Appendix C: References and Further Reading¶
This appendix collects every external source cited across the Employee Lifecycle Security handbook, grouped by type for easier follow-up research.
Standards and Frameworks¶
- NIST SP 800-207, Zero Trust Architecture
- NIST SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems
- NIST Special Publication 800-53 Revision 5
- NIST Special Publication 800-88 Revision 1
- RFC 7644, SCIM Protocol
- OWASP Secrets Management Cheat Sheet
- OWASP Smart Contract Security Verification Standard (SCSVS)
- OWASP Web3 Attack Vectors Top 15
- GDPR Article 17
- ISO/IEC 27001:2022 Annex A control 5.18, Access Rights
- PCI DSS v4.0.1
- American Institute of Certified Public Accountants (AICPA), SOC 2
- MITRE ATT&CK technique T1078, Valid Accounts
- MITRE ATT&CK T1531, Account Access Removal
- EEOC's joint guidance with the FTC on background checks
- FTC guidance for employers using consumer reports
Incidents and Case Studies¶
- Bybit hack summary and attribution
- Christina Chapman case summary
- Coinbase 2025 data breach, Wikipedia summary of public disclosures
- LastPass breaches disclosed in 2022
- Wikipedia: North Korean remote worker infiltration scheme
- Wikipedia: QuadrigaCX
- Wikipedia: Ronin Network
- Halborn, "Explained: The Ronin Hack (March 2022)"
- KnowBe4, "How a North Korean Fake IT Worker Tried to Infiltrate Us"
- FBI IC3 PSA 231018
Tools and Documentation¶
- GitHub documentation, removing a member from your organization
- Safe smart contracts,
OwnerManager.sol - Safe