Primary standards and guidance for enterprise risk management, cybersecurity controls, privacy, and security architecture.
Use the current vendor documentation for platform-specific behavior, and apply organizational policy and professional legal or compliance advice to actual regulatory obligations.