Topics
All posts on this site fall into three clusters. Each cluster starts with the foundational concept and builds toward applied practice.
GRC Fundamentals
What governance, risk, and compliance require, how the analyst role works, and which frameworks to apply. Covers the full range from entry-level concept to practitioner decision-making.
9 postsSOC 2
What SOC 2 requires, the five Trust Services Criteria, the documentation auditors test, and what SaaS companies need to know before enterprise deals require it.
5 postsAI Governance
How to govern AI systems inside a GRC program. Covers ISO 42001, the EU AI Act, OWASP AI Top 10, agentic AI risk, and a step-by-step program build.
7 posts