Knowledge Hub

The hard parts, written down.

Practical writing on security, risk, compliance and architecture — from the people who do this work inside enterprise and government programs. Detail over commentary, and sources you can check.

What we write about
  • Cloud security
  • AI security & governance
  • Security architecture
  • Risk & compliance
  • Privacy
  • Audit & assurance
20 articles New every week or two

All articles

20
Topics
Risk & Compliance01

From Assessment to Accountability: A Risk Register That Actually Works

Assessments identify risk; the register manages it — the ownership model that turns findings into decisions, and how CtrlFort runs it

·17 min Read
Risk & Compliance02

How Dangerous, How Exposed, What Remains: A Working Model for Residual Risk

The three-formula risk model inside CtrlFort Assess — threat from likelihood and capability, vulnerability from prevention and response weakness, and the residual risk left at their intersection

·19 min Read
AI & Governance03

How CtrlFort Uses AI to Deliver Repeatable, Explainable and Defensible Assessments

Code evaluates, AI explains, humans decide — inside the assessment intelligence architecture behind CtrlFort Assess

·11 min Read
Security Architecture04

Control Parameters in ITSG-33 and ITSP.10.033: The Values That Decide What a Control Actually Requires

The bracketed placeholders are not clerical filler — they are where policy becomes an engineering specification and where risk tolerance is quietly set

·13 min Read
Risk & Compliance05

What Makes a Security Control Mandatory in the Government of Canada?

\"Mandatory\" is a real category with real force — but it does not come from the control catalogue, and that misunderstanding costs teams months

·9 min Read
Security Assessment06

Beyond Checklists: Consistent, Repeatable and Reliable Security Assessments

A gated departmental process for on-premises systems — and where ITSP.10.033 assurance activities fit

·9 min Read
Security Architecture07

ITSP.10.033 vs NIST SP 800-53 Rev. 5

What actually differs between the Canadian catalogue and its American parent — and what it costs you to cross the border

·9 min Read
Cloud Security08

Cloud Security Assessment and Authorization in the Government of Canada

From security categorization to authority to operate — how the CCCS process actually fits together

·21 min Read
Security Assessment09

Step 8 — Authorization Is Not the End: Continuous Monitoring and Ongoing Assurance

An authorization describes a system at a moment. Systems do not stay at that moment — and the decision is only as current as what you know

·8 min Read
Security Assessment10

Step 7 — Authorization Decisions: ATOs, IATOs, Risk Acceptance and Sign-Off

The mechanics of the decision itself — who signs, what they are signing, what conditions attach, and what an authorization does not mean

·7 min Read
Security Assessment11

Step 6 — Building the Story: Security Assessment Reports and POA&Ms

The report is an argument addressed to one person who has to make a decision — not a data dump addressed to nobody

·7 min Read
Risk & Compliance12

Step 5 — From Finding to Risk Statement

A failed control is not a risk. It is an input to one — and the translation between them is where most assessment reports lose their executive audience

·7 min Read
Security Assessment13

Step 4 — Met, Partially Met or Not Met? Assessing Control Effectiveness

Turning collected evidence into a defensible result — and why "partially met" is where most assessment programs quietly lose their comparability

·7 min Read
Security Assessment14

Step 3 — Trust but Verify: Control Responses and Objective Evidence Collection

The mechanics of getting evidence out of a system owner — what to ask for, control by control, and what to do when the answer is "we have a policy"

·7 min Read
Security Architecture15

Step 2 — Choosing the Right Controls: Profile Selection and Control Tailoring

A profile is a starting point, not a finished control set — and tailoring is where most of the defensible judgment in an assessment actually happens

·7 min Read
Security Assessment16

Step 1 — Getting the Scope Right: Security Categorization and Assessment Scoping

Every downstream decision inherits this one, and re-scoping halfway through is not a correction — it is starting over

·7 min Read
Security Assessment17

What Makes Assessment Evidence Defensible?

The properties that separate evidence which survives challenge from a screenshot nobody can trace

·7 min Read
Risk & Compliance18

Assessments Don't Reduce Risk. Decisions Do.

Why a closed finding and a reduced risk are not the same thing, and what has to happen in between

·6 min Read
Security Assessment19

SA&A Terminology Explained: Controls, Findings, Risks, SARs, POA&Ms and ATOs

The vocabulary of security assessment — what each term means, what it does not, and where Canadian and American usage part ways

·8 min Read
Security Assessment20

What Is Security Assessment and Authorization (SA&A)?

The discipline that decides whether a system is allowed to carry real work — and who is accountable when it does

·8 min Read

No articles under that topic yet — try another.

Want this applied to your own program?

We'll walk your control library, obligations and evidence through CtrlFort Assess in a 30-minute working session — no slideware.