<?xml version="1.0" encoding="UTF-8"?>
<!-- Generated by scripts/build-blog.mjs — run `npm run blog` to refresh. -->
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>CtrlFort Knowledge Hub</title>
    <link>https://ctrlfort.com/blog/</link>
    <description>Practical writing on security, risk, compliance and architecture — from the people who do this work inside enterprise and government programs. Detail over commentary, and sources you can check.</description>
    <language>en-ca</language>
    <copyright>© 2026 CtrlFort Inc.</copyright>
    <atom:link href="https://ctrlfort.com/feed.xml" rel="self" type="application/rss+xml"/>
    <lastBuildDate>Mon, 24 Aug 2026 09:00:00 GMT</lastBuildDate>
    <item>
      <title>Cloud Security Assessment and Authorization in the Government of Canada</title>
      <link>https://ctrlfort.com/blog/cloud-security-assessment-and-authorization</link>
      <guid isPermaLink="true">https://ctrlfort.com/blog/cloud-security-assessment-and-authorization</guid>
      <pubDate>Mon, 24 Aug 2026 09:00:00 GMT</pubDate>
      <dc:creator>Zeeshan Mahmood</dc:creator>
      <description>A practitioner&#39;s walkthrough of the CCCS cloud security assessment and authorization process — the nine steps, cloud control profiles, CSP versus client assessments, reading third-party attestations, and getting to an authority to operate.</description>
      <category>Cloud Security</category>
      <category>Government of Canada</category>
      <category>Security Assessment</category>
    </item>
  </channel>
</rss>
