<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>DISC Infosec blog</title>
	<atom:link href="http://blog.deurainfosec.com/feed/" rel="self" type="application/rss+xml"/>
	<link>https://blog.deurainfosec.com/</link>
	<description>Dedicated to information security assurance&#13;
Information Security subject matter with related items</description>
	<lastBuildDate>Wed, 09 Sep 2026 19:24:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.1.12</generator>

<image>
	<url>https://blog.deurainfosec.com/wp-content/uploads/2026/07/disc-logo-144x144.jpg</url>
	<title>DISC InfoSec blog</title>
	<link>https://blog.deurainfosec.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<xhtml:meta content="noindex" name="robots" xmlns:xhtml="http://www.w3.org/1999/xhtml"/><item>
		<title>Human Oversight vs Human Control: Where the Human Sits in AI Execution</title>
		<link>https://blog.deurainfosec.com/human-oversight-vs-human-control-where-the-human-sits-in-ai-execution/</link>
					<comments>https://blog.deurainfosec.com/human-oversight-vs-human-control-where-the-human-sits-in-ai-execution/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 19:07:16 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Agent]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[AI execution]]></category>
		<category><![CDATA[alongside the execution]]></category>
		<category><![CDATA[Human control]]></category>
		<category><![CDATA[Human in the loop]]></category>
		<category><![CDATA[Human oversight]]></category>
		<category><![CDATA[Parallel on the loop]]></category>
		<category><![CDATA[Perpendicular in the loop]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36508</guid>

					<description><![CDATA[<p>Where Does the Human Sit Relative to Execution? Outside the loop, in it, on it, or alongside it? The position determines what evidence exists, which risk tiers are defensible, and whether Article 14 oversight is real or theatre. Someone put a question to me recently that I thought was better than most of the governance [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/human-oversight-vs-human-control-where-the-human-sits-in-ai-execution/" data-wpel-link="internal" target="_blank">Human Oversight vs Human Control: Where the Human Sits in AI Execution</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/human-oversight-vs-human-control-where-the-human-sits-in-ai-execution/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>A signed two-page policy beats a fifty-page draft. Every time…</title>
		<link>https://blog.deurainfosec.com/a-signed-two-page-policy-beats-a-fifty-page-draft-every-time/</link>
					<comments>https://blog.deurainfosec.com/a-signed-two-page-policy-beats-a-fifty-page-draft-every-time/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 16:41:24 +0000</pubDate>
				<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[CISO]]></category>
		<category><![CDATA[Data Governance]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[IT Governance]]></category>
		<category><![CDATA[Security policy]]></category>
		<category><![CDATA[vCISO]]></category>
		<category><![CDATA[Bay Area Startups]]></category>
		<category><![CDATA[cybersecurity startups]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36521</guid>

					<description><![CDATA[<p>Startups at Seed or Series A Don&#8217;t Need a CISO to Pontificate. They Still Need Governance. A viral take says early-stage startups need operators, not CISOs. Mostly right — but three of the four things it says startups need are governance work. What actually blocks the audit and the deal. A take went around recently [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/a-signed-two-page-policy-beats-a-fifty-page-draft-every-time/" data-wpel-link="internal" target="_blank">A signed two-page policy beats a fifty-page draft. Every time&#8230;</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/a-signed-two-page-policy-beats-a-fifty-page-draft-every-time/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>We have guardrails for that is not a control – Here’s the difference</title>
		<link>https://blog.deurainfosec.com/we-have-guardrails-for-that-is-not-a-control-heres-the-difference/</link>
					<comments>https://blog.deurainfosec.com/we-have-guardrails-for-that-is-not-a-control-heres-the-difference/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 19:08:00 +0000</pubDate>
				<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Guardrails]]></category>
		<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[AI audit]]></category>
		<category><![CDATA[AI controls]]></category>
		<category><![CDATA[AI Security Assessment]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36490</guid>

					<description><![CDATA[<p>Why AI Systems Are Hard to Audit &#8211; AI doesn’t have controls, it has guardrails — and you can’t audit a guardrail AI Teams Think in Guardrails. Auditors Think in Controls. That Gap Is Where Programs Fail. Steven Ross made an observation in the ISACA Journal earlier this year that I&#8217;ve been chewing on since, [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/we-have-guardrails-for-that-is-not-a-control-heres-the-difference/" data-wpel-link="internal" target="_blank">We have guardrails for that is not a control &#8211; Here&#8217;s the difference</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/we-have-guardrails-for-that-is-not-a-control-heres-the-difference/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Point-in-time remediation is dead against a persistent adversary</title>
		<link>https://blog.deurainfosec.com/point-in-time-remediation-is-dead-against-a-persistent-adversary/</link>
					<comments>https://blog.deurainfosec.com/point-in-time-remediation-is-dead-against-a-persistent-adversary/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 04:31:30 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Agent]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Governance Enforcement]]></category>
		<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[Agentic defense agent]]></category>
		<category><![CDATA[Agentic offensive agent]]></category>
		<category><![CDATA[Autonomous Offensive Loops]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36451</guid>

					<description><![CDATA[<p>The Rise of Fully Autonomous Offensive Loops Agent collectives found zero-days, shared them, escalated, and moved laterally for weeks — by accident. Automated offense now has an existence proof. Automated defense doesn’t. What defenders should do. Every post in this series has been building toward a question that stopped being hypothetical in July 2026: what [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/point-in-time-remediation-is-dead-against-a-persistent-adversary/" data-wpel-link="internal" target="_blank">Point-in-time remediation is dead against a persistent adversary</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/point-in-time-remediation-is-dead-against-a-persistent-adversary/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Your Security Stack Isn’t Obsolete. Your Operating Model Is</title>
		<link>https://blog.deurainfosec.com/your-security-stack-isnt-obsolete-your-operating-model-is/</link>
					<comments>https://blog.deurainfosec.com/your-security-stack-isnt-obsolete-your-operating-model-is/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Wed, 02 Sep 2026 19:20:40 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Enterprise Cybersecurity Infrastructure]]></category>
		<category><![CDATA[Operating Model]]></category>
		<category><![CDATA[Security Stack]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36501</guid>

					<description><![CDATA[<p>Your Security Stack Isn&#8217;t Obsolete. Your Operating Model Is. Is Enterprise Cybersecurity Infrastructure Already Obsolete? The $1T Claim, Examined. Palo Alto&#8217;s CEO put $1 trillion on the table. The latency argument is right — but &#8220;obsolete&#8221; is the wrong diagnosis, and buying faster makes it worse. What&#8217;s actually structurally dead, and what to do first. [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/your-security-stack-isnt-obsolete-your-operating-model-is/" data-wpel-link="internal" target="_blank">Your Security Stack Isn&#8217;t Obsolete. Your Operating Model Is</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/your-security-stack-isnt-obsolete-your-operating-model-is/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Thirty years of security assumed the attacker was unauthorized – Your agent isn’t</title>
		<link>https://blog.deurainfosec.com/thirty-years-of-security-assumed-the-attacker-was-unauthorized-your-agent-isnt/</link>
					<comments>https://blog.deurainfosec.com/thirty-years-of-security-assumed-the-attacker-was-unauthorized-your-agent-isnt/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Mon, 31 Aug 2026 16:37:05 +0000</pubDate>
				<category><![CDATA[AI Agent]]></category>
		<category><![CDATA[AI Guardrails]]></category>
		<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[AI Agents]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36443</guid>

					<description><![CDATA[<p>Agentic AI Governance: Mitigating Liability and Protecting Information Assets The model decided to do that&#8221; is not a legal defense The previous post in this series covered agent security controls — tool scoping, separating decision from execution, memory hygiene, egress control. That&#8217;s the engineering layer. This post is about the layer above it, the one [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/thirty-years-of-security-assumed-the-attacker-was-unauthorized-your-agent-isnt/" data-wpel-link="internal" target="_blank">Thirty years of security assumed the attacker was unauthorized &#8211; Your agent isn&#8217;t</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/thirty-years-of-security-assumed-the-attacker-was-unauthorized-your-agent-isnt/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Frontier Model, Familiar Framework: Reading Fable 5’s Guardrails Through ISO 42001</title>
		<link>https://blog.deurainfosec.com/frontier-model-familiar-framework-reading-fable-5s-guardrails-through-iso-42001/</link>
					<comments>https://blog.deurainfosec.com/frontier-model-familiar-framework-reading-fable-5s-guardrails-through-iso-42001/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Sun, 30 Aug 2026 17:47:35 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[ISO 42001]]></category>
		<category><![CDATA[Fable 5]]></category>
		<category><![CDATA[Frontier Model]]></category>
		<category><![CDATA[Mythos 5]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36474</guid>

					<description><![CDATA[<p>What Claude Fable 5&#8217;s Launch Teaches Us About AI Governance (An ISO 42001 Reading) In June 2026, Anthropic released Claude Fable 5 — the most capable AI model ever made generally available. But the more interesting story isn&#8217;t the benchmarks. It&#8217;s the governance architecture wrapped around the release. Because here&#8217;s the thing: while most organizations [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/frontier-model-familiar-framework-reading-fable-5s-guardrails-through-iso-42001/" data-wpel-link="internal" target="_blank">Frontier Model, Familiar Framework: Reading Fable 5&#8217;s Guardrails Through ISO 42001</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/frontier-model-familiar-framework-reading-fable-5s-guardrails-through-iso-42001/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>ISO 42001 Evidence Checklist: What Auditors Actually Look For (2026)</title>
		<link>https://blog.deurainfosec.com/iso-42001-evidence-checklist-what-auditors-actually-look-for-2026/</link>
					<comments>https://blog.deurainfosec.com/iso-42001-evidence-checklist-what-auditors-actually-look-for-2026/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Sat, 29 Aug 2026 22:49:38 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Internal Audit]]></category>
		<category><![CDATA[ISO 42001]]></category>
		<category><![CDATA[ISO 42001 Evidence Checklist]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36462</guid>

					<description><![CDATA[<p>We Built an ISO 42001 Evidence Checklist for AI Companies — Here&#8217;s What Auditors Actually Look For Controls are rarely why organisations fail an ISO 42001 audit. Evidence is&#8230;A clause-by-clause evidence checklist, the seven patterns that separate a pass from a finding, and the questions auditors actually ask. ISO 42001 evidence checklist, ISO 42001 audit, [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/iso-42001-evidence-checklist-what-auditors-actually-look-for-2026/" data-wpel-link="internal" target="_blank">ISO 42001 Evidence Checklist: What Auditors Actually Look For (2026)</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/iso-42001-evidence-checklist-what-auditors-actually-look-for-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Agents don’t produce wrong answers anymore They take wrong actions – A practitioner’s guide to agent security</title>
		<link>https://blog.deurainfosec.com/agents-dont-produce-wrong-answers-anymore-they-take-wrong-actions-a-practitioners-guide-to-agent-security/</link>
					<comments>https://blog.deurainfosec.com/agents-dont-produce-wrong-answers-anymore-they-take-wrong-actions-a-practitioners-guide-to-agent-security/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Fri, 28 Aug 2026 16:30:22 +0000</pubDate>
				<category><![CDATA[AI Agent]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Governance Enforcement]]></category>
		<category><![CDATA[AI Guardrails]]></category>
		<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[agent least privilege]]></category>
		<category><![CDATA[AI Agent Security]]></category>
		<category><![CDATA[AIMS]]></category>
		<category><![CDATA[EU AI Act Article 14]]></category>
		<category><![CDATA[human-in-the-loop]]></category>
		<category><![CDATA[ISO 42001]]></category>
		<category><![CDATA[ISO 42001 agents]]></category>
		<category><![CDATA[prompt Injection]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36425</guid>

					<description><![CDATA[<p>AI Agent Security: Nobody Authorized That Action, and That&#8217;s the Problem The last two posts in this series ended in the same place from different directions. The one on AI-executable workflows argued that when the convertible tasks leave, what remains valuable is specification, oversight, evidence, boundary judgment, and the signature. The one on Bay Area [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/agents-dont-produce-wrong-answers-anymore-they-take-wrong-actions-a-practitioners-guide-to-agent-security/" data-wpel-link="internal" target="_blank">Agents don&#8217;t produce wrong answers anymore They take wrong actions &#8211; A practitioner&#8217;s guide to agent security</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/agents-dont-produce-wrong-answers-anymore-they-take-wrong-actions-a-practitioners-guide-to-agent-security/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AI Governance for Bay Area Startups: What to Put in Place Before Enterprise Customers Ask</title>
		<link>https://blog.deurainfosec.com/ai-governance-for-bay-area-startups-what-to-put-in-place-before-enterprise-customers-ask/</link>
					<comments>https://blog.deurainfosec.com/ai-governance-for-bay-area-startups-what-to-put-in-place-before-enterprise-customers-ask/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 16:30:03 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[Bay Area Startups]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36418</guid>

					<description><![CDATA[<p>AI Governance for Bay Area Startups: What to Put in Place Before Enterprise Customers Ask There&#8217;s a specific email that changes a startup&#8217;s quarter. It arrives from a champion who is genuinely on your side, and it reads something like: &#8220;Security review went fine, but our AI risk team added a section. Can you send [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/ai-governance-for-bay-area-startups-what-to-put-in-place-before-enterprise-customers-ask/" data-wpel-link="internal" target="_blank">AI Governance for Bay Area Startups: What to Put in Place Before Enterprise Customers Ask</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/ai-governance-for-bay-area-startups-what-to-put-in-place-before-enterprise-customers-ask/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How Much of Your Job Can Become an AI-Executable Workflow — and What’s Left Standing When It Does</title>
		<link>https://blog.deurainfosec.com/how-much-of-your-job-can-become-an-ai-executable-workflow-and-whats-left-standing-when-it-does/</link>
					<comments>https://blog.deurainfosec.com/how-much-of-your-job-can-become-an-ai-executable-workflow-and-whats-left-standing-when-it-does/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Mon, 24 Aug 2026 16:34:30 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[AI-Executable Workflow]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36398</guid>

					<description><![CDATA[<p>How Much of a Job Can AI Automate? What Remains valuable is not the leftover task In my last post I argued that governing AI is a more durable bet than racing to build with it. The obvious follow-up question is the harder one, and it&#8217;s the question I now get asked in almost every [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/how-much-of-your-job-can-become-an-ai-executable-workflow-and-whats-left-standing-when-it-does/" data-wpel-link="internal" target="_blank">How Much of Your Job Can Become an AI-Executable Workflow — and What’s Left Standing When It Does</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/how-much-of-your-job-can-become-an-ai-executable-workflow-and-whats-left-standing-when-it-does/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The AIMS/ISMS readiness ladder: seven steps from curious to certified</title>
		<link>https://blog.deurainfosec.com/the-aims-isms-readiness-ladder-seven-steps-from-curious-to-certified/</link>
					<comments>https://blog.deurainfosec.com/the-aims-isms-readiness-ladder-seven-steps-from-curious-to-certified/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Thu, 20 Aug 2026 17:38:49 +0000</pubDate>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[ISO 27k]]></category>
		<category><![CDATA[ISO 42001]]></category>
		<category><![CDATA[AIMS]]></category>
		<category><![CDATA[isms]]></category>
		<category><![CDATA[iso 27001]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36405</guid>

					<description><![CDATA[<p>A practical seven-step path from a 15-minute readiness call to ISO 42001 and ISO 27001 certification — with the prep work that makes each step fast instead of painful. Most organizations don&#8217;t stall on ISO 42001 or ISO 27001 because the standards are hard. They stall because step one is unclear, and the gap between [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/the-aims-isms-readiness-ladder-seven-steps-from-curious-to-certified/" data-wpel-link="internal" target="_blank">The AIMS/ISMS readiness ladder: seven steps from curious to certified</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/the-aims-isms-readiness-ladder-seven-steps-from-curious-to-certified/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AI Governance Careers: The Skills Gap Nobody Is Filling (2026)</title>
		<link>https://blog.deurainfosec.com/ai-governance-careers-the-skills-gap-nobody-is-filling-2026/</link>
					<comments>https://blog.deurainfosec.com/ai-governance-careers-the-skills-gap-nobody-is-filling-2026/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Mon, 17 Aug 2026 18:51:20 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Guardrails]]></category>
		<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[Cyber career]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36389</guid>

					<description><![CDATA[<p>Everyone Is Learning to Build With AI. Almost Nobody Is Learning to Govern It. I keep meeting people who are burning nights and weekends teaching themselves to build with AI. Agents, RAG pipelines, orchestration frameworks, the whole stack. I understand the instinct completely. The tooling is genuinely exciting, the demand looks self-evident, and nobody wants [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/ai-governance-careers-the-skills-gap-nobody-is-filling-2026/" data-wpel-link="internal" target="_blank">AI Governance Careers: The Skills Gap Nobody Is Filling (2026)</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/ai-governance-careers-the-skills-gap-nobody-is-filling-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AI Governance &amp; Cybersecurity That Holds Up Under Scrutiny</title>
		<link>https://blog.deurainfosec.com/ai-governance-cybersecurity-that-holds-up-under-scrutiny/</link>
					<comments>https://blog.deurainfosec.com/ai-governance-cybersecurity-that-holds-up-under-scrutiny/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Sat, 15 Aug 2026 22:08:34 +0000</pubDate>
				<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[AI Governance & Cybersecurity]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36369</guid>

					<description><![CDATA[<p>AI risk is moving faster than most organizations’ governance programs. Expert AI Governance and Cybersecurity Consulting Strengthening B2B SaaS and Financial Services with Robust Compliance Frameworks &#8211; DISC InfoSec turn AI governance and cybersecurity requirements into practical, defensible programs—not another stack of policies. Deura Information Security Consulting LLC provides expert guidance for B2B SaaS and [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/ai-governance-cybersecurity-that-holds-up-under-scrutiny/" data-wpel-link="internal" target="_blank">AI Governance &amp; Cybersecurity That Holds Up Under Scrutiny</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/ai-governance-cybersecurity-that-holds-up-under-scrutiny/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>“Sorry, Typo”: Why a Markdown File Is Not a Security Control</title>
		<link>https://blog.deurainfosec.com/sorry-typo-why-a-markdown-file-is-not-a-security-control/</link>
					<comments>https://blog.deurainfosec.com/sorry-typo-why-a-markdown-file-is-not-a-security-control/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Mon, 10 Aug 2026 17:33:07 +0000</pubDate>
				<category><![CDATA[AI Governance Enforcement]]></category>
		<category><![CDATA[AI Guardrails]]></category>
		<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Security controls]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36359</guid>

					<description><![CDATA[<p>&#8220;Sorry, Typo&#8221;: Why a Markdown File Is Not a Security Control PCWorld ran a piece last week on the one command you should never let an AI coding agent execute: rm -rf. The reporting is solid and the anecdotes are grim — developers who let an agent handle a routine cleanup task and lost a [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/sorry-typo-why-a-markdown-file-is-not-a-security-control/" data-wpel-link="internal" target="_blank">&#8220;Sorry, Typo&#8221;: Why a Markdown File Is Not a Security Control</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/sorry-typo-why-a-markdown-file-is-not-a-security-control/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>