Methodology & sources
How our tools use sources, assumptions and versioned templates.
Version 1.0.0 · October 1, 2026
Useful structure, visible assumptions
These tools are deterministic, browser-local planning aids. The planner expands user-selected cadences, the worksheet records human access decisions, and the tabletop uses product-authored fictional scenarios. The tools do not inspect systems, evaluate evidence, score compliance or determine legal obligations.
Dates and task frequencies are user choices or product suggestions. No output asserts that a regulator mandates them. Unknown inputs remain unknown. Status colors describe recorded workflow state only.
Source policy
We distinguish voluntary guidance, vendor documentation and product suggestions. No binding rule or examination observation is implemented as a requirement in this release. Regulatory modules are deferred for current primary-source and expert review. SEC-registered and state-registered firms can have different obligations; we do not infer universal applicability.
Sources below support only the stated background propositions. The task wording, cadences and exercise scenarios are our suggestions, not quotations or regulator-endorsed templates.
Cybersecurity Framework 2.0: Small Business Quick-Start Guide ↗
- Publication / update
- 2024-02-26
- Last checked
- 2026-10-01
- Supported proposition
- Provides a starting point for small organizations to organize cybersecurity risk management.
- Applicability
- Voluntary guidance; no RIA-specific frequency or legal deadline is derived here.
- Content version
- 1.0.0
- Review state
- Primary page checked; product suggestions require organization review.
What are access reviews? ↗
- Publication / update
- 2026-03-12 (page updated)
- Last checked
- 2026-10-01
- Supported proposition
- Access reviews can evaluate continued need for group membership, application access and role assignments.
- Applicability
- Microsoft product guidance. This worksheet is a manual record and does not connect to Entra or inherit its automation.
- Content version
- 1.0.0
- Review state
- Primary page checked; technical applicability remains the user's responsibility.
Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities ↗
- Publication / update
- 2006-09-21
- Last checked
- 2026-10-01
- Supported proposition
- Describes designing, conducting and evaluating exercises for organizational IT plans.
- Applicability
- Exercise methodology background, originally in a federal context. Our fictional scenarios and minute allocations are product-authored suggestions.
- Content version
- 1.0.0
- Review state
- Primary publication page checked; no regulatory applicability inferred.
Versions & corrections
Projects and exports carry template and source versions. A future template change will not silently rewrite your downloaded records. Guides were checked against the linked primary pages; expert legal/content approval is separate and has not been claimed.
Contact: support@riacybercompliance.com · riacybercompliance.com