Author: Nexus Academy
-

AI governance is an inventory problem before it is a policy problem
You cannot govern AI systems you cannot list. Start with the register, then apply NIST AI RMF and the EU AI Act.
-

MITRE ATLAS gives AI attacks a shared vocabulary
ATT&CK made network intrusion discussable. ATLAS is doing the same for machine learning systems.
-

Prompt injection is not a bug you patch
In an LLM application the instruction and the data arrive through the same channel. That is an architectural problem, not a filtering one.
-

HIPAA is losing the word that practices have hidden behind
For twenty years, addressable safeguards let organisations defer encryption and MFA. That flexibility is ending.
-

GovRAMP is how state and local buyers will shortlist you
State and local agencies increasingly buy only authorised cloud. Here is what the program asks and what it is worth.
-

FedRAMP 20x and the authorisation boundary that eats your roadmap
Federal revenue is real, and so is the cost of getting authorised. Understand the boundary before you promise a date.
-

CMMC scoping: the enclave decision that sets your entire cost
Where you draw the CUI boundary determines how many systems you must harden, evidence and defend. Draw it once, carefully.
-

SOC 2 Type II: the observation window is the whole exam
A Type I report says your controls exist. A Type II report says they kept working while nobody was watching.
-

The Statement of Applicability is where ISO 27001 audits are won or lost
Most failed ISO 27001 Stage 2 audits trace back to one document that was written last and understood least.