23 篇文章 · security
The SEC gives you four business days after you determine an incident is material. The hard part is the determination, and the record of how you made it.
ML-DSA and SLH-DSA are standardised. The harder question for regulated organisations is what happens to the integrity proofs you created before them.
On 21 September, the remaining FIPS 140-2 certificates move to historical status. The immediate impact is procurement.
Registration closes today. The incident reporting clock, the management accountability provisions, and the supervisory relationship all start tomorrow.
Residency requirements are usually implemented as a storage decision. Regulators increasingly care about a second question that storage location does not answer.
The Department of Defense paused Phase 2 in July and guidance is expected in mid-September. The pause is an opportunity, and the work that pays off either way is evidence work.
This month's releases are about control: getting deleted things back, deciding who can reach what from where, and labelling data so the platform can enforce the difference.
The 60-working-day registration window opened by CNCS closes in mid-September. Registering is the easy part - the evidence you keep afterwards is what an audit will actually test.
A successful restore tells you the backup worked. It doesn't tell you the data you just restored is actually clean.
关于数据完整性、合规与连续性的实用、可审计指南--发布即送达。