<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:georss="http://www.georss.org/georss" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>DISC Infosec blog</title>
	<atom:link href="http://blog.deurainfosec.com/feed/" rel="self" type="application/rss+xml"/>
	<link>https://blog.deurainfosec.com/</link>
	<description>Dedicated to information security assurance&#13;
Information Security subject matter with related items</description>
	<lastBuildDate>Mon, 08 Jun 2026 16:28:31 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.1.10</generator>

<image>
	<url>https://blog.deurainfosec.com/wp-content/uploads/2023/05/disc-logo-144x144.jpg</url>
	<title>DISC InfoSec blog</title>
	<link>https://blog.deurainfosec.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">7400975</site>	<xhtml:meta content="noindex" name="robots" xmlns:xhtml="http://www.w3.org/1999/xhtml"/><item>
		<title>GRC at Machine Speed: Four Anchors Reshaping Governance in the Cloud and AI Era</title>
		<link>https://blog.deurainfosec.com/grc-at-machine-speed-four-anchors-reshaping-governance-in-the-cloud-and-ai-era/</link>
					<comments>https://blog.deurainfosec.com/grc-at-machine-speed-four-anchors-reshaping-governance-in-the-cloud-and-ai-era/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Mon, 08 Jun 2026 16:11:51 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Cloud computing]]></category>
		<category><![CDATA[GRC]]></category>
		<category><![CDATA[GRC at Machine Speed]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=35795</guid>

					<description><![CDATA[<p>GRC at Machine Speed: Four Anchors Reshaping Governance in the Cloud and AI Era For most of its history, Governance, Risk, and Compliance has run at the speed of paper. Spreadsheets tracked controls. Evidence arrived by email the week before an audit. Risk registers were reviewed quarterly, if that. The whole discipline was built around [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/grc-at-machine-speed-four-anchors-reshaping-governance-in-the-cloud-and-ai-era/" data-wpel-link="internal" target="_blank">GRC at Machine Speed: Four Anchors Reshaping Governance in the Cloud and AI Era</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/grc-at-machine-speed-four-anchors-reshaping-governance-in-the-cloud-and-ai-era/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">35795</post-id>	</item>
		<item>
		<title>AI Can Pentest Your Network Now. That’s Not the Risk You Should Worry About</title>
		<link>https://blog.deurainfosec.com/ai-can-pentest-your-network-now-thats-not-the-risk-you-should-worry-about/</link>
					<comments>https://blog.deurainfosec.com/ai-can-pentest-your-network-now-thats-not-the-risk-you-should-worry-about/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Fri, 05 Jun 2026 20:04:16 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Governance Tools]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[AI Governance tools]]></category>
		<category><![CDATA[Pentesting tools]]></category>
		<category><![CDATA[security tools]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=35769</guid>

					<description><![CDATA[<p>Two Open-Source AI Pentesting Tools, One Governance Question: What METATRON and PentestSwarm Mean for SMEs Frontier AI has removed that friction from both sides of the table simultaneously. The same reasoning capability that lets a model chain reconnaissance, classify findings, and suggest exploit paths is now available in open-source tooling that an SME can run [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/ai-can-pentest-your-network-now-thats-not-the-risk-you-should-worry-about/" data-wpel-link="internal" target="_blank">AI Can Pentest Your Network Now. That&#8217;s Not the Risk You Should Worry About</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/ai-can-pentest-your-network-now-thats-not-the-risk-you-should-worry-about/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">35769</post-id>	</item>
		<item>
		<title>GRC at Machine Speed: How AI Is Reshaping Governance, Risk, and Compliance</title>
		<link>https://blog.deurainfosec.com/grc-at-machine-speed-how-ai-is-reshaping-governance-risk-and-compliance/</link>
					<comments>https://blog.deurainfosec.com/grc-at-machine-speed-how-ai-is-reshaping-governance-risk-and-compliance/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Thu, 04 Jun 2026 15:28:43 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[GRC]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[and Compliance]]></category>
		<category><![CDATA[Governance]]></category>
		<category><![CDATA[Risk]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=35749</guid>

					<description><![CDATA[<p>AI is not simply another technology that GRC teams will govern — it will fundamentally reshape how GRC is practiced, measured, and delivered. From an AI governance perspective, the biggest shift over the next few years is that GRC will move from periodic, documentation-heavy activities toward continuous assurance. Traditional models built around annual assessments, point-in-time [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/grc-at-machine-speed-how-ai-is-reshaping-governance-risk-and-compliance/" data-wpel-link="internal" target="_blank">GRC at Machine Speed: How AI Is Reshaping Governance, Risk, and Compliance</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/grc-at-machine-speed-how-ai-is-reshaping-governance-risk-and-compliance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">35749</post-id>	</item>
		<item>
		<title>Building AI Governance That Actually Works: From Ethics to the Exam Room</title>
		<link>https://blog.deurainfosec.com/building-ai-governance-that-actually-works-from-ethics-to-the-exam-room/</link>
					<comments>https://blog.deurainfosec.com/building-ai-governance-that-actually-works-from-ethics-to-the-exam-room/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Wed, 03 Jun 2026 17:02:18 +0000</pubDate>
				<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[AI Ethics]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=35686</guid>

					<description><![CDATA[<p>Below is the HTML format of our post. Click to view it in a separate window Four risks, three frameworks, and what real-world mapping across ISO 27001, ISO 42001, and NIST 800-53 Rev. 5 actually looks like The AI Governance Quick-Start: Defensible in 10 Days, Not 4 Quarters DISC InfoSec is an active ISO 42001 [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/building-ai-governance-that-actually-works-from-ethics-to-the-exam-room/" data-wpel-link="internal" target="_blank">Building AI Governance That &lt;em&gt;Actually Works&lt;/em&gt;: From Ethics to the Exam Room</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/building-ai-governance-that-actually-works-from-ethics-to-the-exam-room/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">35686</post-id>	</item>
		<item>
		<title>Corporate Visibility as an Attack Surface: Managing Risk in the AI Era</title>
		<link>https://blog.deurainfosec.com/corporate-visibility-as-an-attack-surface-managing-risk-in-the-ai-era/</link>
					<comments>https://blog.deurainfosec.com/corporate-visibility-as-an-attack-surface-managing-risk-in-the-ai-era/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 16:12:28 +0000</pubDate>
				<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[Cyber Attack]]></category>
		<category><![CDATA[Security Risk Assessment]]></category>
		<category><![CDATA[Attack Surface]]></category>
		<category><![CDATA[Managing Risk]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=35634</guid>

					<description><![CDATA[<p>Corporate visibility has become a business requirement rather than a marketing choice. Organizations publish employee profiles, leadership pages, technical blogs, social links, and recruiting content to build trust, attract talent, and improve customer confidence. However, every piece of public information expands the organization’s attack surface and creates intelligence opportunities for adversaries. The challenge is no [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/corporate-visibility-as-an-attack-surface-managing-risk-in-the-ai-era/" data-wpel-link="internal" target="_blank">Corporate Visibility as an Attack Surface: Managing Risk in the AI Era</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/corporate-visibility-as-an-attack-surface-managing-risk-in-the-ai-era/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">35634</post-id>	</item>
		<item>
		<title>GRC Engineering Is the Future of Cloud Compliance</title>
		<link>https://blog.deurainfosec.com/grc-engineering-is-the-future-of-cloud-compliance/</link>
					<comments>https://blog.deurainfosec.com/grc-engineering-is-the-future-of-cloud-compliance/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 19:41:47 +0000</pubDate>
				<category><![CDATA[AWS Security]]></category>
		<category><![CDATA[Cloud computing]]></category>
		<category><![CDATA[GRC]]></category>
		<category><![CDATA[Cloud Compliance]]></category>
		<category><![CDATA[GRC Engineering]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=35611</guid>

					<description><![CDATA[<p>Most GRC material stays stuck at the policy and framework level. This book is one of the few that actually tries to push the discipline into something the industry has been struggling with for years: engineering governance, risk, and compliance as a system—not a documentation exercise. GRC ENGINEERING FOR AWS: A Hands-On Guide to Governance, [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/grc-engineering-is-the-future-of-cloud-compliance/" data-wpel-link="internal" target="_blank">GRC Engineering Is the Future of Cloud Compliance</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/grc-engineering-is-the-future-of-cloud-compliance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">35611</post-id>	</item>
		<item>
		<title>Four risks, three frameworks, and what real-world mapping across ISO 27001, ISO 42001, and NIST 800-53 Rev. 5 actually looks like</title>
		<link>https://blog.deurainfosec.com/four-risks-three-frameworks-and-what-real-world-mapping-across-iso-27001-iso-42001-and-nist-800-53-rev-5-actually-looks-like/</link>
					<comments>https://blog.deurainfosec.com/four-risks-three-frameworks-and-what-real-world-mapping-across-iso-27001-iso-42001-and-nist-800-53-rev-5-actually-looks-like/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 16:52:13 +0000</pubDate>
				<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[ISO 27k]]></category>
		<category><![CDATA[ISO 42001]]></category>
		<category><![CDATA[NIST CSF]]></category>
		<category><![CDATA[AI Risk Register]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=35506</guid>

					<description><![CDATA[<p>Your Risk Register Is Probably Built Backwards Four risks, three frameworks, and what mapping ISO 27001, ISO 42001, and NIST 800-53r5 actually looks like in practice. Most risk registers are built backwards. Someone exports a control list from a framework, generates a row for each control, and reverse-engineers a &#8220;risk&#8221; to justify it. The result [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/four-risks-three-frameworks-and-what-real-world-mapping-across-iso-27001-iso-42001-and-nist-800-53-rev-5-actually-looks-like/" data-wpel-link="internal" target="_blank">Four risks, three frameworks, and what real-world mapping across ISO 27001, ISO 42001, and NIST 800-53 Rev. 5 actually looks like</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/four-risks-three-frameworks-and-what-real-world-mapping-across-iso-27001-iso-42001-and-nist-800-53-rev-5-actually-looks-like/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">35506</post-id>	</item>
		<item>
		<title>The Bus Factor Just Inverted: Governing the Agents Your Engineers Leave Behind</title>
		<link>https://blog.deurainfosec.com/the-bus-factor-just-inverted-governing-the-agents-your-engineers-leave-behind/</link>
					<comments>https://blog.deurainfosec.com/the-bus-factor-just-inverted-governing-the-agents-your-engineers-leave-behind/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Thu, 28 May 2026 15:56:21 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[Selling cyber security]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[AI Agents]]></category>
		<category><![CDATA[Bus Factor]]></category>
		<category><![CDATA[CyberSecurity Confidence]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=35521</guid>

					<description><![CDATA[<p>Earning Cybersecurity Confidence in the Age of Agentic AI — A Practitioner&#8217;s Read Hrvoje Englman, CISO at Span, used his keynote at the Span Cyber Security Arena to describe a defender&#8217;s job that has been rewritten in roughly twenty-four months. Engineering teams are now writing their own software with AI coding assistants, spinning up agents [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/the-bus-factor-just-inverted-governing-the-agents-your-engineers-leave-behind/" data-wpel-link="internal" target="_blank">The Bus Factor Just Inverted: Governing the Agents Your Engineers Leave Behind</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/the-bus-factor-just-inverted-governing-the-agents-your-engineers-leave-behind/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">35521</post-id>	</item>
		<item>
		<title>ISO 42001 Just Got Easier to Prove: Anthropic Opens Claude to 28 Security and Compliance Tools</title>
		<link>https://blog.deurainfosec.com/iso-42001-just-got-easier-to-prove-anthropic-opens-claude-to-28-security-and-compliance-tools/</link>
					<comments>https://blog.deurainfosec.com/iso-42001-just-got-easier-to-prove-anthropic-opens-claude-to-28-security-and-compliance-tools/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Wed, 27 May 2026 16:09:23 +0000</pubDate>
				<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[ISO 42001]]></category>
		<category><![CDATA[Security Compliance]]></category>
		<category><![CDATA[Anthropic]]></category>
		<category><![CDATA[Claude security]]></category>
		<category><![CDATA[Compliance tools]]></category>
		<category><![CDATA[Evidence Layer]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=35469</guid>

					<description><![CDATA[<p>As enterprise adoption of generative AI accelerates, the operational gap between &#8220;AI as productivity tool&#8221; and &#8220;AI as governed enterprise application&#8221; has widened. Anthropic has moved to close that gap by introducing 28 integrations with security and compliance tools that allow IT and security teams to manage Claude in the same way they manage other [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/iso-42001-just-got-easier-to-prove-anthropic-opens-claude-to-28-security-and-compliance-tools/" data-wpel-link="internal" target="_blank">ISO 42001 Just Got Easier to Prove: Anthropic Opens Claude to 28 Security and Compliance Tools</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/iso-42001-just-got-easier-to-prove-anthropic-opens-claude-to-28-security-and-compliance-tools/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">35469</post-id>	</item>
		<item>
		<title>Modern GRC Maturity: Connecting Governance, Risk, Controls, and Technology</title>
		<link>https://blog.deurainfosec.com/modern-grc-maturity-connecting-governance-risk-controls-and-technology/</link>
					<comments>https://blog.deurainfosec.com/modern-grc-maturity-connecting-governance-risk-controls-and-technology/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Tue, 26 May 2026 15:27:25 +0000</pubDate>
				<category><![CDATA[GRC]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[GRC Layers]]></category>
		<category><![CDATA[GRC Maturity]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=35431</guid>

					<description><![CDATA[<p>The Six Layers of a Mature GRC Operating Model In today’s rapidly evolving business environment, Governance, Risk, and Compliance (GRC) can no longer operate as disconnected activities managed by separate teams and spreadsheets. Organizations facing cyber threats, AI risks, regulatory pressure, and operational complexity need a unified GRC operating model that connects governance, risk management, [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/modern-grc-maturity-connecting-governance-risk-controls-and-technology/" data-wpel-link="internal" target="_blank">Modern GRC Maturity: Connecting Governance, Risk, Controls, and Technology</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/modern-grc-maturity-connecting-governance-risk-controls-and-technology/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">35431</post-id>	</item>
		<item>
		<title>The One Security Book That Got Louder With Every Passing Year</title>
		<link>https://blog.deurainfosec.com/the-one-security-book-that-got-louder-with-every-passing-year/</link>
					<comments>https://blog.deurainfosec.com/the-one-security-book-that-got-louder-with-every-passing-year/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Fri, 22 May 2026 18:05:58 +0000</pubDate>
				<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Security Awareness]]></category>
		<category><![CDATA[Bruce Schneier]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=35435</guid>

					<description><![CDATA[<p>The One Security Book That Got Louder With Every Passing Year Why Click Here to Kill Everybody by Bruce Schneier belongs on every CISO&#8217;s, CAIO&#8217;s, and board director&#8217;s shelf — in that order There are security books you read once and shelve. And then there is Bruce Schneier&#8217;s Click Here to Kill Everybody, which somehow [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/the-one-security-book-that-got-louder-with-every-passing-year/" data-wpel-link="internal" target="_blank">The One Security Book That Got Louder With Every Passing Year</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/the-one-security-book-that-got-louder-with-every-passing-year/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">35435</post-id>	</item>
		<item>
		<title>Microsoft Just Made AI Agent Security a CI/CD Problem — Here’s Why That Matters</title>
		<link>https://blog.deurainfosec.com/microsoft-just-made-ai-agent-security-a-ci-cd-problem-heres-why-that-matters/</link>
					<comments>https://blog.deurainfosec.com/microsoft-just-made-ai-agent-security-a-ci-cd-problem-heres-why-that-matters/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Fri, 22 May 2026 15:16:06 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Governance Tools]]></category>
		<category><![CDATA[AI Agent]]></category>
		<category><![CDATA[AI Agent Security]]></category>
		<category><![CDATA[Clarity]]></category>
		<category><![CDATA[RAMPART]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=35354</guid>

					<description><![CDATA[<p>Microsoft Just Open-Sourced the Missing Piece of AI Agent Security: A Practitioner&#8217;s Take on RAMPART and Clarity On May 20, Microsoft&#8217;s AI Red Team released two open-source tools that should be on every CISO&#8217;s and AI program owner&#8217;s reading list this week: RAMPART, a continuous testing framework for AI agents, and Clarity, a structured design-review [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/microsoft-just-made-ai-agent-security-a-ci-cd-problem-heres-why-that-matters/" data-wpel-link="internal" target="_blank">Microsoft Just Made AI Agent Security a CI/CD Problem — Here&#8217;s Why That Matters</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/microsoft-just-made-ai-agent-security-a-ci-cd-problem-heres-why-that-matters/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">35354</post-id>	</item>
		<item>
		<title>Free AI Governance Maturity Calculator for Modern Enterprises</title>
		<link>https://blog.deurainfosec.com/free-ai-governance-maturity-calculator-for-modern-enterprises/</link>
					<comments>https://blog.deurainfosec.com/free-ai-governance-maturity-calculator-for-modern-enterprises/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Thu, 21 May 2026 20:54:16 +0000</pubDate>
				<category><![CDATA[AI Governance Tools]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Free AI Governance Maturity Calculator]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=35364</guid>

					<description><![CDATA[<p>AI adoption is accelerating — but most organizations still lack a clear way to measure whether their AI governance program is secure, compliant, and audit-ready. That’s why DISC InfoSec created the free AI Governance Maturity Calculator — a practical assessment tool designed to help organizations benchmark their AI governance capabilities against leading frameworks including ISO/IEC [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/free-ai-governance-maturity-calculator-for-modern-enterprises/" data-wpel-link="internal" target="_blank">Free AI Governance Maturity Calculator for Modern Enterprises</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/free-ai-governance-maturity-calculator-for-modern-enterprises/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">35364</post-id>	</item>
		<item>
		<title>Why ISO 42001 Will Be the Next SOC 2</title>
		<link>https://blog.deurainfosec.com/why-iso-42001-will-be-the-next-soc-2/</link>
					<comments>https://blog.deurainfosec.com/why-iso-42001-will-be-the-next-soc-2/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Thu, 21 May 2026 16:10:12 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[ISO 42001]]></category>
		<category><![CDATA[Gen AI Hype]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=35337</guid>

					<description><![CDATA[<p>The Quiet Truth in the Gen AI Hype: Governance Is the Product I just finished Generative AI and LLMs For Dummies — a solid primer aimed at executives and non-technical leaders trying to understand what they&#8217;ve already bought into. Most of it is what you&#8217;d expect: foundation models, transformers, prompt engineering, RAG, vector embeddings. But [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/why-iso-42001-will-be-the-next-soc-2/" data-wpel-link="internal" target="_blank">Why ISO 42001 Will Be the Next SOC 2</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/why-iso-42001-will-be-the-next-soc-2/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">35337</post-id>	</item>
		<item>
		<title>Managing AI Risk: A Practical Approach to Secure, Responsible, and Effective AI Adoption</title>
		<link>https://blog.deurainfosec.com/managing-ai-risk-a-practical-approach-to-secure-responsible-and-effective-ai-adoption/</link>
					<comments>https://blog.deurainfosec.com/managing-ai-risk-a-practical-approach-to-secure-responsible-and-effective-ai-adoption/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Wed, 20 May 2026 15:04:32 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[Managing AI Risk]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=35331</guid>

					<description><![CDATA[<p>Managing AI Risk: A Practical Approach to Secure, Responsible, and Effective AI Adoption Artificial Intelligence is transforming how organizations operate, compete, and innovate. From automating business workflows to enhancing cybersecurity detection and accelerating decision-making, AI offers enormous opportunities. Yet alongside these benefits comes a rapidly expanding landscape of risks that organizations can no longer ignore. [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/managing-ai-risk-a-practical-approach-to-secure-responsible-and-effective-ai-adoption/" data-wpel-link="internal" target="_blank">Managing AI Risk: A Practical Approach to Secure, Responsible, and Effective AI Adoption</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/managing-ai-risk-a-practical-approach-to-secure-responsible-and-effective-ai-adoption/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">35331</post-id>	</item>
	</channel>
</rss>