Compliance and Risk

Articles about compliance and risk from security operations practitioners.

Compliance and Risk

Mapping ISO 27001 to your SOC without double work

The ISO 27001-to-SOC crosswalk takes an afternoon. The decision that actually costs you is whether audit evidence gets generated by your production systems as a byproduct, or reconstructed by an analyst every audit cycle. I build for the first, so the evidence is a record of operations, not a second job.

DCDaniel C. · Sep 12, 2026
Compliance and Risk

ISO compliance mapping: from the SecOps seat

ISO 27001 mapping rarely begins with a missing SOC capability. The trigger is usually a customer request, a 93-control Annex A spreadsheet, and a harder question: can I prove what my SOC actually does? The answer lives in evidence, ownership, and an honest Statement of Applicability, not a SIEM screenshot.

DCDaniel C. · Aug 28, 2026
Compliance and Risk

NIST CSF 2.0: a SecOps-friendly read

Before last quarter's board prep, I re-cut our security operations budget against the six functions of NIST CSF 2.0. Detection tooling dominated the sheet; recovery had almost nothing against it, and governance wasn't even a line. Read as a checklist, the framework sends your budget in the wrong order.

DCDaniel C. · Jul 25, 2026
Compliance and Risk

Financial compliance controls most SOCs already have and don't get credit for

I sat through a GRC platform renewal two weeks before a PCI assessment, watched the dashboard go green, and then watched the assessor ask for evidence that lived entirely in my SOC. Financial compliance isn't a project you buy. Most of the controls a financial-sector audit tests already run in the SOC, which just never gets credit for them.

DCDaniel C. · Jul 17, 2026
Compliance and Risk

Financial services compliance from the SOC seat

I've run security operations at two companies with financial services compliance obligations. The regulatory frameworks were different, but the SOC's experience was consistent: we were the team that produced the evidence everyone else attested to, on timelines nobody had briefed us on before the audit.

DCDaniel C. · Jul 4, 2026
Compliance and Risk

Security questionnaires: A working shortcut for SOCs

The first security questionnaire is a research project; every one after that should be a lookup. Build a reusable evidence library once, route each section to its real owner, and stop answering the same encryption question from scratch every quarter.

DCDaniel C. · Jun 19, 2026

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

Compliance and Risk | Future of SecOps