Writing

Articles on audit readiness, compliance architecture and cloud cost governance, by Kenio Shirley.

  1. Population Completeness: The ITGC Finding Nobody Plans For

    · 7 min read

    Teams prepare for the sample. They almost never prepare for the question that comes first: how do you know this list of changes is all of them? That question is where SOX ITGC and SOC 2 audits actually go wrong.

  2. Your CAB Isn't the Problem. Its Design Is.

    · 9 min read

    DORA says formal external approval doesn't reduce change failure rates. NIST CM-3 names the change advisory board directly. Both are right, because the frameworks never asked for a meeting — they asked for a record.

Subscribe by RSS.

Monthly compliance insights

One email a month on audit readiness, FedRAMP and SOC 2 programs, and IT general controls that survive an auditor. No pitches, unsubscribe any time.