Evidence register
Every external source this site cites, and what it returned when it was last fetched. Including the ones that failed.
How the register is built
The register is not maintained by hand. It is computed from the same content the pages render, so adding a citation to a page enrols it for checking automatically. A source cannot be published here and go unchecked, because there is no second step to forget.
There are currently 37 external sources. 37 of them carry a result from the weekly job. A successful fetch also writes a copy to private storage, so that a claim survives its source being reorganised.
Some organisations refuse automated requests as a matter of policy. Those entries are reported as refused rather than broken, because the two are different and conflating them would misstate the health of the register. The page a person sees is fine.
Sources
- ISA/IEC 62443
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- NIST SP 800-82 Revision 3
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- NIST SP 800-207
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- Adapting Zero Trust Principles to Operational Technology
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- NIST Cybersecurity Framework 2.0
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- MITRE ATT&CK for ICS
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- ISO/IEC 27001 and 27002
- Cited on /frameworks/. Refused an automated request (403), last checked 2026-08-09.
- NIST AI Risk Management Framework 1.0
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- ISO/IEC 42001:2023
- Cited on /frameworks/. Refused an automated request (403), last checked 2026-08-09.
- Regulation (EU) 2024/1689, the AI Act
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- OECD AI Principles
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- Bank Negara Malaysia, Risk Management in Technology (RMiT)
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- Monetary Authority of Singapore, Technology Risk Management Guidelines
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- APRA Prudential Standard CPS 234, Information Security
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- Digital Operational Resilience Act
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- FinOps Foundation Framework
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- AWS Certified Cloud Practitioner, Amazon Web Services: verifiable badge record
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- AWS Certified AI Practitioner (Early Adopter), Amazon Web Services: verifiable badge record
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- FinOps Certified Professional, The Linux Foundation: verifiable badge record
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- Certificate of Competence in Zero Trust (CCZT), Cloud Security Alliance: badge record to be added
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- FinOps Certified Engineer, FinOps Foundation
- Cited on /frameworks/. Refused an automated request (403), last checked 2026-08-09.
- PyTorch and Deep Learning for Decision Makers (LFS116), Linux Foundation
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- Task force announcement, MTSFB
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- What a technical code is, and why compliance is optional, MTSFB
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- Advisor listing published by Alibaba Group
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- List of participants (TD/B/C.II/MEM.4/INF.8), UNCTAD
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- International Trade Centre
- Cited on /frameworks/. Reachable (200), last checked 2026-08-09.
- Model AI Governance Framework for Agentic AI, IMDA Singapore, version 1.5, 20 May 2026
- Cited on /doctrine/governing-agentic-systems/. Reachable (200), last checked 2026-08-09.
- Request for Information: Security Considerations for AI Agents, NIST CAISI, docket NIST-2025-0035, 8 January 2026
- Cited on /doctrine/governing-agentic-systems/. Reachable (200), last checked 2026-08-09.
- AI Agent Standards Initiative, NIST, 17 February 2026
- Cited on /doctrine/governing-agentic-systems/. Reachable (200), last checked 2026-08-09.
- Accelerating the Adoption of Software and AI Agent Identity and Authorization, NIST NCCoE concept paper, 5 February 2026
- Cited on /doctrine/governing-agentic-systems/. Reachable (200), last checked 2026-08-09.
- OWASP Top 10 for Agentic Applications, 2026
- Cited on /doctrine/governing-agentic-systems/. Reachable (200), last checked 2026-08-09.
- NIST IR 8596, Cybersecurity Profile for Artificial Intelligence, initial public draft
- Cited on /doctrine/governing-agentic-systems/. Reachable (200), last checked 2026-08-09.
- CIS Critical Security Control 1, Inventory and Control of Enterprise Assets
- Cited on /doctrine/finops-as-control/. Reachable (200), last checked 2026-08-09.
- NIST Cybersecurity Framework 2.0: Identify function
- Cited on /doctrine/finops-as-control/. Reachable (200), last checked 2026-08-09.
- FinOps Framework capabilities, including allocation and tagging
- Cited on /doctrine/finops-as-control/. Reachable (200), last checked 2026-08-09.
- On-demand learning on AirAsia Academy
- Cited on /notes/on-demand-learning/. Refused an automated request (429), last checked 2026-08-09.
When a source dies
It happens, and it has happened here. A certification body moved its catalogue to another domain without leaving a redirect. A training platform was renamed and its course pages went with it. Both were found by this check and both were repaired: one now points at the certification's current page, the other at an archived copy of the original, because the archived copy still carries the course title and names him in its description.
That is the standard applied. A replacement link has to prove the same thing the original proved. A page that merely exists on the right organisation's website is not a substitute, and a link that returns a healthy response while showing something unrelated is worse than an honest gap, because a reader who clicks it has been given the impression of verification without the substance.
If you find a source here that does not support the claim it is attached to, please say so. That is a defect and it will be treated as one.