The hard parts, written down.
Practical writing on security, risk, compliance and architecture — from the people who do this work inside enterprise and government programs. Detail over commentary, and sources you can check.
- Cloud security
- AI security & governance
- Security architecture
- Risk & compliance
- Privacy
- Audit & assurance
How CtrlFort Uses AI to Deliver Repeatable, Explainable and Defensible Assessments
Code evaluates, AI explains, humans decide — inside the assessment intelligence architecture behind CtrlFort Assess
Read the article →In this article
- The Problem with Documents-In, Verdict-Out
- The CtrlFort Approach
- Knowledge Intelligence: The Context an Assessment Runs On
- Control Intelligence: Methodology as an Asset
- The Deterministic Assessment Engine: Where Repeatability Comes From
All articles
20From Assessment to Accountability: A Risk Register That Actually Works
Assessments identify risk; the register manages it — the ownership model that turns findings into decisions, and how CtrlFort runs it
How Dangerous, How Exposed, What Remains: A Working Model for Residual Risk
The three-formula risk model inside CtrlFort Assess — threat from likelihood and capability, vulnerability from prevention and response weakness, and the residual risk left at their intersection
How CtrlFort Uses AI to Deliver Repeatable, Explainable and Defensible Assessments
Code evaluates, AI explains, humans decide — inside the assessment intelligence architecture behind CtrlFort Assess
Control Parameters in ITSG-33 and ITSP.10.033: The Values That Decide What a Control Actually Requires
The bracketed placeholders are not clerical filler — they are where policy becomes an engineering specification and where risk tolerance is quietly set
What Makes a Security Control Mandatory in the Government of Canada?
\"Mandatory\" is a real category with real force — but it does not come from the control catalogue, and that misunderstanding costs teams months
Beyond Checklists: Consistent, Repeatable and Reliable Security Assessments
A gated departmental process for on-premises systems — and where ITSP.10.033 assurance activities fit
ITSP.10.033 vs NIST SP 800-53 Rev. 5
What actually differs between the Canadian catalogue and its American parent — and what it costs you to cross the border
Cloud Security Assessment and Authorization in the Government of Canada
From security categorization to authority to operate — how the CCCS process actually fits together
Step 8 — Authorization Is Not the End: Continuous Monitoring and Ongoing Assurance
An authorization describes a system at a moment. Systems do not stay at that moment — and the decision is only as current as what you know
Step 7 — Authorization Decisions: ATOs, IATOs, Risk Acceptance and Sign-Off
The mechanics of the decision itself — who signs, what they are signing, what conditions attach, and what an authorization does not mean
Step 6 — Building the Story: Security Assessment Reports and POA&Ms
The report is an argument addressed to one person who has to make a decision — not a data dump addressed to nobody
Step 5 — From Finding to Risk Statement
A failed control is not a risk. It is an input to one — and the translation between them is where most assessment reports lose their executive audience
Step 4 — Met, Partially Met or Not Met? Assessing Control Effectiveness
Turning collected evidence into a defensible result — and why "partially met" is where most assessment programs quietly lose their comparability
Step 3 — Trust but Verify: Control Responses and Objective Evidence Collection
The mechanics of getting evidence out of a system owner — what to ask for, control by control, and what to do when the answer is "we have a policy"
Step 2 — Choosing the Right Controls: Profile Selection and Control Tailoring
A profile is a starting point, not a finished control set — and tailoring is where most of the defensible judgment in an assessment actually happens
Step 1 — Getting the Scope Right: Security Categorization and Assessment Scoping
Every downstream decision inherits this one, and re-scoping halfway through is not a correction — it is starting over
What Makes Assessment Evidence Defensible?
The properties that separate evidence which survives challenge from a screenshot nobody can trace
Assessments Don't Reduce Risk. Decisions Do.
Why a closed finding and a reduced risk are not the same thing, and what has to happen in between
SA&A Terminology Explained: Controls, Findings, Risks, SARs, POA&Ms and ATOs
The vocabulary of security assessment — what each term means, what it does not, and where Canadian and American usage part ways
What Is Security Assessment and Authorization (SA&A)?
The discipline that decides whether a system is allowed to carry real work — and who is accountable when it does
No articles under that topic yet — try another.
Want this applied to your own program?
We'll walk your control library, obligations and evidence through CtrlFort Assess in a 30-minute working session — no slideware.