๐Ÿ“Review Incoming...

This week, we dive into GRC. Andrew Chrostowski provides a Hall of Fame Rec for ๐™๐™๐™š ๐˜พ๐™ฎ๐™—๐™š๐™ง๐™จ๐™š๐™˜๐™ช๐™ง๐™ž๐™ฉ๐™ฎ ๐™‚๐™ช๐™ž๐™™๐™š ๐™ฉ๐™ค ๐™‚๐™ค๐™ซ๐™š๐™ง๐™ฃ๐™–๐™ฃ๐™˜๐™š, ๐™๐™ž๐™จ๐™ , ๐™–๐™ฃ๐™™ ๐˜พ๐™ค๐™ข๐™ฅ๐™ก๐™ž๐™–๐™ฃ๐™˜๐™š by Jason Edwards and Griffin Weaver.

Andrew's review ๐Ÿ‘‰ https://cybercanon.org/the-cybersecurity-guide-to-governance-risk-and-compliance/

#CybersecurityBooks #GRC #CyberCanonHoFCandidate

0541 ฮคฮ™ฮ“ฮกฮ•ฮ™ฮฃ ฮคฮ—ฮฃ ฮ˜ฮ‘ฮ›ฮ‘ฮฃฮฃฮ‘ฮฃ -TIGRES DEL MAR-

Serie: Mar
Paรญs: GRC
Fab/Dist: TENCO, EXIN
Aรฑo: 1984

Mรกs info en: https://refstente.com/id/1318

#TENTE #RefsTENTE #TENCO #EXIN #Serie_Mar #GRC #Aรฑo_1984 #Marรญtimo #Militar #Mar_Militar #Color_Gris #Ref_0541

24 hours until the CfP for "Security BSides Knoxville 2026" closes: https://papercall.io/cfps/6517/submissions/new

#cfp #conference #Offensive security #Defensive security #Application security #Intelligence #Malware #Exploit development #Social engineering #Security management #Grc #Ciso #Dfir #Soc #Osint #Breaking into industry #Physical pen testing #Body hacking #Red team #Blue team #Human factors #Hardware #Soft skills #Management #Appsec #Ics/scada

PaperCall.io

Elodie is pretty sure no one here has been through this process (grc overseas route)?

She started (again) the application process yesterday, having finally got all the docs certified etc, only to find that there is no longer a specific overseas route form on the gov website.

She doesnโ€™t know when this changed ๐Ÿคฆโ€โ™€๏ธ๐Ÿคทโ€โ™€๏ธ

A search found a few references to the forms but all the links are broken.

Applying for the DE SBGG took months because the rules didnโ€™t understand the specific situation (the lovely lady at the Standesamt who was dealing with elodie was dogged in her determination tho ๐Ÿ’•)

Fuck ๐Ÿ˜ฟ

#grc
#transuk
Plz boost for coverage ๐Ÿ™๐Ÿฉต๐Ÿฉท๐Ÿค

Something shifted quietly in AI governance.
Colorado's AI Act gives organizations an affirmative defense if they can show compliance with the NIST AI Risk Management Framework or ISO 42001 โ€” meaning a voluntary framework now reduces legal liability.
For nonprofits and small teams, this reframes the question. It's not "do we have capacity for AI governance." It's "what does a defensible posture actually require."

https://www.linkedin.com/posts/carlosrmunozjr_aigovernance-aireadiness-grc-share-7437218111625490433-RQ90
#AIPolicy #GRC #Compliance

#aigovernance #aireadiness #grc #riskmanagement #compliance | Carlos Muรฑoz

Voluntary frameworks just became legal armor. That changes the math for every organization still treating AI governance as optional. Colorado's AI Act includes an affirmative defense clause. Organizations that can demonstrate compliance with the NIST AI Risk Management Framework โ€” a structured, government-developed tool for identifying and managing AI-related risks โ€” or ISO 42001, its international counterpart, can use that compliance to reduce liability exposure when a violation is discovered. That is not a policy recommendation. That is a statute. For years, the pitch for AI governance frameworks was built around trust, maturity, and "responsible AI." Legitimate arguments. But not urgent ones for a team of twelve running a nonprofit or a compliance lead at a regional SME already stretched thin. Here's what changes when a framework becomes a legal safe harbor: it stops being aspirational and starts being actuarial. The practical question isn't whether to implement. It's what a defensible posture actually requires โ€” documented controls, an AI impact assessment on record, clear human oversight responsibilities, evidence of continuous review. Not perfection. Defensibility. Colorado set this precedent. Other states are watching. What does your organization's AI governance posture look like if a regulator โ€” or a plaintiff's attorney โ€” asked to see it today? #AIGovernance #AIReadiness #GRC #RiskManagement #Compliance

LinkedIn