Blog & News

What the regulation
actually means for you.

Practical analysis on governance, risk and compliance — regulatory convergence, framework overlap, AI governance, and what shifting standards mean for a programme you already have to run.

Latest

NIST's Cyber AI Profile meets ISO 27001

Thought Leadership March 2026 8 min read

What the new framework convergence means for your ISMS

In December 2025 NIST released its draft Cybersecurity Framework Profile for Artificial Intelligence (NISTIR 8596), mapping AI-specific cybersecurity considerations onto the CSF 2.0 structure.

  • Your ISMS now has to account for AI three times over — as a security asset, as a defence, and as a threat vector.
  • Where the Cyber AI Profile intersects ISO 27001 controls, and which of your existing controls already carry the weight.
  • A shared control architecture prevents the duplication that quietly overwhelms security teams.
Read the full article

By Steve — AssureLogic

What we write about

Less commentary on what a regulation says. More on what it costs you to comply with it.

Framework convergence

Where standards overlap and where they genuinely differ, and how a shared control architecture lets you do the work once instead of five times.

See all 29 standards

AI governance

EU AI Act obligations in practice, ISO 42001 as a management system, and treating AI as asset, as defence and as threat at the same time.

Explore AI governance

Regulatory change

DORA, NIS2 and the UK cyber resilience agenda; Provision 29 and board-level declarations; CSRD and sustainability disclosure.

Provision 29

Reading about it is one thing.
Running it is another.

See how the platform handles overlapping frameworks without overlapping effort.