38 篇文章 · compliance
The SEC gives you four business days after you determine an incident is material. The hard part is the determination, and the record of how you made it.
Twenty-three member states have transposed. Several have not, and seven have been referred to the Court of Justice. Multinational entities are compliance-planning against a moving target.
ML-DSA and SLH-DSA are standardised. The harder question for regulated organisations is what happens to the integrity proofs you created before them.
On 21 September, the remaining FIPS 140-2 certificates move to historical status. The immediate impact is procurement.
Registration closes today. The incident reporting clock, the management accountability provisions, and the supervisory relationship all start tomorrow.
Residency requirements are usually implemented as a storage decision. Regulators increasingly care about a second question that storage location does not answer.
The ESAs named their first critical ICT third-party providers. Most of the commentary focused on the providers. The more interesting consequences land on their customers.
The Department of Defense paused Phase 2 in July and guidance is expected in mid-September. The pause is an opportunity, and the work that pays off either way is evidence work.
Electricity operators are subject to a second, sector-specific cybersecurity regime that most NIS2 readiness programmes ignore entirely.
关于数据完整性、合规与连续性的实用、可审计指南--发布即送达。