<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SentinelPanda Insights</title>
    <link>https://sentinelpanda.com/insights</link>
    <atom:link href="https://sentinelpanda.com/insights/rss.xml" rel="self" type="application/rss+xml" />
    <description>Practical guides on PCI DSS, SOC 2, ISO 27001, HIPAA, NIST CSF, ISO 42001, and COBIT — from the SentinelPanda team.</description>
    <language>en-us</language>
    <lastBuildDate>Sat, 20 Jun 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>COBIT 2019 focus areas</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-focus-areas</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-focus-areas</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Focus areas are how COBIT zooms in on a topic — cybersecurity, DevOps, cloud — without abandoning the core model. They are the framework's specialised lenses.]]></description>
    </item>
    <item>
      <title>COBIT 2019 vs COBIT 5: what changed</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-vs-cobit-5</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-vs-cobit-5</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[COBIT 2019 is an evolution of COBIT 5, not a revolution — but design factors and focus areas made it genuinely more tailorable.]]></description>
    </item>
    <item>
      <title>COBIT 2019 vs the NIST CSF</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-vs-nist-csf</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-vs-nist-csf</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[COBIT governs IT broadly; the NIST CSF governs cybersecurity risk specifically. One is the wide governance frame, the other a focused security lens that slots inside it.]]></description>
    </item>
    <item>
      <title>COBIT 2019 performance management</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-performance-management</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-performance-management</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[You cannot improve governance you do not measure. COBIT Performance Management is how the framework turns "are we governing well?" into a number you can track.]]></description>
    </item>
    <item>
      <title>Roles and RACI charts in COBIT 2019</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-roles-and-raci</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-roles-and-raci</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Governance fails on ambiguity about who owns what. COBIT's RACI charts make responsibility explicit — for every objective, who is Responsible, Accountable, Consulted, Informed.]]></description>
    </item>
    <item>
      <title>COBIT 2019 for small business</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-for-small-business</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-for-small-business</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[COBIT is not only for big enterprises — its tailoring model is exactly what lets a small company take the parts that matter and leave the rest.]]></description>
    </item>
    <item>
      <title>Using the COBIT 2019 Design Guide</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-design-guide</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-design-guide</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The Design Guide is COBIT's instructions for making it yours — a workflow that turns generic objectives into a governance system shaped to your context.]]></description>
    </item>
    <item>
      <title>COBIT 2019 enterprise and alignment goals</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-enterprise-goals</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-enterprise-goals</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The enterprise and alignment goals are COBIT's shared vocabulary for "what the business wants" and "what IT must deliver" — the rungs of the goals cascade.]]></description>
    </item>
    <item>
      <title>COBIT 2019 explained</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-explained</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-explained</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[COBIT is not a security framework — it is a governance framework for enterprise IT. It answers "is IT delivering value and managed well," not "are we secure."]]></description>
    </item>
    <item>
      <title>The COBIT 2019 principles</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-principles</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-principles</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[COBIT 2019 rests on two sets of principles — one for what a good governance system looks like, one for the framework itself. They are the philosophy behind the structure.]]></description>
    </item>
    <item>
      <title>The COBIT 2019 goals cascade</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-goals-cascade</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-goals-cascade</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The goals cascade is COBIT's answer to "why are we doing this IT thing?" — it traces every IT objective back to an enterprise goal and a stakeholder need.]]></description>
    </item>
    <item>
      <title>The five COBIT 2019 domains</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-domains-overview</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-domains-overview</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[COBIT's 40 objectives live in five domains — one for governance, four for management. Knowing the domains is the map to the whole framework.]]></description>
    </item>
    <item>
      <title>COBIT 2019 EDM domain (Evaluate, Direct, Monitor)</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-edm-domain</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-edm-domain</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[EDM is the governance domain — the only one that is the board's job, not management's. It is where COBIT's governance/management split becomes concrete.]]></description>
    </item>
    <item>
      <title>COBIT 2019 APO domain (Align, Plan, Organise)</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-apo-domain</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-apo-domain</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[APO is where IT gets its act together before building anything — strategy, architecture, risk, and the planning that the build-and-run domains depend on.]]></description>
    </item>
    <item>
      <title>COBIT 2019 BAI domain (Build, Acquire, Implement)</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-bai-domain</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-bai-domain</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[BAI is where COBIT's plans become real systems — programs, projects, changes, and the discipline of implementing them without breaking what works.]]></description>
    </item>
    <item>
      <title>COBIT 2019 DSS domain (Deliver, Service, Support)</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-dss-domain</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-dss-domain</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[DSS is the keep-the-lights-on domain — operations, service desk, incidents, and the security services that run every day, not just on audit day.]]></description>
    </item>
    <item>
      <title>COBIT 2019 MEA domain (Monitor, Evaluate, Assess)</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-mea-domain</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-mea-domain</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[MEA is the domain that checks the others — performance, internal control, and compliance. It is how COBIT closes the loop and feeds governance with evidence.]]></description>
    </item>
    <item>
      <title>COBIT 2019 governance and management objectives</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-objectives</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-objectives</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[COBIT's 40 objectives are the framework's working units. You do not implement all of them equally — you prioritise the ones your goals and risk demand.]]></description>
    </item>
    <item>
      <title>COBIT 2019 governance components</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-components</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-components</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Components are COBIT's recognition that governance is not just process — it is also structures, culture, skills, and information working together.]]></description>
    </item>
    <item>
      <title>Implementing COBIT 2019</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-implementation</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-implementation</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[You do not "install" COBIT — you improve toward it, one prioritised cycle at a time. The implementation guide is about change management as much as governance.]]></description>
    </item>
    <item>
      <title>COBIT 2019 vs ITIL</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-vs-itil</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-vs-itil</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[COBIT governs IT; ITIL runs IT services. They are complementary layers, not competitors — COBIT sets the what and why, ITIL the how of service delivery.]]></description>
    </item>
    <item>
      <title>COBIT 2019 vs ISO 27001</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-vs-iso-27001</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-vs-iso-27001</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[COBIT is broad IT governance; ISO 27001 is deep information security. One is wide and shallow, the other narrow and deep — and they map together.]]></description>
    </item>
    <item>
      <title>An ISO 42001 readiness checklist</title>
      <link>https://sentinelpanda.com/insights/iso-42001-readiness-checklist</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-readiness-checklist</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[ISO 42001 looks large until you list it out. For most organisations it is an AI inventory, a risk and impact assessment, the AI-specific controls, and the management machinery.]]></description>
    </item>
    <item>
      <title>Getting started with ISO 42001</title>
      <link>https://sentinelpanda.com/insights/iso-42001-getting-started</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-getting-started</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Start where the risk is: inventory your AI, assess it, and build the management system around the systems that actually matter.]]></description>
    </item>
    <item>
      <title>The ISO 42001 AI risk assessment</title>
      <link>https://sentinelpanda.com/insights/iso-42001-risk-assessment</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-risk-assessment</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[An AI risk assessment looks outward in a way a security one does not — at the people the system affects, not just the assets it runs on.]]></description>
    </item>
    <item>
      <title>AI system impact assessment under ISO 42001</title>
      <link>https://sentinelpanda.com/insights/iso-42001-impact-assessment</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-impact-assessment</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The impact assessment is where AI governance gets serious about people — documenting who a system affects and how, before it affects them.]]></description>
    </item>
    <item>
      <title>Data governance under ISO 42001</title>
      <link>https://sentinelpanda.com/insights/iso-42001-data-governance</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-data-governance</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[ISO 42001 puts data governance at the centre because most AI risk is really data risk wearing a model's clothes.]]></description>
    </item>
    <item>
      <title>Transparency requirements in ISO 42001</title>
      <link>https://sentinelpanda.com/insights/iso-42001-transparency</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-transparency</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Transparency is the control that makes the others possible — you cannot oversee, contest, or trust an AI system you are kept in the dark about.]]></description>
    </item>
    <item>
      <title>Human oversight under ISO 42001</title>
      <link>https://sentinelpanda.com/insights/iso-42001-human-oversight</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-human-oversight</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[ISO 42001, like the EU AI Act, wants humans who can actually understand and override AI — not ones who reflexively approve whatever the model says.]]></description>
    </item>
    <item>
      <title>The AI system lifecycle in ISO 42001</title>
      <link>https://sentinelpanda.com/insights/iso-42001-lifecycle</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-lifecycle</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[AI risk is not a launch-day event — it shifts across the lifecycle. ISO 42001 governs the whole arc, not just the model you shipped.]]></description>
    </item>
    <item>
      <title>The ISO 42001 statement of applicability</title>
      <link>https://sentinelpanda.com/insights/iso-42001-statement-of-applicability</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-statement-of-applicability</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The applicability statement is where you justify your AI control set — which Annex A controls you apply, which you do not, and why.]]></description>
    </item>
    <item>
      <title>ISO 42001 internal audit</title>
      <link>https://sentinelpanda.com/insights/iso-42001-internal-audit</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-internal-audit</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[You audit your own AIMS before the certification body does — and an AI audit asks questions a security audit never would.]]></description>
    </item>
    <item>
      <title>ISO 42001 management review</title>
      <link>https://sentinelpanda.com/insights/iso-42001-management-review</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-management-review</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The management review is where leadership owns AI risk on the record — and given how fast AI moves, it is a review that actually has news.]]></description>
    </item>
    <item>
      <title>AI objectives and measurement in ISO 42001</title>
      <link>https://sentinelpanda.com/insights/iso-42001-objectives</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-objectives</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Responsible-AI goals you cannot measure are slogans. ISO 42001 asks for AI objectives with numbers — and proof you watch them.]]></description>
    </item>
    <item>
      <title>Continual improvement in an AI management system</title>
      <link>https://sentinelpanda.com/insights/iso-42001-continual-improvement</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-continual-improvement</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[AI changes fast, so an AIMS that stands still falls behind. Continual improvement is the engine that keeps governance current with the technology.]]></description>
    </item>
    <item>
      <title>Third-party AI under ISO 42001</title>
      <link>https://sentinelpanda.com/insights/iso-42001-third-party-ai</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-third-party-ai</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[ISO 42001 does not only govern the AI you build — it governs the AI you buy, which for most organisations is most of it.]]></description>
    </item>
    <item>
      <title>How much does ISO 42001 cost?</title>
      <link>https://sentinelpanda.com/insights/iso-42001-cost</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-cost</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[ISO 42001 costs scale with how much AI you actually govern. A company consuming one AI API is a very different number from one building models.]]></description>
    </item>
    <item>
      <title>Defining your ISO 42001 scope</title>
      <link>https://sentinelpanda.com/insights/iso-42001-scope</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-scope</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Your AIMS scope decides which AI the certificate actually covers. Scope to the AI that matters — buyers and regulators read the boundary.]]></description>
    </item>
    <item>
      <title>Risk assessment in the NIST CSF</title>
      <link>https://sentinelpanda.com/insights/nist-csf-risk-assessment</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-risk-assessment</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Risk assessment is where the CSF stops listing assets and starts deciding what to worry about — the input that makes the whole program risk-based.]]></description>
    </item>
    <item>
      <title>Access control in the NIST CSF</title>
      <link>https://sentinelpanda.com/insights/nist-csf-access-control</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-access-control</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Access control is the highest-value cluster in Protect, and it is the same MFA-and-least-privilege work every other framework asks for.]]></description>
    </item>
    <item>
      <title>Data security in the NIST CSF</title>
      <link>https://sentinelpanda.com/insights/nist-csf-data-security</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-data-security</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Data security in the CSF is the CIA triad applied to your data — and it leans on the encryption and classification you build for every other framework.]]></description>
    </item>
    <item>
      <title>Continuous monitoring in the NIST CSF</title>
      <link>https://sentinelpanda.com/insights/nist-csf-continuous-monitoring</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-continuous-monitoring</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Continuous monitoring is the difference between detecting an incident and being told about it by a customer. It is the engine of the Detect function.]]></description>
    </item>
    <item>
      <title>NIST CSF categories and subcategories, explained</title>
      <link>https://sentinelpanda.com/insights/nist-csf-categories-and-subcategories</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-categories-and-subcategories</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The functions are the headlines; the categories and subcategories are where the actual work lives. Understanding the structure is how you use the CSF.]]></description>
    </item>
    <item>
      <title>NIST CSF informative references</title>
      <link>https://sentinelpanda.com/insights/nist-csf-informative-references</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-informative-references</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Informative references are why the CSF is a great organising layer: each outcome points to the 800-53, ISO 27001, and other controls that achieve it.]]></description>
    </item>
    <item>
      <title>Using the NIST CSF quick-start guides</title>
      <link>https://sentinelpanda.com/insights/nist-csf-quick-start-guides</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-quick-start-guides</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The quick-start guides are NIST meeting you where you are — short, audience-specific on-ramps into a framework that can otherwise feel abstract.]]></description>
    </item>
    <item>
      <title>What is an AI Management System? ISO 42001 explained</title>
      <link>https://sentinelpanda.com/insights/iso-42001-aims-explained</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-aims-explained</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[ISO 42001 does for AI what ISO 27001 did for security: a certifiable management system for governing it responsibly across its lifecycle.]]></description>
    </item>
    <item>
      <title>ISO 42001 vs ISO 27001</title>
      <link>https://sentinelpanda.com/insights/iso-42001-vs-iso-27001</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-vs-iso-27001</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Same management-system DNA, different subject. ISO 27001 governs your information security; ISO 42001 governs your AI — and they slot together.]]></description>
    </item>
    <item>
      <title>The ISO 42001 certification process</title>
      <link>https://sentinelpanda.com/insights/iso-42001-certification</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-certification</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[If you have certified to ISO 27001, ISO 42001 certification will feel familiar — the same two-stage audit, applied to your AI management system.]]></description>
    </item>
    <item>
      <title>ISO 42001 Annex A controls</title>
      <link>https://sentinelpanda.com/insights/iso-42001-annex-a-controls</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-annex-a-controls</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[ISO 42001's Annex A is the AI-governance control set — the concrete things you do to manage AI responsibly, selected to fit your risk.]]></description>
    </item>
    <item>
      <title>Writing an AI policy for ISO 42001</title>
      <link>https://sentinelpanda.com/insights/iso-42001-ai-policy</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-ai-policy</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The AI policy is the apex document of your AI management system — leadership's statement of intent that every AI control hangs from.]]></description>
    </item>
    <item>
      <title>ISO 42001 for startups</title>
      <link>https://sentinelpanda.com/insights/iso-42001-for-startups</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-for-startups</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[For an AI-first startup, ISO 42001 can be an early differentiator — if you keep the management system lean and tie it to the AI you actually ship.]]></description>
    </item>
    <item>
      <title>The NIST CSF Identify function</title>
      <link>https://sentinelpanda.com/insights/nist-csf-identify-function</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-identify-function</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[You cannot protect what you have not identified. The Identify function is the inventory-and-understanding work the rest of the CSF builds on.]]></description>
    </item>
    <item>
      <title>The NIST CSF Protect function</title>
      <link>https://sentinelpanda.com/insights/nist-csf-protect-function</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-protect-function</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Protect is the function with the most controls — the safeguards that keep an incident from happening or contain it when it does.]]></description>
    </item>
    <item>
      <title>The NIST CSF Detect function</title>
      <link>https://sentinelpanda.com/insights/nist-csf-detect-function</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-detect-function</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Prevention fails eventually. Detect is the function that decides whether you notice in minutes or read about it in the news months later.]]></description>
    </item>
    <item>
      <title>The NIST CSF Respond function</title>
      <link>https://sentinelpanda.com/insights/nist-csf-respond-function</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-respond-function</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Respond is incident response by another name. The function asks whether you have a plan, follow it, and communicate — not whether you panic well.]]></description>
    </item>
    <item>
      <title>The NIST CSF Recover function</title>
      <link>https://sentinelpanda.com/insights/nist-csf-recover-function</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-recover-function</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Recover is the function that gets you back to normal — and proves, through testing, that you actually can.]]></description>
    </item>
    <item>
      <title>What is new in NIST CSF 2.0</title>
      <link>https://sentinelpanda.com/insights/nist-csf-2-0-whats-new</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-2-0-whats-new</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[CSF 2.0's headline is Govern — a sixth function that reframes cybersecurity from a technical checklist into an enterprise-risk discipline.]]></description>
    </item>
    <item>
      <title>Getting started with the NIST CSF</title>
      <link>https://sentinelpanda.com/insights/nist-csf-getting-started</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-getting-started</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The CSF does not hand you a to-do list. The way in is a current profile, a target profile, and the gap between them.]]></description>
    </item>
    <item>
      <title>NIST CSF for small business</title>
      <link>https://sentinelpanda.com/insights/nist-csf-for-small-business</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-for-small-business</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[CSF 2.0 was rewritten with small businesses in mind. Used right, it is a flexible, free way to build a real security program without a compliance budget.]]></description>
    </item>
    <item>
      <title>NIST CSF current and target profiles</title>
      <link>https://sentinelpanda.com/insights/nist-csf-current-and-target-profiles</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-current-and-target-profiles</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The profile is the CSF's core mechanic: describe where you are, where you want to be, and let the gap write your roadmap.]]></description>
    </item>
    <item>
      <title>Running a NIST CSF gap assessment</title>
      <link>https://sentinelpanda.com/insights/nist-csf-gap-assessment</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-gap-assessment</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A CSF gap assessment is just the current profile meeting the target profile — and writing down everything in between.]]></description>
    </item>
    <item>
      <title>NIST CSF vs NIST 800-53</title>
      <link>https://sentinelpanda.com/insights/nist-csf-vs-nist-800-53</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-vs-nist-800-53</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The CSF is the map; 800-53 is the parts catalogue. Most companies use the CSF to organise and 800-53 (if at all) for control detail.]]></description>
    </item>
    <item>
      <title>NIST CSF vs SOC 2</title>
      <link>https://sentinelpanda.com/insights/nist-csf-vs-soc-2</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-vs-soc-2</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The CSF helps you build a security program; SOC 2 proves it to customers. One is the work, the other is the receipt buyers ask for.]]></description>
    </item>
    <item>
      <title>Supply-chain risk in the NIST CSF</title>
      <link>https://sentinelpanda.com/insights/nist-csf-supply-chain-risk</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-supply-chain-risk</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[CSF 2.0 moved supply-chain risk to the front, into Govern — because for most organisations, the biggest risks now run through their vendors.]]></description>
    </item>
    <item>
      <title>Asset management in the NIST CSF</title>
      <link>https://sentinelpanda.com/insights/nist-csf-asset-management</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-asset-management</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Asset management is the least glamorous and most foundational CSF outcome. Skip it and every other function has blind spots.]]></description>
    </item>
    <item>
      <title>Validating and evaluating AI systems before deployment</title>
      <link>https://sentinelpanda.com/insights/ai-validation-and-evaluation</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-validation-and-evaluation</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Monitoring tells you how the model behaves in production. Validation is meant to stop the worst behaviour from getting there in the first place.]]></description>
    </item>
    <item>
      <title>Building an AI system inventory</title>
      <link>https://sentinelpanda.com/insights/ai-system-inventory</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-system-inventory</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Every AI governance framework starts the same way: know what AI you actually run. The inventory is the map the rest of governance draws on.]]></description>
    </item>
    <item>
      <title>Classifying AI system risk</title>
      <link>https://sentinelpanda.com/insights/ai-risk-classification</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-risk-classification</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A spam filter and a hiring model are not the same risk. AI governance, like security, is risk-based — classify first, then spend effort where the stakes are.]]></description>
    </item>
    <item>
      <title>Standing up an AI governance committee</title>
      <link>https://sentinelpanda.com/insights/ai-governance-committee</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-governance-committee</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[AI decisions cut across legal, security, product, and data. A governance committee is how you stop those decisions from falling through the cracks between them.]]></description>
    </item>
    <item>
      <title>Writing an AI acceptable use policy</title>
      <link>https://sentinelpanda.com/insights/ai-acceptable-use-policy</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-acceptable-use-policy</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Your team is already pasting things into AI tools. An AI acceptable use policy is how you make sure customer data and secrets are not among them.]]></description>
    </item>
    <item>
      <title>Shadow AI: governing ungoverned AI use</title>
      <link>https://sentinelpanda.com/insights/ai-shadow-usage</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-shadow-usage</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Shadow AI is shadow IT on fast-forward. The tools are free, instantly adopted, and hungry for exactly the data you most need to protect.]]></description>
    </item>
    <item>
      <title>Data governance for AI systems</title>
      <link>https://sentinelpanda.com/insights/ai-data-governance</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-data-governance</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Garbage in, liability out. The EU AI Act and ISO 42001 both put data governance at the centre — because most AI risk traces back to the data.]]></description>
    </item>
    <item>
      <title>AI bias and fairness in practice</title>
      <link>https://sentinelpanda.com/insights/ai-bias-and-fairness</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-bias-and-fairness</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[AI bias is rarely malice — it is unrepresentative data and unexamined proxies. The governance question is whether you looked, and what you did when you found it.]]></description>
    </item>
    <item>
      <title>Human oversight of AI systems</title>
      <link>https://sentinelpanda.com/insights/ai-human-oversight</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-human-oversight</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A human "in the loop" who always clicks approve is not oversight. Meaningful oversight means the human can actually understand and override the system.]]></description>
    </item>
    <item>
      <title>AI explainability and transparency</title>
      <link>https://sentinelpanda.com/insights/ai-explainability</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-explainability</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[You cannot oversee, contest, or trust a decision you cannot understand. Explainability is the control that makes the other AI controls possible.]]></description>
    </item>
    <item>
      <title>AI model cards and documentation</title>
      <link>https://sentinelpanda.com/insights/ai-model-cards</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-model-cards</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A model card is the spec sheet for an AI system — what it does, how it was trained, where it fails. It is becoming table stakes for governed AI.]]></description>
    </item>
    <item>
      <title>AI red teaming</title>
      <link>https://sentinelpanda.com/insights/ai-red-teaming</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-red-teaming</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Red teaming is penetration testing for model behaviour — deliberately trying to make the AI do the things it should not.]]></description>
    </item>
    <item>
      <title>AI prompt injection and LLM security</title>
      <link>https://sentinelpanda.com/insights/ai-prompt-injection</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-prompt-injection</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Prompt injection is the SQL injection of the LLM era: untrusted text that the model treats as instructions. There is no perfect fix — only layered defence.]]></description>
    </item>
    <item>
      <title>Managing third-party LLM and AI vendor risk</title>
      <link>https://sentinelpanda.com/insights/ai-third-party-llm-risk</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-third-party-llm-risk</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[You probably buy your AI, not build it. That makes AI governance largely a vendor-management problem — with some sharp, AI-specific edges.]]></description>
    </item>
    <item>
      <title>Monitoring and logging AI systems</title>
      <link>https://sentinelpanda.com/insights/ai-monitoring-logging</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-monitoring-logging</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A model that was fine at launch can quietly degrade as the world changes. Monitoring is how AI governance survives contact with production.]]></description>
    </item>
    <item>
      <title>The AI bill of materials (AIBOM)</title>
      <link>https://sentinelpanda.com/insights/ai-bill-of-materials</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-bill-of-materials</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[You cannot govern or secure an AI system whose ingredients you cannot list. The AIBOM is the ingredient label for AI — models, data, and dependencies.]]></description>
    </item>
    <item>
      <title>A practical HIPAA compliance checklist</title>
      <link>https://sentinelpanda.com/insights/hipaa-compliance-checklist</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-compliance-checklist</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[HIPAA looks sprawling until you list it out. For a tech business associate it comes down to a risk analysis, the safeguards, BAAs, and a breach process — done and documented.]]></description>
    </item>
    <item>
      <title>The HIPAA minimum necessary standard</title>
      <link>https://sentinelpanda.com/insights/hipaa-minimum-necessary</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-minimum-necessary</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[HIPAA's minimum necessary rule is least privilege for health data: people see only the PHI they need for their job, nothing more.]]></description>
    </item>
    <item>
      <title>HIPAA audit controls</title>
      <link>https://sentinelpanda.com/insights/hipaa-audit-controls</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-audit-controls</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[HIPAA wants a record of who touched ePHI. After a breach, that audit log is the difference between "we know what happened" and a guess.]]></description>
    </item>
    <item>
      <title>HIPAA encryption requirements</title>
      <link>https://sentinelpanda.com/insights/hipaa-encryption</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-encryption</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA["Addressable" does not mean optional. With ePHI it means: encrypt it, or write a very good explanation of why you did not — and there rarely is one.]]></description>
    </item>
    <item>
      <title>The HIPAA Omnibus Rule, explained</title>
      <link>https://sentinelpanda.com/insights/hipaa-omnibus-rule</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-omnibus-rule</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The Omnibus Rule is why your SaaS is directly on the hook for HIPAA — it extended liability from covered entities to their business associates and subcontractors.]]></description>
    </item>
    <item>
      <title>HIPAA enforcement and penalties</title>
      <link>https://sentinelpanda.com/insights/hipaa-penalties</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-penalties</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[HIPAA fines scale with how culpable you were, and willful neglect is the expensive tier. "We did not know" is only a defence if you genuinely could not have.]]></description>
    </item>
    <item>
      <title>HIPAA de-identification: Safe Harbor and Expert Determination</title>
      <link>https://sentinelpanda.com/insights/hipaa-de-identification</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-de-identification</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Data that is properly de-identified is no longer PHI — and no longer your HIPAA problem. There are exactly two approved ways to get there.]]></description>
    </item>
    <item>
      <title>The HIPAA right of access</title>
      <link>https://sentinelpanda.com/insights/hipaa-right-of-access</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-right-of-access</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The right of access is the HIPAA rule OCR fines most. Patients get their records, promptly, at reasonable cost — and "we were slow" is an expensive answer.]]></description>
    </item>
    <item>
      <title>The HIPAA contingency plan</title>
      <link>https://sentinelpanda.com/insights/hipaa-contingency-plan</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-contingency-plan</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[HIPAA's contingency plan is BC/DR for health data, with one part the law makes non-negotiable: you must back up ePHI and be able to restore it.]]></description>
    </item>
    <item>
      <title>HIPAA vs SOC 2: do you need both?</title>
      <link>https://sentinelpanda.com/insights/hipaa-vs-soc-2</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-vs-soc-2</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[HIPAA is the law; SOC 2 is the proof your customers ask for. Handling health data, you often end up doing both — and the work mostly overlaps.]]></description>
    </item>
    <item>
      <title>HIPAA vs HITRUST: what is the difference?</title>
      <link>https://sentinelpanda.com/insights/hipaa-vs-hitrust</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-vs-hitrust</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[HIPAA tells you what to do; HITRUST gives you a certificate that proves you did. In healthcare, big buyers increasingly ask for the certificate.]]></description>
    </item>
    <item>
      <title>HIPAA risk management vs risk analysis</title>
      <link>https://sentinelpanda.com/insights/hipaa-risk-management</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-risk-management</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The risk analysis finds the risks to ePHI; risk management does something about them. HIPAA requires both, and skipping the second is a classic finding.]]></description>
    </item>
    <item>
      <title>HIPAA workforce training</title>
      <link>https://sentinelpanda.com/insights/hipaa-workforce-training</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-workforce-training</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Everyone who touches PHI needs HIPAA training — and the record proving they got it. It is mostly your security awareness program with a health-data lens.]]></description>
    </item>
    <item>
      <title>HIPAA incident response</title>
      <link>https://sentinelpanda.com/insights/hipaa-incident-response</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-incident-response</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Not every security incident is a HIPAA breach — but you need a process that can tell, fast, because the breach clock starts at discovery.]]></description>
    </item>
    <item>
      <title>HIPAA subcontractor BAAs</title>
      <link>https://sentinelpanda.com/insights/hipaa-subcontractor-baa</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-subcontractor-baa</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Your obligations flow downhill. Every subcontractor that touches your customers' PHI needs its own BAA with you — and many vendors miss this.]]></description>
    </item>
    <item>
      <title>ISO 27001 vs ISO 27002</title>
      <link>https://sentinelpanda.com/insights/iso-27001-vs-iso-27002</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-vs-iso-27002</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[You get certified to 27001 and you implement using 27002. One is the requirement; the other is the how-to manual for the controls.]]></description>
    </item>
    <item>
      <title>The documented information ISO 27001 requires</title>
      <link>https://sentinelpanda.com/insights/iso-27001-documented-information</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-documented-information</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[ISO 27001 names the documents you must keep — fewer than people fear. The trap is producing documentation the standard never asked for.]]></description>
    </item>
    <item>
      <title>ISO 27001 surveillance audits and recertification</title>
      <link>https://sentinelpanda.com/insights/iso-27001-surveillance-audits</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-surveillance-audits</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The certificate lasts three years, but the auditor comes back every year. Surveillance audits are how the certification stays honest.]]></description>
    </item>
    <item>
      <title>ISO 27001 leadership and roles (Clause 5)</title>
      <link>https://sentinelpanda.com/insights/iso-27001-leadership-and-roles</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-leadership-and-roles</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[ISO 27001 will not let leadership delegate security and walk away. Clause 5 makes top-management ownership an auditable requirement.]]></description>
    </item>
    <item>
      <title>ISO 27001 security objectives and measurement</title>
      <link>https://sentinelpanda.com/insights/iso-27001-objectives-and-measurement</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-objectives-and-measurement</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Objectives you cannot measure are wishes. ISO 27001 asks for security goals with numbers behind them — and proof you actually watch them.]]></description>
    </item>
    <item>
      <title>The ISO 27001 risk treatment plan</title>
      <link>https://sentinelpanda.com/insights/iso-27001-risk-treatment-plan</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-risk-treatment-plan</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The risk assessment finds the risks; the risk treatment plan does something about them. One without the other is half a control.]]></description>
    </item>
    <item>
      <title>Continual improvement in an ISMS</title>
      <link>https://sentinelpanda.com/insights/iso-27001-continual-improvement</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-continual-improvement</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[An ISMS that looks identical year to year is, by ISO 27001's logic, not being managed. Continual improvement is the engine the whole standard assumes.]]></description>
    </item>
    <item>
      <title>HIPAA for SaaS and tech companies</title>
      <link>https://sentinelpanda.com/insights/hipaa-for-saas</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-for-saas</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[You do not have to be a hospital for HIPAA to apply. Touch PHI on behalf of a covered entity and you are a business associate, on the hook.]]></description>
    </item>
    <item>
      <title>HIPAA administrative safeguards</title>
      <link>https://sentinelpanda.com/insights/hipaa-administrative-safeguards</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-administrative-safeguards</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The administrative safeguards are most of the Security Rule, and they are about process, not technology — risk analysis, training, access management, and incident response.]]></description>
    </item>
    <item>
      <title>HIPAA technical safeguards</title>
      <link>https://sentinelpanda.com/insights/hipaa-technical-safeguards</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-technical-safeguards</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The technical safeguards are the engineering half of HIPAA — and they map almost one-to-one onto the access, logging, and encryption controls you already build.]]></description>
    </item>
    <item>
      <title>HIPAA physical safeguards</title>
      <link>https://sentinelpanda.com/insights/hipaa-physical-safeguards</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-physical-safeguards</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Like ISO 27001's physical controls, most HIPAA physical safeguards are inherited from your cloud provider — but your laptops and your media disposal are still on you.]]></description>
    </item>
    <item>
      <title>The HIPAA Breach Notification Rule</title>
      <link>https://sentinelpanda.com/insights/hipaa-breach-notification</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-breach-notification</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[HIPAA does not just ask you to prevent breaches — it dictates exactly who you tell, and when, if one happens. Encryption is the safe harbour.]]></description>
    </item>
    <item>
      <title>What is an ISMS? ISO 27001 explained</title>
      <link>https://sentinelpanda.com/insights/iso-27001-isms-explained</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-isms-explained</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[ISO 27001 does not certify that you are secure. It certifies that you run a managed, improving system for staying secure — that distinction is the whole framework.]]></description>
    </item>
    <item>
      <title>The ISO 27001 certification process</title>
      <link>https://sentinelpanda.com/insights/iso-27001-certification-process</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-certification-process</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[ISO 27001 certification is a two-stage external audit on top of your own internal audit. Knowing the sequence keeps the timeline honest.]]></description>
    </item>
    <item>
      <title>Running an ISO 27001 internal audit</title>
      <link>https://sentinelpanda.com/insights/iso-27001-internal-audit</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-internal-audit</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The internal audit is not a dry run you fake — it is a required control, and a real one catches the gaps before the external auditor does.]]></description>
    </item>
    <item>
      <title>The ISO 27001 management review</title>
      <link>https://sentinelpanda.com/insights/iso-27001-management-review</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-management-review</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The management review is where leadership owns the ISMS on the record. Skip it or fake it and you have a major nonconformity.]]></description>
    </item>
    <item>
      <title>How much does ISO 27001 cost?</title>
      <link>https://sentinelpanda.com/insights/iso-27001-cost</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-cost</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The certification body is a recurring line item SOC 2 does not have. Scope and internal time are still the bigger numbers.]]></description>
    </item>
    <item>
      <title>ISO 27001 timeline: how long to certification</title>
      <link>https://sentinelpanda.com/insights/iso-27001-timeline</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-timeline</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[ISO 27001 is gated by your ISMS needing to actually run for a while before it can be audited — you cannot certify a system with no operating history.]]></description>
    </item>
    <item>
      <title>Defining your ISO 27001 scope</title>
      <link>https://sentinelpanda.com/insights/iso-27001-scope-definition</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-scope-definition</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Your certificate is only as meaningful as its scope statement. Scope too wide and you drown; too narrow and buyers notice.]]></description>
    </item>
    <item>
      <title>ISO 27001 Annex A: organizational controls (A.5)</title>
      <link>https://sentinelpanda.com/insights/iso-27001-annex-a-organizational-controls</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-annex-a-organizational-controls</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A.5 is the biggest Annex A theme and the most policy-heavy. It is also where most of your existing governance already lives.]]></description>
    </item>
    <item>
      <title>ISO 27001 Annex A: people controls (A.6)</title>
      <link>https://sentinelpanda.com/insights/iso-27001-annex-a-people-controls</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-annex-a-people-controls</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A.6 is the people theme: hiring, training, offboarding, and the rules of working. Most of it lives with HR as much as security.]]></description>
    </item>
    <item>
      <title>ISO 27001 Annex A: physical controls (A.7)</title>
      <link>https://sentinelpanda.com/insights/iso-27001-annex-a-physical-controls</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-annex-a-physical-controls</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[For a cloud-first company, A.7 is mostly inherited from your data-centre providers — but "we use AWS" is an answer you still have to document.]]></description>
    </item>
    <item>
      <title>ISO 27001 Annex A: technological controls (A.8)</title>
      <link>https://sentinelpanda.com/insights/iso-27001-annex-a-technological-controls</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-annex-a-technological-controls</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A.8 is where the engineering lives: access, crypto, logging, secure development, and network security. It overlaps almost entirely with SOC 2's technical controls.]]></description>
    </item>
    <item>
      <title>ISO 27001 nonconformities and corrective action</title>
      <link>https://sentinelpanda.com/insights/iso-27001-nonconformities</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-nonconformities</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A nonconformity is not failure — an audit with zero findings is more suspicious than one with a few. What matters is how you close them.]]></description>
    </item>
    <item>
      <title>ISO 27001 for startups</title>
      <link>https://sentinelpanda.com/insights/iso-27001-for-startups</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-for-startups</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[ISO 27001 looks heavier than SOC 2 because of the management-system machinery. For a startup, the trick is keeping that machinery small but real.]]></description>
    </item>
    <item>
      <title>How to answer a security questionnaire</title>
      <link>https://sentinelpanda.com/insights/security-questionnaire-how-to-answer</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/security-questionnaire-how-to-answer</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A security questionnaire is a sales document in disguise. Answer it like one: accurate, confident, and backed by evidence you can produce on request.]]></description>
    </item>
    <item>
      <title>Encryption at rest and in transit</title>
      <link>https://sentinelpanda.com/insights/encryption-at-rest-in-transit</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/encryption-at-rest-in-transit</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Encryption is the control everyone claims and few fully cover. The gaps are always the same: a backup, an internal hop, a key in a config file.]]></description>
    </item>
    <item>
      <title>Writing a data retention policy</title>
      <link>https://sentinelpanda.com/insights/data-retention-policy</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/data-retention-policy</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Most retention policies describe a discipline nobody actually follows. The value is in the deletion that actually happens, not the schedule on paper.]]></description>
    </item>
    <item>
      <title>A practical data classification scheme</title>
      <link>https://sentinelpanda.com/insights/data-classification</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/data-classification</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Four tiers is plenty. The mistake is a beautiful classification scheme that nobody applies to actual data.]]></description>
    </item>
    <item>
      <title>Building an asset inventory auditors trust</title>
      <link>https://sentinelpanda.com/insights/asset-inventory</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/asset-inventory</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Every framework assumes you know what you own. A stale inventory quietly invalidates half your other controls.]]></description>
    </item>
    <item>
      <title>How to build a risk register</title>
      <link>https://sentinelpanda.com/insights/risk-register-how-to-build</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/risk-register-how-to-build</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A risk register is only useful if risks move through it — identified, owned, treated, reviewed. A static list is just anxiety in a spreadsheet.]]></description>
    </item>
    <item>
      <title>Security awareness training that counts</title>
      <link>https://sentinelpanda.com/insights/security-awareness-training</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/security-awareness-training</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Awareness training is mocked because most of it is theatre. Done right it is one of the cheapest defences against the attacks that actually land.]]></description>
    </item>
    <item>
      <title>Secure offboarding, step by step</title>
      <link>https://sentinelpanda.com/insights/secure-offboarding</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/secure-offboarding</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Lingering access from departed employees is one of the most common — and most dangerous — audit findings. Make offboarding a checklist, not a memory.]]></description>
    </item>
    <item>
      <title>A password policy that matches modern guidance</title>
      <link>https://sentinelpanda.com/insights/password-policy</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/password-policy</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Forced 90-day rotations and complexity gymnastics are out. Length, screening against breached passwords, and MFA are in.]]></description>
    </item>
    <item>
      <title>Writing an acceptable use policy</title>
      <link>https://sentinelpanda.com/insights/acceptable-use-policy</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/acceptable-use-policy</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The AUP is the one policy every employee should actually read. Write it for them, not for the auditor.]]></description>
    </item>
    <item>
      <title>Which compliance framework should you do first?</title>
      <link>https://sentinelpanda.com/insights/which-compliance-framework-first</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/which-compliance-framework-first</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Do the framework your customers are actually asking for — not the one that looks most impressive. Demand, not prestige, picks the order.]]></description>
    </item>
    <item>
      <title>Compliance for fully-remote teams</title>
      <link>https://sentinelpanda.com/insights/compliance-for-remote-teams</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/compliance-for-remote-teams</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A remote company has no network perimeter — so identity and the endpoint become the perimeter. Build the controls around those.]]></description>
    </item>
    <item>
      <title>Shadow IT: the compliance blind spot</title>
      <link>https://sentinelpanda.com/insights/shadow-it-risk</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/shadow-it-risk</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The riskiest vendor in your stack is the one you do not know you have. Shadow IT is where your carefully-built controls have gaps you cannot see.]]></description>
    </item>
    <item>
      <title>Change management for SOC 2</title>
      <link>https://sentinelpanda.com/insights/soc-2-change-management</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-change-management</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[You almost certainly already do change management — it is called code review. The SOC 2 work is mostly proving the review and approval happened.]]></description>
    </item>
    <item>
      <title>The SOC 2 risk assessment</title>
      <link>https://sentinelpanda.com/insights/soc-2-risk-assessment</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-risk-assessment</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The risk assessment is not paperwork for the auditor — it is supposed to explain why you chose the controls you did. Write it so it actually does that.]]></description>
    </item>
    <item>
      <title>Logging and monitoring for SOC 2</title>
      <link>https://sentinelpanda.com/insights/soc-2-logging-monitoring</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-logging-monitoring</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Collecting logs is the easy half. SOC 2 wants evidence that someone notices when they say something — alerts that fire and get actioned.]]></description>
    </item>
    <item>
      <title>Encryption controls for SOC 2</title>
      <link>https://sentinelpanda.com/insights/soc-2-encryption</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-encryption</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[SOC 2 is principles-based, so there is no "use AES-256" rule — but a report without TLS everywhere and encryption at rest will draw questions fast.]]></description>
    </item>
    <item>
      <title>Business continuity and disaster recovery for SOC 2</title>
      <link>https://sentinelpanda.com/insights/soc-2-business-continuity</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-business-continuity</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A disaster recovery plan you have never tested is the most common BC/DR finding. The test is the control; the document is just the script.]]></description>
    </item>
    <item>
      <title>SOC 2 exceptions and qualified opinions</title>
      <link>https://sentinelpanda.com/insights/soc-2-exceptions</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-exceptions</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Buyers read the opinion and the exceptions, not just the logo. Knowing the difference between a noted exception and a qualified opinion is how you read — and pass — a report.]]></description>
    </item>
    <item>
      <title>Choosing your SOC 2 observation period</title>
      <link>https://sentinelpanda.com/insights/soc-2-observation-period</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-observation-period</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Three months gets you a report fastest; twelve gives buyers the most assurance. Pick the window for the deals in front of you, then settle into an annual rhythm.]]></description>
    </item>
    <item>
      <title>The SOC 2 gap assessment</title>
      <link>https://sentinelpanda.com/insights/soc-2-gap-assessment</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-gap-assessment</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Before you hire an auditor, find out what is missing. A gap assessment turns "are we ready?" into a dated to-do list.]]></description>
    </item>
    <item>
      <title>The SOC 2 controls list: what to expect</title>
      <link>https://sentinelpanda.com/insights/soc-2-controls-list</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-controls-list</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[SOC 2 does not hand you a control list — you derive it from the criteria. Here are the families that appear in essentially every report.]]></description>
    </item>
    <item>
      <title>Is a penetration test required for SOC 2?</title>
      <link>https://sentinelpanda.com/insights/soc-2-penetration-testing</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-penetration-testing</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Strictly, SOC 2 asks for a vulnerability management program — not a specific pen test. In practice, buyers ask for the pen test report, so most teams run one.]]></description>
    </item>
    <item>
      <title>Network segmentation to shrink PCI scope</title>
      <link>https://sentinelpanda.com/insights/pci-network-segmentation</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/pci-network-segmentation</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Everything that can reach the cardholder data environment is in scope. Segmentation draws the boundary — done well, it can take dozens of systems out of your SAQ.]]></description>
    </item>
    <item>
      <title>PCI compensating controls, done right</title>
      <link>https://sentinelpanda.com/insights/pci-compensating-controls</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/pci-compensating-controls</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A compensating control is not an excuse to skip a requirement. It is a different control that meets the intent and rigour of the original — and it has to be justified in writing.]]></description>
    </item>
    <item>
      <title>Tokenization for PCI scope reduction</title>
      <link>https://sentinelpanda.com/insights/pci-tokenization</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/pci-tokenization</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[If your systems only ever hold tokens, most of them fall out of PCI scope — because a token, on its own, is worthless to an attacker.]]></description>
    </item>
    <item>
      <title>PCI DSS penetration testing requirements</title>
      <link>https://sentinelpanda.com/insights/pci-penetration-testing</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/pci-penetration-testing</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A penetration test is not the same as an ASV scan, and not every merchant needs one. Here is what PCI actually requires and when.]]></description>
    </item>
    <item>
      <title>PCI DSS multi-factor authentication requirements</title>
      <link>https://sentinelpanda.com/insights/pci-mfa-requirements</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/pci-mfa-requirements</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[PCI DSS 4.0 pushed MFA well beyond remote admin access. If card data is involved, the bar is now "MFA for all access into the CDE."]]></description>
    </item>
    <item>
      <title>How much does a SOC 2 actually cost?</title>
      <link>https://sentinelpanda.com/insights/soc-2-cost</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-cost</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The auditor invoice is only part of the bill. The bigger costs are scope, internal time, and whether you do a Type I first.]]></description>
    </item>
    <item>
      <title>SOC 2 timeline: how long it really takes</title>
      <link>https://sentinelpanda.com/insights/soc-2-timeline</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-timeline</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The work you control takes weeks; the observation period takes months. Knowing which is which keeps your sales promises honest.]]></description>
    </item>
    <item>
      <title>SOC 2 evidence collection without the scramble</title>
      <link>https://sentinelpanda.com/insights/soc-2-evidence-collection</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-evidence-collection</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A SOC 2 is an evidence exercise. The teams that suffer are the ones who try to assemble a period's worth of proof in the final week.]]></description>
    </item>
    <item>
      <title>SOC 2 for startups: the lean path</title>
      <link>https://sentinelpanda.com/insights/soc-2-for-startups</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-for-startups</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Your first SOC 2 should be the smallest one that unlocks the deals in front of you — not a monument to every control you might one day need.]]></description>
    </item>
    <item>
      <title>Access reviews that pass a SOC 2 audit</title>
      <link>https://sentinelpanda.com/insights/soc-2-access-reviews</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-access-reviews</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Access creep is the most common audit finding there is. A repeatable quarterly review closes it — and the same record credits PCI and ISO too.]]></description>
    </item>
    <item>
      <title>Vendor management for SOC 2</title>
      <link>https://sentinelpanda.com/insights/soc-2-vendor-management</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-vendor-management</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Your SOC 2 covers your controls — but your vendors hold your customers' data too. Auditors want to see you manage that risk, not just list the logos.]]></description>
    </item>
    <item>
      <title>Least privilege access, in practice</title>
      <link>https://sentinelpanda.com/insights/least-privilege-access</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/least-privilege-access</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Least privilege is not a one-time grant — it is a habit of giving the minimum and taking it back. The proof an auditor wants is the taking-back.]]></description>
    </item>
    <item>
      <title>Rolling out MFA everywhere</title>
      <link>https://sentinelpanda.com/insights/mfa-everywhere</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/mfa-everywhere</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[MFA is the single control that stops the most attacks for the least effort. The work is not turning it on — it is leaving no account behind.]]></description>
    </item>
    <item>
      <title>Penetration testing vs vulnerability scanning</title>
      <link>https://sentinelpanda.com/insights/penetration-testing-vs-vulnerability-scanning</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/penetration-testing-vs-vulnerability-scanning</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A scan tells you what is exposed; a penetration test tells you what an attacker could actually do with it. Most programs need both — but not always.]]></description>
    </item>
    <item>
      <title>Tiering third-party vendors by risk</title>
      <link>https://sentinelpanda.com/insights/third-party-risk-tiering</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/third-party-risk-tiering</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Treating every vendor the same is how third-party risk management dies of its own weight. Tier by the data they touch, then spend your effort accordingly.]]></description>
    </item>
    <item>
      <title>Do I need a QSA for PCI DSS?</title>
      <link>https://sentinelpanda.com/insights/do-i-need-a-qsa</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/do-i-need-a-qsa</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Most small and mid-sized merchants can self-assess with an SAQ and sign their own AOC. A QSA is required only at the top — here is exactly where the line sits.]]></description>
    </item>
    <item>
      <title>Inside the PCI Attestation of Compliance (AOC)</title>
      <link>https://sentinelpanda.com/insights/pci-attestation-of-compliance</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/pci-attestation-of-compliance</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The SAQ is the work. The AOC is the one signed page that proves you did it — and the document your acquirer actually files.]]></description>
    </item>
    <item>
      <title>Security policies auditors accept</title>
      <link>https://sentinelpanda.com/insights/security-policies-that-pass-audit</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/security-policies-that-pass-audit</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A policy is not a wish list. Auditors test whether it is approved, current, communicated, and actually followed — write for that.]]></description>
    </item>
    <item>
      <title>What a Data Processing Agreement (DPA) must contain</title>
      <link>https://sentinelpanda.com/insights/data-processing-agreement-explained</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/data-processing-agreement-explained</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[If a vendor handles personal data on your behalf, you owe a DPA. Here is what a defensible one actually contains.]]></description>
    </item>
    <item>
      <title>Incident response that satisfies SOC 2, PCI, and ISO at once</title>
      <link>https://sentinelpanda.com/insights/soc-2-incident-response</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-incident-response</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[You do not need three incident response plans. You need one good one, tested, that every framework can credit.]]></description>
    </item>
    <item>
      <title>Access reviews that pass an ISO 27001 audit</title>
      <link>https://sentinelpanda.com/insights/iso-27001-access-control-review</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-access-control-review</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Access creep is the most common audit finding there is. A repeatable review closes it — and one record satisfies four frameworks.]]></description>
    </item>
    <item>
      <title>The HIPAA policies and procedures you actually need</title>
      <link>https://sentinelpanda.com/insights/hipaa-policies-and-procedures</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-policies-and-procedures</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[HIPAA does not hand you a checklist of documents. Here is the practical policy set that satisfies the Security Rule safeguards.]]></description>
    </item>
    <item>
      <title>The NIST AI RMF Generative AI Profile, in practice</title>
      <link>https://sentinelpanda.com/insights/nist-ai-rmf-genai-profile</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-ai-rmf-genai-profile</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The Generative AI Profile is the AI RMF customised for the systems your teams are actually shipping. Twelve risk areas, mapped to Govern, Map, Measure, Manage.]]></description>
    </item>
    <item>
      <title>AI incident response: building the runbook</title>
      <link>https://sentinelpanda.com/insights/ai-incident-response</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-incident-response</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Your existing IR runbook does not cover the failure modes that matter for AI systems. Build the AI-specific one before you need it.]]></description>
    </item>
    <item>
      <title>AI governance for startups: a 30-day starter plan</title>
      <link>https://sentinelpanda.com/insights/ai-governance-for-startups</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-governance-for-startups</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[You do not need ISO 42001 certification on day one. You do need to answer the AI questions in customer questionnaires without flinching.]]></description>
    </item>
    <item>
      <title>The complete PCI DSS SAQ walkthrough: a step-by-step guide</title>
      <link>https://sentinelpanda.com/insights/pci-saq-complete-walkthrough</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/pci-saq-complete-walkthrough</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Most SAQ guides stop at "pick the right type." This one walks the entire cycle end-to-end — what to gather before you start, how to read each requirement, what evidence actually satisfies it, and what happens after you submit.]]></description>
    </item>
    <item>
      <title>SAQ A walkthrough: fully outsourced e-commerce</title>
      <link>https://sentinelpanda.com/insights/saq-a-walkthrough</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/saq-a-walkthrough</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[SAQ A is among the shortest PCI SAQs but the easiest to misuse. The eligibility bar is strict; the 4.0.1 script controls trip up almost everyone the first year.]]></description>
    </item>
    <item>
      <title>SAQ A-EP walkthrough: e-commerce that partly controls the payment</title>
      <link>https://sentinelpanda.com/insights/saq-a-ep-walkthrough</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/saq-a-ep-walkthrough</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[SAQ A-EP is what you actually need when your payment page is "mostly outsourced." Substantially heavier than A; substantially shorter than D.]]></description>
    </item>
    <item>
      <title>SAQ B walkthrough: standalone dial-out terminals</title>
      <link>https://sentinelpanda.com/insights/saq-b-walkthrough</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/saq-b-walkthrough</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[SAQ B is the smallest PCI SAQ. It assumes a very narrow setup — and the moment your terminal touches IP, you switch to SAQ B-IP.]]></description>
    </item>
    <item>
      <title>SAQ B-IP walkthrough: standalone IP-connected terminals</title>
      <link>https://sentinelpanda.com/insights/saq-b-ip-walkthrough</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/saq-b-ip-walkthrough</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[SAQ B-IP sits between SAQ B and SAQ C. The terminal is "smart" (IP-connected) but standalone (not integrated into a POS system).]]></description>
    </item>
    <item>
      <title>SAQ C walkthrough: payment application on an internet-connected POS</title>
      <link>https://sentinelpanda.com/insights/saq-c-walkthrough</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/saq-c-walkthrough</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[SAQ C is for the integrated POS case: a payment application on a system you operate, connected to the internet, no card storage. Heavier than B-IP, lighter than D.]]></description>
    </item>
    <item>
      <title>SAQ C-VT walkthrough: virtual terminal on a dedicated computer</title>
      <link>https://sentinelpanda.com/insights/saq-c-vt-walkthrough</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/saq-c-vt-walkthrough</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[SAQ C-VT is narrow: a virtual terminal in a browser, one computer, one transaction at a time, no storage. The "isolated computer" requirement is the hard bit.]]></description>
    </item>
    <item>
      <title>SAQ P2PE walkthrough: validated point-to-point encryption</title>
      <link>https://sentinelpanda.com/insights/saq-p2pe-walkthrough</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/saq-p2pe-walkthrough</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[SAQ P2PE is the shortest SAQ and the most attractive — but only if you use a PCI-listed P2PE solution. Self-built "encryption" does not qualify.]]></description>
    </item>
    <item>
      <title>SAQ D-Merchant walkthrough: when none of the others fit</title>
      <link>https://sentinelpanda.com/insights/saq-d-merchant-walkthrough</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/saq-d-merchant-walkthrough</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[SAQ D-Merchant is the comprehensive SAQ. If you do not qualify for A through P2PE, this is where you land — closest to a full ROC in coverage.]]></description>
    </item>
    <item>
      <title>SAQ D-Service Provider walkthrough</title>
      <link>https://sentinelpanda.com/insights/saq-d-service-provider-walkthrough</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/saq-d-service-provider-walkthrough</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Service providers carry obligations merchants do not. SAQ D-Service Provider is the eligible self-assessment route for service providers below the Level 1 threshold.]]></description>
    </item>
    <item>
      <title>AI impact assessments: ISO 42001 and the EU AI Act</title>
      <link>https://sentinelpanda.com/insights/ai-impact-assessment</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-impact-assessment</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The impact assessment is the one document that survives every audit you face on an AI system. Build it once with both standards in mind.]]></description>
    </item>
    <item>
      <title>AI vendor due diligence: the questions to ask</title>
      <link>https://sentinelpanda.com/insights/ai-vendor-due-diligence</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/ai-vendor-due-diligence</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A standard vendor questionnaire was built for SaaS that does not change underneath you. AI vendors do. Here is what to add.]]></description>
    </item>
    <item>
      <title>ISO 42001 vs NIST AI RMF: a side-by-side</title>
      <link>https://sentinelpanda.com/insights/iso-42001-vs-nist-ai-rmf</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-vs-nist-ai-rmf</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Both produce defensible AI governance. They are not interchangeable, and you can comfortably implement both.]]></description>
    </item>
    <item>
      <title>Is your AI system high-risk under the EU AI Act?</title>
      <link>https://sentinelpanda.com/insights/eu-ai-act-high-risk-classification</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/eu-ai-act-high-risk-classification</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Most AI Act compliance work attaches to the high-risk tier. Knowing whether your system is in it is the most consequential reading you do all year.]]></description>
    </item>
    <item>
      <title>OWASP LLM Top 10 for security teams</title>
      <link>https://sentinelpanda.com/insights/owasp-llm-top-10</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/owasp-llm-top-10</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[OWASP's LLM Top 10 is the closest thing the GenAI security space has to a shared vocabulary. Treat it as a threat-model checklist, not a compliance bingo card.]]></description>
    </item>
    <item>
      <title>NIST AI Risk Management Framework: the four functions</title>
      <link>https://sentinelpanda.com/insights/nist-ai-rmf</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-ai-rmf</guid>
      <pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[NIST CSF for AI, with a twist. Same structural elegance, applied to an AI system you have actually scoped.]]></description>
    </item>
    <item>
      <title>EU AI Act timeline: what applies, and when</title>
      <link>https://sentinelpanda.com/insights/eu-ai-act-timeline</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/eu-ai-act-timeline</guid>
      <pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Governance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[You probably do not need to be ready for all of the AI Act today, but two of its phases are already in force. The rest land on a published calendar.]]></description>
    </item>
    <item>
      <title>ISO 42001 vs EU AI Act: how they complement each other</title>
      <link>https://sentinelpanda.com/insights/iso-42001-vs-eu-ai-act</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-vs-eu-ai-act</guid>
      <pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Two different instruments answering related questions. Confusing them costs time and money; treating them as complementary is how mature programs use both.]]></description>
    </item>
    <item>
      <title>Writing the SOC 2 System Description (Section 3)</title>
      <link>https://sentinelpanda.com/insights/soc-2-system-description</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-system-description</guid>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A SOC 2 report has four sections. Section 3 — the System Description — is the one written by management, and the one auditors test against. Get it wrong and you earn a qualified opinion.]]></description>
    </item>
    <item>
      <title>SOC 1 vs SOC 2 vs SOC 3: which report do you actually need?</title>
      <link>https://sentinelpanda.com/insights/soc-1-vs-soc-2-vs-soc-3</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-1-vs-soc-2-vs-soc-3</guid>
      <pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The "SOC" family is three reports with the same brand and three different purposes. Pick the wrong one and you spend a quarter producing assurance that no buyer asked for.]]></description>
    </item>
    <item>
      <title>Vendor risk management, explained</title>
      <link>https://sentinelpanda.com/insights/vendor-risk-management</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/vendor-risk-management</guid>
      <pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Your compliance posture includes the vendors that touch your data. Auditors know it, frameworks require it, and a spreadsheet of questionnaires is not a program.]]></description>
    </item>
    <item>
      <title>NIST CSF vs ISO 27001: how to choose (and how to run both)</title>
      <link>https://sentinelpanda.com/insights/nist-csf-vs-iso-27001</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-vs-iso-27001</guid>
      <pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[NIST CSF is a map. ISO 27001 is a system. You can read a map without running a system, but you cannot run a system without a map.]]></description>
    </item>
    <item>
      <title>COBIT 2019 design factors and tailoring</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-design-factors</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-design-factors</guid>
      <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Trying to run all 40 COBIT objectives at full intensity is how programs die quietly. The design factors are how the framework was designed to be scaled down to your context.]]></description>
    </item>
    <item>
      <title>A compliance audit readiness checklist</title>
      <link>https://sentinelpanda.com/insights/compliance-audit-readiness-checklist</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/compliance-audit-readiness-checklist</guid>
      <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Audits go badly when readiness is assembled the week before. Here is what to have standing, in roughly the order an auditor will ask for it.]]></description>
    </item>
    <item>
      <title>HIPAA Business Associate Agreements: when you need one and what it must contain</title>
      <link>https://sentinelpanda.com/insights/hipaa-business-associate-agreements</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-business-associate-agreements</guid>
      <pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[If your software touches PHI on behalf of a covered entity, you are a business associate. A signed BAA is the price of doing the work — and the obligations that come with it are not just contractual.]]></description>
    </item>
    <item>
      <title>SOC 2 bridge letters: what they are and when to send one</title>
      <link>https://sentinelpanda.com/insights/soc-2-bridge-letters</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-bridge-letters</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A SOC 2 report covers a finite window. Customers who rely on it want assurance that nothing has changed between that window and today — that is what a bridge letter is for.]]></description>
    </item>
    <item>
      <title>SOC 2 or ISO 27001: which should you do first?</title>
      <link>https://sentinelpanda.com/insights/soc-2-vs-iso-27001</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-vs-iso-27001</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[They overlap heavily, but they are not interchangeable. The right first choice depends on who is asking and where your buyers are.]]></description>
    </item>
    <item>
      <title>ISO 42001 explained: the AI management system standard</title>
      <link>https://sentinelpanda.com/insights/iso-42001-explained</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-42001-explained</guid>
      <pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate>
      <category>ISO 42001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[For organisations developing or deploying AI systems, ISO 42001 is what ISO 27001 was for information security: a defensible, certifiable management system that buyers and regulators will start to expect.]]></description>
    </item>
    <item>
      <title>HIPAA Security Rule: administrative, physical, and technical safeguards</title>
      <link>https://sentinelpanda.com/insights/hipaa-security-rule-safeguards</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-security-rule-safeguards</guid>
      <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The 18 standards in the Security Rule are the spine of any HIPAA program. Knowing what is required versus addressable is the difference between a clean audit and a tense conversation with OCR.]]></description>
    </item>
    <item>
      <title>PCI DSS non-compliance: fines, fees, and downstream costs</title>
      <link>https://sentinelpanda.com/insights/pci-noncompliance-penalties</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/pci-noncompliance-penalties</guid>
      <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[PCI is enforced through contracts, not statutes. That makes the penalties less visible than a regulatory fine — and often more expensive once you add them up.]]></description>
    </item>
    <item>
      <title>What changed in ISO 27001:2022 Annex A</title>
      <link>https://sentinelpanda.com/insights/iso-27001-annex-a-2022-changes</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-annex-a-2022-changes</guid>
      <pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The 2022 revision is structural, not philosophical. Most of the old controls survived under new numbers; the change is in the grouping and the 11 controls that did not exist before.]]></description>
    </item>
    <item>
      <title>PCI DSS scope reduction: how to shrink your CDE</title>
      <link>https://sentinelpanda.com/insights/pci-dss-scope-reduction</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/pci-dss-scope-reduction</guid>
      <pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Every system in your cardholder data environment is a system you have to secure and assess. The cheapest control is the one you remove from scope entirely.]]></description>
    </item>
    <item>
      <title>NIST CSF Profiles and Implementation Tiers</title>
      <link>https://sentinelpanda.com/insights/nist-csf-profiles-and-tiers</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-profiles-and-tiers</guid>
      <pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A CSF assessment that does not use Profiles and Tiers is a list of yes/no answers without a destination. They are the framework's mechanism for "right-size this to my organisation."]]></description>
    </item>
    <item>
      <title>PCI DSS quarterly ASV scans: what they cover and how to pass</title>
      <link>https://sentinelpanda.com/insights/pci-asv-scans</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/pci-asv-scans</guid>
      <pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[ASV scans are the most visible recurring PCI obligation: four passing attestations a year on every internet-facing system in scope. Knowing how the scan thinks is how you stop them from owning your quarter-end.]]></description>
    </item>
    <item>
      <title>COBIT 2019 capability levels (0–5), explained</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-capability-levels</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-capability-levels</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[COBIT 2019 rates each objective on a 0–5 capability scale. Knowing what each level means turns a governance assessment into a roadmap.]]></description>
    </item>
    <item>
      <title>COBIT 2019 governance objectives vs management objectives</title>
      <link>https://sentinelpanda.com/insights/cobit-2019-governance-vs-management</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cobit-2019-governance-vs-management</guid>
      <pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate>
      <category>COBIT 2019</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Governance directs. Management plans, builds, runs, monitors. COBIT 2019 makes the distinction explicit because confusing the two is how IT investments end up disconnected from enterprise value.]]></description>
    </item>
    <item>
      <title>ISO 27001 risk assessment and treatment under clause 6.1</title>
      <link>https://sentinelpanda.com/insights/iso-27001-risk-assessment</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-risk-assessment</guid>
      <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A good ISMS is a chain of decisions: identify risks, evaluate them, treat them, and document the result. Clause 6.1 is where that chain is built, and where most certification findings start.]]></description>
    </item>
    <item>
      <title>A SOC 2 readiness checklist</title>
      <link>https://sentinelpanda.com/insights/soc-2-readiness-checklist</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-readiness-checklist</guid>
      <pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A SOC 2 audit is mostly won before the auditor arrives. This checklist runs the program in the order auditors expect to find it.]]></description>
    </item>
    <item>
      <title>HIPAA Security Rule risk analysis: what is required</title>
      <link>https://sentinelpanda.com/insights/hipaa-security-risk-analysis</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-security-risk-analysis</guid>
      <pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The risk analysis is the foundation of HIPAA Security Rule compliance — and the single most common finding when something goes wrong.]]></description>
    </item>
    <item>
      <title>HIPAA Privacy Rule vs Security Rule: what each covers</title>
      <link>https://sentinelpanda.com/insights/hipaa-privacy-vs-security-rule</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/hipaa-privacy-vs-security-rule</guid>
      <pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate>
      <category>HIPAA</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Engineers tend to default to "the Security Rule" when they say HIPAA. Most procurement reviews and breach notifications start with the Privacy Rule. Knowing the difference matters.]]></description>
    </item>
    <item>
      <title>NIST CSF 2.0: the new Govern function explained</title>
      <link>https://sentinelpanda.com/insights/nist-csf-2-0-govern-function</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-2-0-govern-function</guid>
      <pubDate>Tue, 17 Mar 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[CSF 2.0's biggest change is a new function that wraps the other five: Govern. It moves cybersecurity from a technical checklist to an enterprise-risk discipline.]]></description>
    </item>
    <item>
      <title>NIST CSF 2.0 core functions: Govern, Identify, Protect, Detect, Respond, Recover</title>
      <link>https://sentinelpanda.com/insights/nist-csf-2-0-core-functions</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/nist-csf-2-0-core-functions</guid>
      <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
      <category>NIST CSF</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The Cybersecurity Framework is a conceptual map, not a control checklist. Knowing the six functions cold is how you have a useful conversation with executives, customers, and procurement.]]></description>
    </item>
    <item>
      <title>Manual vs continuous compliance evidence</title>
      <link>https://sentinelpanda.com/insights/manual-vs-continuous-evidence</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/manual-vs-continuous-evidence</guid>
      <pubDate>Tue, 03 Mar 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Screenshots taken the week before an audit prove one thing: that the control worked once, under observation. Continuous evidence proves it works.]]></description>
    </item>
    <item>
      <title>SOC 2 Common Criteria (CC1 to CC9), explained</title>
      <link>https://sentinelpanda.com/insights/soc-2-common-criteria-explained</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-common-criteria-explained</guid>
      <pubDate>Fri, 27 Feb 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Every SOC 2 report covers the same nine Common Criteria categories. Knowing what each one expects is how you stop a friendly Type I conversation from turning into a list of management responses.]]></description>
    </item>
    <item>
      <title>PCI scoping: identifying your cardholder data environment</title>
      <link>https://sentinelpanda.com/insights/pci-cde-scoping</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/pci-cde-scoping</guid>
      <pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The PCI requirements only apply to systems in scope. Defining scope is the first and most consequential decision in any assessment, and the easiest one to get wrong.]]></description>
    </item>
    <item>
      <title>The ISO 27001 Statement of Applicability, done right</title>
      <link>https://sentinelpanda.com/insights/iso-27001-statement-of-applicability</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-statement-of-applicability</guid>
      <pubDate>Wed, 18 Feb 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The SoA is the single document a certification auditor measures everything else against. Get it right and the audit goes smoothly.]]></description>
    </item>
    <item>
      <title>ISO 27001 mandatory clauses 4 to 10, explained</title>
      <link>https://sentinelpanda.com/insights/iso-27001-clauses-4-to-10</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/iso-27001-clauses-4-to-10</guid>
      <pubDate>Fri, 13 Feb 2026 00:00:00 GMT</pubDate>
      <category>ISO 27001</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[ISO 27001 is a management system standard. The 93 Annex A controls are the visible half; clauses 4 to 10 are the management system itself, and they decide whether the audit goes well.]]></description>
    </item>
    <item>
      <title>PCI DSS service provider levels and what SaaS owes</title>
      <link>https://sentinelpanda.com/insights/pci-service-provider-levels</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/pci-service-provider-levels</guid>
      <pubDate>Mon, 09 Feb 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[If your software handles card data on behalf of your customers, you are a service provider in the PCI DSS sense. The customer-facing AOC you owe is one of the most common compliance artifacts you will be asked for.]]></description>
    </item>
    <item>
      <title>SOC 2 Type I vs Type II: which do you need?</title>
      <link>https://sentinelpanda.com/insights/soc-2-type-1-vs-type-2</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-type-1-vs-type-2</guid>
      <pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A Type I proves your controls are designed well today. A Type II proves they actually worked over months. Most buyers want the second one.]]></description>
    </item>
    <item>
      <title>The five SOC 2 Trust Services Criteria, explained</title>
      <link>https://sentinelpanda.com/insights/soc-2-trust-services-criteria</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/soc-2-trust-services-criteria</guid>
      <pubDate>Fri, 30 Jan 2026 00:00:00 GMT</pubDate>
      <category>SOC 2</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[A SOC 2 report covers five Trust Services Criteria, but only one is mandatory. Picking the rest is a scoping decision driven by what you promise customers.]]></description>
    </item>
    <item>
      <title>Which PCI SAQ type applies to you?</title>
      <link>https://sentinelpanda.com/insights/which-pci-saq-type</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/which-pci-saq-type</guid>
      <pubDate>Thu, 22 Jan 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The right SAQ depends entirely on how you handle card data. Pick the wrong one and you either over-report or, worse, under-scope.]]></description>
    </item>
    <item>
      <title>Completing a PCI DSS Self-Assessment Questionnaire, step by step</title>
      <link>https://sentinelpanda.com/insights/pci-saq-step-by-step</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/pci-saq-step-by-step</guid>
      <pubDate>Fri, 16 Jan 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[The SAQ is short next to a full Report on Compliance, but it is still an annual evidentiary document with real legal weight. Treating it like a form-filling exercise is how programs end up missing things.]]></description>
    </item>
    <item>
      <title>PCI DSS 4.0.1: what changed and how to prepare</title>
      <link>https://sentinelpanda.com/insights/pci-dss-4-0-1-what-changed</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/pci-dss-4-0-1-what-changed</guid>
      <pubDate>Fri, 09 Jan 2026 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[PCI DSS 4.0 (refined as 4.0.1) is the largest revision of the standard in a decade. Here is what actually changed, and a pragmatic order to tackle it.]]></description>
    </item>
    <item>
      <title>PCI DSS merchant levels (1 through 4), explained</title>
      <link>https://sentinelpanda.com/insights/pci-merchant-levels</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/pci-merchant-levels</guid>
      <pubDate>Tue, 09 Dec 2025 00:00:00 GMT</pubDate>
      <category>PCI DSS</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Your merchant level decides the validation path. Knowing where you sit, and what triggers a promotion, is the difference between a quarter of self-assessment work and a year of ROC fieldwork.]]></description>
    </item>
    <item>
      <title>Cross-framework control mapping, explained</title>
      <link>https://sentinelpanda.com/insights/cross-framework-control-mapping</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/cross-framework-control-mapping</guid>
      <pubDate>Wed, 12 Nov 2025 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[Most security frameworks ask for the same things in different words. Mapping is how you stop proving the same control five times.]]></description>
    </item>
    <item>
      <title>What is a GRC platform?</title>
      <link>https://sentinelpanda.com/insights/what-is-a-grc-platform</link>
      <guid isPermaLink="true">https://sentinelpanda.com/insights/what-is-a-grc-platform</guid>
      <pubDate>Tue, 21 Oct 2025 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>noreply@sentinelpanda.com (Sam Rivera)</author>
      <description><![CDATA[GRC stands for governance, risk, and compliance. A GRC platform is the system of record that ties all three together instead of scattering them across spreadsheets.]]></description>
    </item>
  </channel>
</rss>
