Articles on security leadership, audit readiness, email security, CMMC, and AI governance for regulated and trust-sensitive organizations. Each article cites its primary sources.
A five-part guide to putting the NIST AI Risk Management Framework to work: the framework overview, then the GOVERN, MAP, MEASURE, and MANAGE functions.
An accidental email containing a live deal pipeline shows why access control alone is not enough, and why classification, DLP, encryption and endpoint controls have to work together.
The Department of War suspended CMMC Phase 2 on July 13, 2026, but Level 2 self-assessment and NIST SP 800-171 obligations remain in force. Five readiness gaps affect whether a contractor's affirmation will hold up.
The MANAGE function of the NIST AI RMF explained: risk prioritization, deployment gates, AI incident response, vendor monitoring, and decommissioning.
The MEASURE function of the NIST AI RMF explained: TEVV, bias and fairness testing, adversarial evaluation, drift monitoring, and documenting tradeoffs.
The MAP function of the NIST AI RMF explained: intended use, AI system documentation, stakeholder impact analysis, and risk identification, including generative AI risks.
The GOVERN function of the NIST AI RMF explained: accountability, AI policy, risk tolerance, AI inventories, and third-party oversight, and the gap between paper and practice.
The NIST AI Risk Management Framework (AI RMF 1.0) explained: the four functions, the seven trustworthy AI characteristics, and how to start using it.
Many organizations publish a DMARC record at p=none and never advance it. A sequenced approach, grounded in aggregate reports and sender alignment, allows a domain to reach enforcement with controlled risk.
An acceptable use policy alone does not establish AI governance. Regulated organizations need an AI system inventory, a risk-tiering rule, and an approval process aligned with the NIST AI Risk Management Framework.
Audit findings frequently trace to missing operating records rather than weak control design. Building evidence into routine work prepares an organization for SOC 2 Type 2 examinations, HIPAA reviews, and NIST-based assessments.
The first quarter of a fractional CISO engagement should establish accountability, document the organization's obligations, and put core processes into operation. This plan outlines the priorities for each 30-day phase.
AI introduces risks that traditional risk management approaches may not address. The NIST AI Risk Management Framework gives organizations a structured way to identify and mitigate them.
No articles in this topic yet.
Tell us what you are dealing with now, what kind of support you may need, and whether you are looking for a focused project, ongoing advisory, or both.