Library

    Everything published here, newest first.

    Working methods and regulatory briefings for security governance, risk and compliance practitioners.

    Type
    Pillar
    Track
    Framework

    114 of 114

    Insight

    The AI bill of materials is the next SBOM

    Three articles in one issue argue that the supply chain is now four chains. The bill of materials that stops at code no longer describes what ships.

    Security practice6 Sept 20264 min read

    AI governance
    Engagement pattern

    CRA readiness

    Getting a manufacturer ready for the CRA: class, route, vulnerability handling, support period, the technical file, and a rehearsed reporting clock.

    Governance6 Sept 20265 min read

    Product & OT
    Digest

    Radar digest: September 2026

    Twenty-eight entries joined the radar this month: guidance, codes, national acts, catalogue moves and seven dated privacy instruments beyond the EU.

    5 Sept 20262 min read

    Insight

    The permissions review that did not happen

    An agent reaches production on its installer's identity, holding every tool that person held. This is the review that should have run first.

    AI5 Sept 20265 min read

    AI governance
    Template

    AI system register

    A three-sheet register: every AI system with its two roles and its owner, one impact assessment per system, and the Annex A statement of applicability.

    Compliance5 Sept 20263 min read

    AI governance
    Template

    AI use-case triage form

    A twenty-two column form that runs the AI Act decision test over one AI use case per row and closes each row with proceed, conditions or stop.

    Compliance5 Sept 20263 min read

    AI governance
    Playbook

    BCM under ISO 22301: BIA, strategy, exercise

    Turning a continuity document into a management system: impact analysis, disruption risk, costed strategies, exercised plans and evaluation evidence.

    Risk5 Sept 202622 min read

    Playbook

    The BISO operating model

    A method for designing the business information security officer role: mandate, decision rights, placement, operating rhythm, interfaces, measures and pitfalls.

    Governance5 Sept 202622 min read

    Playbook

    Board and management reporting for security

    A method for putting security in front of a board and getting a decision: five to seven risks, measured controls, and an outcome that is written down.

    Governance5 Sept 202621 min read

    Reference

    China–EU regulatory bridge

    Which Chinese instrument answers which EU instrument for vehicles and for personal data, where the two only partly meet, and where no counterpart exists.

    Compliance5 Sept 202613 min read

    Product & OT
    Template

    Control catalogue

    A sixteen-column register of the controls that actually run: owner, evidence producer, approver, reference controls served, evidence record and last test.

    Governance5 Sept 20263 min read

    Playbook

    Control ownership and the control catalogue

    A method for building one list of the controls that actually run, each with an owner, an evidence record and a test result, mapped to the frameworks they serve.

    Governance5 Sept 202622 min read

    Template

    Control test workpaper

    A twenty-one-column record of one control test: the population, its completeness check, the sample, the procedure, the evidence and a conclusion two roles sign.

    Compliance5 Sept 20263 min read

    Playbook

    Control testing and ITGC

    A method for proving controls operated over a period: the ITGC map, complete populations, risk-based samples, workpapers a second person can re-perform.

    Compliance5 Sept 202622 min read

    Playbook

    Choosing the CRA conformity route

    Which Article 32 procedure applies to each product, who signs the declaration, and what the chosen route must produce before 11 December 2027.

    Governance5 Sept 202622 min read

    Product & OT
    Briefing

    The support period decision

    How a CRA support period is set, evidenced, published and closed: the Article 13(8) criteria, the duties that run over it, and who owns each.

    Governance5 Sept 20269 min read

    Product & OT
    Template

    CRA technical documentation index

    Four sheets that map the Annex VII file: one row per element per product, the declaration's Annex V items, and a retention schedule with derived end dates.

    Compliance5 Sept 20263 min read

    Product & OT
    Playbook

    Vulnerability handling and the SBOM under the CRA

    Annex I Part II run as a process: the bill of materials, component due diligence, intake, triage, the security update, disclosure and the Article 14 record.

    Risk5 Sept 202622 min read

    Product & OT
    Insight

    CRA in fifteen months: what to do first

    Article 14 starts in September 2026 and the essential requirements in December 2027. The first quarter is three decisions, not a compliance programme.

    Regulation and audit5 Sept 20265 min read

    Product & OT
    Briefing

    Cyber resilience beyond continuity

    What NIS2, DORA and the CER Directive each ask of resilience, the objectives that come before plans, and the exercise a policy cannot replace.

    Risk5 Sept 20269 min read

    Playbook

    DORA implementation

    A method for turning DORA into a running programme: scope, framework, incidents, testing, third-party risk, and the register of information built last.

    Compliance5 Sept 202622 min read

    BFSI
    Briefing

    EU AI Act for security governance

    The AI Act as consolidated on 27 July 2026: the scope test, obligations by article, the split high-risk timetable, and what security owns.

    Compliance5 Sept 20269 min read

    AI governance
    Template

    Findings-to-closure tracker template

    A sixteen-column register that carries every external audit finding from the auditor's wording to a verification date, with correction and cause kept apart.

    Compliance5 Sept 20263 min read

    Playbook

    The first 90 days as a security leader

    A ninety-day method: inventory the mandate, the obligations and the risk picture, decide appetite and operating model, then take one decision to the board.

    Governance5 Sept 202622 min read

    Briefing

    Governing AI and agents: who decides what

    AI governance as a table of decision rights: the three objects, a five-question test, who decides what an agent may do, and the evidence each decision leaves.

    Governance5 Sept 20269 min read

    AI governance
    Engagement pattern

    Governing security in the product organisation

    Where product security decisions are actually taken: the decision rights, the risk assessment they run on, and the conformity evidence they leave behind.

    Governance5 Sept 20265 min read

    Product & OT
    Reference

    GRC automation patterns

    Seven patterns for automating compliance work, each with the evidence it produces, the place it breaks, and the requirement it actually serves.

    Compliance5 Sept 202613 min read

    AI governance
    Briefing

    IEC 62443 for governance people

    IEC 62443 as a system of roles and decisions: which part binds which role, the concepts a governance reader must own, and where the series gets misread.

    Governance5 Sept 20269 min read

    Product & OT
    Playbook

    Incident governance

    A method for governing incidents end to end: declaration, decision records, the reporting clock across four regimes, and corrective action verified closed.

    Governance5 Sept 202622 min read

    Reference

    Key risk indicators that predict, not describe

    Leading indicators for eleven common security risks, each with the source of the number, the threshold, the role that acts, and where the indicator misleads.

    Risk5 Sept 202613 min read

    Template

    One-page risk picture

    A one-page board view of five to seven risks, each with an owner role, a position against appetite, a trend and the decision the body is asked to take.

    Governance5 Sept 20263 min read

    Template

    One-page security strategy

    One approvable page: five to seven security objectives, each tied to a business objective and a risk, with a measure, a baseline, a target and an owner role.

    Governance5 Sept 20263 min read

    Playbook

    Policy architecture people can find

    A method for turning a pile of documents into a tiered policy set with owners, review dates and exceptions, so a reader can find the rule that applies.

    Governance5 Sept 202622 min read

    Template

    Policy map

    A fourteen-column register of the policy set: tier, owner, approver, audience, the requirement that put each document there, and its next review date.

    Governance5 Sept 20263 min read

    Playbook

    Product CSMS as a management system

    Running the cyber security management system UN R155 requires as an operating system rather than a document set, on the clause pattern an ISMS already follows.

    Governance5 Sept 202622 min read

    Product & OT
    Template

    Register of information starter

    A five-sheet starter that mirrors the standard templates for the register of information, so the function, arrangement and provider data is collected once.

    Compliance5 Sept 20263 min read

    BFSI
    Playbook

    Risk acceptance and residual risk

    A method for turning "we accept that risk" into a dated record: a named approver, a residual level tested against criteria, compensating controls and an expiry.

    Risk5 Sept 202622 min read

    Template

    Risk acceptance record

    A fifteen-column record for accepted risks, with the authority table that says who may accept each level and an expiry log that forces a re-decision.

    Risk5 Sept 20263 min read

    Template

    Risk criteria and appetite statement

    Appetite per risk category, anchored consequence and likelihood scales, and a published lookup that says which level is accepted, treated or escalated.

    Risk5 Sept 20263 min read

    Playbook

    Running the external audit

    A method for hosting the certification body: evidence architecture, the opening meeting, nonconformity handling, and findings tracked to verified closure.

    Compliance5 Sept 202622 min read

    Playbook

    Scenario-based risk assessment

    Fifteen to forty scenarios a committee can decide on: risk sources with a desired end state, consequences over time, likelihood with a stated basis, and owners.

    Risk5 Sept 202622 min read

    Template

    Scenario library

    The maintained set of risk scenarios a committee can decide on: sources with a desired end state, consequence and likelihood with a basis, and an owner per row.

    Risk5 Sept 20263 min read

    Playbook

    Security awareness that changes behaviour

    A method for running an awareness programme against measured behaviour instead of completion rates, with the training records falling out as a by-product.

    Governance5 Sept 202622 min read

    Playbook

    The security operating model

    A method for writing down how security decisions are made: the functions, the decision rights, the three lines, the interfaces and the operating calendar.

    Governance5 Sept 202622 min read

    Playbook

    Security strategy on one page

    A method for turning business objectives, obligations and the risk picture into five to seven measured security objectives that fit on one approved page.

    Governance5 Sept 202622 min read

    Insight

    The board question is not the CVE count

    A vendor piece uses Anthropic's Mythos findings to argue that boards should hear attack paths and expected loss, not patch rates. Half of it holds.

    Security practice5 Sept 20263 min read

    Playbook

    Third-party risk across the contract lifecycle

    A lifecycle method for supplier assurance: tier first, assess by tier, contract for the rights you will need, keep assurance running, and exit on plan.

    Risk5 Sept 202622 min read

    BFSI
    Template

    Third-party tiering

    A four-sheet workbook that scores suppliers on five closed-option factors, bands the scores into three tiers, and sets the depth of assurance each earns.

    Risk5 Sept 20263 min read

    BFSI
    Template

    Vulnerability handling record

    Four sheets for Annex I Part II: an SBOM index by product version, a disclosure log, an update log, and a reporting clock with the two Article 14 anchors.

    Risk5 Sept 20263 min read

    Product & OT
    Briefing

    CRA obligations by product class

    Regulation (EU) 2024/2847 by product class: the scope test, the obligations by article, the conformity route, and what starts on 11 September 2026.

    Compliance4 Sept 20269 min read

    Product & OT
    Playbook

    From regulation to controls

    A repeatable method for turning a legal instrument into control objectives, controls, evidence and owners, worked end to end on NIS2 and on the CRA.

    Compliance4 Sept 202622 min read

    Engagement pattern

    AI governance stand-up under the EU AI Act

    Standing up AI governance from a blank sheet: role and classification first, then the management system, the impact work and the incident clocks.

    Governance3 Sept 20265 min read

    AI governance
    Playbook

    Building an ISMS people actually use

    A method for standing up an ISO/IEC 27001 management system that produces evidence in daily operation instead of a binder assembled before the audit.

    Governance3 Sept 202622 min read

    Engagement pattern

    ISO 27001 first certification

    The shape of a first certification cycle: scope, risk assessment and treatment, the operating record, and the evidence an accredited body reads.

    Compliance3 Sept 20265 min read

    Briefing

    NIS2 for the security officer

    Directive (EU) 2022/2555 in one pass: the scope test, the obligations by article, the reporting clock, the fine ceilings and a mapping to ISO 27001 Annex A.

    Compliance3 Sept 20269 min read

    Engagement pattern

    NIS2 readiness for an important entity

    How readiness is shaped for an entity in the important tier: the scope test, the Article 21 measures, the reporting chain and the evidence behind them.

    Compliance3 Sept 20265 min read

    Engagement pattern

    Product cybersecurity under R155, ISO 21434 and the CRA

    One product, three instruments. How the management system, the per-product file and the reporting clocks are built so a single evidence set answers all three.

    Compliance3 Sept 20265 min read

    Product & OT
    Template

    Risk register template

    A sixteen-column information security risk register with anchored 1-5 scales, a published combination rule and two mandatory decisions on every row.

    Risk3 Sept 20263 min read

    Playbook

    The risk register other people trust

    Risk statements that name a source, an event and a consequence; scales that survive argument; and every row closed by a named approver on a dated decision.

    Risk3 Sept 202622 min read

    Briefing

    The 90-day SOC 2 Type 1 plan

    A week-by-week sequence for a first SOC 2 type 1 examination: scope, policy set, evidence pipeline, risk assessment, fieldwork.

    Compliance10 Jul 20268 min read

    SaaS