The Audit Defense Library

Practitioner-depth analysis across federal and private compliance: FISMA and NIST RMF, FedRAMP, CMMC, federal AI governance, SOC 2, AI governance, cybersecurity, and GRC engineering. Written by a CPA, CISSP, CISA with Big 4 audit experience.

All FISMA & NIST RMF FedRAMP CMMC Federal AI Governance GovCon Compliance Federal Cybersecurity Federal Zero Trust Federal GRC Engineering AI Governance GRC Engineering Cybersecurity Cloud Security HIPAA SOC 2
AI Governance

EU AI Act Prohibited AI Practices: Eight Bans Now, Two More From December 2026

Updated August 30, 2026: Article 5 is no longer a closed list. Regulation (EU) 2026/1744, in force since July 27, 2026, adds two further prohibited practices, both applying from December 2, 2026. The eight bans...

Read the Guide
Cloud Security

Cloud Shared Responsibility Model: Where Your Compliance Obligation Begins

Most security and compliance leaders know their cloud provider carries SOC 2 Type II and ISO 27001 certifications. Many assume those certifications cover their organization's compliance obligations. They do not. AWS's SOC 2 report attests...

Read the Guide
GRC Engineering

Cyber Risk Quantification with the FAIR Model: From Heat Maps to Dollar Amounts

Every risk assessment I reviewed during my first decade in technology risk and cybersecurity consulting ended the same way: a heat map. Red squares in the upper-right corner. Yellow squares cascading down the middle. Green...

Read the Guide
Cybersecurity

CMMC 2.0 Compliance Guide: What Defense Contractors Still Have to Do

Updated July 30, 2026: On July 13, 2026 the Department of War suspended CMMC Phase II, which had been scheduled for November 10, 2026. Phase I self-assessment requirements, DFARS 252.204-7012, NIST SP 800-171 Rev 2,...

Read the Guide
AI Governance

AI Governance Board Reporting: What CISOs Present to the Board in 2026

Among the 85% of enterprises planning moderate-to-significant AI deployment, only 21% report mature AI governance programs [Deloitte State of AI in the Enterprise, 8th Edition, 2026, n=3,235]. That figure is not surprising in isolation. What...

Read the Guide
GRC Engineering

GRC Automation ROI: Building the Business Case for Engineering-Led Compliance

Organization A runs its compliance program the way most organizations do. A compliance manager owns a spreadsheet of 180 controls across SOC 2 and HIPAA. Every 90 days, she emails 14 system owners asking for...

Read the Guide
Cloud Security

Cloud Security Compliance Frameworks: CSA CCM, ISO 27017, and SOC 2 Mapped for Multi-Cloud

How many cloud security compliance frameworks apply to your organization right now? Not the ones your CISO listed in the last board presentation. All of them. The framework your AWS environment technically falls under because...

Read the Guide
AI Governance

AI Incident Response Plan: When AI Systems Fail, Your Cybersecurity Playbook Won’t Help

How fast does your organization respond when an AI system produces a discriminatory hiring decision? Not a cybersecurity breach. Not a data exfiltration event. A model that screened out 34% of qualified female candidates for...

Read the Guide
GRC Engineering

Programmatic Control Testing: Writing Automated Tests for Security Controls

Every SOC 2 audit I have reviewed in the last two years shares the same evidence problem. The controls exist. The policies are documented. The tools are deployed. And the proof that those controls actually...

Read the Guide
AI Governance

EU AI Act and GDPR: Where Data Protection and AI Regulation Overlap

When GDPR enforcement began in May 2018, most organizations treated the regulation as a data protection exercise: update the privacy policy, appoint a DPO, build a consent mechanism. The fines were theoretical. Four years later,...

Read the Guide
GRC Engineering

Compliance Gates in CI/CD Pipelines: Blocking Non-Compliant Deployments

Organization A deploys to production through a CI/CD pipeline with branch protection, automated SAST scans, and policy gates at three stages. Every deployment generates an immutable log: who approved, what changed, which tests passed, and...

Read the Guide
GRC Engineering

NIST OSCAL: Machine-Readable Compliance Documentation for Automated Audits

A GRC engineer at a federal contractor opens FedRAMP's RFC-0024 notice in January 2026. The notice requires machine-readable authorization submissions for new FedRAMP provider submissions. Her organization's System Security Plan is a 487-page Word document....

Read the Guide
The Authority Brief

One compliance analysis per week from Josef Kamara, CPA, CISSP, CISA. Federal and private compliance, written for practitioners.