cursor index & docs
Dublin Core
Title
Creator
Date Created
Date
Rights
CC BY-NC 4.0 - 非営利目的のみ許可
Tool Item Type Metadata
Feedback
01 Cursor / Agent / MCP / PromptOps
[01] 12 Factor Agents - HumanLayer
https://www.humanlayer.dev/12-factor-agents
[01] [Cursor] @Docs
https://cursor.com/docs/agent/prompting
[01] [Cursor] Agent / Modes
https://cursor.com/docs/agent/overview
[01] [Cursor] MCP
https://cursor.com/docs/mcp
[01] [Cursor] Rules
https://cursor.com/docs/rules
[01] [Cursor] Tools
https://cursor.com/docs/agent/overview#tools
[01] [MCP] Resources
https://modelcontextprotocol.io/specification/2025-11-25/server/resources
[01] [MCP] Roots
https://modelcontextprotocol.io/specification/2025-11-25/client/roots
[01] [MCP] Tools
https://modelcontextprotocol.io/specification/2025-11-25/server/tools
[01] [PromptOps] Anthropic Prompt Engineering Overview
https://docs.anthropic.com/en/docs/build-with-claude/prompt-engineering/overview
[01] [PromptOps] OpenAI Prompt Engineering Best Practices
https://help.openai.com/en/articles/10032626-prompt-engineering-best-practices-for-chatgpt
[01] Effective Agents - Anthropic
https://www.anthropic.com/research/building-effective-agents
[01] Subagents - Claude Docs
https://docs.claude.com/en/docs/claude-code/subagents
02 Requirements / API / Documentation
[02] [Git] Conventional Commits
https://www.conventionalcommits.org/
[02] Agile Delivery - GOV.UK Core Principles
https://www.gov.uk/service-manual/agile-delivery/core-principles-agile
[02] API Design Guide - Google
https://cloud.google.com/apis/design
[02] AsyncAPI Specification
https://www.asyncapi.com/docs/reference/specification/v3.0.0
[02] Documentation Framework - Diátaxis
https://diataxis.fr/
[02] Google Developer Documentation Style Guide
https://developers.google.com/style/
[02] ISO/IEC/IEEE 29148 Requirements Engineering
https://www.iso.org/standard/72089.html
[02] JSON Schema Validation
https://json-schema.org/draft/2020-12/json-schema-validation
[02] OpenAPI Learn
https://learn.openapis.org/introduction.html
[02] Plain Language - CDC
https://www.cdc.gov/health-literacy/php/develop-materials/plain-language.html
[02] Requirement Keywords - RFC 2119
https://www.rfc-editor.org/rfc/rfc2119
[02] Requirement Keywords - RFC 8174
https://www.rfc-editor.org/rfc/rfc8174.html
[02] REST API Guidelines - Microsoft
https://github.com/microsoft/api-guidelines
[02] Semantic Versioning
https://semver.org/
[02] Web API Design - Heroku
https://github.com/interagent/http-api-design
03 Software Architecture / Code Quality
[03] AHA Programming Principle
https://kentcdodds.com/blog/aha-programming
[03] Architecture Decision Records - MIT
https://mitlibraries.github.io/guides/misc/adr.html
[03] Architecture Diagrams - C4 Model
https://c4model.com/
[03] Architecture Principles - Microsoft
https://learn.microsoft.com/en-us/dotnet/architecture/modern-web-apps-azure/architectural-principles
[03] Brooks's Law
https://en.wikipedia.org/wiki/Brooks%27s_law
[03] Code Smells - Refactoring.Guru
https://refactoring.guru/refactoring/smells
[03] Composition over Inheritance - Wikipedia
https://en.wikipedia.org/wiki/Composition_over_inheritance
[03] Conway's Law - Mel Conway
https://www.melconway.com/Home/Conways_Law.html
[03] Dependency Injection - Martin Fowler
https://martinfowler.com/articles/injection.html
[03] Domain-Driven Design Reference - Eric Evans
https://www.domainlanguage.com/ddd/reference/
[03] DRY Principle - DevIQ
https://deviq.com/principles/dont-repeat-yourself
[03] Gall's Law
https://en.wikipedia.org/wiki/John_Gall_%28author%29#Gall's_law
[03] Google Engineering Practices - Code Review
https://google.github.io/eng-practices/review/
[03] Google Style Guides
https://google.github.io/styleguide/
[03] High Cohesion and Low Coupling - Wikipedia
https://en.wikipedia.org/wiki/Coupling_(computer_programming)
[03] Hyrum's Law
https://www.hyrumslaw.com/
[03] Inversion of Control - Martin Fowler
https://martinfowler.com/bliki/InversionOfControl.html
[03] KISS Principle - DevIQ
https://deviq.com/principles/keep-it-simple-stupid
[03] Law of Demeter - DevIQ
https://deviq.com/principles/law-of-demeter
[03] Lehman's Laws of Software Evolution
https://en.wikipedia.org/wiki/Lehman%27s_laws_of_software_evolution
[03] Make It Work, Make It Right, Make It Fast
https://wiki.c2.com/?MakeItWorkMakeItRightMakeItFast
[03] Out of the Tar Pit
http://curtclifton.net/papers/MoseleyMarks06a.pdf
[03] Premature Optimization - Knuth Quote Context
https://wiki.c2.com/?PrematureOptimization
[03] Programming Principles - webpro
https://github.com/webpro/programming-principles
[03] Robustness Principle - Wikipedia
https://en.wikipedia.org/wiki/Robustness_principle
[03] Separation of Concerns - Wikipedia
https://en.wikipedia.org/wiki/Separation_of_concerns
[03] Seven Principles of Software Development - C2 Wiki
https://c2.com/cgi/wiki?SevenPrinciplesOfSoftwareDevelopment=
[03] Software Design Principles - Principles Wiki
https://www.principles-wiki.net/
[03] Software Engineering Principles - Principles.dev
https://principles.dev/
[03] SOLID Principles (Overview) - Microsoft
https://learn.microsoft.com/en-us/dotnet/architecture/microservices/microservice-ddd-cqrs-patterns/architectural-principles
[03] The Boy Scout Rule - DevIQ
https://deviq.com/principles/boy-scout-rule
[03] The Law of Leaky Abstractions - Joel Spolsky
https://www.joelonsoftware.com/2002/11/11/the-law-of-leaky-abstractions/
[03] Twelve-Factor App
https://12factor.net/
[03] Unix Philosophy - Wikipedia
https://en.wikipedia.org/wiki/Unix_philosophy
[03] Worse is Better - MIT
https://www.dreamsongs.com/WorseIsBetter.html
[03] YAGNI - Martin Fowler
https://martinfowler.com/bliki/Yagni.html
04 Testing / Verification / Formal Methods
[04] [Testing] Hypothesis Property-Based Testing
https://hypothesis.readthedocs.io/
[04] [Testing] Stryker Mutation Testing
https://stryker-mutator.io/docs/
[04] Abstract Interpretation
https://doi.org/10.1145/512950.512973
[04] Alloy Analyzer
https://alloytools.org/
[04] Behavior-Driven Development - Cucumber
https://cucumber.io/docs/bdd/
[04] Definition of Done - Scrum.org
https://www.scrum.org/resources/definition-done
[04] Design by Contract
https://se.ethz.ch/~meyer/publications/computer/contract.pdf
[04] Differential Testing
https://doi.org/10.1145/24039.24048
[04] Hoare Logic
https://doi.org/10.1145/363235.363259
[04] Metamorphic Testing
https://doi.org/10.1109/SESS.2009.5069055
[04] Model Checking - Clarke, Emerson, Sifakis
https://doi.org/10.1145/1592434.1592436
[04] Models & Simulations - NASA STD 7009
https://standards.nasa.gov/standard/NASA/NASA-STD-7009
[04] OWASP Web Security Testing Guide
https://owasp.org/www-project-web-security-testing-guide
[04] Specifying Concurrent Systems with TLA+
https://lamport.org/pubs/lamport-spec-tla-plus.pdf
[04] Test-Driven Development - Agile Alliance
https://agilealliance.org/glossary/tdd/
[04] Testing Strategy - Practical Test Pyramid
https://martinfowler.com/articles/practical-test-pyramid.html
05 Security / Privacy / Supply Chain
[05] [Supply Chain] CycloneDX SBOM
https://cyclonedx.org/capabilities/
[05] [Supply Chain] OpenSSF Scorecard
https://openssf.org/projects/scorecard/
[05] Application Security - OWASP Cheat Sheets
https://owasp.org/www-project-cheat-sheets/
[05] C-SCRM - NIST SP 800-161
https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final
[05] CIS Controls
https://www.cisecurity.org/controls
[05] Defense in Depth
https://en.wikipedia.org/wiki/Defense_in_depth_(computing)
[05] LLM Security - OWASP Top 10 for LLM Apps
https://owasp.org/www-project-top-10-for-large-language-model-applications
[05] MITRE ATT&CK
https://attack.mitre.org/
[05] NIST Secure Software Development Framework
https://csrc.nist.gov/pubs/sp/800/218/final
[05] OWASP ASVS
https://owasp.org/www-project-application-security-verification-standard/
[05] Privacy by Design
https://www.ipc.on.ca/en/resources-and-decisions/privacy-by-design
[05] Privacy Framework - NIST
https://www.nist.gov/privacy-framework
[05] Secure by Design - CISA
https://www.cisa.gov/resources-tools/resources/secure-by-design
[05] Security Principles of Saltzer and Schroeder
https://shostack.org/blog/the-security-principles-of-saltzer-and-schroeder
[05] SLSA - Supply-chain Levels for Software Artifacts
https://slsa.dev/
[05] STRIDE Threat Modeling
https://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-threats
[05] Threat Modeling - OWASP
https://owasp.org/www-project-threat-modeling/
[05] Zero Trust Architecture - NIST SP 800-207
https://csrc.nist.gov/pubs/sp/800/207/final
[05] NIST Cybersecurity Framework 2.0
https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20
[05] NIST SP 800-61r3 - Incident Response Recommendations
https://csrc.nist.gov/pubs/sp/800/61/r3/final
[05] CISA Known Exploited Vulnerabilities Catalog
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
[05] OWASP SAMM - Software Assurance Maturity Model
https://owasp.org/www-project-samm/
[05] CVSS v4.0 Specification - FIRST
https://www.first.org/cvss/v4-0/specification-document
https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20
[05] NIST SP 800-61r3 - Incident Response Recommendations
https://csrc.nist.gov/pubs/sp/800/61/r3/final
[05] CISA Known Exploited Vulnerabilities Catalog
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
[05] OWASP SAMM - Software Assurance Maturity Model
https://owasp.org/www-project-samm/
[05] CVSS v4.0 Specification - FIRST
https://www.first.org/cvss/v4-0/specification-document
06 SRE / Operations / Performance
[06] [DevOps] DORA Continuous Delivery
https://dora.dev/capabilities/continuous-delivery/
[06] Amdahl's Law - HPC Wiki
https://hpc-wiki.info/hpc/Amdahl%27s_Law
[06] AWS Caching Patterns
https://docs.aws.amazon.com/whitepapers/latest/database-caching-strategies-using-redis/caching-patterns.html
[06] Azure Cloud Design Patterns
https://learn.microsoft.com/azure/architecture/patterns
[06] Backpressure - Reactive Manifesto
https://www.reactivemanifesto.org/glossary#Back-Pressure
[06] Cache-Aside Pattern - Azure
https://learn.microsoft.com/en-us/azure/architecture/patterns/cache-aside
[06] CAP Theorem - Gilbert & Lynch
https://doi.org/10.1109/MC.2011.389
[06] Chaos Engineering Principles
https://principlesofchaos.org/
[06] Circuit Breaker - Martin Fowler
https://martinfowler.com/bliki/CircuitBreaker
[06] Cloud Bulkhead Pattern - Azure
https://learn.microsoft.com/en-us/azure/architecture/patterns/bulkhead
[06] CUDA Memory Hierarchy - NVIDIA
https://docs.nvidia.com/cuda/cuda-c-programming-guide/index.html
[06] FinOps Framework
https://www.finops.org/framework/
[06] FLP Impossibility
https://doi.org/10.1145/3149.214121
[06] Intel 64 and IA-32 Optimization Reference Manual
https://www.intel.com/content/www/us/en/developer/articles/technical/intel64-and-ia32-architectures-optimization.html
[06] Kubernetes Resource Management
https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
[06] Log Management - NIST SP 800-92
https://csrc.nist.gov/pubs/sp/800/92/final
[06] Logging Cheat Sheet - OWASP
https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html
[06] Monitoring Distributed Systems - Google SRE Golden Signals
https://sre.google/sre-book/monitoring-distributed-systems/
[06] OpenTelemetry Documentation
https://opentelemetry.io/docs/
[06] OpenTelemetry Observability Primer
https://opentelemetry.io/docs/concepts/observability-primer/
[06] Performance Efficiency - AWS Well-Architected
https://docs.aws.amazon.com/wellarchitected/latest/framework/a-performance-efficiency.html
[06] Performance Efficiency - Azure Well-Architected
https://learn.microsoft.com/en-gb/azure/architecture/performance/
[06] Postmortem Culture - Google SRE
https://sre.google/sre-book/postmortem-culture/
[06] Raft Consensus
https://raft.github.io/raft.pdf
[06] Service Reliability - Google SRE SLO
https://sre.google/sre-book/service-level-objectives/
[06] Universal Scalability Law - Performance Dynamics
https://www.perfdynamics.com/Manifesto/USLscalability.html
[06] USE Method - Brendan Gregg
https://www.brendangregg.com/usemethod.html
07 UX / Accessibility / SEO / Human Factors
[07] [Accessibility] WCAG 2 Overview
https://www.w3.org/WAI/standards-guidelines/wcag/
[07] [Accessibility] WCAG 2.2
https://www.w3.org/TR/wcag/
[07] Accessibility Checklist - A11Y Project
https://www.a11yproject.com/checklist/
[07] Core Web Vitals - Google
https://web.dev/articles/vitals
[07] Design - Humane by Design
https://humanebydesign.com/principles
[07] Design Principles - Principles.design
https://principles.design/
[07] Double Diamond - Design Council
https://www.designcouncil.org.uk/our-resources/the-double-diamond/
[07] Google SEO Starter Guide
https://developers.google.com/search/docs/fundamentals/seo-starter-guide
[07] Google Search Essentials
https://developers.google.com/search/docs/essentials
[07] Helpful, Reliable, People-First Content
https://developers.google.com/search/docs/fundamentals/creating-helpful-content
[07] Heuristics - Nielsen Norman Group
https://www.nngroup.com/articles/ten-usability-heuristics/
[07] Human Factors Design Standard - FAA
https://hf.tc.faa.gov/hfds/
[07] Human Integration Design Handbook - NASA
https://www.nasa.gov/human-integration-design-handbook/
[07] Human-Centered AI - NIST
https://www.nist.gov/programs-projects/human-centered-ai
[07] Human-Centered Design - NIST
https://www.nist.gov/itl/iad/visualization-and-usability-group/human-factors-human-centered-design
[07] ISO 9241-110 Interaction Principles
https://www.iso.org/standard/75258.html
[07] Jobs To Be Done
https://hbr.org/2016/09/know-your-customers-jobs-to-be-done
[07] MDN HTTP
https://developer.mozilla.org/en-US/docs/Web/HTTP
[07] NASA Human Systems Integration Handbook
https://ntrs.nasa.gov/citations/20210010952
[07] Progressive Enhancement - MDN
https://developer.mozilla.org/en-US/docs/Glossary/Progressive_Enhancement
[07] Resilient Web Design
https://resilientwebdesign.com/
[07] Structured Data Introduction
https://developers.google.com/search/docs/appearance/structured-data/intro-structured-data
[07] UX Principles - Laws of UX
https://lawsofux.com/
[07] [Accessibility] WCAG 3.0 - Draft / Tracking Only
https://www.w3.org/TR/wcag-3.0/
[07] [Accessibility] Requirements for WCAG 3.0 - Draft / Tracking Only
https://www.w3.org/TR/wcag-3.0-requirements/
https://www.w3.org/TR/wcag-3.0/
[07] [Accessibility] Requirements for WCAG 3.0 - Draft / Tracking Only
https://www.w3.org/TR/wcag-3.0-requirements/
08 Research / Statistics / Measurement
[08] Bayesian Epistemology - Stanford Encyclopedia
https://plato.stanford.edu/entries/epistemology-bayesian/
[08] Bayes’ Theorem - Stanford Encyclopedia
https://seop.illc.uva.nl/entries/bayes-theorem/
[08] Belmont Report - HHS
https://www.hhs.gov/ohrp/regulations-and-policy/belmont-report/index.html
[08] Causality - Brave and True
https://matheusfacure.github.io/python-causality-handbook/landing-page.html
[08] Construct Validity - Cronbach & Meehl
https://doi.org/10.1037/h0056932
[08] Data Visualization - Purdue OWL
https://owl.purdue.edu/owl/general_writing/visual_rhetoric/data_visualization/index.html
[08] FAIR Data Principles - Nature Scientific Data
https://www.nature.com/articles/sdata201618
[08] IMRaD Report Writing - GMU
https://writingcenter.gmu.edu/writing-resources/imrad/writing-an-imrad-report
[08] Inter-Rater Reliability - Cohen's Kappa
https://doi.org/10.1177/001316446002000104
[08] Item Response Theory - Rasch Model
https://www.rasch.org/rmt/rmt91n.htm
[08] NIST Measurement Uncertainty
https://www.nist.gov/statistical-engineering-division/measurement-uncertainty
[08] Preregistration - OSF
https://help.osf.io/article/410-registration-files
[08] Reference Class Forecasting - Flyvbjerg
https://doi.org/10.1080/09654310701747936
[08] Research Reproducibility - The Turing Way
https://book.the-turing-way.org/reproducible-research/reproducible-research/
[08] Responsible Research - National Academies
https://nap.nationalacademies.org/catalog/12192/on-being-a-scientist-a-guide-to-responsible-conduct-in
[08] Science Method - Berkeley
https://undsci.berkeley.edu/understanding-science-101/how-science-works/
[08] Sequential Analysis - Wald
https://doi.org/10.1214/aoms/1177731118
[08] SI Dimensions and Quantities - NIST SP 811 Chapter 7
https://www.nist.gov/pml/special-publication-811/nist-guide-si-chapter-7-rules-and-style-conventions-expressing-values
[08] SI Units - NIST
https://www.nist.gov/pml/weights-and-measures/metric-si/si-units
[08] Source Evaluation - SIFT Method
https://libguides.ucmerced.edu/news/evaluation/sift-method
[08] Statistical Power Analysis - Cohen
https://doi.org/10.1037/0033-2909.112.1.155
[08] Statistics & Measurement - NIST
https://www.itl.nist.gov/div898/handbook/
[08] Synthesis - Purdue OWL
https://owl.purdue.edu/owl/research_and_citation/conducting_research/research_overview/synthesizing_sources.html
[08] Validity Framework - Messick
https://doi.org/10.3102/0013189X018002005
09 AI Risk / Evaluation / Data
[09] Adversarial Examples
https://arxiv.org/abs/1412.6572
[09] AI Risk Management - NIST AI RMF
https://www.nist.gov/itl/ai-risk-management-framework
[09] AI RMF Playbook - NIST
https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook
[09] Calibration of Modern Neural Networks
https://arxiv.org/abs/1706.04599
[09] Concrete Problems in AI Safety - Amodei et al.
https://arxiv.org/abs/1606.06565
[09] Data Leakage in Machine Learning
https://doi.org/10.1145/3531146.3533235
[09] Dataset Cards
https://doi.org/10.1145/3491102.3501951
[09] Datasheets for Datasets
https://doi.org/10.1145/3458723
[09] Distribution Shift - WILDS Benchmark
https://arxiv.org/abs/2012.07421
[09] Generative AI Risk - NIST AI 600-1
https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence
[09] Model Cards - Hugging Face
https://huggingface.co/docs/hub/model-card-annotated
[09] Red Teaming Language Models
https://arxiv.org/abs/2202.03286
[09] Reward Hacking in Reinforcement Learning
https://arxiv.org/abs/2206.01862
[09] Specification Gaming - DeepMind
https://deepmind.google/discover/blog/specification-gaming-the-flip-side-of-ai-ingenuity/
10 Systems / Decision / Risk
[10] Abduction - Stanford Encyclopedia
https://plato.stanford.edu/entries/abduction/
[10] After Action Review - NWCG
https://www.nwcg.gov/wfldp/toolbox/aars
[10] Analysis of Competing Hypotheses - CIA / CSI
https://www.cia.gov/resources/csi/books-monographs/psychology-of-intelligence-analysis-2/
[10] Applied Critical Thinking / Red Team Handbook
https://rdl.train.army.mil/catalog-ws/view/arimcpii/downloads/Red_Team_Handbook_v9.pdf
[10] Argument Mapping - Monash
https://www.monash.edu/student-academic-success/enhance-your-thinking/critical-thinking/create-argument/structure-your-argument
[10] Black Swan Theory
https://en.wikipedia.org/wiki/Black_swan_theory
[10] Bowtie Method - Barrier Based Risk Management
https://www.wolterskluwer.com/en/solutions/enablon/bowtie/expert-insights/barrier-based-risk-management-knowledge-base/the-bowtie-method
[10] Campbell's Law
https://en.wikipedia.org/wiki/Campbell%27s_law
[10] Chesterton's Fence
https://fs.blog/chestertons-fence/
[10] Cognitive Biases - The Decision Lab
https://thedecisionlab.com/biases
[10] College of Policing Analytical Techniques
https://www.college.police.uk/app/intelligence-management/analysis/analytical-techniques
[10] Cobra Effect
https://en.wikipedia.org/wiki/Cobra_effect
[10] Critical Thinking - Monash
https://www.monash.edu/student-academic-success/enhance-your-thinking/critical-thinking/evaluate-arguments-of-others
[10] Cynefin Framework
https://cynefin.io/index.php/Cynefin
[10] Decision Analysis - NASA
https://www.nasa.gov/reference/6-8-decision-analysis/
[10] Decision Quality Framework - Illinois Tech
https://www.iit.edu/decision-quality-center/decision-quality-framework
[10] Failure Mode and Effects Analysis - ASQ
https://asq.org/learn-about-quality/process-analysis-tools/overview/fmea.html
[10] Goodhart's Law
https://en.wikipedia.org/wiki/Goodhart%27s_law
[10] Kanban Guide - Kanban University
https://kanban.university/kanban-guide/
[10] Little’s Law for Professional Scrum with Kanban
https://www.scrum.org/resources/littles-law-professional-scrum-kanban
[10] McNamara Fallacy
https://en.wikipedia.org/wiki/McNamara_fallacy
[10] Normal Accidents - Yale University Press
https://yalebooks.yale.edu/book/9780691004129/normal-accidents/
[10] One-way and Two-way Door Decisions - Amazon
https://www.aboutamazon.com/news/company-news/2015-letter-to-shareholders
[10] OODA Loop - Air University
https://www.airuniversity.af.edu/News/Display/Article/420819/ooda-loop-makes-its-mark-on-maxwell/
[10] PDCA Cycle - ASQ
https://asq.org/quality-resources/pdca-cycle
[10] Planning Fallacy
https://en.wikipedia.org/wiki/Planning_fallacy
[10] Poka-yoke
https://en.wikipedia.org/wiki/Poka-yoke
[10] Premortem - Atlassian
https://www.atlassian.com/team-playbook/plays/pre-mortem
[10] Real Options - Martin Fowler
https://martinfowler.com/bliki/RealOptions.html
[10] Resilience Engineering Association
https://www.resilience-engineering-association.org/about-rea
[10] Risk Assessment - NIST SP 800-30
https://csrc.nist.gov/pubs/sp/800/30/r1/final
[10] SEIPS Model - Work System Design
https://pmc.ncbi.nlm.nih.gov/articles/PMC2464868/
[10] Second-Order Effects
https://fs.blog/second-order-thinking/
[10] Systems Engineering - NASA
https://www.nasa.gov/reference/systems-engineering-handbook/
[10] Systems Thinking - Donella Meadows
https://donellameadows.org/archives/leverage-points-places-to-intervene-in-a-system/
[10] System-Theoretic Process Analysis - STPA Handbook
https://psas.scripts.mit.edu/home/books-and-handbooks/
[10] Theory of Constraints - Five Focusing Steps
https://www.tocinstitute.org/five-focusing-steps.html
[10] Toulmin Argument - Purdue OWL
https://owl.purdue.edu/owl/general_writing/academic_writing/historical_perspectives_on_argumentation/toulmin_argument
[10] Unknown Unknowns
https://en.wikipedia.org/wiki/There_are_unknown_unknowns
[10] Wardley Mapping 101
https://www.wardleymaps.com/guides/wardley-mapping-101
11 Data / Knowledge / DB
[11] Data Management - DAMA-DMBOK
https://dama.org/learning-resources/dama-data-management-body-of-knowledge-dmbok/
[11] Data on the Web Best Practices - W3C
https://www.w3.org/news/2017/data-on-the-web-best-practices-are-now-a-w3c-recommendation/
[11] Database Design Basics - Microsoft
https://support.microsoft.com/en-us/office/database-design-basics-eb2159cf-1e30-401a-8084-bd4f9c9ca1f5
[11] Evolutionary Database Design - Fowler
https://martinfowler.com/articles/evodb.html
[11] PROV - W3C Provenance
https://www.w3.org/TR/prov-overview/
[11] SKOS Primer - W3C
https://www.w3.org/TR/skos-primer/
12 Community / Governance / Incentives / Licensing
[12] Adverse Selection
https://en.wikipedia.org/wiki/Adverse_selection
[12] Arrow's Impossibility Theorem
https://plato.stanford.edu/entries/arrows-theorem/
[12] Common Knowledge - Stanford Encyclopedia
https://plato.stanford.edu/entries/common-knowledge/
[12] Community Tool Box - University of Kansas
https://ctb.ku.edu/en/toolkits
[12] Creative Commons License Chooser
https://creativecommons.org/chooser/
[12] DACI - Atlassian
https://www.atlassian.com/team-playbook/plays/daci
[12] Digital Public Goods Standard
https://new.digitalpublicgoods.net/standard
[12] Event Storming
https://www.eventstorming.com/
[12] Game Theory with Engineering Applications - MIT OCW
https://ocw.mit.edu/courses/6-254-game-theory-with-engineering-applications-spring-2010/
[12] Governing the Commons - Ostrom
https://doi.org/10.1017/CBO9780511807763
[12] Harvard BATNA
https://www.pon.harvard.edu/daily/batna/translate-your-batna-to-the-current-deal/
[12] Mechanism Design Theory - Nobel Prize
https://www.nobelprize.org/prizes/economic-sciences/2007/9276-mechanism-design-theory/
[12] Moral Hazard
https://en.wikipedia.org/wiki/Moral_hazard
[12] Mozilla Community Participation Guidelines
https://www.mozilla.org/en-US/about/governance/policies/participation/
[12] OSI Approved Licenses
https://opensource.org/licenses
[12] Page-Led Meetings - Atlassian
https://www.atlassian.com/team-playbook/plays/page-led-meeting
[12] Principal-Agent Problem
https://en.wikipedia.org/wiki/Principal%E2%80%93agent_problem
[12] Reputation Systems
https://doi.org/10.1145/355112.355122
[12] Social Choice Theory - Stanford Encyclopedia
https://plato.stanford.edu/entries/social-choice/
[12] SPDX License List
https://spdx.org/licenses/
[12] Sybil Attack
https://doi.org/10.1007/3-540-45748-8_24
[12] Tragedy of the Commons
https://en.wikipedia.org/wiki/Tragedy_of_the_commons
13 Algorithms / Math / CS
[13] Bias–Variance Tradeoff
https://en.wikipedia.org/wiki/Bias%E2%80%93variance_tradeoff
[13] Exploration–Exploitation Tradeoff
https://en.wikipedia.org/wiki/Exploration%E2%80%93exploitation_dilemma
[13] Idempotence
https://en.wikipedia.org/wiki/Idempotence
[13] Mathematics for Computer Science - MIT OCW
https://ocw.mit.edu/courses/6-1200j-mathematics-for-computer-science-spring-2024/
[13] MIT Design and Analysis of Algorithms 6.046J
https://ocw.mit.edu/courses/6-046j-introduction-to-algorithms-sma-5503-fall-2005/
[13] MIT Introduction to Algorithms 6.006
https://ocw.mit.edu/courses/6-006-introduction-to-algorithms-spring-2020/
[13] MIT Introduction to Convex Optimization
https://ocw.mit.edu/courses/6-079-introduction-to-convex-optimization-fall-2009/
[13] No Free Lunch Theorem
https://en.wikipedia.org/wiki/No_free_lunch_theorem
[13] Open Logic Project
https://openlogicproject.org/
[13] What Every Computer Scientist Should Know About Floating-Point Arithmetic
https://doi.org/10.1145/103162.103163
14 Design / Innovation / Problem Solving
[14] Design Heuristics 77 Cards
https://creativity.psu.edu/project/design-heuristics-77-cards
[14] General Morphological Analysis
https://www.swemorph.com/ma.html
[14] Soft Systems Methodology - Checkland
https://link.springer.com/chapter/10.1007/978-1-84882-809-4_5
[14] TRIZ 40 Inventive Principles
https://triz.org/principles/
[14] TRIZ Contradictions - MATRIZ
https://wiki.matriz.org/knowledge-base/triz/problem-solving-tools-5890/contradictions/
[14] TRIZ Matrix
https://www.triz-consulting.de/about-triz/triz-matrix/?lang=en
15 Biology / Physics / System Analogies
[15] Adaptive Evolution - General Biology
https://pressbooks.online.ucf.edu/bsc2011c/chapter/19-3-adaptive-evolution/
[15] Conservation of Energy - Feynman Lectures
https://www.feynmanlectures.caltech.edu/I_04.html
[15] Dimensional Analysis - MIT OCW
https://ocw.mit.edu/courses/2-25-advanced-fluid-mechanics-fall-2013/pages/dimensional-analysis/
[15] Ecosystems - Khan Academy
https://www.khanacademy.org/science/biology/ecology/intro-to-an-ecosystems/a/what-is-an-ecosystem
[15] Feedback Systems - Åström & Murray
https://fbswiki.org/wiki/index.php/Main_Page
[15] Homeostasis - OpenStax Biology
https://openstax.org/books/biology-2e/pages/33-3-homeostasis
[15] Law of Requisite Variety
https://en.wikipedia.org/wiki/Variety_(cybernetics)
[15] Mechanisms of Evolution - OpenStax
https://openstax.org/books/concepts-biology/pages/11-2-mechanisms-of-evolution
[15] Newton’s Laws - Feynman Lectures
https://www.feynmanlectures.caltech.edu/I_09.html
[15] Population Genetics - OpenStax Biology 2e
https://openstax.org/books/biology-2e/pages/19-2-population-genetics
[15] Population Limits - OpenStax Biology
https://openstax.org/books/biology-2e/pages/45-3-environmental-limits-to-population-growth
[15] Speciation - OpenStax
https://openstax.org/books/concepts-biology/pages/11-4-speciation
16 Military Planning / Red Team
[16] Army Design Methodology - ATP 5-0.1
https://rdl.train.army.mil/catalog-ws/view/arimanagingcomplexproblems/downloads/Army_Design_Methodology_ATP_5-0.1_July_2015.pdf
[16] Command and Control - MCDP 6
https://www.marines.mil/portals/1/publications/mcdp%206%20command%20and%20control.pdf
[16] Joint Planning - JP 5-0
https://www.jcs.mil/Doctrine/DOCNET/JP-5-0-Joint-Planning/
[16] Military Planning Philosophy - MCDP 5 Planning
https://www.marines.mil/News/Publications/MCPEL/Electronic-Library-Display/Article/899841/mcdp-5/
[16] Troop Leading Procedures - U.S. Army
https://www.benning.army.mil/Infantry/DoctrineSupplement/ATP3-21.8/appendix_a/StepsofTroopLeadingProcedures/Introduction/index.html
[16] Warfighting Philosophy - MCDP 1
https://www.marines.mil/News/Publications/MCPEL/Electronic-Library-Display/Article/899837/mcdp-1/
17 Learning / Workplace Safety
[17] ADHD Task Breakdown - CDC
https://www.cdc.gov/adhd/treatment/index.html
[17] Effective Study Strategies - Cornell
https://lsc.cornell.edu/how-to-study/studying-for-and-taking-exams/effective-study-strategies/
[17] GSA Indoor Environmental Quality
https://www.gsa.gov/governmentwide-initiatives/federal-highperformance-buildings/highperformance-building-clearinghouse/health/indoor-environmental-quality
[17] Metacognition and Self-Regulation - EEF
https://educationendowmentfoundation.org.uk/education-evidence/evidence-reviews/metacognition-and-self-regulation
[17] NIOSH Hierarchy of Controls
https://www.cdc.gov/niosh/hierarchy-of-controls/about/index.html
[17] NIOSH Office Environments and Your Safety
https://www.cdc.gov/niosh/office-environment/about/index.html
[17] OSHA Hazard Identification
https://www.osha.gov/safety-management/hazard-identification
[17] Ready.gov Emergency Planning
https://www.ready.gov/make-a-plan
[17] Research-Based Learning Findings - MIT
https://openlearning.mit.edu/mit-faculty/research-based-learning-findings/
[17] UDL Guidelines - CAST
https://udlguidelines.cast.org/
18 Media / 3D / Blender
[18] Blender Color Management
https://docs.blender.org/manual/en/5.0/render/color_management.html
[18] Blender Mesh Structure
https://docs.blender.org/manual/en/latest/modeling/meshes/structure.html
19 Public Service / Policy
[19] Better Regulation Framework - GOV.UK
https://www.gov.uk/government/publications/better-regulation-framework
[19] Service Standard - GOV.UK
https://www.gov.uk/service-manual/service-standard
20 Laws / Concepts / Economics
[20] Automation Bias
https://en.wikipedia.org/wiki/Automation_bias
[20] Fallacies of Distributed Computing
https://en.wikipedia.org/wiki/Fallacies_of_distributed_computing
[20] Iron Triangle - Project Management
https://en.wikipedia.org/wiki/Project_management_triangle
[20] Lindy Effect
https://en.wikipedia.org/wiki/Lindy_effect
[20] Lock-in and Switching Costs
https://en.wikipedia.org/wiki/Switching_barriers
[20] Pareto Principle
https://en.wikipedia.org/wiki/Pareto_principle
[20] Path Dependence
https://en.wikipedia.org/wiki/Path_dependence
21 AI Governance / ModelOps / AI Supply Chain
[21] ISO/IEC 42001 - AI Management Systems
https://www.iso.org/standard/81230.html
[21] ISO/IEC 23894 - AI Risk Management
https://www.iso.org/standard/77304.html
[21] ISO/IEC 22989 - AI Concepts and Terminology
https://www.iso.org/standard/74296.html
[21] ISO/IEC 23053 - Framework for AI Systems Using Machine Learning
https://www.iso.org/standard/74438.html
[21] MITRE ATLAS - Adversarial Threat Landscape for AI Systems
https://atlas.mitre.org/
[21] OWASP AIBOM Project
https://owaspaibom.org/
[21] OWASP AIBOM / AI SBOM Initiative
https://genai.owasp.org/ai-sbom-initiative/
[21] OWASP CycloneDX - Bill of Materials Specification
https://owasp.org/www-project-cycloned
[21] CycloneDX Specification Repository
https://github.com/CycloneDX/specification
[22] Trustworthy Online Controlled Experiments - Kohavi, Tang, Xu
https://www.cambridge.org/core/books/trustworthy-online-controlled-experiments/trustworthy-online-controlled-experiments/524D7D0FDF6A542F732D047118618645
[22] Online Controlled Experiments and A/B Testing - Kohavi, Longbotham
https://link.springer.com/rwe/10.1007/978-1-4899-7687-1_891
[22] Controlled Experiments on the Web - Survey and Practical Guide
https://link.springer.com/article/10.1007/s10618-008-0114-1
[22] OpenFeature - Feature Flagging Specification
https://openfeature.dev/docs/reference/intro
[23] Introduction to Information Retrieval - Manning, Raghavan, Schütze
https://nlp.stanford.edu/IR-book/html/htmledition/irbook.html
[23] BEIR - Heterogeneous Benchmark for Zero-shot Information Retrieval
https://huggingface.co/papers/2104.08663
[23] BEIR GitHub Repository
https://github.com/beir-cellar/beir
[23] Retrieval-Augmented Generation for Knowledge-Intensive NLP Tasks
https://huggingface.co/papers/2005.11401
[23] RAG Original Paper - UCL NLP
https://nlp.cs.ucl.ac.uk/publications/2020-05-retrieval-augmented-generation-for-knowledge-intensive-nlp-tasks/
[24] W3C Verifiable Credentials Data Model v2.0
https://www.w3.org/TR/vc-data-model-2.0/
[24] W3C Verifiable Credential Data Integrity 1.0
https://www.w3.org/TR/vc-data-integrity/
[24] W3C Verifiable Credentials 2.0 Recommendation Announcement
https://www.w3.org/news/2025/the-verifiable-credentials-2-0-family-of-specifications-is-now-a-w3c-recommendation/
[25] NIST SP 800-63-4 - Digital Identity Guidelines
https://pages.nist.gov/800-63-4/
[25] OAuth 2.0 Security Best Current Practice - RFC 9700
https://www.rfc-editor.org/rfc/rfc9700.html
[25] OpenID Connect Core 1.0
https://openid.net/specs/openid-connect-core-1_0.html
[25] Web Authentication Level 3 - W3C Candidate Recommendation / Tracking Only
https://www.w3.org/TR/webauthn-3/
[25] OWASP Authentication Cheat Sheet
https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html
[25] OWASP Authorization Cheat Sheet
https://cheatsheetseries.owasp.org/cheatsheets/Authorization_Cheat_Sheet.html
ここから
[26] Trust & Safety Professional Association - Content Moderation and Operations
https://www.tspa.org/curriculum/ts-fundamentals/content-moderation-and-operations/what-is-content-moderation/
[26] Santa Clara Principles - Transparency and Accountability in Content Moderation
https://santaclaraprinciples.org/
[26] EU Digital Services Act - Platform Accountability / Reference Only
https://digital-strategy.ec.europa.eu/en/policies/digital-services-act-package
[26] NIST Privacy Framework
https://www.nist.gov/privacy-framework
[27] NIST SP 800-57 Part 1 Rev. 5 - Recommendation for Key Management
https://csrc.nist.gov/pubs/sp/800/57/pt1/r5/final
[27] NIST Key Management Guidelines
https://csrc.nist.gov/Projects/Key-Management/Key-Management-Guidelines
[27] OWASP Secrets Management Cheat Sheet
https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
[28] Progressive Web Apps - web.dev
https://web.dev/learn/pwa/progressive-web-apps
[28] Web Application Manifest - W3C Working Draft / Tracking Only
https://www.w3.org/TR/appmanifest/
[28] Service Worker API - MDN
https://developer.mozilla.org/en-US/docs/Web/API/ServiceWorker
[28] IndexedDB API - MDN
https://developer.mozilla.org/en-US/docs/Web/API/IndexedDB_API
[28] Using IndexedDB - MDN
https://developer.mozilla.org/en-US/docs/Web/API/IndexedDB_API/Using_IndexedDB
[29] NIST SP 800-34 Rev. 1 - Contingency Planning Guide for Federal Information Systems
https://csrc.nist.gov/pubs/sp/800/34/r1/final
[29] ISO 22301:2019 - Business Continuity Management Systems
https://www.iso.org/standard/75106.html
[30] OWASP Automated Threats to Web Applications
https://owasp.org/www-project-automated-threats-to-web-applications/
[30] OWASP API Security Top 10 2023
https://owasp.org/API-Security/editions/2023/en/0x00-header/
[30] OWASP API Security Risks 2023
https://owasp.org/API-Security/editions/2023/en/0x10-api-security-risks/
[30] HTTP 429 Too Many Requests - MDN
https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/429
[31] PCI DSS - PCI Security Standards Council
https://www.pcisecuritystandards.org/standards/pci-dss/
[31] PCI SSC Document Library
https://www.pcisecuritystandards.org/document_library
[31] PCI DSS v4.0.1 Publication Notice - PCI SSC
https://blog.pcisecuritystandards.org/just-published-pci-dss-v4-0-1
[31] Payment Request API - W3C Candidate Recommendation / Tracking Only
https://www.w3.org/TR/payment-request/
[32] OWASP File Upload Cheat Sheet
https://cheatsheetseries.owasp.org/cheatsheets/File_Upload_Cheat_Sheet.html
[32] OWASP Unrestricted File Upload
https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload
[32] OWASP Input Validation Cheat Sheet
https://cheatsheetseries.owasp.org/cheatsheets/Input_Validation_Cheat_Sheet.html
[32] W3C File API - Working Draft / Tracking Only
https://www.w3.org/TR/FileAPI/
[32] MDN File API
https://developer.mozilla.org/en-US/docs/Web/API/File_API
[33] NIST SP 800-88 Rev. 2 - Guidelines for Media Sanitization
https://csrc.nist.gov/pubs/sp/800/88/r2/final
[33] NIST SP 800-92 - Guide to Computer Security Log Management
https://csrc.nist.gov/pubs/sp/800/92/final
[33] OWASP Logging Cheat Sheet
https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html
[33] W3C PROV - Provenance Overview
https://www.w3.org/TR/prov-overview/
[34] CloudEvents - CNCF Project
https://www.cncf.io/projects/cloudevents/
[34] CloudEvents Specification
https://github.com/cloudevents/spec
[34] AsyncAPI Initiative
https://www.asyncapi.com/
[34] AsyncAPI Specification
https://www.asyncapi.com/docs/reference/specification/v3.0.0
[35] Push API - W3C Working Draft / Tracking Only
https://www.w3.org/TR/push-api/
[35] RFC 8030 - Generic Event Delivery Using HTTP Push
https://www.rfc-editor.org/rfc/rfc8030
[35] WebSub - W3C Recommendation
https://www.w3.org/TR/websub/
[35] ActivityPub - W3C Recommendation
https://www.w3.org/TR/activitypub/
[35] ActivityStreams 2.0 - W3C Recommendation
https://www.w3.org/TR/activitystreams-core/
[35] Matrix Specification
https://spec.matrix.org/
[36] Terms of Service; Didn’t Read - Ratings and Cases
https://tosdr.org/
[36] Creative Commons License Chooser
https://creativecommons.org/chooser/
[36] Santa Clara Principles - Content Moderation Transparency
https://santaclaraprinciples.org/
[36] NIST Privacy Framework
https://www.nist.gov/privacy-framework
[21] ISO/IEC 42001 - AI Management Systems
https://www.iso.org/standard/81230.html
[21] ISO/IEC 23894 - AI Risk Management
https://www.iso.org/standard/77304.html
[21] ISO/IEC 22989 - AI Concepts and Terminology
https://www.iso.org/standard/74296.html
[21] ISO/IEC 23053 - Framework for AI Systems Using Machine Learning
https://www.iso.org/standard/74438.html
[21] MITRE ATLAS - Adversarial Threat Landscape for AI Systems
https://atlas.mitre.org/
[21] OWASP AIBOM Project
https://owaspaibom.org/
[21] OWASP AIBOM / AI SBOM Initiative
https://genai.owasp.org/ai-sbom-initiative/
[21] OWASP CycloneDX - Bill of Materials Specification
https://owasp.org/www-project-cycloned
[21] CycloneDX Specification Repository
https://github.com/CycloneDX/specification
22 Experimentation / Product Validation / Release Control
[22] Trustworthy Online Controlled Experiments - Kohavi, Tang, Xu
https://www.cambridge.org/core/books/trustworthy-online-controlled-experiments/trustworthy-online-controlled-experiments/524D7D0FDF6A542F732D047118618645
[22] Online Controlled Experiments and A/B Testing - Kohavi, Longbotham
https://link.springer.com/rwe/10.1007/978-1-4899-7687-1_891
[22] Controlled Experiments on the Web - Survey and Practical Guide
https://link.springer.com/article/10.1007/s10618-008-0114-1
[22] OpenFeature - Feature Flagging Specification
https://openfeature.dev/docs/reference/intro
23 Information Retrieval / RAG / Search Evaluation
[23] Introduction to Information Retrieval - Manning, Raghavan, Schütze
https://nlp.stanford.edu/IR-book/html/htmledition/irbook.html
[23] BEIR - Heterogeneous Benchmark for Zero-shot Information Retrieval
https://huggingface.co/papers/2104.08663
[23] BEIR GitHub Repository
https://github.com/beir-cellar/beir
[23] Retrieval-Augmented Generation for Knowledge-Intensive NLP Tasks
https://huggingface.co/papers/2005.11401
[23] RAG Original Paper - UCL NLP
https://nlp.cs.ucl.ac.uk/publications/2020-05-retrieval-augmented-generation-for-knowledge-intensive-nlp-tasks/
24 Identity / Provenance / Verifiable Records
[24] W3C Verifiable Credentials Data Model v2.0
https://www.w3.org/TR/vc-data-model-2.0/
[24] W3C Verifiable Credential Data Integrity 1.0
https://www.w3.org/TR/vc-data-integrity/
[24] W3C Verifiable Credentials 2.0 Recommendation Announcement
https://www.w3.org/news/2025/the-verifiable-credentials-2-0-family-of-specifications-is-now-a-w3c-recommendation/
25 Identity / AuthN / AuthZ / Session
[25] NIST SP 800-63-4 - Digital Identity Guidelines
https://pages.nist.gov/800-63-4/
[25] OAuth 2.0 Security Best Current Practice - RFC 9700
https://www.rfc-editor.org/rfc/rfc9700.html
[25] OpenID Connect Core 1.0
https://openid.net/specs/openid-connect-core-1_0.html
[25] Web Authentication Level 3 - W3C Candidate Recommendation / Tracking Only
https://www.w3.org/TR/webauthn-3/
[25] OWASP Authentication Cheat Sheet
https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html
[25] OWASP Authorization Cheat Sheet
https://cheatsheetseries.owasp.org/cheatsheets/Authorization_Cheat_Sheet.html
ここから
26 Trust & Safety / Moderation / Platform Governance
[26] Trust & Safety Professional Association - Content Moderation and Operations
https://www.tspa.org/curriculum/ts-fundamentals/content-moderation-and-operations/what-is-content-moderation/
[26] Santa Clara Principles - Transparency and Accountability in Content Moderation
https://santaclaraprinciples.org/
[26] EU Digital Services Act - Platform Accountability / Reference Only
https://digital-strategy.ec.europa.eu/en/policies/digital-services-act-package
[26] NIST Privacy Framework
https://www.nist.gov/privacy-framework
27 Cryptography / Key / Secrets Management
[27] NIST SP 800-57 Part 1 Rev. 5 - Recommendation for Key Management
https://csrc.nist.gov/pubs/sp/800/57/pt1/r5/final
[27] NIST Key Management Guidelines
https://csrc.nist.gov/Projects/Key-Management/Key-Management-Guidelines
[27] OWASP Secrets Management Cheat Sheet
https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
28 Web Platform / PWA / Offline Storage
[28] Progressive Web Apps - web.dev
https://web.dev/learn/pwa/progressive-web-apps
[28] Web Application Manifest - W3C Working Draft / Tracking Only
https://www.w3.org/TR/appmanifest/
[28] Service Worker API - MDN
https://developer.mozilla.org/en-US/docs/Web/API/ServiceWorker
[28] IndexedDB API - MDN
https://developer.mozilla.org/en-US/docs/Web/API/IndexedDB_API
[28] Using IndexedDB - MDN
https://developer.mozilla.org/en-US/docs/Web/API/IndexedDB_API/Using_IndexedDB
29 Continuity / Backup / Disaster Recovery
[29] NIST SP 800-34 Rev. 1 - Contingency Planning Guide for Federal Information Systems
https://csrc.nist.gov/pubs/sp/800/34/r1/final
[29] ISO 22301:2019 - Business Continuity Management Systems
https://www.iso.org/standard/75106.html
30 Abuse / Anti-Bot / Rate Limiting
[30] OWASP Automated Threats to Web Applications
https://owasp.org/www-project-automated-threats-to-web-applications/
[30] OWASP API Security Top 10 2023
https://owasp.org/API-Security/editions/2023/en/0x00-header/
[30] OWASP API Security Risks 2023
https://owasp.org/API-Security/editions/2023/en/0x10-api-security-risks/
[30] HTTP 429 Too Many Requests - MDN
https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/429
31 Payments / Billing / Compliance
[31] PCI DSS - PCI Security Standards Council
https://www.pcisecuritystandards.org/standards/pci-dss/
[31] PCI SSC Document Library
https://www.pcisecuritystandards.org/document_library
[31] PCI DSS v4.0.1 Publication Notice - PCI SSC
https://blog.pcisecuritystandards.org/just-published-pci-dss-v4-0-1
[31] Payment Request API - W3C Candidate Recommendation / Tracking Only
https://www.w3.org/TR/payment-request/
32 File / Media / User Upload Safety
[32] OWASP File Upload Cheat Sheet
https://cheatsheetseries.owasp.org/cheatsheets/File_Upload_Cheat_Sheet.html
[32] OWASP Unrestricted File Upload
https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload
[32] OWASP Input Validation Cheat Sheet
https://cheatsheetseries.owasp.org/cheatsheets/Input_Validation_Cheat_Sheet.html
[32] W3C File API - Working Draft / Tracking Only
https://www.w3.org/TR/FileAPI/
[32] MDN File API
https://developer.mozilla.org/en-US/docs/Web/API/File_API
33 Data Lifecycle / Retention / Deletion
[33] NIST SP 800-88 Rev. 2 - Guidelines for Media Sanitization
https://csrc.nist.gov/pubs/sp/800/88/r2/final
[33] NIST SP 800-92 - Guide to Computer Security Log Management
https://csrc.nist.gov/pubs/sp/800/92/final
[33] OWASP Logging Cheat Sheet
https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html
[33] W3C PROV - Provenance Overview
https://www.w3.org/TR/prov-overview/
34 Events / Queues / Async Architecture
[34] CloudEvents - CNCF Project
https://www.cncf.io/projects/cloudevents/
[34] CloudEvents Specification
https://github.com/cloudevents/spec
[34] AsyncAPI Initiative
https://www.asyncapi.com/
[34] AsyncAPI Specification
https://www.asyncapi.com/docs/reference/specification/v3.0.0
35 Notification / Subscription / Federation
[35] Push API - W3C Working Draft / Tracking Only
https://www.w3.org/TR/push-api/
[35] RFC 8030 - Generic Event Delivery Using HTTP Push
https://www.rfc-editor.org/rfc/rfc8030
[35] WebSub - W3C Recommendation
https://www.w3.org/TR/websub/
[35] ActivityPub - W3C Recommendation
https://www.w3.org/TR/activitypub/
[35] ActivityStreams 2.0 - W3C Recommendation
https://www.w3.org/TR/activitystreams-core/
[35] Matrix Specification
https://spec.matrix.org/
36 Product Legal Docs / Terms / Policy Ops
[36] Terms of Service; Didn’t Read - Ratings and Cases
https://tosdr.org/
[36] Creative Commons License Chooser
https://creativecommons.org/chooser/
[36] Santa Clara Principles - Content Moderation Transparency
https://santaclaraprinciples.org/
[36] NIST Privacy Framework
https://www.nist.gov/privacy-framework
Collection
Citation
unjuno, “cursor index & docs,” unjuno'sResearchLibrary, accessed October 6, 2026, https://archive.unjuno.org/items/show/168.
コメント