RIA CYBER COMPLIANCE

Methodology & sources

How our tools use sources, assumptions and versioned templates.

Version 1.0.0 · October 1, 2026

Useful structure, visible assumptions

These tools are deterministic, browser-local planning aids. The planner expands user-selected cadences, the worksheet records human access decisions, and the tabletop uses product-authored fictional scenarios. The tools do not inspect systems, evaluate evidence, score compliance or determine legal obligations.

Dates and task frequencies are user choices or product suggestions. No output asserts that a regulator mandates them. Unknown inputs remain unknown. Status colors describe recorded workflow state only.

Source policy

We distinguish voluntary guidance, vendor documentation and product suggestions. No binding rule or examination observation is implemented as a requirement in this release. Regulatory modules are deferred for current primary-source and expert review. SEC-registered and state-registered firms can have different obligations; we do not infer universal applicability.

Sources below support only the stated background propositions. The task wording, cadences and exercise scenarios are our suggestions, not quotations or regulator-endorsed templates.

NIST-1300 / NIST

Cybersecurity Framework 2.0: Small Business Quick-Start Guide ↗

Publication / update
2024-02-26
Last checked
2026-10-01
Supported proposition
Provides a starting point for small organizations to organize cybersecurity risk management.
Applicability
Voluntary guidance; no RIA-specific frequency or legal deadline is derived here.
Content version
1.0.0
Review state
Primary page checked; product suggestions require organization review.
MS-ACCESS / Microsoft

What are access reviews? ↗

Publication / update
2026-03-12 (page updated)
Last checked
2026-10-01
Supported proposition
Access reviews can evaluate continued need for group membership, application access and role assignments.
Applicability
Microsoft product guidance. This worksheet is a manual record and does not connect to Entra or inherit its automation.
Content version
1.0.0
Review state
Primary page checked; technical applicability remains the user's responsibility.
NIST-84 / NIST

Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities ↗

Publication / update
2006-09-21
Last checked
2026-10-01
Supported proposition
Describes designing, conducting and evaluating exercises for organizational IT plans.
Applicability
Exercise methodology background, originally in a federal context. Our fictional scenarios and minute allocations are product-authored suggestions.
Content version
1.0.0
Review state
Primary publication page checked; no regulatory applicability inferred.

Versions & corrections

Projects and exports carry template and source versions. A future template change will not silently rewrite your downloaded records. Guides were checked against the linked primary pages; expert legal/content approval is separate and has not been claimed.

Contact: support@riacybercompliance.com · riacybercompliance.com