175 practitioner articles on where governance programs look complete and are not, and what to do about it. From the author of the #DoNotBeLarry series.
Ask any privacy officer whether their organization practices data minimization. The answer is yes. Ask them to show you where data minimization requirements are enforced…
Alert fatigue is the condition in which the volume of security alerts exceeds the capacity of the security team to investigate them meaningfully, resulting in alerts bein…
NIST CSF 2.0 includes continuous monitoring across multiple functions: in Identify, to maintain an accurate picture of the organizational environment and its risks; in De…
The NIST CSF 2.0 has six functions: Govern, Identify, Protect, Detect, Respond, Recover. Most governance programs invest sequentially in the first four.
Year one of NIST CSF implementation is about gap assessment and roadmap development. Year two is about control implementation and evidence collection.
NIST CSF 2.0's GV.SC subcategory — cybersecurity supply chain risk management — is one of the most substantive additions to the framework's governance dimension.
Recovery planning in most business continuity programs is architected around availability: restoring systems to operational status within the recovery time objective.
If you asked most security practitioners which NIST CSF function receives the least investment relative to its importance, the answer would be Detect.
The NIST CSF mapping was comprehensive. Every subcategory was assessed. Gaps were documented. A roadmap was developed. Progress was reported to the board quarterly.
Risk reporting that has stopped reflecting reality is a more common governance condition than most practitioners acknowledge. The indicators are subtle: metrics that have…
The risk appetite statement was developed over three months. It involved the board, the executive team, the CISO, and the CRO. It was approved at the highest governance l…
The slide deck is the governance product that the security and privacy functions deliver to leadership. It is curated, organized, and designed to communicate effectively…
The CISO presented the quarterly security report to the board. The report was accurate in every particular: the metrics were correctly calculated, the risk ratings were d…
The CISO's quarterly report to the board contained forty-three slides. It covered vulnerabilities patched, phishing simulations completed, security awareness training com…
The security dashboard presents: 94,000 vulnerabilities remediated this quarter. 2,847 phishing emails blocked. 99.3 percent of systems with current endpoint protection.
This is not a claim that your data is fabricated or your team is incompetent. It is a claim about the nature of risk measurement. Risk is the product of likelihood and im…
The post-incident investigation produced a finding that was uncomfortable in its specificity: the attacker had navigated the environment with a precision that suggested d…
The conditional access policy was designed to enforce authentication requirements based on user context: stronger authentication when accessing from unusual locations, ad…
Identity governance programs are designed around formal access requests: a user submits a request, the request is approved by the appropriate authority, and the access is…
An orphaned account is an account in an organizational system with no current, identifiable owner — no active employee, no active contractor, no active vendor relationshi…
Privilege creep is the gradual accumulation of access rights by users who move through roles, projects, and responsibilities over time. Each addition is individually just…
Enterprise SaaS environments accumulate roles faster than any identity governance program was designed to manage. Every SaaS application has its own role model.
The zero trust market is worth billions of dollars. Vendors offer zero trust platforms, zero trust network access, zero trust architecture solutions.
Identity federation allows users to authenticate with one identity provider and access resources across multiple systems and organizations. It is one of the most signific…