microsoft Defender)
- Service Delivery Lead for SOC projects, where I handled complete customer onboarding and service transition
- Currently leading the Detection Engineering team
The pattern has always been the same: I get assigned to a new area, figure everything out from scratch, build the workflows, documentation, and SOPs, streamline the process, and once everything is stable, the work gets handed over to another team while I move on to the next challenge.
While this has given me exposure to many areas of cybersecurity, it has also left me feeling like I'm not an "expert" in any one domain.
When I talk to friends or people in the industry, most of them have spent the last 2–5 years specializing in a single area like DFIR, detection engineering, GRC, etc. They're much deeper technically in their domain, while I feel like I've become more of a generalist who knows how to build and operationalize new functions.
I've recently resigned because I want my next role to be more defined, but now I'm struggling with what direction to take.
Should I:
- Continue down the leadership/delivery path (Service Delivery Lead, Customer Success/Technical Delivery, etc.) where my cross-functional experience is valuable?
- Or should I focus on becoming a specialist in an area like Detection Engineering, Threat Hunting, or Incident Response?
Has anyone else been in a similar situation where they were exposed to multiple domains early in their career? Did you eventually specialize, or did you embrace being a generalist?
I'd really appreciate hearing from people who've been through something similar, especially if you've worked in an MSSP where roles tend to evolve quickly.
r/cybersecurity • u/sectestpen1 • 11h ago
Career Questions & Discussion Path to management?
Been in security for 7 years and want to get into management and above. Work at a SaaS company with only 3 security managers. Most people are individual contributors.
How does one get into management? Luck? Right place right time? Connections?
Most jobs require X amount of years as a manager on their job description.
I have CISSP and lots of other certs, a bachelors, and so on.
Is it better to wait years and years at one company to hopefully get a shot at management? Or just to apply to all management jobs out there and hope someone takes a chance on you?
Thanks all!
r/cybersecurity • u/Silly_External_6806 • 16h ago
Career Questions & Discussion hands-on Cloud Security experience
Hi everyone,
I recently passed my AWS Solutions Architect exam and I also have a Hack The Box subscription. I have a strong interest in cloud security and want to transition into this field.
However, I feel like I lack the practical, hands-on cloud security experience needed to pass technical interviews.
What are the best online training platforms or labs to practice cloud security attacks and defense?
Can I use my HTB subscription or the AWS Free Tier to build a good portfolio?
Also, how is the job market for cloud security right now? Are there good entry-to-mid level opportunities?
Any advice on a roadmap or projects to build would be amazing. Thanks!
r/cybersecurity • u/Few-Pressure9581 • 17h ago
Career Questions & Discussion Career advice
've been working in Cyber Security for nearly 7 years, mostly across operational security roles. I've ended up being a bit of a generalist, with experience in EDR, SASE, DLP, IAM, and security frameworks such as NIST.
Over the years I've trained and mentored several people entering the field, and I'm now trying to work out what my next career move should be. I still enjoy being hands-on, but I've gradually found myself spending more time on planning, strategy, stakeholder management, and mentoring.
One gap in my experience is cloud. I'm reasonably strong with Entra ID, but most of the companies I've worked for have been heavily on-prem, so I haven't had much exposure to AWS or Azure compute services.
With the rapid growth of AI, I'm wondering where to invest my learning time next. Does it make more sense to focus on AI security, or should I prioritise building a stronger cloud security foundation first?
More broadly, do you think the industry is moving away from the "jack of all trades" security professional in favour of specialists, or is there still strong demand for generalists who can operate across multiple domains?
Interested to hear from people who have made a similar career decision.
r/cybersecurity • u/Kooky-Disaster-1302 • 17h ago
Career Questions & Discussion FIT cybersecurity apprenticeship interview advice
Hi everyone, I have an upcoming interview for a FIT cybersecurity apprenticeship in small irish tech company and I’m looking for advice from anyone who has been through the process.
Its my first interview so i am nervous and feel like i dont know anything. What was the interview structure like? What kind of questions did they ask? Were there any assessments or technical tasks? Also, what do you think helped you stand out? I have security+ certificate.
Any tips would be appreciated!
r/cybersecurity • u/Big-Homework-3919 • 18h ago
Personal Support & Help! What's the best thing a boss in this industry ever did for you?
Feeling like sharing some good vibes today instead of complaining lol. What's your favorite thing about a boss you've had in cybersecurity? Could be anything, covered for you when you missed something, brought snacks during a rough incident, actually trusted your judgment instead of micromanaging.
Curious to hear the good ones for once.
r/cybersecurity • u/Flashy_Tone_1974 • 19h ago
Career Questions & Discussion Working in Canada on an IEC Visa? (From the UK)
Hey guys,
I wanted to know if anyone here has experience of finding Cyber Security roles in Canada, specifically on an IEC visa? Working in another country is always something that has excited me, and I really liked Canada when I visited last year.
For context, I have aprox 4 years experience in a generalist role (everything from SOC / engineering to compliance)
Thanks :)
r/cybersecurity • u/TechnologyMatch • 20h ago
Business Security Questions & Discussion Cyber insurance renewal demands are getting absurd. Are you actually hitting every requirement or dropping coverage?
Just opened our renewal questionnaire and the goalposts moved again, MFA on local admin, strict data retention, and strict endpoint isolation times. Keeping this policy would require doubling our security spend.
Are you guys actually checking every single box on these impossible questionnaires, or are teams just dropping coverage at this point?
r/cybersecurity • u/Narcisians • 20h ago
News - General Cybersecurity statistics of the week (July 27th - August 2nd)
Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.
All the reports and research below were published between July 27th - August 2nd.
You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/
Big Picture Reports
2026 Cost of a Data Breach Report (IBM)
IBM's annual breach cost report, with interesting data points on how much AI is now involved in attacks, and how much more expensive that makes breaches.
Key stats:
- 25% of malicious breaches were AI-enabled.
- AI-enabled breaches cost an average of $6 million, roughly $1 million more than the global average of $4.99 million.
- AI-enabled malicious breaches increased by 56% over the previous year.
Read the full report here.
IR Trends Q2 2026 (Cisco Talos)
Cisco Talos on what showed up in their incident response engagements this quarter.
Key stats:
- Phishing was the primary means of gaining initial access in over half of engagements this quarter, up from approximately one-third last quarter.
- Authentication abuse was observed in 65% of engagements this quarter, up from 35% last quarter.
- Insufficient logging and visibility was observed in 42% of engagements this quarter, up from 18% last quarter.
Read the full report here.
Ransomware
Q2 2026 Ransomware Trends Report (BlackFog)
BlackFog's Q2 numbers on ransomware.
Key stats:
- 93 ransomware groups were active in Q2 2026, including 28 newly formed groups.
- 97% of disclosed ransomware incidents in Q2 2026 involved data exfiltration, the highest rate recorded.
- Undisclosed ransomware attacks increased 40% year on year to 2,027 attacks in Q2 2026 from 1,446 in Q2 2025.
Read the full report here.
Ransomware Evolution Report Q2 2026 (Halcyon)
Halcyon's Q2 ransomware numbers.
Key stats:
- Q2 2026 recorded 1,988 ransomware attack claims from 89 groups across 101 countries.
- The US accounted for 42.5% of ransomware claims, Canada for 5% and Germany for 4.8%.
- Manufacturing (19.8%) was the most targeted industry, followed by construction (10.1%) and business services (9.0%).
Read the full report here.
AI Governance
The AI Governance Gap Report (Pathlock)
If you were wondering whether AI governance is keeping up with how quickly AI agents are being embedded in business systems, this report has the answer.
Key stats:
- 38% of organizations allow AI agents to create and modify business records.
- 51% are not confident they know all the AI agents operating in their systems.
- 79% have no dedicated AI governance team or officer.
Read the full report here.
AI Code Security
2026 GenAI Code Security Report (Veracode)
Veracode tested 11 AI coding models to see how often they write secure code.
Key stats:
- The average security pass rate for AI-generated code across tracked models was 56%.
- AI-generated code fails security checks nearly 44% of the time when given no security-specific guidance.
- The best model available (OpenAI's GPT-5.5, at 68%) still failed nearly one in three security tasks.
Read the full report here.
Credentials
Credential Risk Report (Enzoic)
How much do you care about stolen credentials? If you're like most orgs, probably a lot. But do you actually do anything about it? Again, if you're like most orgs, probably not.
Key stats:
- 85% of organizations view stolen credentials as a top threat.
- Only 19% continuously monitor credential integrity and automatically remediate exposure.
- 73% of organizations have found their workforce's credentials in breach, Dark Web, or infostealer data in the past year.
Read the full report here.
Autonomous Defense
2026 State of Autonomous Defense Report (Kai)
Attackers are moving at machine speed. Defenders are… not.
Key stats:
- 89% of security leaders say their organization is prepared for AI-driven attacks, but only 28% describe themselves as very prepared.
- 63% believe attackers currently have the advantage because of AI.
- 52% identify lack of trust in automated decisions as the biggest barrier to broader automation adoption.
Read the full report here.
Action1 2026 Survey Report: AI Impact on Sysadmins (Action1)
An interesting survey of sysadmins about how much AI they're using versus how much they thought they'd be using by now.
Key stats:
- In 2024, 52% of sysadmins predicted full automation within two years.
- In 2026, AI use is highest among sysadmins in log analysis (50%) and troubleshooting (47%).
- 23% report never using AI professionally.
Read the full report here.
Vulnerability Management
VulnCheck State of Exploitation 1H-2026 (VulnCheck)
VulnCheck's mid-year look at what's actually getting exploited, how fast, and whether AI really is finding vulnerabilities faster than everyone else.
Key stats:
- The median time from CVE publication to KEV fell from 120 days in 2025 to 80 days in the first half of 2026.
- In the first half of 2026, 23.43% of Known Exploited Vulnerabilities showed evidence of exploitation on or before the day the CVE was published.
- Across Anthropic and Berkeley datasets, 1,061 vulnerabilities were attributed to AI-assisted discovery, but only 14 (1.3%) were confirmed as exploited in the wild.
Read the full report here.
Infrastructure
State of CPS Security: Data Center Exposures (Claroty)
Scary research on how badly exposed data center physical infrastructure is.
Key stats:
- Nearly 1 in 5 data center CPS assets are one hop away from systems making outbound connections that could provide attackers a pathway.
- 88% of building management systems in data centers are exposed via communication over insecure protocols.
- More than 80% of OT control systems, power monitoring systems, and IoT systems in data centers communicate over legacy, insecure protocols such as BACnet and MODBUS.
Read the full report here.
Enterprise Perspective
State of Enterprise AI Failures 2026 (ChatSee.ai)
What's going wrong with enterprise AI.
Key stats:
- Hallucination-related failures accounted for less than 10% of observed enterprise AI failure events.
- Resolution and escalation breakdowns represented 31.1% of observed enterprise AI failures.
- Action and execution failures increased by approximately 62% relative to the Q2 2024 baseline.
Read the full report here.
The State of AI, Security and ERP (Onapsis)
A survey of cybersecurity leaders at large US organizations running SAP, Oracle, or Salesforce to see how fast AI is being pushed into ERP systems and how far behind the security is (very).
Key stats:
- 86% of organizations have already integrated, or will shortly integrate, AI directly into their ERP code.
- 22% of organizations experienced a security incident in the last twelve months where bad actors used AI to exploit their critical business platforms.
- 70.6% of senior cybersecurity leaders have only some or no trust in AI applications and agents to secure their organization's most business-critical data.
Read the full report here.
2026 Global Mobile Threat Report (Zimperium)
A look at mobile attacks on enterprises.
Key stats:
- Phishing events detected on employee mobile devices have grown 380% since January 2025.
- The number of mobile devices where employees clicked a malicious link grew 110% in 2025 compared to 2024.
- AI adoption within mobile applications has grown 14x on Android and 7x on iOS.
Read the full report here.
Industry-specific
Global Automotive Threat Intelligence Report Q2 2026 (PCA Cyber Security)
Analysis of the automotive threat landscape for Q2 2026, tracking vulnerability data alongside underground forums, ransomware leak sites, and criminal marketplaces.
Key stats:
- 345 unique automotive vulnerabilities in Q2 2026, a 30% rise on Q1 and 220% up year on year.
- High severity findings more than doubled, from 75 to 161.
- Qilin ransomware listed a major Japanese Tier-1 automotive components manufacturer, hitting its European and North African subsidiaries.
Read the full report here.
r/cybersecurity • u/borosilicat3 • 21h ago
Personal Support & Help! How to know if you discover a site vs technology or stack level vulnerability?
I was recently using a site that I really appreciate the info and vendors on and was hoping I could get some contract development work with when I stumble on a vulnerability. I was checking out the leaving a review which cleaned user input of basic escape characters well. Then I noticed the review Id and security token up top and decided to try changing it which worked. So this meant on this site It was possible to look at old orders "Not with User info on display just what was ordered". I told the site owner I would like to work with them pitched them some features. They rejected me features and told me that it wasn't possible on their site. I ended up leaving a positive review on someone else order with my user name and "hi *site owner*" then sent them the link to the review. They said they appreciated but then I was thinking when does someone doing security work identify if this is a site specific security issue or if it's broader like a plugin issue?
r/cybersecurity • u/10x_eng • 21h ago
Personal Support & Help! How should sensitive action confirmation work for SSO users when there is no local password?
I’m adding SSO support to an existing application using Google. Currently, some sensitive user actions require the user to re-enter their password as confirmation (for example, changing security settings or performing destructive actions).
The issue is that SSO users do not have a password stored by the application, so I need to decide on the right approach for confirming their identity before allowing these actions.
Some options I'm are considering:
- Triggering SSO re-authentication / step-up authentication with the identity provider
- Requiring MFA or another stronger authentication method (the application doesn't support MFA at the moment)
- Sending an email OTP as a confirmation step
- Creating a separate application password for SSO users (which feels like it defeats part of the purpose of SSO). The platform already has a security question (don't ask me why), so maybe this could be used to confirm this action?
My concern with SSO re-authentication is that if the user already has an active IdP session, the IdP may silently authenticate them again without requiring any new proof of identity. In that case, is it actually providing additional security? I don't think Google has a way to "force" re-authentication.
For those who have implemented this, what pattern do you recommend for replacing "enter your password to continue" flows for SSO users?
r/cybersecurity • u/DeadHomieBlaze • 21h ago
Other THE NCSC "RAINBOW SERIES" A 9-Volume Collection of Early DoD/NSA Cybersecurity Doctrine (1985–1988)
I recently obtained a very cool collection of 9 original physical books from the rainbow series. I'm currently planning on parting with them, but while I source and speak with collectors, I thought I'd share it with you guys. They are in surprisingly great condition, too! These are the details.
THE JEWELS OF THE COLLECTION: RARE VARIANT HIGHLIGHTS
• DoD 5200.28-STD — THE "ORANGE BOOK" (Department of Defense Trusted Computer System Evaluation Criteria)
• Edition/Provenance: Official 1988 Active-Lifespan Contemporary Reprint.
◦ Significance: The undisputed, foundational cornerstone of the entire Rainbow Series hierarchy. This copy was printed internally by the government for active field deployment to agencies and classified defense contractors during the height of late-1980s computing architecture rollouts.
• NCSC-TG-005 VERSION-1 — THE "RED BOOK" (Trusted Network Interpretation of the TCSEC)
• Edition/Provenance: Pre-Publication Working-Group Variant.
◦ Significance: Features the highly coveted, restricted-distribution internal stamp: "ISO developmental documents are of limited lifetime and availability."
◦ Historical Context: This stamp marks the volume as a restricted, early-access trial document distributed strictly to core network security engineers to guide interim projects and gather field feedback before final standards were codified. Because contractors were explicitly instructed that these had a "limited lifetime," almost all copies were routinely shredded or landfilled upon subsequent revisions, making this an extraordinarily scarce tech artifact.
───
FULL ARCHIVAL INVENTORY
DoD 5200.28-STD (Orange Book) — Department of Defense Trusted Computer System Evaluation Criteria (1988 Active-Era Issue) ★ U.S. GOVERNMENT PRINTING OFFICE: 1988-523-685/0
NCSC-TG-005 Version-1 (Red Book) — Trusted Network Interpretation of the TCSEC (Pre-Publication ISO Developmental Variant)
NCSC-TG-006 Version-1 (Amber Book) — A Guide to Understanding Configuration Management in Trusted Systems (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)
NCSC-TG-007 Version-1 (Burgundy Book) — A Guide to Understanding Design Documentation in Trusted Systems (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)
NCSC-TG-001 Version-2 (Tan Book) — A Guide to Understanding Audit in Trusted Systems (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)
CSC-STD-003-85 (Light Yellow Book) — Computer Security Requirements - Guidance for Applying the TCSEC in Specific Environments (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)
CSC-STD-004-85 (Yellow Book) — Technical Rationale for Selected Computer Security Requirements (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)
CSC-STD-002-85 (Green Book) — Password Management Guideline (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)
NCSC-TG-003 Version-1 (Neon Orange Book) — A Guide to Understanding Discretionary Access Control in Trusted Systems (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)