Talks and Appearances
Podcast appearances and conference sessions on audit readiness, FedRAMP authorization, and the controls that keep regulated platforms defensible.
Topics Kenio speaks on
FedRAMP Moderate: what happens after the ATO letter
Authorization boundary decisions, continuous monitoring and the change-management discipline that keeps a system inside its authorization.
Building an audit-ready IT general controls program
Why most SOX ITGC and SOC 2 CC8 findings trace back to population completeness, access reviews and change evidence — and how to fix them before the auditor arrives.
Compliance architecture inside a HIPAA business associate
What changes when a bad deploy is a breach rather than an outage, and how that reshapes control design for ePHI platforms.
Inheriting a compliance program after an acquisition
Two ownership changes, two control environments merging, and the specific places auditors find the gaps in the first 90 days.
What AI system deployment means for assurance frameworks
Model versions, prompt changes and retraining as configuration items, and how SOC 2, ISO 27001 and emerging AI assurance schemes are starting to ask for them.
Podcast appearances
No podcast appearances are listed yet. Kenio is available for interviews on FedRAMP, SOC 2, SOX ITGC, HIPAA and compliance architecture.
Conference talks
No conference talks are listed yet.
Book Kenio to speak
Bios, headshot, pronunciation and suggested topics are in the press kit. Background on his work is on the about page. For booking, email iam@kenioshirley.com.