<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>DefenseLogix Blog</title>
    <link>https://www.defenselogix.com/blog/</link>
    <atom:link href="https://www.defenselogix.com/blog/feed.xml" rel="self" type="application/rss+xml" />
    <description>Articles on security leadership, audit readiness, email security, CMMC, and AI governance.</description>
    <language>en-us</language>
    <lastBuildDate>Wed, 23 Sep 2026 12:00:00 +0000</lastBuildDate>
    <item>
      <title>The Morgan Stanley Leak Wasn&#x27;t a Hack. That&#x27;s the Problem.</title>
      <link>https://www.defenselogix.com/blog/morgan-stanley-email-leak-dlp/</link>
      <guid isPermaLink="true">https://www.defenselogix.com/blog/morgan-stanley-email-leak-dlp/</guid>
      <pubDate>Wed, 23 Sep 2026 12:00:00 +0000</pubDate>
      <category>Data Protection</category>
      <description>An accidental email containing a live deal pipeline shows why access control alone is not enough, and why classification, DLP, encryption and endpoint controls have to work together.</description>
    </item>
    <item>
      <title>CMMC Level 2 readiness after the Phase 2 suspension.</title>
      <link>https://www.defenselogix.com/blog/cmmc-level-2-after-phase-2-suspension/</link>
      <guid isPermaLink="true">https://www.defenselogix.com/blog/cmmc-level-2-after-phase-2-suspension/</guid>
      <pubDate>Tue, 22 Sep 2026 12:00:00 +0000</pubDate>
      <category>CMMC</category>
      <description>The Department of War suspended CMMC Phase 2 on July 13, 2026, but Level 2 self-assessment and NIST SP 800-171 obligations remain in force. Five readiness gaps affect whether a contractor&#x27;s affirmation will hold up.</description>
    </item>
    <item>
      <title>MANAGE: Where AI Risk Management Earns Its Keep</title>
      <link>https://www.defenselogix.com/blog/nist-ai-rmf-manage-function/</link>
      <guid isPermaLink="true">https://www.defenselogix.com/blog/nist-ai-rmf-manage-function/</guid>
      <pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate>
      <category>AI Risk Management</category>
      <description>The MANAGE function of the NIST AI RMF explained: risk prioritization, deployment gates, AI incident response, vendor monitoring, and decommissioning.</description>
    </item>
    <item>
      <title>MEASURE: Working Is Not the Same as Trustworthy</title>
      <link>https://www.defenselogix.com/blog/nist-ai-rmf-measure-function/</link>
      <guid isPermaLink="true">https://www.defenselogix.com/blog/nist-ai-rmf-measure-function/</guid>
      <pubDate>Tue, 18 Aug 2026 12:00:00 +0000</pubDate>
      <category>AI Risk Management</category>
      <description>The MEASURE function of the NIST AI RMF explained: TEVV, bias and fairness testing, adversarial evaluation, drift monitoring, and documenting tradeoffs.</description>
    </item>
    <item>
      <title>MAP: Why Many AI Failures Are Context Failures</title>
      <link>https://www.defenselogix.com/blog/nist-ai-rmf-map-function/</link>
      <guid isPermaLink="true">https://www.defenselogix.com/blog/nist-ai-rmf-map-function/</guid>
      <pubDate>Tue, 04 Aug 2026 12:00:00 +0000</pubDate>
      <category>AI Risk Management</category>
      <description>The MAP function of the NIST AI RMF explained: intended use, AI system documentation, stakeholder impact analysis, and risk identification, including generative AI risks.</description>
    </item>
    <item>
      <title>GOVERN: The AI RMF Function That Decides Whether the Other Three Matter</title>
      <link>https://www.defenselogix.com/blog/nist-ai-rmf-govern-function/</link>
      <guid isPermaLink="true">https://www.defenselogix.com/blog/nist-ai-rmf-govern-function/</guid>
      <pubDate>Tue, 21 Jul 2026 12:00:00 +0000</pubDate>
      <category>AI Risk Management</category>
      <description>The GOVERN function of the NIST AI RMF explained: accountability, AI policy, risk tolerance, AI inventories, and third-party oversight, and the gap between paper and practice.</description>
    </item>
    <item>
      <title>What Is the NIST AI Risk Management Framework? A Plain-English Field Guide</title>
      <link>https://www.defenselogix.com/blog/what-is-nist-ai-rmf/</link>
      <guid isPermaLink="true">https://www.defenselogix.com/blog/what-is-nist-ai-rmf/</guid>
      <pubDate>Tue, 07 Jul 2026 12:00:00 +0000</pubDate>
      <category>AI Risk Management</category>
      <description>The NIST AI Risk Management Framework (AI RMF 1.0) explained: the four functions, the seven trustworthy AI characteristics, and how to start using it.</description>
    </item>
    <item>
      <title>Moving to DMARC enforcement without disrupting legitimate email.</title>
      <link>https://www.defenselogix.com/blog/dmarc-enforcement/</link>
      <guid isPermaLink="true">https://www.defenselogix.com/blog/dmarc-enforcement/</guid>
      <pubDate>Tue, 30 Jun 2026 12:00:00 +0000</pubDate>
      <category>Email Security</category>
      <description>Many organizations publish a DMARC record at p=none and never advance it. A sequenced approach, grounded in aggregate reports and sender alignment, allows a domain to reach enforcement with controlled risk.</description>
    </item>
    <item>
      <title>AI governance for regulated organizations: inventory, tiering, and oversight.</title>
      <link>https://www.defenselogix.com/blog/ai-governance-regulated-organizations/</link>
      <guid isPermaLink="true">https://www.defenselogix.com/blog/ai-governance-regulated-organizations/</guid>
      <pubDate>Tue, 19 May 2026 12:00:00 +0000</pubDate>
      <category>AI Risk Management</category>
      <description>An acceptable use policy alone does not establish AI governance. Regulated organizations need an AI system inventory, a risk-tiering rule, and an approval process aligned with the NIST AI Risk Management Framework.</description>
    </item>
    <item>
      <title>Audit evidence: designing controls that produce their own records.</title>
      <link>https://www.defenselogix.com/blog/audit-evidence-controls-that-produce-records/</link>
      <guid isPermaLink="true">https://www.defenselogix.com/blog/audit-evidence-controls-that-produce-records/</guid>
      <pubDate>Tue, 24 Mar 2026 12:00:00 +0000</pubDate>
      <category>Audit Readiness</category>
      <description>Audit findings frequently trace to missing operating records rather than weak control design. Building evidence into routine work prepares an organization for SOC 2 Type 2 examinations, HIPAA reviews, and NIST-based assessments.</description>
    </item>
    <item>
      <title>A 90-day plan for a fractional CISO engagement.</title>
      <link>https://www.defenselogix.com/blog/fractional-ciso-90-day-plan/</link>
      <guid isPermaLink="true">https://www.defenselogix.com/blog/fractional-ciso-90-day-plan/</guid>
      <pubDate>Tue, 10 Feb 2026 12:00:00 +0000</pubDate>
      <category>vCISO</category>
      <description>The first quarter of a fractional CISO engagement should establish accountability, document the organization&#x27;s obligations, and put core processes into operation. This plan outlines the priorities for each 30-day phase.</description>
    </item>
    <item>
      <title>The NIST AI Risk Management Framework: Safeguarding Your Organization in the Age of Artificial Intelligence</title>
      <link>https://www.defenselogix.com/blog/securing-the-future-how-nists-ai-risk-management-framework-protects-organizations/</link>
      <guid isPermaLink="true">https://www.defenselogix.com/blog/securing-the-future-how-nists-ai-risk-management-framework-protects-organizations/</guid>
      <pubDate>Wed, 26 Feb 2025 12:00:00 +0000</pubDate>
      <category>AI Risk Management</category>
      <description>AI introduces risks that traditional risk management approaches may not address. The NIST AI Risk Management Framework gives organizations a structured way to identify and mitigate them.</description>
    </item>
  </channel>
</rss>
