Standards / Network and Security / MYTHOS-SEC

Cybersecurity

Network engineering and cybersecurity standards, from topology and source of truth to zero trust and detection. Visual language: Topology, routing and state graphs, trust zones, packet and control flows, attack paths, enforcement boundaries, and evidence chains.

Standards
17
Pages
545
Controls and criteria
115
Companions
21

MYTHOS-SEC

Cybersecurity standards

All domains →

Companions

Guides and portfolios for this series

Field guides, living guides, and portfolio editions that decompose or consolidate the MYTHOS-SEC standards.

  • MYTHOS-FG-SEC-0001

    Threat Modeling and Security Architecture

    A system-level threat-modeling and security-architecture guide covering assets, data flows, trust boundaries, actors, attack surfaces, abuse cases, STRIDE-style analysis, attack trees, adversary behavior, control selection, residual risk, architecture review, verification, and living-model governance.

    Focused Field Guide 55 pp PDF
  • MYTHOS-FG-SEC-0002

    Zero-Trust Architecture and Continuous Authorization

    A zero-trust engineering guide covering policy decision and enforcement, identity, devices, workloads, networks, applications, data, telemetry, continuous evaluation, microsegmentation, SASE, service identity, hybrid cloud, failure design, migration, maturity, and operational assurance.

    Focused Field Guide 55 pp PDF
  • MYTHOS-FG-SEC-0003

    Enterprise Firewall Engineering and Policy Architecture

    A vendor-neutral enterprise firewall guide covering packet flow, sessions, zones, policy evaluation, objects, NAT, application and identity controls, TLS inspection, clustering, routing, virtual systems, cloud enforcement, policy lifecycle, automation, telemetry, performance, troubleshooting, and blast-radius control.

    Focused Field Guide 55 pp PDF
  • MYTHOS-FG-SEC-0004

    IPsec, TLS VPN, Remote Access, and Tunnel Troubleshooting

    A tunnel and remote-access guide covering IPsec architecture, IKEv2, ESP, SAs, traffic selectors, NAT traversal, certificates, routing, policy, TLS VPN, client posture, split tunneling, clustering, mobility, MTU, observability, packet troubleshooting, and hybrid post-quantum transition.

    Focused Field Guide 55 pp PDF
  • MYTHOS-FG-SEC-0005

    Microsegmentation, Workload Isolation, and East-West Security

    A microsegmentation guide covering workload identity, policy models, distributed enforcement, host and hypervisor controls, Kubernetes network policy, service mesh, east-west traffic, dependencies, brownfield adoption, policy testing, observability, failure containment, and zero-trust integration.

    Focused Field Guide 55 pp PDF
  • MYTHOS-FG-SEC-0006

    Identity, Access, PKI, Secrets, and Privileged Access Engineering

    An identity-security engineering guide covering proofing, directories, authentication, passkeys, federation, OAuth and OIDC, authorization, PKI, certificates, workload identity, secrets, key management, privileged access, non-human and agent identity, lifecycle, recovery, monitoring, and post-quantum readiness.

    Focused Field Guide 55 pp PDF
  • MYTHOS-FG-SEC-0007

    Vulnerability, Exposure, and Attack-Surface Management

    A vulnerability and exposure guide covering asset authority, discovery, scanning, CVE and product data, CVSS v4.0, KEV, SSVC, exploitability, attack paths, business context, remediation, mitigation, exceptions, patching, cloud and application exposures, external attack surface, validation, metrics, automation, and governance.

    Focused Field Guide 55 pp PDF
  • MYTHOS-FG-SEC-0008

    SIEM Architecture, Log Engineering, and Security Analytics

    A SIEM and analytics guide covering logging strategy, source onboarding, collection, time, parsing, schemas, normalization, enrichment, storage, search, correlation, detection, UEBA, hunting, evidence, privacy, integrity, performance, cost, cloud architecture, engineering lifecycle, incident operations, and AI-assisted analytics.

    Focused Field Guide 55 pp PDF
  • MYTHOS-FG-SEC-0009

    SOAR, Case Management, and Security Workflow Automation

    A security-orchestration guide covering operating models, alert and case lifecycle, evidence, machine-readable playbooks, integrations, safe actions, approvals, automation testing, metrics, failure recovery, and governed AI-assisted response.

    Focused Field Guide 55 pp PDF
  • MYTHOS-FG-SEC-0010

    Detection Engineering and Detection-as-Code

    A detection-engineering guide covering hypotheses, data requirements, ATT&CK-informed coverage, event semantics, Sigma, analytics, correlation, testing, version control, deployment, observability, tuning, retirement, and AI-assisted detection development.

    Focused Field Guide 55 pp PDF
  • MYTHOS-FG-SEC-0011

    Threat Hunting and Adversary-Informed Investigation

    A threat-hunting guide covering hunt strategy, adversary behavior, intelligence, hypotheses, telemetry, endpoint, network, identity, cloud, timelines, graph analysis, findings, operationalization, metrics, and governed AI-assisted investigation.

    Focused Field Guide 55 pp PDF
  • MYTHOS-FG-SEC-0012

    Incident Response, Forensics, and Recovery Engineering

    An incident-response and recovery guide covering preparation, triage, command, containment, evidence, forensics, scoping, eradication, recovery, crisis communication, legal and privacy coordination, exercises, automation, and continuous improvement.

    Focused Field Guide 55 pp PDF
  • MYTHOS-FG-SEC-0013

    Application, API, and Web Security Engineering

    An application-security guide covering secure architecture, browser and web controls, APIs, authentication, authorization, sessions, input and output, cryptography, data, business logic, abuse resistance, testing, verification, deployment, monitoring, and incident readiness.

    Focused Field Guide 55 pp PDF
  • MYTHOS-FG-SEC-0014

    Software and AI Supply-Chain Security

    A software and AI supply-chain guide covering source, dependencies, build systems, CI/CD, provenance, signing, SBOMs, VEX, model and dataset lineage, release, distribution, updates, suppliers, validation, incident response, and governed automation.

    Focused Field Guide 56 pp PDF
  • MYTHOS-FG-SEC-0015

    Cloud, Container, Kubernetes, and Workload Security

    A cloud-native security guide covering shared responsibility, cloud identity, network and data controls, containers, images, registries, Kubernetes control plane, nodes, admission, pod security, workload identity, network policy, secrets, runtime defense, observability, incident response, and confidential workloads.

    Focused Field Guide 55 pp PDF
  • MYTHOS-FG-SEC-0016

    Applied Cryptography, PKI, and Key Management

    An applied cryptography guide covering security goals, randomness, symmetric encryption, hashes, MACs, KDFs, public-key cryptography, signatures, key establishment, protocols, PKI, certificates, HSMs, FIPS 140-3, key lifecycle, crypto agility, testing, and implementation failures.

    Focused Field Guide 56 pp PDF
  • MYTHOS-FG-SEC-0017

    Post-Quantum Cryptography Implementation and Migration

    A post-quantum implementation and migration guide covering quantum risk, cryptographic discovery, FIPS 203/204/205, KEM use, signatures, hybrid protocols, PKI, code signing, data protection, performance, interoperability, testing, vendors, governance, and phased enterprise transition.

    Focused Field Guide 56 pp PDF
  • MYTHOS-FG-SEC-0018

    Confidential Computing, TEEs, Attestation, FHE, and ZKP

    An advanced assurance and privacy-enhancing cryptography guide covering trusted execution environments, data-in-use protection, threat models, remote attestation, RATS, EAT, key release, confidential containers and AI, multi-party data collaboration, fully homomorphic encryption, zero-knowledge proofs, integration, performance, governance, and adoption limits.

    Focused Field Guide 56 pp PDF
  • MYTHOS-FG-SEC-0019

    Offensive Security, Penetration Testing, and Control Validation

    A governed offensive-security guide covering authorization, scoping, rules of engagement, attack-surface analysis, vulnerability validation, adversary emulation, web, API, cloud, identity, network, wireless, application, social and physical boundaries, control testing, evidence, reporting, remediation, retesting, and safe automation.

    Focused Field Guide 55 pp PDF
  • MYTHOS-GUIDE-SEC-0001

    Security Engineering and Information Security

    Integrated engineering guide connecting the relevant Mythos standards, implementation patterns, operating procedures, architecture decisions, evidence expectations, and maturity path for enterprise cybersecurity architecture and operations.

    Living Guide 47 pp PDF
  • MYTHOS-SEC-PORT-0001

    Cybersecurity Standards Portfolio

    Portfolio Edition in the Standards Portfolios collection of the MYTHOS Engineering Standards Library.

    Portfolio Edition 547 pp PDF

Candidate status describes publication review state. It does not establish certification, legal compliance, implementation conformance, benchmark reproduction, or product readiness.