Ideas and field notes

Blog

Practical writing about cybersecurity, compliance, and sustainable security operations.

Not all evidence is equally believable

Audit practice ranks evidence by how far it sits from the party with an interest in the outcome. Organizations can choose what their procedures produce, and stronger evidence usually costs no more than weak evidence.

What an annual security policy review should produce

An annual review should test a policy against current obligations and operations, then record decisions, evidence, owners, and follow-up work. Most standards require the review; few organizations get full value from it.