RAND SL3 implementation framework published 25 August 2026
262 controls; 31 attack vectorsobserved
| Value kind | observed — Reported measurements, counts, and specifications keep the precision and scope stated by their source; an exact specification is not treated as a range. |
|---|---|
| Scope | Framework adapted from NIST SP 800-53 for organized cybercrime and insider threats. Selection of mapped controls is planning coverage, not proof of elimination of risk. |
| As of | 2026-08-25 |
| Source | RAND; : https://www.rand.org/pubs/research_reports/RRA4704-1.html · Publication summary; supporting repository README |
| Review | checking…review by 2026-12-05 · standard cadence |
| Recorded changes | none recorded |
| Claim id | p11-rand-sl3-2026 |
Where the guide uses it
Not quoted in a chapter yet; it is kept in the curated register.
← Full numbers register — every date-stamped figure in the guide, with revision history.