<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Governance on The Final Hour</title><link>https://lpri.me/tags/governance/</link><description>Recent content in Governance on The Final Hour</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 23 Jul 2026 06:24:09 +0000</lastBuildDate><atom:link href="https://lpri.me/tags/governance/index.xml" rel="self" type="application/rss+xml"/><item><title>Understanding Key Security Indicators (KSIs)</title><link>https://lpri.me/posts/ksi-key-security-indicators/</link><pubDate>Thu, 23 Jul 2026 06:24:09 +0000</pubDate><guid>https://lpri.me/posts/ksi-key-security-indicators/</guid><description>&lt;p&gt;FedRAMP 20X is sort of around the corner, switching from the old approach of framework reliance to the new evidence-based verification method. In plain English, instead of checking the Implemented box on the SSP, you now have to provide machine-readable evidence. There are 46 KSIs, and every one will require persistent evaluation. Start preparing now, because this process will become exponentially more expensive year over year. I have warned people about the inflation for over a decade; I have always been proven right.&lt;/p&gt;
&lt;p&gt;What if you don&amp;rsquo;t care about FedRAMP? If you want/need to be NIST compliant and/or you are taking your security posture seriously, you should start to implement at least a limited set of indicators now, targeting a full implementation by the end of 2027. This method of compliance testing is going to be the norm going forward.&lt;/p&gt;</description></item><item><title>Phase 2 of CMMC delayed. Again.</title><link>https://lpri.me/posts/tragedy-of-cmmc/</link><pubDate>Thu, 11 Jun 2026 12:24:09 +0000</pubDate><guid>https://lpri.me/posts/tragedy-of-cmmc/</guid><description>&lt;p&gt;Is this how Vladimir Putin feels? Expected a 3-day operation, but 5 years later you keep getting bombed?&lt;/p&gt;
&lt;p&gt;CMMC Stage 2 has been effectively canceled until further notice, and CMMC AB is on the verge of irrelevance, if not complete collapse.&lt;/p&gt;
&lt;p&gt;Fireside chats and refinery bombings will continue until morale improves&amp;hellip;&lt;/p&gt;</description></item><item><title>AI is not your friend</title><link>https://lpri.me/posts/ai-is-not-your-friend/</link><pubDate>Mon, 04 May 2026 16:24:09 +0000</pubDate><guid>https://lpri.me/posts/ai-is-not-your-friend/</guid><description>&lt;p&gt;Jer Crane is the founder of PocketOS.&lt;/p&gt;
&lt;p&gt;He is also someone who has no idea how LLMs work and should not be allowed near a production environment until he learns.&lt;/p&gt;
&lt;p&gt;Instead of focusing on the (many) errors in judgment, I instead look at how basic AI governance would have prevented this comedy of errors.&lt;/p&gt;</description></item><item><title>HOWTO: Teach users to correctly pick a Sensitivity Label</title><link>https://lpri.me/posts/3am-sensitivity-labels/</link><pubDate>Sat, 11 Apr 2026 20:17:03 +0000</pubDate><guid>https://lpri.me/posts/3am-sensitivity-labels/</guid><description>&lt;p&gt;Teaching users how to correctly choose a sensitivity label is one of the most critical parts of any Microsoft Purview implementation.&lt;/p&gt;
&lt;p&gt;The labels themselves may be technically configured correctly, but the deployment will still fail if users do not understand how to apply them. First impressions matter. The process needs to feel simple, predictable, and easy to explain, even when the underlying classification model is not always intuitive.&lt;/p&gt;
&lt;p&gt;I have always used what I call the Sensitivity/Audience Rule.&lt;/p&gt;</description></item><item><title>3:00AM SOC2 is useless so now what?</title><link>https://lpri.me/posts/3am-soc2-is-useless/</link><pubDate>Sat, 11 Apr 2026 12:24:09 +0000</pubDate><guid>https://lpri.me/posts/3am-soc2-is-useless/</guid><description>&lt;p&gt;It&amp;rsquo;s 3:00 AM and a client CIO is absolutely raging mad. I can almost feel little bits of spit hitting me through the monitor as she screams into her laptop (they now require face-to-face communications). Vendors are submitting vibe-coded reports that are so uniformly bad that you can easily identify Claude vs. ChatGPT down to the model version.&lt;/p&gt;
&lt;p&gt;I know why I am on this call. Why are there 8 other people here?&lt;/p&gt;</description></item></channel></rss>