Category: Compliance & GRC
ISO 27001, SOC 2, CMMC, FedRAMP, HIPAA and the audits behind them.
-

CIS Benchmarks are a build standard, not a document
Hardening that is applied once and never enforced is hardening that lasted about a fortnight.
-

FedRAMP 20x and the authorisation boundary that eats your roadmap
Federal revenue is real, and so is the cost of getting authorised. Understand the boundary before you promise a date.
-

GovRAMP is how state and local buyers will shortlist you
State and local agencies increasingly buy only authorised cloud. Here is what the program asks and what it is worth.
-

HIPAA is losing the word that practices have hidden behind
For twenty years, addressable safeguards let organisations defer encryption and MFA. That flexibility is ending.
-

CMMC scoping: the enclave decision that sets your entire cost
Where you draw the CUI boundary determines how many systems you must harden, evidence and defend. Draw it once, carefully.
-

The Statement of Applicability is where ISO 27001 audits are won or lost
Most failed ISO 27001 Stage 2 audits trace back to one document that was written last and understood least.
-

SOC 2 Type II: the observation window is the whole exam
A Type I report says your controls exist. A Type II report says they kept working while nobody was watching.