Field Notes

Regulation, translated into SOC decisions.

No legal summaries — just what a new circular or direction actually changes about how a SOC should operate.

Reading Compliance Frameworks as a Maturity Roadmap, Not a Checklist

Most organisations treat frameworks like CERT-In Directions or ISO 27001 as a checklist. Mapped against SOC-CMM, they read more like a multi-year maturity roadmap.

Read more →

CERT-In Directions 2022: What a Six-Hour Reporting Clock Means for SOC Staffing

A six-hour incident reporting window is a SOC staffing and runbook problem before it is a compliance problem.

Read more →

Five SOC-CMM Domains, Explained for a Board That Has Ten Minutes

Business, People, Process, Technology, Services — a one-page translation of the SOC-CMM domains for a non-technical board audience.

Read more →

We use cookies for basic site function and, where ads are enabled, for advertising personalisation. See our Privacy Policy.