Ideas and field notes

Blog

Practical writing about cybersecurity, compliance, and sustainable security operations.

A POA&M is a commitment, not a parking space

A plan of action and milestones converts a known gap into managed work. Used properly it is evidence of a functioning program; used as storage it is a list of things nobody intends to do.

The risk assessment that should come first

A risk assessment tells the organization which risks it actually has. Nearly every other governance activity, the policy review included, is guesswork without it.