Evidence register
Every external source this site cites, and what it returned when it was last fetched. Including the ones that failed.
How the register is built
The register is not maintained by hand. It is computed from the same content the pages render, so adding a citation to a page enrols it for checking automatically. A source cannot be published here and go unchecked, because there is no second step to forget.
There are currently 53 external sources. 53 of them carry a result from the weekly job. A successful fetch also writes a copy to private storage, so that a claim survives its source being reorganised.
Some organisations refuse automated requests as a matter of policy. Those entries are reported as refused rather than broken, because the two are different and conflating them would misstate the health of the register. The page a person sees is fine.
Sources
- ISA/IEC 62443
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- NIST SP 800-82 Revision 3
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- NIST SP 800-207
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- Adapting Zero Trust Principles to Operational Technology
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- NIST Cybersecurity Framework 2.0
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- MITRE ATT&CK for ICS
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- ISO/IEC 27001 and 27002
- Cited on /frameworks/. Refused an automated request (403), last checked 2026-08-23.
- NIST AI Risk Management Framework 1.0
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- ISO/IEC 42001:2023
- Cited on /frameworks/. Refused an automated request (403), last checked 2026-08-23.
- Regulation (EU) 2024/1689, the AI Act
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- OECD AI Principles
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- Artificial Intelligence Systems Cyber Security Framework (AISCF)
- Cited on /frameworks/. Refused an automated request (403), last checked 2026-08-23.
- Gartner: over 40 per cent of agentic AI projects will be cancelled by end of 2027
- Cited on /frameworks/. Refused an automated request (403), last checked 2026-08-23.
- Bank Negara Malaysia, Risk Management in Technology (RMiT)
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- Monetary Authority of Singapore, Technology Risk Management Guidelines
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- APRA Prudential Standard CPS 234, Information Security
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- Digital Operational Resilience Act
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- FinOps Foundation Framework
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- AWS Certified Cloud Practitioner, Amazon Web Services: verifiable badge record
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- AWS Certified AI Practitioner (Early Adopter), Amazon Web Services: verifiable badge record
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- FinOps Certified Professional, The Linux Foundation: verifiable badge record
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- FinOps Certified Instructor, The Linux Foundation: verifiable badge record
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- HRD Corp Accredited Trainer, Human Resource Development Corporation, Malaysia: verifiable trainer record, accredited 25 July 2024 to 25 July 2027
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- Certificate of Competence in Zero Trust (CCZT), Cloud Security Alliance: badge record to be added
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- FinOps Certified Engineer, FinOps Foundation
- Cited on /frameworks/. Refused an automated request (403), last checked 2026-08-23.
- PyTorch and Deep Learning for Decision Makers (LFS116), Linux Foundation
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- Cybercrime Investigations, Maltego: subject area published by the vendor, not a record of completion
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- Task force announcement, MTSFB
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- What a technical code is, MTSFB
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- Cyber Security Act 2024 (Act 854), Attorney General’s Chambers
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- Advisor listing published by Alibaba Group
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- List of participants (TD/B/C.II/MEM.4/INF.8), UNCTAD
- Cited on /frameworks/. Reachable (200), last checked 2026-08-23.
- Netherlands Trust Fund IV programme, International Trade Centre
- Cited on /frameworks/. Refused an automated request (403), last checked 2026-08-23.
- Zero trust network access reference architectures, NCSC, which describe the outbound reverse-tunnel pattern this document had characterised as its own
- Cited on /doctrine/air-gap-to-zero-trust/. Reachable (200), last checked 2026-08-23.
- NIST SP 800-207A, A Zero Trust Architecture Model for Access Control in Cloud-Native Applications in Multi-Cloud Environments, September 2023
- Cited on /doctrine/air-gap-to-zero-trust/. Reachable (200), last checked 2026-08-23.
- Model AI Governance Framework for Agentic AI, IMDA Singapore, published 22 January 2026, updated 20 May 2026
- Cited on /doctrine/governing-agentic-systems/. Reachable (200), last checked 2026-08-23.
- Regulation (EU) 2026/1744 of 8 July 2026, the Digital Omnibus on AI, amending Regulation (EU) 2024/1689, in force 27 July 2026
- Cited on /doctrine/governing-agentic-systems/. Reachable (200), last checked 2026-08-23.
- SP 800-53 Control Overlays for Securing AI Systems (COSAiS), NIST, five planned overlays including single-agent and multi-agent
- Cited on /doctrine/governing-agentic-systems/. Reachable (200), last checked 2026-08-23.
- AI agents in telecom network architecture, Ericsson, 17 October 2025, revised 21 July 2026
- Cited on /doctrine/governing-agentic-systems/. Reachable (200), last checked 2026-08-23.
- Request for Information: Security Considerations for AI Agents, NIST CAISI, docket NIST-2025-0035, 8 January 2026
- Cited on /doctrine/governing-agentic-systems/. Reachable (200), last checked 2026-08-23.
- AI Agent Standards Initiative, NIST, 17 February 2026
- Cited on /doctrine/governing-agentic-systems/. Reachable (200), last checked 2026-08-23.
- Accelerating the Adoption of Software and AI Agent Identity and Authorization, NIST NCCoE concept paper, 5 February 2026
- Cited on /doctrine/governing-agentic-systems/. Reachable (200), last checked 2026-08-23.
- OWASP Top 10 for Agentic Applications, 2026
- Cited on /doctrine/governing-agentic-systems/. Reachable (200), last checked 2026-08-23.
- NIST IR 8596, Cybersecurity Profile for Artificial Intelligence, initial public draft
- Cited on /doctrine/governing-agentic-systems/. Reachable (200), last checked 2026-08-23.
- CIS Critical Security Control 1, Inventory and Control of Enterprise Assets
- Cited on /doctrine/finops-as-control/. Reachable (200), last checked 2026-08-23.
- NIST Cybersecurity Framework 2.0: Identify function
- Cited on /doctrine/finops-as-control/. Reachable (200), last checked 2026-08-23.
- FinOps Framework capabilities, including allocation and tagging
- Cited on /doctrine/finops-as-control/. Reachable (200), last checked 2026-08-23.
- Ron Westrum, A typology of organisational cultures, Quality and Safety in Health Care 13 (2004), doi:10.1136/qshc.2003.009522
- Cited on /doctrine/the-adoption-problem/. No response, last checked 2026-08-23.
- Safe Software Deployment: How Software Manufacturers Can Ensure Reliability for Customers, CISA, FBI and ASD ACSC joint guide, October 2024
- Cited on /doctrine/the-adoption-problem/. No response, last checked 2026-08-23.
- Amy C. Edmondson, Psychological Safety and Learning Behavior in Work Teams, Administrative Science Quarterly 44 (1999)
- Cited on /doctrine/the-adoption-problem/. No response, last checked 2026-08-23.
- DORA, Generative organizational culture, including the six Westrum survey measures
- Cited on /doctrine/the-adoption-problem/. No response, last checked 2026-08-23.
- Mark Hughes, Do 70 Per Cent of All Organizational Change Initiatives Really Fail?, Journal of Change Management 11 (2011)
- Cited on /doctrine/the-adoption-problem/. No response, last checked 2026-08-23.
- On-demand learning on AirAsia Academy
- Cited on /notes/on-demand-learning/. Reachable (200), last checked 2026-08-23.
A limit this register cannot close
Two of the largest figures on this site, the jobs and the investment associated with the negotiations of 2013 to 2015, have no source link beside them, and they are not going to get one. That work was done on a government’s behalf and carries confidentiality obligations that have not lapsed. The counterparties are not named anywhere on this site for that reason.
This is stated rather than left as a silent gap, because a reader working through the register would otherwise find the biggest numbers here unsupported and be entitled to wonder why. The honest position is that these two figures rest on his own account of work he is not free to document, while everything else on the site points at something you can open and read. A reader who wants to weigh them accordingly is weighing them correctly.
When a source dies
It happens, and it has happened here. A certification body moved its catalogue to another domain without leaving a redirect. A training platform was renamed and its course pages went with it. Both were found by this check and both were repaired: one now points at the certification's current page, the other at an archived copy of the original, because the archived copy still carries the course title and names him in its description.
That is the standard applied. A replacement link has to prove the same thing the original proved. A page that merely exists on the right organisation's website is not a substitute, and a link that returns a healthy response while showing something unrelated is worse than an honest gap, because a reader who clicks it has been given the impression of verification without the substance.
If you find a source here that does not support the claim it is attached to, please say so. That is a defect and it will be treated as one.