175 practitioner articles on where governance programs look complete and are not, and what to do about it. From the author of the #DoNotBeLarry series.
The EU AI Act does not classify AI systems by what organizations intend them to do. It classifies them by what they actually do, and by the context in which they operate.
Privacy program maturity assessments measure whether the right elements are in place: policies documented, processes defined, tools deployed, responsibilities assigned.
Privacy programs report on what they measure. They measure what they can count. What they can count is process activity: training completion rates, DPIA completion rates,…
A privacy control that exists and functions is a governance achievement. A privacy control that exists and is not monitored for continued effectiveness is documentation o…
Privacy notices disclose that data is shared with third parties. Data processing agreements govern how those parties are permitted to use data.
A deletion workflow that finds and removes data from the systems it was designed to search is a deletion workflow that works correctly within its defined scope.
Consent creates a specific authorization for a specific processing activity. Organizations capture consent at a single point and then process data across dozens of system…
Every privacy policy says it. Every framework requires it. Almost no enterprise has operationalized it at the level its operational data estate requires.
Incident response plans are one of the most universally documented governance artifacts in enterprise security. They are required by every major framework.
Data protection controls are implemented at known data locations. Data moves to unknown locations constantly: copied to analytics environments, exported to SaaS tools, ca…
NIST CSF 2.0 introduced a Govern function that sits above and connects Identify, Protect, Detect, Respond, and Recover. The governance mandate is clear: organizations mus…
Boards receive reports that describe what the security and privacy organization has done: incidents responded to, controls implemented, assessments completed, training de…
Enterprise identity governance was built on the premise that identity is centralized: a directory, an IAM platform, a set of federation standards.
Privilege escalation is typically framed as a security concern about attackers gaining access beyond what they were authorized to have. The more common and more difficult…
Organizations have built excellent infrastructure for giving people access. Joining triggers automation: account creation, group assignment, license provisioning, entitle…
Every system addition is a potential privileged access expansion. Every cloud resource provisioned, every SaaS application deployed, every microservice added creates a ne…
Service accounts are the identity type that enterprise governance programs most consistently underaddress. Human accounts are governed by HR processes, access reviews, an…
Least privilege is one of the most widely adopted access control principles in enterprise security. It is documented in every security framework, required by every compli…
Access controls are designed to enforce defined permissions at a point in time. They do not prevent permissions from accumulating over time as users change roles, join pr…
An audit finding identifies what was observed: a control was absent, a process was not followed, evidence was missing, a configuration was incorrect.
Governance programs map controls to systems. Data does not follow system boundaries. It moves between systems, through integrations, across vendor boundaries, and into en…
GRC platforms are excellent at tracking what organizations have documented about their control environments. They track policy assignments, control mappings, audit eviden…
Security and governance metrics are designed to show improvement over time. They measure training completion, patch coverage, vulnerability closure rates, and control ass…
Audit readiness programs are designed to produce passing audit outcomes. They are effective at this objective. The governance problem is that passing an audit and having…