Skip to main content

Filed under

Compliance

  1. Security·8 min read·

    The Policy Is the Part That Moves

    A proved gate is only as good as the policy it enforces, and the policy is the part that changes while the agent is running. What OSCAL and the agent-authorization drafts both assume, and what breaks.

  2. Security·7 min read·

    The Firewall Stays Put. The Agent Improvises.

    Rewriting security controls for probabilistic agents. Static control catalogs assume systems that do what they're told; AI agents don't — so here's how to express agent guardrails (tool allowlists, secret-egress denial, audit) as machine-checkable OSCAL component definitions.

  3. AI·8 min read·

    Exploring Claude CLI Context and Compliance with My Standards Repository

    A CLAUDE.md is a prompt, not a loader. What a standards repository can and cannot enforce, and where the real enforcement has to live.

  4. Automation·10 min read·

    Vulnerability Management at Scale with Open Source Tools

    Build enterprise vulnerability management with open source: scanning, remediation tracking, and compliance using OpenVAS, Trivy, and Airflow.