FSSC 22000 Unannounced Audit: Rules and Preparation 2026 Governance Docs29th September 2026 What to expect from an FSSC 22000 unannounced audit, including blackout dates, findings and how to stay ready… Read More
FedRAMP 20x KSI: Key Security Indicators Explained 2026 Governance Docs29th September 2026 FedRAMP 20x replaces control narratives with Key Security Indicators. See the themes, validation modes and how to prepare. Read More
IVDR Post-Market Surveillance: PMS Plan, Report and PSUR 2026 Governance Docs29th September 2026 What the IVDR requires after CE marking: the PMS plan, PMS reports, PSURs by class, PMPF and trend… Read More
CAIQ Security Questionnaire: Build a Reusable Answer Library 2026 Governance Docs29th September 2026 Build a CAIQ security questionnaire answer library from your STAR Level 1 submission to answer customer reviews faster… Read More
COSO Risk Appetite: Principle 7 Guide with Examples 2026 Governance Docs29th September 2026 Learn what COSO ERM Principle 7 requires, how appetite differs from tolerance and how to turn a statement… Read More
CIS Controls Safe Harbor: State Law Protection in 2026 Governance Docs29th September 2026 Some US states give legal protection to organisations that conform to recognised frameworks. See how the CIS Controls… Read More
CCPA Opt-Out Preference Signal: GPC Compliance Guide 2026 Governance Docs29th September 2026 Section 7025 requires businesses to honour opt-out preference signals such as GPC. Learn what to build, test and… Read More
BSI C5 Report Review: A Customer Checklist for 2026 Governance Docs29th September 2026 A practical checklist for cloud customers reading a BSI C5 attestation report: scope, deviations, shared responsibility and subservice… Read More
AS9100 Configuration Management: Clause 8.1.2 Guide 2026 Governance Docs29th September 2026 A practical guide to AS9100D clause 8.1.2: how to scope, identify and control configuration, with change control steps… Read More
WISP Service Provider Oversight: Safeguards Rule Guide 2026 Governance Docs29th September 2026 A practical guide to service provider oversight in your written information security plan under the FTC Safeguards Rule. Read More
UK IDTA and Addendum: Which to Use in 2026 Governance Docs29th September 2026 Choosing between the UK IDTA and the Addendum for restricted transfers, and the transfer risk assessment that must… Read More
SWIFT CSP Non-Compliance: Consequences and Recovery 2026 Governance Docs29th September 2026 SWIFT CSP non-compliance is visible to supervisors and counterparties. Learn the categories, consequences and a practical recovery plan. Read More