Skip to main content

Further Reading

Further reading should be curated, sourced, and version-aware where relevant. Use this page to organize public guidance, standards, and specifications that support the handbook's mappings.

Source Discipline

  • Cite public guidance, standards, or specifications when making factual claims about them.
  • Distinguish direct quotation, paraphrase, and interpretation.
  • Do not imply endorsement by a standards body unless formally confirmed.
  • Label interpretive mappings as guidance.
  • Avoid saying a standard requires something unless the source clearly says so.
  • Prefer "may support", "can be used for", "is commonly associated with", or "is relevant to" where the relationship is advisory.
  • Include publication date or version where relevant.
  • Keep further reading curated, not exhaustive.

Governance, Risk, And Supply-Chain Guidance

SourceUse it forVersion or date note
NIST Cybersecurity Framework 2.0Governance, risk, and supply-chain-risk framingCSF 2.0
NIST SP 1305: CSF 2.0 Quick-Start Guide for C-SCRMUsing CSF 2.0 to establish and communicate C-SCRM requirementsPublished 2024-10-21
NIST SP 800-161r1-upd1Cybersecurity supply-chain-risk management practicesUpdated 2024
NIST SP 800-218 SSDF v1.1Secure software development and supplier communication for software securityFinal, 2022-02-03
ISO/IEC 27036-3:2023Supplier relationship and hardware/software/services supply-chain security guidanceEdition 2, published 2023-06
ENISA Good Practices for Supply Chain CybersecurityEU supply-chain cybersecurity practices and NIS2-related contextCite publication page/date when used
ENISA Threat Landscape for Supply Chain AttacksAttack/failure mode context and threat examplesCite publication page/date when used
UK NCSC Supply Chain Security GuidanceSupplier assurance, supply-chain principles, and assessment practicesUse page version/review date where available
CISA SBOM topic pageSBOM policy, adoption, and operationalization contextUse page and resource dates where available
CISA 2025 Minimum Elements for SBOMSBOM minimum elements and software transparency expectationsDraft guidance, published 2025-08-22

Evidence Models And Attestation

SourceUse it forVersion or date note
IETF RATS Working GroupRemote attestation architecture and evidence model contextCite exact RFC or Internet-Draft
Entity Attestation Token RFC informationEAT media types and links to EAT-related RFCsRFC 9782; also cite EAT RFC used
IETF CoRIM Internet-DraftCoRIM/CoMID reference values and endorsementsDraft status; cite revision number
TCG Platform Certificate Profile 2.1Platform identity and composition claimsVersion 2.1
TCG DICE Certificate Profiles v1.1DICE certificate profiles and identity/attestation certificatesVersion 1.1, 2025-04-24
TCG DICE Attestation Architecture v1.2DICE attestation architecture and certificate extensionsVersion 1.2

Transparency Artifacts

SourceUse it forVersion or date note
SPDXSPDX SBOM and systems/package data exchange referencesSPDX is identified by the project as ISO/IEC 5962:2021; cite artifact version used
CycloneDXCycloneDX BOM capabilities, including SBOM, HBOM, CBOM, VEX, and other BOM typesCite exact CycloneDX version used
ECMA-424 CycloneDX specificationFormal CycloneDX Bill of Materials specificationCite edition/version used

Trust Anchors, Device Security, And Protocols

SourceUse it forVersion or date note
DMTF SPDM standards pageSPDM overview and links to related specificationsCite exact DSP version used
DMTF DSP0274 SPDM 1.4.0Security Protocol and Data Model messages, data objects, and sequencesVersion 1.4.0, 2025-05-15 document date
GlobalPlatform specification libraryGlobalPlatform TEE, Secure Element, and related specificationsCite exact document ID and version
GlobalPlatform TEE System Architecture v1.3TEE architecture contextGPD_SPE_009, published 2022-05
GlobalPlatform TEE Secure Element API v1.1.2TEE to Secure Element API contextGPD_SPE_024, published 2021-02
OCP S.A.F.E. programHardware and firmware security appraisal contextCite current program page and repository references
OCP S.A.F.E. GitHub repositoryOCP S.A.F.E. framework, reports, and process documentsCite commit, file, or release where appropriate
Caliptra project documentationOpen silicon root-of-trust project contextCite exact project documentation or specification referenced

Relationship To Existing Guidance

This handbook should acknowledge that extensive supply-chain-security guidance already exists. Its role is to bridge needs, guidance, evidence, lifecycle assurance, and technology mappings.