Who Does the FTC Safeguards Rule Apply To? The Complete 2026 Guide Governance Docs05th September 2026 The FTC Safeguards Rule covers 13 types of non-bank financial institution, not just banks. Here is the two-part… Read More
User Access Review: A Complete 2026 Guide for ISO 27001 and SOC 2 Governance Docs04th September 2026 A user access review is the control auditors test hardest. Here is the seven-step process, the ISO 27001… Read More
NIST Privacy Framework Data Map: How to Build One (ID.IM-P8) Governance Docs03rd September 2026 A NIST Privacy Framework data map shows every data action, store and party. What to include, how much… Read More
NIST Privacy Framework vs ISO 27701: Which One in 2026? Governance Docs03rd September 2026 NIST Privacy Framework vs ISO 27701: a free risk model against a certifiable management system. Which to start… Read More
NIST Privacy Framework vs GDPR: How They Fit Together Governance Docs03rd September 2026 NIST Privacy Framework vs GDPR: one is a voluntary risk model, one is law. Where they overlap, where… Read More
NIST Privacy Framework Implementation Tiers: Not a Maturity Model Governance Docs03rd September 2026 NIST Privacy Framework Implementation Tiers: Partial, Risk Informed, Repeatable and Adaptive — and why Tier 4 is not… Read More
NIST Privacy Framework Profiles: Current vs Target in 2026 Governance Docs03rd September 2026 A NIST Privacy Framework Profile records what you achieve and what you need. How to build an honest… Read More
Problematic Data Actions: The Privacy Risk Security Misses Governance Docs03rd September 2026 A problematic data action can arise from processing that is authorised, accurate and secure. The ten questions that… Read More
NIST Privacy Framework 1.1 vs 1.0: Every Change Mapped Governance Docs03rd September 2026 NIST Privacy Framework 1.1 vs 1.0: four Categories retired, six added and all 34 Subcategory identifiers that moved,… Read More
Privacy Risk vs Cybersecurity Risk: The Critical 2026 Difference Governance Docs03rd September 2026 Privacy risk vs cybersecurity risk: why a privacy problem can arise from processing that is authorised, accurate and… Read More
NIST Privacy Framework: The Complete 2026 Guide Governance Docs03rd September 2026 The NIST Privacy Framework explained: the Core, Profiles and Implementation Tiers, all 102 Subcategories, and why version 1.1… Read More
WISP for a Sole Practitioner: The 4 Elements You Can Skip Governance Docs03rd September 2026 A WISP for a sole practitioner is smaller, but not for the reason most assume. What 16 CFR… Read More