Compliance
Cloud Security and Shared Responsibility
Cloud security failures are rarely failures of the platform. They are usually a misunderstanding about where the provider's obligation ends, acted on for long enough that nobody rechecks it.
This page sets out the model,...
Government and Public-Sector Cloud Infrastructure
Public-sector infrastructure decisions are made under constraints that commercial organizations do not share. The technology is the same; the authorization, procurement, records and transparency obligations around it are...
Cybersecurity Risk Assessments
A cybersecurity risk assessment answers one question: what could go wrong here that would matter, and which of those things is worth spending money on first. Everything else in the method exists to make that answer defen...
Cybersecurity Policies and Documentation
Security documentation has a reputation problem. It is associated with binders written for an audit, approved once, and never read again. That reputation is deserved for a great deal of it, and it obscures the fact that ...
Continuous Security and Compliance Monitoring
Passing an assessment and maintaining an effective security program are different achievements, and the second is considerably harder. An assessment measures a moment. A program has to hold a position while the environme...
The NIST Cybersecurity Framework
The NIST Cybersecurity Framework is the most widely used way of organizing a conversation about cybersecurity risk, and it is regularly misdescribed. It is not a standard, not a control catalog, and not something an orga...
NIST SP 800-53 Security Controls
NIST SP 800-53 is a catalog of security and privacy controls. It is thorough, it is long, and it is routinely misunderstood as a list an organization is supposed to complete. It is not, and reading it that way produces e...
ISO/IEC 27001 and Information Security Management
ISO/IEC 27001 differs from the other frameworks in this cluster in one decisive respect: an organization can be certified against it by an accredited third party. That single fact explains most of how it is used, and mos...
Managed Cybersecurity for Regulated and Public-Sector Environments
Regulated and public sector organizations do not have a different security problem from anyone else. They have the same problem plus an obligation to demonstrate, to somebody external, that they are addressing it.
That s...
AI Data Residency and Data Sovereignty
Data residency is a question about geography: where information is stored and processed. Data sovereignty is a question about jurisdiction: whose laws reach it, and who can compel its disclosure. They are related, they a...