Cyber Knowledge · Reference index

Editorial and Source Policy

The evidence, review, correction, versioning, and AI-assistance rules used to maintain Cyber Knowledge.

Editorial correction review: 2026-09-09. Imported research with unrecovered citations remains unverified. A checked ATT&CK identifier confirms taxonomy, not procedure attribution. Use npm run check-editorial before publication; intentional artifact examples must be inside code blocks. Preserve publication, substantive modification, dataset release, and editorial-review dates separately. Rebuilding output does not constitute a new review.

Evidence and editorial policy

Source selection

Prefer official standards, government publications, framework owners, first-party documentation, peer-reviewed research, and technically credible primary research. Internal 1200km material is labelled as research, a lab, a tool, or a workflow—not as an external standard. The Knowledge Sources module records scope, strengths, limitations, quality dimensions, and intended use for its curated entries.

Review and versioning

Guide metadata records publication and last-review dates. Version-sensitive claims should name the document or framework revision. “Reviewed” describes an editorial source review; it does not claim independent certification.

Corrections

Report a factual issue, broken link, or outdated reference through the public GitHub issue form. Include the affected URL, quoted claim, proposed source, and reason for correction.

AI assistance

AI may assist drafting, classification, comparison, or navigation. It is not treated as evidence. Technical claims, mappings, citations, and operational recommendations require human review against the cited source and relevant environment.

Claims and uncertainty

Facts, interpretation, assumptions, recommendations, confidence, and uncertainty should remain distinguishable. Indicators do not independently prove compromise; framework mappings do not prove control effectiveness.