Netspective Logo

Third-Party Resources

NIST, TOGAF, IEEE, and other industry standards and frameworks

Third-party resources provide industry-recognized standards, frameworks, and best practices that complement the Netspective Unified Process. These resources help ensure alignment with established methodologies and regulatory requirements.

Resource Categories

┌─────────────────────────────────────────────────────────────────────────────┐
│                      THIRD-PARTY RESOURCES                                   │
└─────────────────────────────────────────────────────────────────────────────┘

┌─────────────────────────────────────────────────────────────────────────────┐
│                      SECURITY & COMPLIANCE                                   │
│  NIST Frameworks, OWASP, CIS Benchmarks                                     │
└─────────────────────────────────────────────────────────────────────────────┘

┌─────────────────────────────────────────────────────────────────────────────┐
│                    ARCHITECTURE FRAMEWORKS                                   │
│  TOGAF, Zachman, C4 Model                                                   │
└─────────────────────────────────────────────────────────────────────────────┘

┌─────────────────────────────────────────────────────────────────────────────┐
│                     ENGINEERING STANDARDS                                    │
│  IEEE, ISO, IEC Standards                                                   │
└─────────────────────────────────────────────────────────────────────────────┘

┌─────────────────────────────────────────────────────────────────────────────┐
│                    ENGINEERING PLAYBOOKS                                     │
│  Microsoft, Google, Industry Best Practices                                  │
└─────────────────────────────────────────────────────────────────────────────┘

Available Resources

ResourceCategoryUse Case
NIST ResourcesSecurity & ComplianceRisk management, cybersecurity
TOGAF ResourcesArchitectureEnterprise architecture
IEEE StandardsEngineeringSoftware engineering standards

Key Industry Standards

Security Standards

StandardPublisherFocus
NIST Cybersecurity FrameworkNISTRisk management
NIST 800-53NISTSecurity controls
ISO 27001ISOInformation security
OWASP Top 10OWASPWeb application security
CIS BenchmarksCISSystem hardening

Software Engineering Standards

StandardPublisherFocus
IEEE 730IEEESoftware quality assurance
IEEE 829IEEESoftware test documentation
IEEE 1012IEEESoftware verification & validation
ISO/IEC 12207ISO/IECSoftware lifecycle processes
IEC 62304IECMedical device software

Architecture Frameworks

FrameworkPublisherFocus
TOGAFThe Open GroupEnterprise architecture
ZachmanZachman InternationalArchitecture taxonomy
C4 ModelSimon BrownSoftware architecture diagrams
ArchiMateThe Open GroupArchitecture modeling

Microsoft Engineering Playbook

The Microsoft Engineering Playbook provides modern engineering best practices that align with NUP principles.

Key Resources

TopicDescriptionLink
Agile DevelopmentSprint practices, ceremoniesView
Code ReviewsReview process and checklistsView
Automated TestingTesting strategiesView
CI/CDPipeline practicesView
DesignDesign reviews, patternsView
DocumentationDocumentation standardsView
SecuritySecurity practicesView
ObservabilityMonitoring, loggingView

Regulatory Resources

FDA Guidance

DocumentPurpose
General Principles of Software ValidationSoftware validation guidance
Software as Medical DeviceSaMD classification
21 CFR Part 11Electronic records

HIPAA Resources

ResourcePurpose
HIPAA Security RuleSecurity requirements
HIPAA Privacy RulePrivacy requirements
HHS GuidanceImplementation guidance

FedRAMP Resources

ResourcePurpose
FedRAMP.govProgram overview
FedRAMP MarketplaceAuthorized providers
FedRAMP DocumentsTemplates and guidance

How to Use These Resources

Integration with NUP

┌─────────────────────────────────────────────────────────────────────────────┐
│                   RESOURCE INTEGRATION MODEL                                 │
└─────────────────────────────────────────────────────────────────────────────┘

     NUP Phases & Disciplines


    ┌─────────────────┐
    │  Map to         │
    │  Standards      │────▶  Select applicable standards
    └────────┬────────┘       (NIST, IEEE, ISO, etc.)


    ┌─────────────────┐
    │  Adopt          │
    │  Practices      │────▶  Integrate best practices
    └────────┬────────┘       (MS Playbook, OWASP)


    ┌─────────────────┐
    │  Generate       │
    │  Evidence       │────▶  Document compliance
    └─────────────────┘       (audits, certifications)

Selection Criteria

Choose resources based on:

  1. Regulatory Requirements - What compliance is needed?
  2. Industry Context - Healthcare, finance, government?
  3. Project Scope - Enterprise-wide or single application?
  4. Team Expertise - What does the team already know?


Compliance

This section fulfills ISO 13485 requirements for regulatory requirements (4.1.1), external documentation (4.2.3), and standards compliance (4.1), and ISO 27001 requirements for compliance with legal requirements (A.5.31), external references (A.5.37), and information security policies (A.5.1).

View full compliance matrix

How is this guide?

Last updated on

On this page