Segregation of Duties: 6 Proven Steps for SOX and ISO 27001 Governance Docs16th August 2026 One term covers three problems: transaction level, entitlement level and function level. What SOX 404, DORA Article 6(4)… Read More
Data Classification: 6 Proven Steps for ISO 27001 Governance Docs16th August 2026 Most schemes classify confidentiality only and have no rule for mixed data. What FIPS 199 and ISO 27001… Read More
Coordinated Vulnerability Disclosure: 7 Essential CRA Steps Governance Docs16th August 2026 The CRA requires you to put in place and enforce a CVD policy. What Annex I Part II(5),… Read More
SBOM Requirements: 6 Proven Steps to CRA Compliance Governance Docs16th August 2026 The CRA asks for an SBOM in four separate places. What Annex I Part II(1), Annex VII, Article… Read More
Business Continuity Exercise: 6 Proven Steps to Test the Switchover Governance Docs16th August 2026 DORA requires yearly testing of continuity, recovery and crisis communication plans, including cyber-attack and switchover scenarios. How to… Read More
Threat-Led Penetration Testing: Who DORA Actually Requires It From Governance Docs16th August 2026 DORA TLPT applies only to entities their regulator identifies. Live production systems, a scope the authority validates, and… Read More
HIPAA Safeguards: Addressable Does Not Mean Optional Governance Docs16th August 2026 The HIPAA Security Rule labels specifications Required or Addressable. Addressable means assess, then implement or document why not… Read More
NIS2 Management Liability: Three Duties on Named People Governance Docs16th August 2026 NIS2 Article 20 makes management approve, oversee and be liable for cybersecurity measures — and Article 32(5) can… Read More
Bridge Letter: What It Covers, and What It Does Not Governance Docs16th August 2026 A SOC 2 bridge letter is written by management, not the auditor, and nothing in it is tested.… Read More
Complementary User Entity Controls: The Half You Must Do Governance Docs16th August 2026 A SOC 2 report lists controls the provider assumes you operate. Nobody tests them. How to extract, own… Read More
Prohibited AI Practices: Article 5 Is Already In Force Governance Docs16th August 2026 The EU AI Act's eight prohibited AI practices have applied since 2 February 2025, with fines up to… Read More
Third-Party Risk Management: One Inventory, Four Regimes Governance Docs16th August 2026 DORA, NIS2, ISO 27001 and sector schemes ask about the same suppliers in different formats. Build one inventory… Read More