From AI Ambition to AI Assurance
Five executive briefings for CISOs, CIOs, CTOs and board sponsors on governing, securing and scaling enterprise AI. One paper per day, this week.
The InfoSecAI library is the long-form, evergreen home for our published thinking. Each item is authored by Paul Jolliffe, written for senior practitioners, and structured to support a decision rather than fill a feed. Reviewed when standards change, not on a schedule.
Five executive briefings for CISOs, CIOs, CTOs and board sponsors on governing, securing and scaling enterprise AI. One paper per day, this week.
A practitioner field note on the mandatory documented information ISO 22301 requires by clause, the supporting documentation, the Business Impact Analysis spine, and why documented is not the same as demonstrated.
A practitioner field note on the mandatory documented information ISO 42001 requires by clause, the supporting documentation by Annex A, the impact-assessment spine, and why a 42001 certificate is not the EU AI Act.
A practitioner field note on the mandatory documented information ISO 27001 requires by clause, the supporting documentation by Annex A, and the four places Stage 2 audits actually break.
A practitioner's white paper for CEOs, boards, CISOs and hiring committees on how security leadership has changed and the operating model boards must now build around it.
Thirty control domains mapped across ISO 27001:2022, NIST CSF 2.0, CIS Controls v8.1, DORA, NIS 2, UK GDPR and the EU AI Act with ISO 42001.
The structured first three months of a fractional CISO engagement. Three phases, twelve milestones, the artefacts the board will be shown.
The decisions every UK board, audit committee chair and CISO should make before EU AI Act high-risk obligations begin.
Pillar-by-pillar self-check, third-party criticality matrix and the four-hour major incident notification clock, one year into DORA enforcement.
A long-form treatment of the persistent disconnect between AI board policy and the engineering practice that actually deploys models into production.
A practitioner's read of NIS 2 essential and important entity scope, focused on UK firms with EU subsidiaries, customers or supply chain exposure.
No papers in the library match the current filter combination.
LIBRARY NOTE · PAPERS ARE EVERGREEN, REVIEWED ON MATERIAL CHANGE TO STANDARDS OR REGULATION
The InfoSecAI Brief sends each new white paper, briefing and field note to subscribers' inboxes on the day it is published. No tracking pixels, no marketing automation, no upsell sequences. Unsubscribe in a single click.