Deep TrustGovernance Series

Governance that holds up under pressure.

175 practitioner articles on where governance programs look complete and are not, and what to do about it. From the author of the #DoNotBeLarry series.

DTG-PV04 · Privacy Governance · 7 min

Data Minimization Is the Principle Everyone Claims and Nobody Operationalizes

Ask any privacy officer whether their organization practices data minimization. The answer is yes. Ask them to show you where data minimization requirements are enforced…

DTG-NF18 · NIST CSF in Practice · 4 min

Alert Fatigue Is a Detection Design Problem, Not a Staffing Problem

Alert fatigue is the condition in which the volume of security alerts exceeds the capacity of the security team to investigate them meaningfully, resulting in alerts bein…

DTG-NF14 · NIST CSF in Practice · 4 min

Continuous Monitoring Is a NIST Requirement. It Is Also the Hardest to Operationalize

NIST CSF 2.0 includes continuous monitoring across multiple functions: in Identify, to maintain an accurate picture of the organizational environment and its risks; in De…

DTG-NF10 · NIST CSF in Practice · 4 min

Respond Is the Function That Reveals Whether Govern Was Ever Real

The NIST CSF 2.0 has six functions: Govern, Identify, Protect, Detect, Respond, Recover. Most governance programs invest sequentially in the first four.

DTG-NF09 · NIST CSF in Practice · 4 min

What a Mature NIST CSF Implementation Looks Like Three Years In

Year one of NIST CSF implementation is about gap assessment and roadmap development. Year two is about control implementation and evidence collection.

DTG-NF07 · NIST CSF in Practice · 4 min

The Supply Chain Risk Category That Gets Ticked and Not Managed

NIST CSF 2.0's GV.SC subcategory — cybersecurity supply chain risk management — is one of the most substantive additions to the framework's governance dimension.

DTG-NF06 · NIST CSF in Practice · 4 min

Recovery Planning That Doesn't Account for Data Integrity Is Not Recovery Planning

Recovery planning in most business continuity programs is architected around availability: restoring systems to operational status within the recovery time objective.

DTG-NF05 · NIST CSF in Practice · 4 min

Detect Is the NIST Function Most Organizations Under-Invest In

If you asked most security practitioners which NIST CSF function receives the least investment relative to its importance, the answer would be Detect.

DTG-NF04 · NIST CSF in Practice · 4 min

The Organization That Mapped to NIST and Still Had the Incident

The NIST CSF mapping was comprehensive. Every subcategory was assessed. Gaps were documented. A roadmap was developed. Progress was reported to the board quarterly.

DTG-MR19 · Board & Executive Governance · 4 min

How Do You Know When Your Risk Reporting Has Stopped Reflecting Reality?

Risk reporting that has stopped reflecting reality is a more common governance condition than most practitioners acknowledge. The indicators are subtle: metrics that have…

DTG-MR17 · Board & Executive Governance · 4 min

The Risk Appetite Statement Nobody Refers to When Making Risk Decisions

The risk appetite statement was developed over three months. It involved the board, the executive team, the CISO, and the CRO. It was approved at the highest governance l…

DTG-MR15 · Board & Executive Governance · 4 min

When Leadership Visibility Ends at the Edge of the Slide Deck

The slide deck is the governance product that the security and privacy functions deliver to leadership. It is curated, organized, and designed to communicate effectively…

DTG-MR11 · Board & Executive Governance · 4 min

The CISO's Report Was Accurate. The Board's Understanding Was Not

The CISO presented the quarterly security report to the board. The report was accurate in every particular: the metrics were correctly calculated, the risk ratings were d…

DTG-MR09 · Board & Executive Governance · 4 min

The Board Asked About Cyber Risk. The Report Answered About Cyber Activity

The CISO's quarterly report to the board contained forty-three slides. It covered vulnerabilities patched, phishing simulations completed, security awareness training com…

DTG-MR08 · Board & Executive Governance · 4 min

Activity Metrics Are Not Risk Metrics. Stop Presenting Them as the Same Thing

The security dashboard presents: 94,000 vulnerabilities remediated this quarter. 2,847 phishing emails blocked. 99.3 percent of systems with current endpoint protection.

DTG-MR02 · Board & Executive Governance · 4 min

The Numbers That Run Your Risk Program Are Wrong

This is not a claim that your data is fabricated or your team is incompetent. It is a claim about the nature of risk measurement. Risk is the product of likelihood and im…

DTG-IG25 · Identity Governance · 4 min

What the Attacker Knew About Your Access Model That You Didn't

The post-incident investigation produced a finding that was uncomfortable in its specificity: the attacker had navigated the environment with a precision that suggested d…

DTG-IG22 · Identity Governance · 4 min

The Conditional Access Policy That Failed Under Operational Pressure

The conditional access policy was designed to enforce authentication requirements based on user context: stronger authentication when accessing from unusual locations, ad…

DTG-IG21 · Identity Governance · 4 min

How Does Your Organization Govern Access That Was Never Formally Requested?

Identity governance programs are designed around formal access requests: a user submits a request, the request is approved by the appropriate authority, and the access is…

DTG-IG19 · Identity Governance · 4 min

The Orphaned Account Problem That Never Gets Fully Solved

An orphaned account is an account in an organizational system with no current, identifiable owner — no active employee, no active contractor, no active vendor relationshi…

DTG-IG14 · Identity Governance · 5 min

Privilege Creep Is Not a Failure of Technology. It Is a Failure of Process

Privilege creep is the gradual accumulation of access rights by users who move through roles, projects, and responsibilities over time. Each addition is individually just…

DTG-IG09 · Identity Governance · 4 min

Role Explosion in SaaS Environments and Why Nobody Is Cleaning It Up

Enterprise SaaS environments accumulate roles faster than any identity governance program was designed to manage. Every SaaS application has its own role model.

DTG-IG08 · Identity Governance · 5 min

Zero Trust Is Not a Product. It Is a Commitment to Identity Discipline

The zero trust market is worth billions of dollars. Vendors offer zero trust platforms, zero trust network access, zero trust architecture solutions.

DTG-IG05 · Identity Governance · 4 min

Identity Federation Means Your Trust Boundary Is Someone Else's Problem

Identity federation allows users to authenticate with one identity provider and access resources across multiple systems and organizations. It is one of the most signific…

Put it into practice

See your own scorecardMonitor your own attack surface the way buyers and auditors see it.Get my scorecard
View your vendors' scorecardsRatings, exposures and privacy posture for the vendors you rely on.See vendor scorecards
Publish your Trust CenterYour rating, policies and certifications in one shareable page.Preview my Trust Center