Risk Criteria: A Clear Guide to Setting Them Under ISO 31000 Governance Docs02nd September 2026 Risk criteria under ISO 31000: the 6 decisions to make before assessing anything, how they differ from risk… Read More
NIST 800-53 Control Families: A Clear Guide to All 20 Governance Docs02nd September 2026 All 20 NIST 800-53 control families with their two-letter IDs, base controls versus enhancements, and the 3 families… Read More
Critical ICT Third-Party Providers: A Clear DORA Guide for 2026 Governance Docs02nd September 2026 Critical ICT third-party providers under DORA: the 4 designation criteria, how a Lead Overseer is chosen, and the… Read More
DORA Incident Reporting: A Clear Guide to the 4-Hour Rule Governance Docs02nd September 2026 DORA incident reporting has 3 deadlines: 4 hours from classification, 72 hours for the intermediate report, one month… Read More
Cybersecurity Risk Register: A Clear Guide to the 10 Elements Governance Docs02nd September 2026 A cybersecurity risk register in 10 elements, from NIST IR 8286 Revision 1 - what each field is… Read More
NIST RMF: A Clear Guide to the 7 Steps of SP 800-37 Governance Docs02nd September 2026 The NIST RMF in 7 steps, from Prepare to Monitor, with the publication behind each - and how… Read More
OPRP vs CCP: A Clear Guide to Effective ISO 22000 Hazard Control Governance Docs02nd September 2026 OPRP vs CCP under ISO 22000: a CCP has a measurable critical limit, an OPRP an action criterion.… Read More
QHSE Documentation: A Clear Guide to the 4 Tiers Governance Docs02nd September 2026 QHSE documentation works when the tiers are decided first: manual, procedures, work instructions, records. What belongs in each… Read More
COSO 17 Principles: A Clear Guide to the 5 Components Governance Docs02nd September 2026 The COSO 17 principles listed by component, plus the present-and-functioning test, what counts as a major deficiency, and… Read More
HACCP Plan: A Clear Guide to the 12 Codex Steps Governance Docs02nd September 2026 A HACCP plan is built from the 12 Codex steps - 5 preliminary steps then the 7 principles.… Read More
ISO 45001 Assessment: A Clear Guide to the 4 Types Governance Docs02nd September 2026 An ISO 45001 assessment can mean 4 things: self-assessment, gap analysis, internal audit or certification audit. What each… Read More
CIS Benchmarks vs CIS Controls: A Clear Guide for 2026 Governance Docs02nd September 2026 CIS Benchmarks are configuration guides; CIS Controls are a prioritized program. What each covers, the 3 profile levels,… Read More