{
    "schema": "https://update.dsesecurity.com/source-register/v1",
    "content_modified_at": "2026-07-19T21:29:04+00:00",
    "article_count": 87,
    "primary_source_count": 82,
    "editorial_method": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
    "articles": [
        {
            "title": "“ONVIF compatible” is not enough: verify the exact model, firmware, and profile",
            "url": "https://update.dsesecurity.com/updates/verify-onvif-conformance-model-firmware-profile/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Access Control",
                "Cybersecurity",
                "Video Surveillance"
            ],
            "primary_source": {
                "name": "ONVIF — Conformant Products",
                "url": "https://www.onvif.org/conformant-products/",
                "published": null,
                "authority": "ONVIF"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:15+00:00"
        },
        {
            "title": "A privacy operating model for video surveillance based on SIA’s 2025 Code",
            "url": "https://update.dsesecurity.com/updates/video-surveillance-privacy-operating-model-sia-code/",
            "format": "playbook",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "Video Surveillance"
            ],
            "primary_source": {
                "name": "Security Industry Association — Data Privacy Code of Practice: Video Surveillance",
                "url": "https://www.securityindustry.org/wp-content/uploads/2025/06/SIA-Video-Code-of-Practice-2025.pdf",
                "published": null,
                "authority": "Security Industry Association"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:39+00:00"
        },
        {
            "title": "A production-safe update window for servers, networks, and endpoints",
            "url": "https://update.dsesecurity.com/updates/production-safe-it-update-window/",
            "format": "checklist",
            "priority": "info",
            "topics": [
                "IT"
            ],
            "primary_source": {
                "name": "DSE Updates editorial methodology",
                "url": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "published": null,
                "authority": "DSE Security editorial guidance"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:06:30+00:00"
        },
        {
            "title": "Access control update readiness: protect the doors while changing the software",
            "url": "https://update.dsesecurity.com/updates/access-control-update-readiness/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Access Control",
                "Cybersecurity"
            ],
            "primary_source": {
                "name": "DSE Updates editorial methodology",
                "url": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "published": null,
                "authority": "DSE Security editorial guidance"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:06:30+00:00"
        },
        {
            "title": "Apply Defender for Office 365 preset policies without overprotecting the wrong users",
            "url": "https://update.dsesecurity.com/updates/defender-office-365-preset-policy-safe-rollout/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Preset security policies in cloud organizations",
                "url": "https://learn.microsoft.com/en-us/defender-office-365/preset-security-policies",
                "published": "2026-07-03",
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:53+00:00"
        },
        {
            "title": "Ask cybersecurity questions before buying a network-connected security device",
            "url": "https://update.dsesecurity.com/updates/security-device-procurement-cybersecurity/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Access Control",
                "Cybersecurity",
                "Networks & Infrastructure",
                "Video Surveillance"
            ],
            "primary_source": {
                "name": "NIST IR 8259 Rev. 1 — Foundational Cybersecurity Activities for IoT Product Manufacturers",
                "url": "https://csrc.nist.gov/pubs/ir/8259/r1/final",
                "published": "2026-04-20",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:04:47+00:00"
        },
        {
            "title": "AXIS OS security updates: verify camera firmware tracks and deployed versions",
            "url": "https://update.dsesecurity.com/updates/axis-os-security-updates-firmware-tracks/",
            "format": "briefing",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "Video Surveillance"
            ],
            "primary_source": {
                "name": "Axis Security Advisories",
                "url": "https://help.axis.com/en-US/security-advisories",
                "published": null,
                "authority": "Axis Communications"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:06:30+00:00"
        },
        {
            "title": "Back up physical-security controllers like OT: configurations, tools, licenses, spares, and restore tests",
            "url": "https://update.dsesecurity.com/updates/physical-security-ot-backup-restore-testing/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Access Control",
                "Business Continuity",
                "Cybersecurity",
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "NIST SP 1339 — OT Backup Quick Start Guide",
                "url": "https://csrc.nist.gov/pubs/sp/1339/final",
                "published": "2026-06-17",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:29:04+00:00"
        },
        {
            "title": "Backups are not recovery until restoration is tested",
            "url": "https://update.dsesecurity.com/updates/backups-restoration-testing-recovery/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "Cybersecurity"
            ],
            "primary_source": {
                "name": "CISA #StopRansomware Guide",
                "url": "https://www.cisa.gov/resources-tools/resources/stopransomware-guide",
                "published": "2023-10-19",
                "authority": "Cybersecurity and Infrastructure Security Agency"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:03:09+00:00"
        },
        {
            "title": "Build a firewall rule lifecycle that survives staff and system changes",
            "url": "https://update.dsesecurity.com/updates/firewall-rule-lifecycle/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "NIST SP 800-41 Rev. 1 — Guidelines on Firewalls and Firewall Policy",
                "url": "https://csrc.nist.gov/pubs/sp/800/41/r1/final",
                "published": "2009-09-28",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:04:22+00:00"
        },
        {
            "title": "Build a practical baseline with CISA Cybersecurity Performance Goals",
            "url": "https://update.dsesecurity.com/updates/cisa-cpg-practical-cybersecurity-baseline/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Cybersecurity"
            ],
            "primary_source": {
                "name": "CISA Cross-Sector Cybersecurity Performance Goals",
                "url": "https://www.cisa.gov/cybersecurity-performance-goals",
                "published": null,
                "authority": "Cybersecurity and Infrastructure Security Agency"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:03:09+00:00"
        },
        {
            "title": "Build a repeatable Microsoft Purview audit-search procedure before an incident",
            "url": "https://update.dsesecurity.com/updates/microsoft-purview-audit-search-incident-readiness/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Search the audit log",
                "url": "https://learn.microsoft.com/en-us/purview/audit-search",
                "published": "2026-06-19",
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:15+00:00"
        },
        {
            "title": "Build an incident-response plan before the first urgent call",
            "url": "https://update.dsesecurity.com/updates/build-incident-response-plan/",
            "format": "playbook",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "Cybersecurity"
            ],
            "primary_source": {
                "name": "NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management",
                "url": "https://csrc.nist.gov/pubs/sp/800/61/r3/final",
                "published": "2025-04-03",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:03:09+00:00"
        },
        {
            "title": "Build cyber supply-chain risk management into the full product lifecycle",
            "url": "https://update.dsesecurity.com/updates/cybersecurity-supply-chain-lifecycle-governance/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "Cybersecurity",
                "IT"
            ],
            "primary_source": {
                "name": "NIST SP 800-161 Rev. 1 Update 1: Cybersecurity Supply Chain Risk Management Practices",
                "url": "https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final",
                "published": "2024-11-01",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:10+00:00"
        },
        {
            "title": "Build event logging that supports detection, investigation, and resilience",
            "url": "https://update.dsesecurity.com/updates/event-logging-detection-integrity-baseline/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "IT",
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "CISA: Best Practices for Event Logging and Threat Detection",
                "url": "https://www.cisa.gov/resources-tools/resources/best-practices-event-logging-and-threat-detection",
                "published": "2024-08-21",
                "authority": "Cybersecurity and Infrastructure Security Agency"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:26:27+00:00"
        },
        {
            "title": "Cable verification, qualification, and certification answer different questions",
            "url": "https://update.dsesecurity.com/updates/cable-verification-qualification-certification/",
            "format": "explainer",
            "priority": "info",
            "topics": [
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "Fluke Networks — Verification, Qualification, Certification: Which Do I Need?",
                "url": "https://www.flukenetworks.com/blog/cabling-chronicles/verification-qualification-certification-which-do-i-need",
                "published": "2019-01-23",
                "authority": "Fluke Networks"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:04:46+00:00"
        },
        {
            "title": "Camera certificate lifecycle management: HTTPS and 802.1X are different jobs",
            "url": "https://update.dsesecurity.com/updates/axis-camera-certificate-lifecycle-https-8021x/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "Networks & Infrastructure",
                "Video Surveillance"
            ],
            "primary_source": {
                "name": "Axis Communications — AXIS Device Manager Security Guide",
                "url": "https://help.axis.com/en-us/adm-security-guide",
                "published": null,
                "authority": "Axis Communications"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:39+00:00"
        },
        {
            "title": "Check Windows Autopatch prerequisites before registering production devices",
            "url": "https://update.dsesecurity.com/updates/windows-autopatch-production-prerequisites/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "IT",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Windows Autopatch prerequisites",
                "url": "https://learn.microsoft.com/en-us/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites",
                "published": "2026-02-27",
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:15+00:00"
        },
        {
            "title": "Choose Teams external access, guest access, or neither for each collaboration need",
            "url": "https://update.dsesecurity.com/updates/microsoft-teams-external-versus-guest-access/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Use guest access and external access to collaborate with people outside your organization",
                "url": "https://learn.microsoft.com/en-us/microsoftteams/communicate-with-users-from-other-organizations",
                "published": "2026-07-01",
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:15+00:00"
        },
        {
            "title": "Choose the right DSE channel: Updates, helpdesk, or main site",
            "url": "https://update.dsesecurity.com/updates/choose-dse-updates-helpdesk-main-site/",
            "format": "guide",
            "priority": "info",
            "topics": [
                "DSE World"
            ],
            "primary_source": {
                "name": "DSE Security contact and support routing",
                "url": "https://dsesecurity.com/contact-us/",
                "published": null,
                "authority": "DSE Security"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:03:57+00:00"
        },
        {
            "title": "Clean up stale Intune records without mistaking hiding for retirement",
            "url": "https://update.dsesecurity.com/updates/intune-device-cleanup-rules-stale-records/",
            "format": "guide",
            "priority": "info",
            "topics": [
                "IT",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Device cleanup rules",
                "url": "https://learn.microsoft.com/en-us/intune/governance/configure-cleanup-rules",
                "published": "2026-05-05",
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:53+00:00"
        },
        {
            "title": "Create a vulnerability-disclosure channel that researchers can actually use",
            "url": "https://update.dsesecurity.com/updates/vulnerability-disclosure-report-handling/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "IT"
            ],
            "primary_source": {
                "name": "NIST SP 800-216: Recommendations for Federal Vulnerability Disclosure Guidelines",
                "url": "https://csrc.nist.gov/pubs/sp/800/216/final",
                "published": "2023-05-24",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:10+00:00"
        },
        {
            "title": "Create an enterprise log-management policy before choosing a SIEM",
            "url": "https://update.dsesecurity.com/updates/enterprise-log-management-policy/",
            "format": "guide",
            "priority": "info",
            "topics": [
                "Cybersecurity",
                "IT",
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "NIST SP 800-92: Guide to Computer Security Log Management",
                "url": "https://csrc.nist.gov/pubs/sp/800/92/final",
                "published": "2006-09-13",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:26:27+00:00"
        },
        {
            "title": "Data breach response: coordinate containment, investigation, communication, and notification",
            "url": "https://update.dsesecurity.com/updates/business-data-breach-response-sequence/",
            "format": "playbook",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "Cybersecurity",
                "IT"
            ],
            "primary_source": {
                "name": "Federal Trade Commission: Data Breach Response — A Guide for Business",
                "url": "https://www.ftc.gov/business-guidance/resources/data-breach-response-guide-business",
                "published": null,
                "authority": "Federal Trade Commission"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:10+00:00"
        },
        {
            "title": "Demand evidence, not promises, when buying digital technology",
            "url": "https://update.dsesecurity.com/updates/secure-verifiable-technology-procurement/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "Cybersecurity",
                "IT"
            ],
            "primary_source": {
                "name": "CISA and international partners: Choosing Secure and Verifiable Technologies",
                "url": "https://www.cisa.gov/resources-tools/resources/choosing-secure-and-verifiable-technologies",
                "published": "2024-12-05",
                "authority": "Cybersecurity and Infrastructure Security Agency"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:10+00:00"
        },
        {
            "title": "Deploy phishing-resistant authentication by user and device readiness",
            "url": "https://update.dsesecurity.com/updates/microsoft-entra-phishing-resistant-authentication-rollout/",
            "format": "playbook",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "IT",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Plan a phishing-resistant passwordless authentication deployment in Microsoft Entra ID",
                "url": "https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-deploy-phishing-resistant-passwordless-authentication",
                "published": "2026-03-26",
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:53+00:00"
        },
        {
            "title": "Deploy Windows LAPS through Intune without creating policy conflicts",
            "url": "https://update.dsesecurity.com/updates/intune-windows-laps-conflict-safe-deployment/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "IT",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Deploy Windows LAPS policy with Microsoft Intune",
                "url": "https://learn.microsoft.com/en-us/intune/device-security/laps/deploy-policy",
                "published": "2026-04-15",
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:53+00:00"
        },
        {
            "title": "Design cyber recovery playbooks around prioritized services and tested evidence",
            "url": "https://update.dsesecurity.com/updates/cybersecurity-event-recovery-playbooks/",
            "format": "playbook",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "Cybersecurity",
                "IT"
            ],
            "primary_source": {
                "name": "NIST SP 800-184: Guide for Cybersecurity Event Recovery",
                "url": "https://csrc.nist.gov/pubs/sp/800/184/final",
                "published": "2016-12-22",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:26:27+00:00"
        },
        {
            "title": "Enable BitLocker with Intune only after recovery is proven",
            "url": "https://update.dsesecurity.com/updates/intune-bitlocker-recovery-first-deployment/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "Cybersecurity",
                "IT"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Encrypt Windows devices with BitLocker using Intune",
                "url": "https://learn.microsoft.com/en-us/intune/device-configuration/endpoint-security/encrypt-bitlocker-windows",
                "published": "2026-04-15",
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:53+00:00"
        },
        {
            "title": "Encrypted DNS in enterprise networks: preserve privacy without losing visibility",
            "url": "https://update.dsesecurity.com/updates/encrypted-dns-enterprise-visibility/",
            "format": "explainer",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "IT",
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "NIST SP 800-81 Rev. 3: Secure Domain Name System (DNS) Deployment Guide",
                "url": "https://csrc.nist.gov/pubs/sp/800/81/r3/final",
                "published": "2026-03-19",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:09+00:00"
        },
        {
            "title": "Harden network infrastructure with isolated management and verifiable configuration",
            "url": "https://update.dsesecurity.com/updates/network-infrastructure-isolated-management-hardening/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "CISA and partners: Enhanced Visibility and Hardening Guidance for Communications Infrastructure",
                "url": "https://www.cisa.gov/resources-tools/resources/enhanced-visibility-and-hardening-guidance-communications-infrastructure",
                "published": "2024-12-04",
                "authority": "Cybersecurity and Infrastructure Security Agency"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:10+00:00"
        },
        {
            "title": "How DSE Updates researches, reviews, and maintains public guidance",
            "url": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
            "format": "explainer",
            "priority": "info",
            "topics": [
                "DSE World"
            ],
            "primary_source": {
                "name": "DSE Security Updates",
                "url": "https://update.dsesecurity.com/",
                "published": null,
                "authority": "DSE Security editorial guidance"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:03:09+00:00"
        },
        {
            "title": "Investigate and remediate risky Microsoft Entra users with evidence",
            "url": "https://update.dsesecurity.com/updates/microsoft-entra-risky-user-remediation-evidence/",
            "format": "playbook",
            "priority": "important",
            "topics": [
                "Cybersecurity",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Remediate risks and unblock users",
                "url": "https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-remediate-unblock",
                "published": "2026-05-27",
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:53+00:00"
        },
        {
            "title": "July 2026 Windows security update: deployment checks for managed environments",
            "url": "https://update.dsesecurity.com/updates/july-2026-windows-security-update-deployment-checks/",
            "format": "briefing",
            "priority": "important",
            "topics": [
                "Cybersecurity",
                "IT"
            ],
            "primary_source": {
                "name": "Microsoft Windows message center",
                "url": "https://learn.microsoft.com/en-us/windows/release-health/windows-message-center",
                "published": null,
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:29:33+00:00"
        },
        {
            "title": "Keep essential functions running with FEMA continuity elements",
            "url": "https://update.dsesecurity.com/updates/fema-essential-functions-continuity-elements/",
            "format": "checklist",
            "priority": "info",
            "topics": [
                "Business Continuity",
                "IT",
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "FEMA Preparedness Toolkit: E.6 Continuity Guidance Circular",
                "url": "https://preptoolkit.fema.gov/web/cip-citap/ncig/-/knowledge_base/ncig/e-6-continuity-guidance-circular",
                "published": null,
                "authority": "Federal Emergency Management Agency"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:26:27+00:00"
        },
        {
            "title": "Keep two emergency Microsoft Entra accounts ready before the tenant needs them",
            "url": "https://update.dsesecurity.com/updates/microsoft-entra-emergency-access-accounts-readiness/",
            "format": "checklist",
            "priority": "important",
            "topics": [
                "Business Continuity",
                "Cybersecurity",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Manage emergency access accounts in Microsoft Entra ID",
                "url": "https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/security-emergency-access",
                "published": "2026-06-05",
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:53+00:00"
        },
        {
            "title": "Make incident response part of every NIST CSF 2.0 function",
            "url": "https://update.dsesecurity.com/updates/incident-response-across-csf-2-functions/",
            "format": "playbook",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "Cybersecurity"
            ],
            "primary_source": {
                "name": "NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management",
                "url": "https://csrc.nist.gov/pubs/sp/800/61/r3/final",
                "published": "2025-04-03",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:26:27+00:00"
        },
        {
            "title": "Measure zero-trust maturity across five pillars before buying more tools",
            "url": "https://update.dsesecurity.com/updates/zero-trust-maturity-five-pillar-assessment/",
            "format": "guide",
            "priority": "info",
            "topics": [
                "Cybersecurity",
                "IT",
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "CISA Zero Trust Maturity Model, Version 2.0",
                "url": "https://www.cisa.gov/sites/default/files/2023-04/CISA_Zero_Trust_Maturity_Model_Version_2_508c.pdf",
                "published": null,
                "authority": "Cybersecurity and Infrastructure Security Agency"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:26:27+00:00"
        },
        {
            "title": "MFA, passkeys, and authentication strength: what the terms mean",
            "url": "https://update.dsesecurity.com/updates/mfa-passkeys-authentication-strength/",
            "format": "explainer",
            "priority": "info",
            "topics": [
                "Cybersecurity"
            ],
            "primary_source": {
                "name": "NIST SP 800-63B-4: Authentication and Authenticator Management",
                "url": "https://csrc.nist.gov/pubs/sp/800/63/b/4/final",
                "published": "2025-07-31",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:03:09+00:00"
        },
        {
            "title": "Microsoft 365 Copilot permissions readiness: fix oversharing before rollout",
            "url": "https://update.dsesecurity.com/updates/microsoft-365-copilot-permissions-readiness/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "Cybersecurity",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Microsoft 365 Copilot data and compliance readiness",
                "url": "https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-minimum-requirements-data-compliance",
                "published": null,
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:04:22+00:00"
        },
        {
            "title": "Microsoft 365 offboarding: secure access and preserve business records in the right order",
            "url": "https://update.dsesecurity.com/updates/microsoft-365-offboarding-secure-preserve-sequence/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "Cybersecurity",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Remove a former employee and secure data",
                "url": "https://learn.microsoft.com/en-us/microsoft-365/admin/add-users/remove-former-employee?view=o365-worldwide",
                "published": null,
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:04:22+00:00"
        },
        {
            "title": "Microsoft Defender for Business: understand the protection and the boundaries",
            "url": "https://update.dsesecurity.com/updates/microsoft-defender-for-business-capabilities-and-boundaries/",
            "format": "explainer",
            "priority": "info",
            "topics": [
                "Cybersecurity",
                "IT"
            ],
            "primary_source": {
                "name": "Microsoft Learn: What is Microsoft Defender for Business?",
                "url": "https://learn.microsoft.com/en-us/defender-business/mdb-overview",
                "published": null,
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:29:33+00:00"
        },
        {
            "title": "Microsoft Entra Conditional Access: plan controls without locking out the tenant",
            "url": "https://update.dsesecurity.com/updates/microsoft-entra-conditional-access-safe-deployment/",
            "format": "playbook",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Plan a Conditional Access deployment",
                "url": "https://learn.microsoft.com/en-us/entra/identity/conditional-access/plan-conditional-access",
                "published": null,
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:04:22+00:00"
        },
        {
            "title": "Microsoft Intune compliance: design the signal before enforcing access",
            "url": "https://update.dsesecurity.com/updates/microsoft-intune-compliance-design-before-enforcement/",
            "format": "explainer",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "IT",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Device compliance policies in Microsoft Intune",
                "url": "https://learn.microsoft.com/en-us/intune/device-security/compliance/overview",
                "published": null,
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:29:33+00:00"
        },
        {
            "title": "Microsoft Teams Phone readiness: validate licensing, network, calling, and emergency workflows",
            "url": "https://update.dsesecurity.com/updates/microsoft-teams-phone-production-readiness/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "Microsoft 365 & Identity",
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Set up Teams Phone in your organization",
                "url": "https://learn.microsoft.com/en-us/microsoftteams/setting-up-your-phone-system",
                "published": null,
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:29:33+00:00"
        },
        {
            "title": "Move Defender ASR rules from audit to block through controlled rings",
            "url": "https://update.dsesecurity.com/updates/microsoft-defender-asr-audit-to-block-rings/",
            "format": "playbook",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "IT"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Plan your attack surface reduction rules deployment",
                "url": "https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-deployment-plan",
                "published": "2026-05-22",
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:53+00:00"
        },
        {
            "title": "Move Windows known folders to OneDrive without creating an empty desktop",
            "url": "https://update.dsesecurity.com/updates/onedrive-known-folder-move-controlled-rollout/",
            "format": "playbook",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "IT",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Redirect and move Windows known folders to OneDrive",
                "url": "https://learn.microsoft.com/en-us/sharepoint/redirect-known-folders",
                "published": "2025-03-27",
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:15+00:00"
        },
        {
            "title": "NIST CSF 2.0 in plain English: a six-function roadmap",
            "url": "https://update.dsesecurity.com/updates/nist-csf-2-six-function-roadmap/",
            "format": "guide",
            "priority": "info",
            "topics": [
                "Business Continuity",
                "Cybersecurity"
            ],
            "primary_source": {
                "name": "NIST Cybersecurity Framework (CSF) 2.0",
                "url": "https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20",
                "published": "2024-02-26",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:03:09+00:00"
        },
        {
            "title": "ONVIF Profile D: keep access decisions in the right place when integrating peripherals",
            "url": "https://update.dsesecurity.com/updates/onvif-profile-d-access-peripheral-decision-boundaries/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Access Control",
                "Networks & Infrastructure",
                "Video Surveillance"
            ],
            "primary_source": {
                "name": "ONVIF — Profile D",
                "url": "https://www.onvif.org/profiles/profile-d/",
                "published": null,
                "authority": "ONVIF"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:39+00:00"
        },
        {
            "title": "ONVIF Profile G acceptance testing for edge recording and retrieval",
            "url": "https://update.dsesecurity.com/updates/onvif-profile-g-edge-recording-acceptance-testing/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "Networks & Infrastructure",
                "Video Surveillance"
            ],
            "primary_source": {
                "name": "ONVIF — Profile G",
                "url": "https://www.onvif.org/profiles/profile-g/",
                "published": null,
                "authority": "ONVIF"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:39+00:00"
        },
        {
            "title": "ONVIF Profile M: what analytics metadata interoperability does—and does not—prove",
            "url": "https://update.dsesecurity.com/updates/onvif-profile-m-analytics-metadata-boundaries/",
            "format": "explainer",
            "priority": "info",
            "topics": [
                "Cybersecurity",
                "Networks & Infrastructure",
                "Video Surveillance"
            ],
            "primary_source": {
                "name": "ONVIF — Profile M",
                "url": "https://www.onvif.org/profiles/profile-m/",
                "published": null,
                "authority": "ONVIF"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:39+00:00"
        },
        {
            "title": "ONVIF Profile S support ends March 31, 2027: plan a tested move to Profile T",
            "url": "https://update.dsesecurity.com/updates/onvif-profile-s-support-end-profile-t-migration/",
            "format": "briefing",
            "priority": "important",
            "topics": [
                "Cybersecurity",
                "Networks & Infrastructure",
                "Video Surveillance"
            ],
            "primary_source": {
                "name": "ONVIF — Profile S Deprecation Q&A",
                "url": "https://www.onvif.org/profiles/profile-s/profile-s-deprecation-qna/",
                "published": null,
                "authority": "ONVIF"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:15+00:00"
        },
        {
            "title": "ONVIF TLS Configuration Add-on v1.0: manage the transition without guessing",
            "url": "https://update.dsesecurity.com/updates/onvif-tls-configuration-addon-v1-transition/",
            "format": "briefing",
            "priority": "important",
            "topics": [
                "Access Control",
                "Cybersecurity",
                "Networks & Infrastructure",
                "Video Surveillance"
            ],
            "primary_source": {
                "name": "ONVIF — TLS Configuration Add-on",
                "url": "https://www.onvif.org/add-on/tls-configuration-add-on/",
                "published": null,
                "authority": "ONVIF"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:39+00:00"
        },
        {
            "title": "OSDP commissioning evidence: Verified profiles, Secure Channel, cabling, and load",
            "url": "https://update.dsesecurity.com/updates/osdp-commissioning-verified-secure-channel-evidence/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Access Control",
                "Cybersecurity"
            ],
            "primary_source": {
                "name": "Security Industry Association — Implementing OSDP Access Control? Follow This Simple Checklist",
                "url": "https://www.securityindustry.org/2026/02/10/implementing-osdp-access-control-follow-this-simple-checklist/",
                "published": "2026-02-10",
                "authority": "Security Industry Association"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:39+00:00"
        },
        {
            "title": "Plan an OSDP Secure Channel migration as a controlled access-system change",
            "url": "https://update.dsesecurity.com/updates/osdp-secure-channel-migration/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Access Control",
                "Cybersecurity",
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "Security Industry Association — Open Supervised Device Protocol (OSDP)",
                "url": "https://www.securityindustry.org/industry-standards/open-supervised-device-protocol/",
                "published": null,
                "authority": "Security Industry Association"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:29:33+00:00"
        },
        {
            "title": "Prepare for DDoS before availability becomes an incident",
            "url": "https://update.dsesecurity.com/updates/ddos-readiness-response-playbook/",
            "format": "playbook",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "Cybersecurity",
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "CISA, FBI, and MS-ISAC: Understanding and Responding to Distributed Denial-of-Service Attacks",
                "url": "https://www.cisa.gov/sites/default/files/2024-03/understanding-and-responding-to-distributed-denial-of-service-attacks_508c.pdf",
                "published": "2024-03-21",
                "authority": "Cybersecurity and Infrastructure Security Agency"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:10+00:00"
        },
        {
            "title": "Protective DNS: evaluate the resolver, the data, and the bypass paths",
            "url": "https://update.dsesecurity.com/updates/protective-dns-provider-selection/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "NIST SP 800-81 Rev. 3: Secure Domain Name System (DNS) Deployment Guide",
                "url": "https://csrc.nist.gov/pubs/sp/800/81/r3/final",
                "published": "2026-03-19",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:26:27+00:00"
        },
        {
            "title": "Ransomware first response: a calm containment checklist",
            "url": "https://update.dsesecurity.com/updates/ransomware-first-response-checklist/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "Cybersecurity"
            ],
            "primary_source": {
                "name": "CISA #StopRansomware Guide",
                "url": "https://www.cisa.gov/resources-tools/resources/stopransomware-guide",
                "published": "2023-10-19",
                "authority": "Cybersecurity and Infrastructure Security Agency"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:03:57+00:00"
        },
        {
            "title": "Reassess broad VPN access for a hybrid, least-privilege environment",
            "url": "https://update.dsesecurity.com/updates/hybrid-network-access-vpn-least-privilege/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "IT",
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "CISA and partners: Modern Approaches to Network Access Security",
                "url": "https://www.cisa.gov/news-events/alerts/2024/06/18/cisa-and-partners-release-guidance-modern-approaches-network-access-security",
                "published": "2024-06-18",
                "authority": "Cybersecurity and Infrastructure Security Agency"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:10+00:00"
        },
        {
            "title": "Recognize, report, and contain a suspected phishing message",
            "url": "https://update.dsesecurity.com/updates/recognize-report-contain-phishing/",
            "format": "playbook",
            "priority": "advisory",
            "topics": [
                "Cybersecurity"
            ],
            "primary_source": {
                "name": "CISA Personal Security Considerations: Action Guide for Critical Infrastructure Workers",
                "url": "https://www.cisa.gov/sites/default/files/2024-06/personal-security-considerations-action-guide-critical-infrastructure-workers_06-07-2024_508.pdf",
                "published": "2024-06-07",
                "authority": "Cybersecurity and Infrastructure Security Agency"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:03:09+00:00"
        },
        {
            "title": "Reduce unnecessary internet exposure before it becomes an incident path",
            "url": "https://update.dsesecurity.com/updates/reduce-unnecessary-internet-exposure/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Access Control",
                "Cybersecurity",
                "Networks & Infrastructure",
                "Video Surveillance"
            ],
            "primary_source": {
                "name": "CISA — Internet Exposure Reduction Guidance",
                "url": "https://www.cisa.gov/resources-tools/resources/exposure-reduction",
                "published": "2025-06-04",
                "authority": "Cybersecurity and Infrastructure Security Agency"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:04:46+00:00"
        },
        {
            "title": "Replace standing administrator access with a controlled PIM lifecycle",
            "url": "https://update.dsesecurity.com/updates/microsoft-entra-pim-controlled-admin-lifecycle/",
            "format": "playbook",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Plan a Privileged Identity Management deployment",
                "url": "https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-deployment-plan",
                "published": "2026-04-23",
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:53+00:00"
        },
        {
            "title": "Retiring camera, recorder, and removable storage under NIST SP 800-88 Rev. 2",
            "url": "https://update.dsesecurity.com/updates/nist-media-sanitization-camera-recorder-storage/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "Cybersecurity",
                "Video Surveillance"
            ],
            "primary_source": {
                "name": "NIST SP 800-88 Rev. 2 — Guidelines for Media Sanitization",
                "url": "https://csrc.nist.gov/pubs/sp/800/88/r2/final",
                "published": "2025-09-26",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:39+00:00"
        },
        {
            "title": "Secure RMM and remote-access software before attackers use it",
            "url": "https://update.dsesecurity.com/updates/secure-rmm-remote-access-software/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "IT",
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "CISA and partners: Guide to Securing Remote Access Software",
                "url": "https://www.cisa.gov/resources-tools/resources/guide-securing-remote-access-software",
                "published": "2023-06-06",
                "authority": "Cybersecurity and Infrastructure Security Agency"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:10+00:00"
        },
        {
            "title": "SharePoint and OneDrive external sharing: reduce exposure without stopping collaboration",
            "url": "https://update.dsesecurity.com/updates/sharepoint-onedrive-external-sharing-governance/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: External sharing in SharePoint and OneDrive",
                "url": "https://learn.microsoft.com/en-us/sharepoint/external-sharing-overview",
                "published": null,
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:04:22+00:00"
        },
        {
            "title": "Signed video: what it proves, what must survive export, and what it does not replace",
            "url": "https://update.dsesecurity.com/updates/axis-signed-video-integrity-export-boundaries/",
            "format": "explainer",
            "priority": "info",
            "topics": [
                "Cybersecurity",
                "Video Surveillance"
            ],
            "primary_source": {
                "name": "Axis Communications — Signed video developer documentation",
                "url": "https://developer.axis.com/video-streaming-and-recording/signed-video/",
                "published": null,
                "authority": "Axis Communications"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:39+00:00"
        },
        {
            "title": "SPF, DKIM, and DMARC: a safer rollout for Microsoft 365 email",
            "url": "https://update.dsesecurity.com/updates/microsoft-365-spf-dkim-dmarc-safer-rollout/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Email authentication in Microsoft 365",
                "url": "https://learn.microsoft.com/en-us/defender-office-365/email-authentication-about",
                "published": null,
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:03:57+00:00"
        },
        {
            "title": "Stop phishing at the control plane, not only at the inbox",
            "url": "https://update.dsesecurity.com/updates/phishing-control-plane-defenses/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "IT",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "CISA and partners: Phishing Guidance — Stopping the Attack Cycle at Phase One",
                "url": "https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one",
                "published": "2023-10-18",
                "authority": "Cybersecurity and Infrastructure Security Agency"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:10+00:00"
        },
        {
            "title": "Suspected Axis device compromise: preserve evidence before cleanup",
            "url": "https://update.dsesecurity.com/updates/axis-device-compromise-evidence-cleanup-playbook/",
            "format": "playbook",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "Cybersecurity",
                "Video Surveillance"
            ],
            "primary_source": {
                "name": "Axis Communications — AXIS OS Forensics Guide",
                "url": "https://help.axis.com/en-US/axis-os-forensics-guide",
                "published": null,
                "authority": "Axis Communications"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:39+00:00"
        },
        {
            "title": "Treat enterprise patching as preventive maintenance, not an emergency ritual",
            "url": "https://update.dsesecurity.com/updates/enterprise-patch-management-preventive-maintenance/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "IT",
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management Planning",
                "url": "https://csrc.nist.gov/pubs/sp/800/40/r4/final",
                "published": "2022-04-06",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:26:27+00:00"
        },
        {
            "title": "Treat physical access control as OT: segment it, constrain remote access, preserve availability",
            "url": "https://update.dsesecurity.com/updates/physical-access-control-ot-segmentation-remote-access/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Access Control",
                "Business Continuity",
                "Cybersecurity",
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "NIST SP 800-82 Rev. 3 — Guide to Operational Technology Security",
                "url": "https://csrc.nist.gov/pubs/sp/800/82/r3/final",
                "published": "2023-09-28",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:29:04+00:00"
        },
        {
            "title": "Turn a business impact analysis into an information-system contingency plan",
            "url": "https://update.dsesecurity.com/updates/information-system-contingency-planning-bia/",
            "format": "guide",
            "priority": "info",
            "topics": [
                "Business Continuity",
                "IT"
            ],
            "primary_source": {
                "name": "NIST SP 800-34 Rev. 1: Contingency Planning Guide for Federal Information Systems",
                "url": "https://csrc.nist.gov/pubs/sp/800/34/r1/upd1/final",
                "published": "2010-11-11",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:26:27+00:00"
        },
        {
            "title": "Turn Microsoft 365 Service health and Message center into an owned operations process",
            "url": "https://update.dsesecurity.com/updates/microsoft-365-service-health-message-center-operations/",
            "format": "playbook",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "IT",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: How to check Microsoft 365 service health",
                "url": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/view-service-health?view=o365-worldwide",
                "published": "2026-02-09",
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:15+00:00"
        },
        {
            "title": "Turn the AXIS OS Hardening Guide into an operating baseline",
            "url": "https://update.dsesecurity.com/updates/axis-os-hardening-operating-baseline/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "Networks & Infrastructure",
                "Video Surveillance"
            ],
            "primary_source": {
                "name": "Axis Communications — AXIS OS Hardening Guide",
                "url": "https://help.axis.com/en-US/axis-os-hardening-guide",
                "published": null,
                "authority": "Axis Communications"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:04:47+00:00"
        },
        {
            "title": "Turn the Genetec Security Center 5.14 Hardening Guide into a measured baseline",
            "url": "https://update.dsesecurity.com/updates/genetec-security-center-514-hardening-baseline/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Access Control",
                "Cybersecurity",
                "Video Surveillance"
            ],
            "primary_source": {
                "name": "Genetec — Security Center Hardening Guide 5.14",
                "url": "https://techdocs.genetec.com/r/en-US/Security-Center-Hardening-Guide-5.14/Introduction-to-the-Security-Center-Hardening-Guide",
                "published": "2026-03-19",
                "authority": "Genetec"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:29:04+00:00"
        },
        {
            "title": "UPS readiness means more than seeing a green status light",
            "url": "https://update.dsesecurity.com/updates/ups-readiness-business-continuity/",
            "format": "checklist",
            "priority": "advisory",
            "topics": [
                "Access Control",
                "Business Continuity",
                "Networks & Infrastructure",
                "Video Surveillance"
            ],
            "primary_source": {
                "name": "Eaton — Considerations for UPS installation",
                "url": "https://www.eaton.com/us/en-us/products/backup-power-ups-surge-it-power-distribution/backup-power-ups/consideration-for-ups-installation.html",
                "published": null,
                "authority": "Eaton"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:29:33+00:00"
        },
        {
            "title": "Use Entra access reviews to remove access that no longer has an owner",
            "url": "https://update.dsesecurity.com/updates/microsoft-entra-access-reviews-recurring-governance/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: What are access reviews?",
                "url": "https://learn.microsoft.com/en-us/entra/id-governance/access-reviews-overview",
                "published": "2026-03-12",
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:27:53+00:00"
        },
        {
            "title": "Use Exchange Online message trace as evidence, not guesswork",
            "url": "https://update.dsesecurity.com/updates/exchange-online-message-trace-evidence/",
            "format": "checklist",
            "priority": "info",
            "topics": [
                "IT",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Message trace in the Exchange admin center in Exchange Online",
                "url": "https://learn.microsoft.com/en-us/exchange/monitoring/trace-an-email-message/message-trace-modern-eac",
                "published": "2026-05-27",
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:15+00:00"
        },
        {
            "title": "Use Microsoft Secure Score as a work queue, not a breach guarantee",
            "url": "https://update.dsesecurity.com/updates/microsoft-secure-score-risk-informed-work-queue/",
            "format": "explainer",
            "priority": "info",
            "topics": [
                "Cybersecurity",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Microsoft Secure Score",
                "url": "https://learn.microsoft.com/en-us/defender-xdr/microsoft-secure-score",
                "published": "2026-03-07",
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:15+00:00"
        },
        {
            "title": "Use ONVIF profiles as a requirements map, not a shortcut",
            "url": "https://update.dsesecurity.com/updates/onvif-profiles-requirements-map/",
            "format": "explainer",
            "priority": "info",
            "topics": [
                "Access Control",
                "Networks & Infrastructure",
                "Video Surveillance"
            ],
            "primary_source": {
                "name": "ONVIF — ONVIF Profiles",
                "url": "https://www.onvif.org/profiles/",
                "published": null,
                "authority": "ONVIF"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:04:47+00:00"
        },
        {
            "title": "Use SharePoint Restricted Access Control as a second access boundary",
            "url": "https://update.dsesecurity.com/updates/sharepoint-restricted-access-control-second-boundary/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "Microsoft 365 & Identity"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Restrict SharePoint site access with Microsoft 365 groups and Microsoft Entra security groups",
                "url": "https://learn.microsoft.com/en-us/sharepoint/restricted-access-control",
                "published": "2026-07-15",
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:28:15+00:00"
        },
        {
            "title": "Welcome to DSE Updates: security guidance without the noise",
            "url": "https://update.dsesecurity.com/updates/welcome-to-dse-updates/",
            "format": "explainer",
            "priority": "info",
            "topics": [
                "DSE World"
            ],
            "primary_source": {
                "name": "DSE Updates editorial methodology",
                "url": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "published": null,
                "authority": "DSE Security editorial guidance"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:29:33+00:00"
        },
        {
            "title": "Why CISA Known Exploited Vulnerabilities should change patch priority",
            "url": "https://update.dsesecurity.com/updates/cisa-known-exploited-vulnerabilities-patch-priority/",
            "format": "explainer",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "IT"
            ],
            "primary_source": {
                "name": "CISA Known Exploited Vulnerabilities Catalog",
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "published": null,
                "authority": "Cybersecurity and Infrastructure Security Agency"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:29:33+00:00"
        },
        {
            "title": "Wi-Fi security is a lifecycle, not a one-time setup",
            "url": "https://update.dsesecurity.com/updates/wifi-security-lifecycle/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "NIST SP 800-153 — Guidelines for Securing Wireless Local Area Networks (WLANs)",
                "url": "https://csrc.nist.gov/pubs/sp/800/153/final",
                "published": "2012-02-21",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:04:22+00:00"
        },
        {
            "title": "Windows deployment rings: move updates from pilot to broad release with evidence",
            "url": "https://update.dsesecurity.com/updates/windows-update-deployment-rings-evidence-based-rollout/",
            "format": "playbook",
            "priority": "advisory",
            "topics": [
                "Business Continuity",
                "IT"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Create a deployment plan",
                "url": "https://learn.microsoft.com/en-us/windows/deployment/update/create-deployment-plan",
                "published": null,
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:03:57+00:00"
        },
        {
            "title": "Windows security baselines: test Microsoft recommendations before broad enforcement",
            "url": "https://update.dsesecurity.com/updates/windows-security-baselines-test-before-enforcement/",
            "format": "guide",
            "priority": "advisory",
            "topics": [
                "Cybersecurity",
                "IT"
            ],
            "primary_source": {
                "name": "Microsoft Learn: Microsoft Security Compliance Toolkit",
                "url": "https://learn.microsoft.com/en-us/windows/security/operating-system-security/device-management/windows-security-configuration-framework/security-compliance-toolkit-10",
                "published": null,
                "authority": "Microsoft Learn"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T19:03:57+00:00"
        },
        {
            "title": "Zero trust in plain English: protect resources, not network locations",
            "url": "https://update.dsesecurity.com/updates/zero-trust-protect-resources-not-locations/",
            "format": "explainer",
            "priority": "info",
            "topics": [
                "Cybersecurity",
                "IT",
                "Networks & Infrastructure"
            ],
            "primary_source": {
                "name": "NIST SP 800-207: Zero Trust Architecture",
                "url": "https://csrc.nist.gov/pubs/sp/800/207/final",
                "published": "2020-08-11",
                "authority": "National Institute of Standards and Technology"
            },
            "dse_reviewed": "2026-07-19",
            "dse_modified": "2026-07-19T21:26:27+00:00"
        }
    ]
}