<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>DISC Infosec blog</title>
	<atom:link href="http://blog.deurainfosec.com/feed/" rel="self" type="application/rss+xml"/>
	<link>https://blog.deurainfosec.com/</link>
	<description>Dedicated to information security assurance&#13;
Information Security subject matter with related items</description>
	<lastBuildDate>Fri, 31 Jul 2026 16:49:46 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.1.10</generator>

<image>
	<url>https://blog.deurainfosec.com/wp-content/uploads/2023/05/disc-logo-144x144.jpg</url>
	<title>DISC InfoSec blog</title>
	<link>https://blog.deurainfosec.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<xhtml:meta content="noindex" name="robots" xmlns:xhtml="http://www.w3.org/1999/xhtml"/><item>
		<title>The Batch Model Is Broken: Vulnerability Management in the Era of AI-Accelerated Discovery</title>
		<link>https://blog.deurainfosec.com/the-batch-model-is-broken-vulnerability-management-in-the-era-of-ai-accelerated-discovery/</link>
					<comments>https://blog.deurainfosec.com/the-batch-model-is-broken-vulnerability-management-in-the-era-of-ai-accelerated-discovery/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Fri, 31 Jul 2026 16:37:22 +0000</pubDate>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Security vulnerabilities]]></category>
		<category><![CDATA[Era of AI-Accelerated Discovery]]></category>
		<category><![CDATA[vulnerability management]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36309</guid>

					<description><![CDATA[<p>The Batch Model Is Broken: Vulnerability Management in the Era of AI-Accelerated Discovery Scheduled scans. Monthly patch windows. A CVSS-sorted queue that someone works down until capacity runs out. That model was never elegant, but it worked because of three assumptions. All three are now false, and the data from the first half of 2026 [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/the-batch-model-is-broken-vulnerability-management-in-the-era-of-ai-accelerated-discovery/" data-wpel-link="internal" target="_blank">The Batch Model Is Broken: Vulnerability Management in the Era of AI-Accelerated Discovery</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/the-batch-model-is-broken-vulnerability-management-in-the-era-of-ai-accelerated-discovery/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>NIST CSF 2.0 and ISO 27001: Why the Strongest Programs Use Both</title>
		<link>https://blog.deurainfosec.com/nist-csf-2-0-and-iso-27001-why-the-strongest-programs-use-both/</link>
					<comments>https://blog.deurainfosec.com/nist-csf-2-0-and-iso-27001-why-the-strongest-programs-use-both/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 16:51:21 +0000</pubDate>
				<category><![CDATA[CISO]]></category>
		<category><![CDATA[ISO 27k]]></category>
		<category><![CDATA[NIST CSF]]></category>
		<category><![CDATA[vCISO]]></category>
		<category><![CDATA[iso 27001]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36305</guid>

					<description><![CDATA[<p>NIST CSF 2.0 and ISO 27001: Why the Strongest Programs Use Both Every security leader eventually gets asked the same question by a board member, a founder, or a prospect&#8217;s procurement team: &#8220;Which framework are we doing?&#8221; The question assumes the frameworks compete. They don&#8217;t. NIST CSF 2.0 and ISO/IEC 27001:2022 are built for different [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/nist-csf-2-0-and-iso-27001-why-the-strongest-programs-use-both/" data-wpel-link="internal" target="_blank">&lt;br&gt;NIST CSF 2.0 and ISO 27001: Why the Strongest Programs Use Both</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/nist-csf-2-0-and-iso-27001-why-the-strongest-programs-use-both/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Continuous NIST 800-53 Compliance: How to Stop Failing in the Eleven Months Between Audits</title>
		<link>https://blog.deurainfosec.com/continuous-nist-800-53-compliance-how-to-stop-failing-in-the-eleven-months-between-audits/</link>
					<comments>https://blog.deurainfosec.com/continuous-nist-800-53-compliance-how-to-stop-failing-in-the-eleven-months-between-audits/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Mon, 27 Jul 2026 14:33:24 +0000</pubDate>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[NIST CSF]]></category>
		<category><![CDATA[Security Compliance]]></category>
		<category><![CDATA[NIST 800-53]]></category>
		<category><![CDATA[NIST-800-53]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36293</guid>

					<description><![CDATA[<p>Continuous NIST 800-53 Compliance: How to Stop Failing in the Eleven Months Between Audits Most organizations do not fail NIST SP 800-53 during the assessment. They fail three months after it, quietly, and only find out the following year when an assessor pulls a sample and the sample doesn&#8217;t hold. The pattern is always the [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/continuous-nist-800-53-compliance-how-to-stop-failing-in-the-eleven-months-between-audits/" data-wpel-link="internal" target="_blank">Continuous NIST 800-53 Compliance: How to Stop Failing in the Eleven Months Between Audits</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/continuous-nist-800-53-compliance-how-to-stop-failing-in-the-eleven-months-between-audits/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AI Governance Readiness Assessment — Service</title>
		<link>https://blog.deurainfosec.com/ai-governance-readiness-assessment-service/</link>
					<comments>https://blog.deurainfosec.com/ai-governance-readiness-assessment-service/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Wed, 22 Jul 2026 21:03:36 +0000</pubDate>
				<category><![CDATA[AI Governance]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36273</guid>

					<description><![CDATA[<p>A fixed-scope, fixed-fee, two-week engagement that tells a company exactly where it stands against an AI governance standard — and hands them a prioritized, costed remediation plan they can execute against. Auditor-grade certainty in two weeks, not a six-month program. Included Explicitly excluded (these are the follow-on engagement) Framework lenses (pick one) Lens Best fit [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/ai-governance-readiness-assessment-service/" data-wpel-link="internal" target="_blank">AI Governance Readiness Assessment — Service</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/ai-governance-readiness-assessment-service/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>GRC Engineering: From Evidence Theater to Genuine Assurance</title>
		<link>https://blog.deurainfosec.com/grc-engineering-from-evidence-theater-to-genuine-assurance/</link>
					<comments>https://blog.deurainfosec.com/grc-engineering-from-evidence-theater-to-genuine-assurance/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 18:14:04 +0000</pubDate>
				<category><![CDATA[GRC]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[GRC Engineering]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36252</guid>

					<description><![CDATA[<p>GRC Engineering: From Evidence Theater to Genuine Assurance Most GRC programs are quietly optimized for the wrong outcome. They are built to survive an audit, not to reduce risk. The busiest weeks on the calendar are the ones before an assessor arrives, and the measure of success is a clean opinion rather than a safer [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/grc-engineering-from-evidence-theater-to-genuine-assurance/" data-wpel-link="internal" target="_blank">GRC Engineering: From Evidence Theater to Genuine Assurance</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/grc-engineering-from-evidence-theater-to-genuine-assurance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AI Risk Management: AIRM isn’t a Security Problem — It’s Bigger</title>
		<link>https://blog.deurainfosec.com/ai-risk-management-airm-isnt-a-security-problem-its-bigger/</link>
					<comments>https://blog.deurainfosec.com/ai-risk-management-airm-isnt-a-security-problem-its-bigger/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Mon, 20 Jul 2026 16:23:53 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36237</guid>

					<description><![CDATA[<p>AI Risk Management: The Discipline Your AI Strategy is Missing Most organizations discovered last year just how much AI they were already running. A customer support chatbot here. Copilot in the IDE. Einstein scoring leads in the CRM. A fraud model someone built in 2021 that nobody owns anymore. When I run AI inventories for [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/ai-risk-management-airm-isnt-a-security-problem-its-bigger/" data-wpel-link="internal" target="_blank">AI Risk Management: AIRM isn&#8217;t a Security Problem — It&#8217;s Bigger</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/ai-risk-management-airm-isnt-a-security-problem-its-bigger/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The adversary that treats your balance sheet as the objective</title>
		<link>https://blog.deurainfosec.com/the-adversary-that-treats-your-balance-sheet-as-the-objective/</link>
					<comments>https://blog.deurainfosec.com/the-adversary-that-treats-your-balance-sheet-as-the-objective/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Sun, 12 Jul 2026 23:02:49 +0000</pubDate>
				<category><![CDATA[Attack Matrix]]></category>
		<category><![CDATA[Cyber Threats]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Threat detection]]></category>
		<category><![CDATA[Threat Modeling]]></category>
		<category><![CDATA[Lazarus Group]]></category>
		<category><![CDATA[TTPS]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36225</guid>

					<description><![CDATA[<p>Download html file AI Attack Surface ScoreCard AI Vulnerability Scorecard: Discover Your AI Attack Surface Before Attackers Do Your Shadow AI Problem Has a Name-And Now It Has a Score Most AI Security Tools Won’t Pass an Audit. Here’s a 15-Minute Way to Find Out. AIMS and Data Governance – Managing data responsibly isn’t just [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/the-adversary-that-treats-your-balance-sheet-as-the-objective/" data-wpel-link="internal" target="_blank">The adversary that treats your balance sheet as the objective</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/the-adversary-that-treats-your-balance-sheet-as-the-objective/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Why Supplier Security Is Under the Spotlight — and How to Build a Vendor Management Program for the AI Era</title>
		<link>https://blog.deurainfosec.com/why-supplier-security-is-under-the-spotlight-and-how-to-build-a-vendor-management-program-for-the-ai-era/</link>
					<comments>https://blog.deurainfosec.com/why-supplier-security-is-under-the-spotlight-and-how-to-build-a-vendor-management-program-for-the-ai-era/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 14:22:30 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[Vendor Assessment]]></category>
		<category><![CDATA[Vendor Management]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36209</guid>

					<description><![CDATA[<p>Why Supplier Security Is Under the Spotlight — and How to Build a Vendor Management Program for the AI Era Your security program is only as strong as the weakest vendor with access to your environment. That&#8217;s not a slogan anymore — it&#8217;s what the breach data says, it&#8217;s what regulators are writing into law, [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/why-supplier-security-is-under-the-spotlight-and-how-to-build-a-vendor-management-program-for-the-ai-era/" data-wpel-link="internal" target="_blank">Why Supplier Security Is Under the Spotlight — and How to Build a Vendor Management Program for the AI Era</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/why-supplier-security-is-under-the-spotlight-and-how-to-build-a-vendor-management-program-for-the-ai-era/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>GDPR Isn’t a Cookie Banner: The Audit Findings That Actually Get Companies Fined</title>
		<link>https://blog.deurainfosec.com/gdpr-isnt-a-cookie-banner-the-audit-findings-that-actually-get-companies-fined/</link>
					<comments>https://blog.deurainfosec.com/gdpr-isnt-a-cookie-banner-the-audit-findings-that-actually-get-companies-fined/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Thu, 09 Jul 2026 17:44:39 +0000</pubDate>
				<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Audit Findings]]></category>
		<category><![CDATA[gdpr]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36204</guid>

					<description><![CDATA[<p>GDPR Isn&#8217;t a Cookie Banner: The Audit Findings That Actually Get Companies Fined Seven years after GDPR took effect, most organizations still treat it like a checkbox they ticked in 2018. They dropped in a cookie banner, published a privacy policy their own lawyers haven&#8217;t read since, and moved on. Then a data subject access [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/gdpr-isnt-a-cookie-banner-the-audit-findings-that-actually-get-companies-fined/" data-wpel-link="internal" target="_blank">GDPR Isn&#8217;t a Cookie Banner: The Audit Findings That Actually Get Companies Fined</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/gdpr-isnt-a-cookie-banner-the-audit-findings-that-actually-get-companies-fined/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>ATT&amp;CK vs. ATLAS: Why Securing AI Systems Needs Its Own Playbook</title>
		<link>https://blog.deurainfosec.com/attck-vs-atlas-why-securing-ai-systems-needs-its-own-playbook/</link>
					<comments>https://blog.deurainfosec.com/attck-vs-atlas-why-securing-ai-systems-needs-its-own-playbook/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 20:04:42 +0000</pubDate>
				<category><![CDATA[Attack Matrix]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[MITRE ATLAS]]></category>
		<category><![CDATA[MITRE ATT&CK]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36194</guid>

					<description><![CDATA[<p>MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems) is specifically about attacks on AI and machine learning systems — things like data poisoning, model evasion, model extraction, and prompt injection. It&#8217;s modeled on the ATT&#38;CK structure (tactics and techniques) but applied to the AI/ML attack surface. The description in your source looks like it may [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/attck-vs-atlas-why-securing-ai-systems-needs-its-own-playbook/" data-wpel-link="internal" target="_blank">ATT&amp;CK vs. ATLAS: Why Securing AI Systems Needs Its Own Playbook</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/attck-vs-atlas-why-securing-ai-systems-needs-its-own-playbook/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>20 State Laws, One Enforcement Standard: Privacy by Design or Pay</title>
		<link>https://blog.deurainfosec.com/20-state-laws-one-enforcement-standard-privacy-by-design-or-pay/</link>
					<comments>https://blog.deurainfosec.com/20-state-laws-one-enforcement-standard-privacy-by-design-or-pay/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Fri, 03 Jul 2026 17:19:46 +0000</pubDate>
				<category><![CDATA[Information Privacy]]></category>
		<category><![CDATA[ISO 27k]]></category>
		<category><![CDATA[ISO 27701]]></category>
		<category><![CDATA[PIMS]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36185</guid>

					<description><![CDATA[<p>Privacy Just Became Infrastructure. Most AI Programs Haven&#8217;t Noticed. By DISC InfoSec For twenty years, privacy compliance meant disclosure: post a policy, collect consent, answer the occasional access request. That era is over. In 2026, privacy is infrastructure — regulators are testing whether your controls actually work, not whether your privacy notice reads well. I [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/20-state-laws-one-enforcement-standard-privacy-by-design-or-pay/" data-wpel-link="internal" target="_blank">20 State Laws, One Enforcement Standard: Privacy by Design or Pay</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/20-state-laws-one-enforcement-standard-privacy-by-design-or-pay/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Compliance Event vs. Compliance Capability: Why ISO 42001 is How You Actually Meet the EU AI Act</title>
		<link>https://blog.deurainfosec.com/compliance-event-vs-compliance-capability-why-iso-42001-is-how-you-actually-meet-the-eu-ai-act/</link>
					<comments>https://blog.deurainfosec.com/compliance-event-vs-compliance-capability-why-iso-42001-is-how-you-actually-meet-the-eu-ai-act/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Thu, 02 Jul 2026 16:50:10 +0000</pubDate>
				<category><![CDATA[ISO 42001]]></category>
		<category><![CDATA[EU AI Act]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36179</guid>

					<description><![CDATA[<p>How they relate The cleanest way to frame it: the EU AI Act defines outcomes; ISO 42001 supplies the machinery to produce them repeatedly. The Act (Regulation (EU) 2024/1689) is enforceable law with fines up to €35M or 7% of global turnover for prohibited practices. ISO 42001 is a voluntary, certifiable management system standard published [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/compliance-event-vs-compliance-capability-why-iso-42001-is-how-you-actually-meet-the-eu-ai-act/" data-wpel-link="internal" target="_blank">Compliance Event vs. Compliance Capability: Why ISO 42001 is How You Actually Meet the EU AI Act</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/compliance-event-vs-compliance-capability-why-iso-42001-is-how-you-actually-meet-the-eu-ai-act/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The AI RMF Gap Nobody’s Talking About: Why GOVERN-Heavy Programs Still Fail Audits</title>
		<link>https://blog.deurainfosec.com/the-ai-rmf-gap-nobodys-talking-about-why-govern-heavy-programs-still-fail-audits/</link>
					<comments>https://blog.deurainfosec.com/the-ai-rmf-gap-nobodys-talking-about-why-govern-heavy-programs-still-fail-audits/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Wed, 01 Jul 2026 15:04:23 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[AI RMF]]></category>
		<category><![CDATA[NIST AI RMF]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36173</guid>

					<description><![CDATA[<p>This is the AI RMF gap assessment, not the checklist version. Most write-ups treat GOVERN, MAP, MEASURE, and MANAGE as four boxes to tick. In practice, the interesting failure isn&#8217;t which box is empty — it&#8217;s the pattern across the boxes. That pattern is what tells you whether your AI program is actually managing risk [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/the-ai-rmf-gap-nobodys-talking-about-why-govern-heavy-programs-still-fail-audits/" data-wpel-link="internal" target="_blank">&lt;strong&gt;The AI RMF Gap Nobody&#8217;s Talking About: Why GOVERN-Heavy Programs Still Fail Audits&lt;/strong&gt;</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/the-ai-rmf-gap-nobodys-talking-about-why-govern-heavy-programs-still-fail-audits/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>ISO/IEC 27001:2022 — The Compliance Bedrock Every Serious InfoSec Program Is Built On</title>
		<link>https://blog.deurainfosec.com/iso-iec-270012022-the-compliance-bedrock-every-serious-infosec-program-is-built-on/</link>
					<comments>https://blog.deurainfosec.com/iso-iec-270012022-the-compliance-bedrock-every-serious-infosec-program-is-built-on/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Mon, 29 Jun 2026 15:53:06 +0000</pubDate>
				<category><![CDATA[CISO]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[ISO 27k]]></category>
		<category><![CDATA[vCISO]]></category>
		<category><![CDATA[isms]]></category>
		<category><![CDATA[iso 27001]]></category>
		<category><![CDATA[security program]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36149</guid>

					<description><![CDATA[<p>ISO/IEC 27001:2022 — The Compliance Bedrock Every Serious InfoSec Program Is Built On By Disc &#124; Principal Consultant, DISC InfoSec There&#8217;s a question I get from almost every B2B SaaS and financial services client at some point: &#8220;Which compliance framework should we start with?&#8221; My answer is almost always the same: ISO/IEC 27001. Not because [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/iso-iec-270012022-the-compliance-bedrock-every-serious-infosec-program-is-built-on/" data-wpel-link="internal" target="_blank">ISO/IEC 27001:2022 — The Compliance Bedrock Every Serious InfoSec Program Is Built On</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/iso-iec-270012022-the-compliance-bedrock-every-serious-infosec-program-is-built-on/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>One Audit – Four Standards – Zero Duplication</title>
		<link>https://blog.deurainfosec.com/one-audit-four-standards-zero-duplication/</link>
					<comments>https://blog.deurainfosec.com/one-audit-four-standards-zero-duplication/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Fri, 26 Jun 2026 18:16:31 +0000</pubDate>
				<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[ISO 27k]]></category>
		<category><![CDATA[ISO 42001]]></category>
		<category><![CDATA[NIST CSF]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[iso 27001]]></category>
		<category><![CDATA[NIST 800-53]]></category>
		<category><![CDATA[One Audit]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36134</guid>

					<description><![CDATA[<p>One Audit. Four Standards. Zero Duplication. How to Build a Master Questionnaire as Your Single Source of Truth for ISO 27001, ISO 42001, NIST 800-53, and GDPR I want to tell you about a problem that is quietly draining compliance teams at SaaS companies right now — and a structural fix that changed how we [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/one-audit-four-standards-zero-duplication/" data-wpel-link="internal" target="_blank">One Audit &#8211; Four Standards &#8211; Zero Duplication</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/one-audit-four-standards-zero-duplication/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>