ISO 27001 Maturity Assessment: A Clear Guide to 6 Levels Governance Docs02nd September 2026 An ISO 27001 maturity assessment scores how well a control works, not whether it exists. The 6 levels,… Read More
Corrective Action Program: A Clear NQA-1 Guide for 2026 Governance Docs02nd September 2026 A corrective action program turns on one classification decision. What conditions adverse to quality require, what significant ones… Read More
Special Characteristics: A Clear IATF 16949 Guide to All 6 Documents Governance Docs02nd September 2026 Special characteristics are one designation flowing through 6 documents. Where each must appear, what it obliges, and the… Read More
DORA Subcontracting: A Clear Guide to the 2025 RTS Governance Docs02nd September 2026 DORA subcontracting under Regulation (EU) 2025/532: what the RTS requires, why the chain is now the unit of… Read More
Breach Risk Assessment: A Clear Guide to the 4 HIPAA Factors Governance Docs02nd September 2026 A HIPAA breach risk assessment starts with 3 exclusions, then the 4 factors in 45 CFR 164.402 -… Read More
External Providers: A Clear Guide to ISO 9001 Clause 8.4 Governance Docs02nd September 2026 External providers under ISO 9001 clause 8.4: the 3 sub-clauses, how to band control by effect on conformity,… Read More
NCA ECC Implementation: A Clear Guide in 6 Steps Governance Docs02nd September 2026 NCA ECC implementation in 6 steps: scope, gap assessment, governance, remediation, internal review and assessment - plus the… Read More
ISO 13485 Purchasing: A Clear Guide to Clause 7.4 Governance Docs02nd September 2026 ISO 13485 purchasing in 3 parts: supplier evaluation, purchasing information and verification - plus the change-notification agreement most… Read More
AI System Impact Assessment: A Clear Guide to ISO 42005 Governance Docs02nd September 2026 An AI system impact assessment looks outward, not inward. What ISO/IEC 42005:2025 asks for in 7 steps, how… Read More
Threat Intelligence: A Clear Guide to ISO 27001 Control 5.7 Governance Docs02nd September 2026 Threat intelligence under ISO 27001 control 5.7: the 3 levels, the 5 artefacts that make it auditable, and… Read More
Plan of Action and Milestones: A Clear POA&M Guide for 2026 Governance Docs02nd September 2026 A plan of action and milestones in 9 fields, where the POA&M is still required in 2026, where… Read More
Shared Responsibility Matrix: A Clear Guide for ISO 27017 Governance Docs02nd September 2026 A shared responsibility matrix decides who patches, configures and restores. What goes in it across IaaS, PaaS and… Read More