CISA's New Logging Guidance Redefines Acceptable Audit Evidence
· 7 min read
Regulated engineering teams treat logging as an operational necessity, but compliance professionals know it is the fundamental currency of audit evidence.
Articles on audit readiness, compliance architecture and cloud cost governance, by Kenio Shirley.
· 7 min read
Regulated engineering teams treat logging as an operational necessity, but compliance professionals know it is the fundamental currency of audit evidence.
· 7 min read
When the suspension was a pair of July memos, it could have been reversed with a third. Now it is binding regulation. That changes your contracting posture — but nothing about your obligation to protect CUI has moved an inch.
· 7 min read
Every ITGC audit arrives at the same question: show me the logs. CISA just published a government-grade reference for what the answer should look like — what to capture, how long to keep it, and how to make it defensible.
· 8 min read
For fifteen years the answer to 'how do we get FedRAMP authorized?' started with 'find an agency sponsor.' As of August 3, 2026, it starts with 'do you have a current SOC 2 Type II?' That changes who the federal market is open to.
· 7 min read
You must transition your approach to SBOMs from a sporadic security activity to a continuous, auditable control process.
· 8 min read
The Department of War paused CMMC Phase II for a 60-day review and half the defense industrial base exhaled. Meanwhile the FAR Council proposed a CUI rule that sweeps in nearly every federal contractor, and DFARS 7012 never went anywhere.
· 8 min read
The PCAOB rewrote how auditors evaluate internal control over financial reporting, and the effective date lands on fiscal years ending December 15, 2026 or later. If your ITGC program has a soft spot, the deficiency math just changed underneath it.
· 8 min read
For twenty years a federal authorization package was a pile of documents a human reviewed. The Consolidated Rules for 2026 make it machine-readable data a pipeline validates. That is not a formatting change — it changes what the evidence is.
· 8 min read
Schleswig-Holstein, Denmark, Austria's armed forces and the French Gendarmerie are all moving public-sector desktops to open platforms. The licence savings are real and mostly beside the point. What changes is the quality of the evidence you can put in front of an auditor.
· 7 min read
The certificate transfers on day one. The control environment does not. Most post-acquisition compliance failures are not discovered in diligence — they are created in the first quarter of integration.
· 7 min read
Teams prepare for the sample. They almost never prepare for the question that comes first: how do you know this list of changes is all of them? That question is where SOX ITGC and SOC 2 audits actually go wrong.
· 8 min read
The authorization boundary is usually treated as a diagram you produce for the SSP. It is actually the single decision that sets your control count, your continuous monitoring bill and your agency ATO timeline.
· 9 min read
DORA says formal external approval doesn't reduce change failure rates. NIST CM-3 names the change advisory board directly. Both are right, because the frameworks never asked for a meeting — they asked for a record.
Subscribe by RSS.
One email a month on audit readiness, FedRAMP and SOC 2 programs, and IT general controls that survive an auditor. No pitches, unsubscribe any time.