Knowledge Hub
The hard parts, written down.
Practical writing on security, risk, compliance and architecture — from the people who do this work inside enterprise and government programs. Detail over commentary, and sources you can check.
What we write about
- Cloud security
- AI security & governance
- Security architecture
- Risk & compliance
- Privacy
- Audit & assurance
Latest
Cloud Security Assessment and Authorization in the Government of Canada
From security categorization to authority to operate — how the CCCS process actually fits together
Read the article →In this article
- The Nine Steps Behind Every Cloud Authorization
- Step 1 — Security Categorization Comes First
- Step 2 — Selecting the Cloud Control Profile
- Step 3 — Deployment and Service Models
- Who Assesses What
All articles
1
Topics
No articles under that topic yet — try another.
Want this applied to your own program?
We'll walk your control library, obligations and evidence through CtrlFort Assess in a 30-minute working session — no slideware.