Fieldbook · forming
Operational Truth
A Shahid Shah Fieldbook
Assurance built on human attestation produces documents, not security. The organizations that survive scrutiny are the ones whose systems can prove their own state continuously, by machine, without anyone being asked to vouch for it.
Compliant insecurity is the failure mode of every paperwork-based control regime. This Fieldbook gathers the machine attestation and compliance-as-code arguments with the operating work that follows: what a CISO actually owns in federal contracting, how healthcare's security crisis is a leadership problem before it is a technical one, and why privileged access is the assumption most audits never test.
Status
Forming. 8 published pieces are feeding this Fieldbook. When the argument holds end to end, it gets consolidated and substantially expanded into a single work.
Argue with me about it →Working Theories
An idea developed enough to use, but important enough to keep questioning.
November 1, 2024
Why Machine Attestation is Key in the Age of CMMC
Under the DoD’s CMMC Program, maintaining continuous compliance is crucial, and machine attestation provides the consistency and accuracy human checks can’t match. By automating compliance tracking, contractors can ensure real-time verification, creating a robust audit trail and reducing compliance risks across contract lifecycles.
September 30, 2023
Embrace Compliance as Code
Exploring the benefits of transitioning to a 'compliance as code' model by reflecting on successful implementations of other 'as code' models.
Operating Notes
How I actually handle this when something real is at stake.
June 1, 2023
The Importance of Chief Information Security Officers in Federal Government Contracts
A Chief Information Security Officer (CISO) is a senior executive responsible for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately…
June 6, 2024
From Vulnerability to Strength: The Role of CISO Services in Cyber Resilience
There was a time when no one really needed a CISO. Today, an organization would be dangerously insane not to have one. And that CISO had better be top-notch. The role of the Chief Information Security Officer (CISO) has evolved significantly from being solely a technology-focused professional to becoming a strategic business leader
September 6, 2024
Healthcare’s Cybersecurity Crisis: Leadership Challenges and Strategic Solutions
Healthcare's cybersecurity crisis is critical, with outdated defenses exposing patient data and trust. Zero Trust is now mandatory, and delays in breach detection can cause immense damage. Effective leadership, including fractional CISOs, is essential for modern defense. Inaction isn't an option, proactive steps are necessary to safeguard against sophisticated threats.
Contrarian Briefs
An argument against an assumption that has become too comfortable.
September 26, 2023
Systems that require human attestation to prove compliance are not secure
While a system may meet all the necessary regulations and standards, it can still be vulnerable to threats and attacks because of human attestation.
June 1, 2022
Compliant Insecurity in Government Agencies and Contractors
I challenge the conventional wisdom on cybersecurity, focusing on the problem of 'compliant insecurity'.
January 6, 2006
If engineers or database administrators can access your data, it’s not secure
There is a general misconception in the IT community that their database servers are somehow their most secure systems and that *because* they are secure their customers data and their own financial information is safe. Let me…
