All posts
Topic
Grc
2 articles on grc.
The Third-Party Risk Questionnaire: What to Ask and Why
Security questionnaires are the backbone of third-party risk management โ when they are focused. What to include, how to avoid questionnaire fatigue, and how to turn answers into decisions.
September 26, 2026
OWASP MCP Governance & Risk: Should You Let That MCP Server Into Your Environment?
A CISO guide to the OWASP MCP Governance & Risk Project: the four non-negotiable gates (owner, logging, scope, review), the Tier 0-4 classification, the eight-factor risk model, and how it maps to the OWASP MCP Top 10, LLM Top 10, NIST AI RMF, ISO 42001 and SOC 2. Plus a free tool that runs the check for a specific server.
September 7, 2026