NIST Current/Target Profile
Compare existing cybersecurity outcomes with the agreed target using NIST’s own spreadsheet.

THE PEOPLEMACH RESOURCE LIBRARY
Practical references for bringing automation into the workplace. Explore the requirements, model records, and guidance behind better-informed safety decisions.
Use existing official tools alongside your company records. Select the right scope before adapting a model.
Compare existing cybersecurity outcomes with the agreed target using NIST’s own spreadsheet.
Hazard correction, investigation and training record examples. Check industry applicability before use.
General workplace inspection checklists to supplement a scoped equipment review.
Start here for California general-industry work. Applicability and exceptions depend on the workplace and task.
Responsibilities, hazard reviews, correction, employee instruction, and program records.
Examples of hazard-correction, investigation, and training records. This model is for non-high-hazard employers; verify the appropriate model for your industry.
A starting index for identifying task-specific training obligations; check the underlying regulation.
Requirements for covered servicing and related work, written procedures, periodic inspections, and role-specific instruction.
PPE assessment, selection, and training provisions, including specified certification requirements and scope limits.
Useful federal references. California has its own applicable requirements; the two sets of rules are not interchangeable.
General federal requirements for protecting workers from machine hazards.
Federal lockout/tagout requirements for covered equipment servicing and maintenance.
OSHA’s technical discussion of robot-system hazards and risk reduction. Guidance is distinct from a regulation.
Use prevention principles when considering how to address a workplace hazard.
Consider elimination, substitution, and engineering controls before relying on administrative controls and PPE.
Use these frameworks where relevant to the actual technology and risks. They do not certify machine safety.
A structure for governing, mapping, measuring, and managing risks when AI is involved.
Suggested actions and documentation practices to help organizations apply the AI RMF in context.
A common structure for managing cybersecurity risk around connected systems and organizational responsibilities.