Ideas and field notes

Blog

Practical writing about cybersecurity, compliance, and sustainable security operations.

Follow the data

Documenting where sensitive data comes from, what it passes through, and where it rests determines both the scope of an obligation and the threats that actually apply.

A POA&M is a commitment, not a parking space

A plan of action and milestones converts a known gap into managed work. Used properly it is evidence of a functioning program; used as storage it is a list of things nobody intends to do.

The risk assessment that should come first

A risk assessment tells the organization which risks it actually has. Nearly every other governance activity, the policy review included, is guesswork without it.

What counts as sensitive data

Sensitive data is not one category with one owner. Each kind carries a different obligation from a different source, and an organization that has not separated them cannot protect any of them deliberately.

Not all evidence is equally believable

Audit practice ranks evidence by how far it sits from the party with an interest in the outcome. Organizations can choose what their procedures produce, and stronger evidence usually costs no more than weak evidence.

What an annual security policy review should produce

An annual review should test a policy against current obligations and operations, then record decisions, evidence, owners, and follow-up work. Most standards require the review; few organizations get full value from it.

A policy says what; a procedure says how

A policy states what the organization will do; its procedures state how, who, and with what. Keeping them apart makes both usable and keeps neither one stale.