<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Chethana M</title>
    <description>The latest articles on DEV Community by Chethana M (@chethana_m_cc98dabb42ce46).</description>
    <link>https://dev.to/chethana_m_cc98dabb42ce46</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4163419%2Fb0334af3-b96f-41a0-9782-3cc3eeeaa8c8.png</url>
      <title>DEV Community: Chethana M</title>
      <link>https://dev.to/chethana_m_cc98dabb42ce46</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/chethana_m_cc98dabb42ce46"/>
    <language>en</language>
    <item>
      <title>HITRUST vs SOC 2: A Practical View for Healthcare SaaS Teams</title>
      <dc:creator>Chethana M</dc:creator>
      <pubDate>Tue, 06 Oct 2026 10:43:41 +0000</pubDate>
      <link>https://dev.to/chethana_m_cc98dabb42ce46/hitrust-vs-soc-2-a-practical-view-for-healthcare-saas-teams-59b1</link>
      <guid>https://dev.to/chethana_m_cc98dabb42ce46/hitrust-vs-soc-2-a-practical-view-for-healthcare-saas-teams-59b1</guid>
      <description>&lt;p&gt;If you build SaaS for healthcare customers in the US, security assurance eventually becomes part of the product conversation.&lt;/p&gt;

&lt;p&gt;Not because customers want another badge on your website, but because enterprise buyers need evidence that vendors have appropriate controls around sensitive systems and information.&lt;/p&gt;

&lt;p&gt;That is why SOC 2 and HITRUST frequently appear in healthcare vendor assessments.&lt;/p&gt;

&lt;p&gt;The two should not be treated as interchangeable.&lt;/p&gt;

&lt;p&gt;SOC 2 evaluates controls against the AICPA Trust Services Criteria. Security is required, while other criteria such as availability, processing integrity, confidentiality, and privacy can be included according to the engagement.&lt;/p&gt;

&lt;p&gt;For a SaaS company, this makes SOC 2 useful well beyond healthcare. If the product serves several industries, a SOC 2 report can provide assurance that applies across a broad customer base.&lt;/p&gt;

&lt;p&gt;You can explore the SOC 2 assurance offering when considering how this type of independent examination fits into a SaaS security program.&lt;/p&gt;

&lt;p&gt;HITRUST approaches the problem differently.&lt;/p&gt;

&lt;p&gt;The HITRUST CSF combines requirements from multiple authoritative sources into a structured framework and provides an assessment and certification model. This makes it particularly relevant to organizations operating in healthcare environments where customers may want assurance that takes healthcare-related security and privacy expectations into account.&lt;/p&gt;

&lt;p&gt;The important part for engineering and security teams is not simply knowing that both frameworks exist. It is understanding what each one is actually demonstrating.&lt;/p&gt;

&lt;p&gt;A SOC 2 report does not automatically equal HITRUST certification.&lt;/p&gt;

&lt;p&gt;There may be substantial overlap in controls around identity and access management, risk management, monitoring, incident response, vendor management, continuity, and change management. However, the assessment models and requirements remain different.&lt;/p&gt;

&lt;p&gt;This distinction becomes important when a healthcare customer asks for a specific certification.&lt;/p&gt;

&lt;p&gt;Imagine a SaaS company already has &lt;a href="https://www.intercert.com/blogs/hitrust-vs-soc-2-for-healthcare" rel="noopener noreferrer"&gt;SOC 2&lt;/a&gt; Type II. A hospital procurement team then requests HITRUST. The company should not assume that its existing report closes the requirement simply because many controls overlap.&lt;/p&gt;

&lt;p&gt;Instead, it needs to compare the existing assurance scope with the customer's expectations and the applicable HITRUST requirements.&lt;/p&gt;

&lt;p&gt;The reverse can also happen. A company may have HITRUST certification because healthcare customers expect it, while a large enterprise customer outside healthcare requests SOC 2.&lt;/p&gt;

&lt;p&gt;This is why mature SaaS organizations sometimes maintain both.&lt;/p&gt;

&lt;p&gt;The decision should ultimately follow the market.&lt;/p&gt;

&lt;p&gt;If your customers are primarily general enterprise technology buyers, SOC 2 may be central to your assurance strategy. If healthcare organizations specifically request HITRUST, that requirement needs to be considered independently.&lt;/p&gt;

&lt;p&gt;And if the business serves both groups, maintaining multiple assurance mechanisms may make commercial sense.&lt;/p&gt;

&lt;p&gt;The useful question is therefore not “Which framework is better?”&lt;/p&gt;

&lt;p&gt;It is:&lt;/p&gt;

&lt;p&gt;Which assurance evidence do our customers actually expect, and does our current control environment demonstrate it?&lt;/p&gt;

&lt;p&gt;That question gives security, compliance, and business teams a much more practical starting point.&lt;/p&gt;

</description>
      <category>saas</category>
      <category>security</category>
    </item>
    <item>
      <title>ISO 27001 for Philippine SMEs: Where Information Security Governance Meets Technology</title>
      <dc:creator>Chethana M</dc:creator>
      <pubDate>Tue, 06 Oct 2026 10:19:35 +0000</pubDate>
      <link>https://dev.to/chethana_m_cc98dabb42ce46/iso-27001-for-philippine-smes-where-information-security-governance-meets-technology-afn</link>
      <guid>https://dev.to/chethana_m_cc98dabb42ce46/iso-27001-for-philippine-smes-where-information-security-governance-meets-technology-afn</guid>
      <description>&lt;p&gt;For technology-driven SMEs in the Philippines, information security is often discussed in terms of firewalls, encryption, access controls, cloud security, vulnerability management, and monitoring.&lt;/p&gt;

&lt;p&gt;These technologies matter.&lt;/p&gt;

&lt;p&gt;But an organization can have a sophisticated security stack and still struggle to demonstrate that information security is being managed systematically across the business.&lt;/p&gt;

&lt;p&gt;This is where ISO/IEC 27001 takes a different approach.&lt;/p&gt;

&lt;p&gt;Rather than being a purely technical security standard, ISO 27001 establishes requirements for an Information Security Management System.&lt;/p&gt;

&lt;p&gt;Technology Is Only One Part of the ISMS&lt;/p&gt;

&lt;p&gt;An ISMS connects technology with organizational processes.&lt;/p&gt;

&lt;p&gt;The organization defines its scope, identifies information security risks, establishes relevant controls, assigns responsibilities, monitors performance, and evaluates whether the management system continues to operate effectively.&lt;/p&gt;

&lt;p&gt;For a Philippine software company, for example, the ISMS scope could include its development environment, cloud infrastructure, information assets, personnel, supporting processes, and customer-facing services depending on the defined certification boundary.&lt;/p&gt;

&lt;p&gt;This creates a broader view of information security.&lt;/p&gt;

&lt;p&gt;Organizations considering the standard can explore ISO 27001 certification to understand how the certification framework applies to an ISMS.&lt;/p&gt;

&lt;p&gt;What Influences Certification Cost?&lt;/p&gt;

&lt;p&gt;Technology companies often assume certification cost is primarily determined by the number of security tools they operate.&lt;/p&gt;

&lt;p&gt;That is not necessarily the case.&lt;/p&gt;

&lt;p&gt;Audit requirements can be influenced by factors such as:&lt;/p&gt;

&lt;p&gt;Number of employees&lt;br&gt;
ISMS scope&lt;br&gt;
Number of locations&lt;br&gt;
Operational complexity&lt;br&gt;
Existing information security maturity&lt;br&gt;
Systems and processes included within the certification boundary&lt;/p&gt;

&lt;p&gt;A small SaaS company with one location and a clearly defined service scope can have very different certification requirements from a technology business operating across several countries.&lt;/p&gt;

&lt;p&gt;Stage 1 vs Stage 2&lt;/p&gt;

&lt;p&gt;The certification audit itself has two primary stages.&lt;/p&gt;

&lt;p&gt;Stage 1 evaluates the structure of the ISMS. This includes areas such as scope, governance, documented information, and the organization's overall approach to the management system.&lt;/p&gt;

&lt;p&gt;Stage 2 moves into operational effectiveness.&lt;/p&gt;

&lt;p&gt;Auditors evaluate evidence to determine whether the ISMS is functioning as intended and whether the organization conforms to ISO/IEC 27001 requirements.&lt;/p&gt;

&lt;p&gt;This distinction matters because certification is not simply a document review.&lt;/p&gt;

&lt;p&gt;The assessment considers how the management system operates in practice.&lt;/p&gt;

&lt;p&gt;Why This Matters for Philippine Tech Companies&lt;/p&gt;

&lt;p&gt;Technology companies in the Philippines increasingly serve customers outside the domestic market.&lt;/p&gt;

&lt;p&gt;A SaaS provider, software development company, BPO organization, fintech platform, or digital services business may encounter security requirements from international customers before a contract is signed.&lt;/p&gt;

&lt;p&gt;ISO 27001 certification can provide independently assessed evidence of an organization's information security management approach.&lt;/p&gt;

&lt;p&gt;This can become particularly valuable when responding to enterprise procurement requirements.&lt;/p&gt;

&lt;p&gt;Certification Is Not a One-Time Technical Project&lt;/p&gt;

&lt;p&gt;Another important point is that maintaining ISO 27001 certification requires continued attention.&lt;/p&gt;

&lt;p&gt;Surveillance audits take place during the certification cycle to evaluate continued conformity.&lt;/p&gt;

&lt;p&gt;The organization also needs to maintain the effectiveness of its ISMS and demonstrate continual improvement.&lt;/p&gt;

&lt;p&gt;At the end of the cycle, recertification is required.&lt;/p&gt;

&lt;p&gt;This means technology SMEs should think about &lt;a href="https://www.intercert.com/blogs/iso-27001-certification-process-cost-philippines-smes" rel="noopener noreferrer"&gt;ISO 27001&lt;/a&gt; as an ongoing management system rather than a one-time security project.&lt;/p&gt;

&lt;p&gt;A Better Way to Think About the Cost&lt;/p&gt;

&lt;p&gt;Instead of asking only, "What is the ISO 27001 price?", businesses should first ask:&lt;/p&gt;

&lt;p&gt;What is our intended certification scope?&lt;/p&gt;

&lt;p&gt;How many employees and locations are involved?&lt;/p&gt;

&lt;p&gt;How complex are our operations?&lt;/p&gt;

&lt;p&gt;How mature is our existing information security management system?&lt;/p&gt;

&lt;p&gt;What customer or market requirements are driving certification?&lt;/p&gt;

&lt;p&gt;The answers to these questions provide a much clearer basis for understanding certification requirements.&lt;/p&gt;

&lt;p&gt;For Philippine technology SMEs, ISO 27001 can therefore connect technical security practices with organizational governance, creating a recognized framework that can demonstrate how information security is managed as the business grows.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>management</category>
      <category>security</category>
    </item>
    <item>
      <title>CSA STAR vs ISO 27001: A Technical Look at Cloud Security Assurance</title>
      <dc:creator>Chethana M</dc:creator>
      <pubDate>Tue, 06 Oct 2026 09:54:57 +0000</pubDate>
      <link>https://dev.to/chethana_m_cc98dabb42ce46/csa-star-vs-iso-27001-a-technical-look-at-cloud-security-assurance-g4j</link>
      <guid>https://dev.to/chethana_m_cc98dabb42ce46/csa-star-vs-iso-27001-a-technical-look-at-cloud-security-assurance-g4j</guid>
      <description>&lt;p&gt;Cloud environments introduce a different security model from traditional on-premises infrastructure.&lt;/p&gt;

&lt;p&gt;Organizations may rely on shared infrastructure, virtualization, distributed services, third-party platforms, identity providers, APIs, and other interconnected technologies. This creates security considerations that cannot always be addressed through a general information security perspective alone.&lt;/p&gt;

&lt;p&gt;That is one reason the distinction between ISO/IEC 27001 and CSA STAR matters.&lt;/p&gt;

&lt;p&gt;Both frameworks contribute to information security assurance, but their scopes differ.&lt;/p&gt;

&lt;p&gt;ISO 27001: The Management-System Layer&lt;/p&gt;

&lt;p&gt;ISO/IEC 27001 establishes requirements for an Information Security Management System.&lt;/p&gt;

&lt;p&gt;From a technical perspective, this means information security is not treated solely as a collection of security technologies.&lt;/p&gt;

&lt;p&gt;The organization establishes a management structure around information security risks, controls, monitoring, performance evaluation, and continual improvement.&lt;/p&gt;

&lt;p&gt;The scope can include cloud environments.&lt;/p&gt;

&lt;p&gt;For example, a SaaS company could include its cloud infrastructure, applications, information assets, employees, processes, and supporting technologies within the defined scope of its ISMS.&lt;/p&gt;

&lt;p&gt;This provides a broader security governance foundation.&lt;/p&gt;

&lt;p&gt;CSA STAR: The Cloud-Specific Layer&lt;/p&gt;

&lt;p&gt;CSA STAR approaches the problem from the perspective of cloud security.&lt;/p&gt;

&lt;p&gt;Cloud environments have characteristics that deserve specific consideration, including:&lt;/p&gt;

&lt;p&gt;Virtualization&lt;br&gt;
Multi-tenancy&lt;br&gt;
Cloud architecture&lt;br&gt;
Identity and access management&lt;br&gt;
Infrastructure security&lt;br&gt;
Data protection&lt;br&gt;
Resilience&lt;br&gt;
Cloud governance&lt;br&gt;
Shared security responsibilities&lt;/p&gt;

&lt;p&gt;The Cloud Security Alliance STAR Program is designed around these types of cloud-specific considerations.&lt;/p&gt;

&lt;p&gt;For organizations exploring this framework, &lt;a href="https://www.intercert.com/blogs/csa-star-vs-iso-27001-cloud-security-certification-eu" rel="noopener noreferrer"&gt;CSA STAR certification&lt;/a&gt; provides a route toward demonstrating cloud security assurance against recognized requirements.&lt;/p&gt;

&lt;p&gt;Why the Two Frameworks Can Work Together&lt;/p&gt;

&lt;p&gt;The interesting part is the relationship between the two.&lt;/p&gt;

&lt;p&gt;CSA STAR Certification Level 2 is built on an ISO/IEC 27001-certified ISMS and introduces additional cloud-focused requirements based on the Cloud Controls Matrix.&lt;/p&gt;

&lt;p&gt;In practical terms, this creates two complementary layers.&lt;/p&gt;

&lt;p&gt;ISO 27001 addresses the organization's broader information security management system.&lt;/p&gt;

&lt;p&gt;CSA STAR adds a cloud-specific security perspective.&lt;/p&gt;

&lt;p&gt;This can be particularly relevant for cloud service providers whose customers want assurance that both organizational security governance and cloud-specific risks are being addressed.&lt;/p&gt;

&lt;p&gt;A Technical Example&lt;/p&gt;

&lt;p&gt;Consider a cloud service provider operating a SaaS platform.&lt;/p&gt;

&lt;p&gt;ISO 27001 can provide the broader management framework for protecting the information processed by the organization.&lt;/p&gt;

&lt;p&gt;The provider can define its ISMS scope, evaluate information security risks, establish appropriate controls, monitor performance, and continually improve its security management processes.&lt;/p&gt;

&lt;p&gt;CSA STAR can then provide additional assurance around cloud-specific areas.&lt;/p&gt;

&lt;p&gt;The provider's customers may be particularly interested in how the cloud environment addresses issues such as tenant separation, cloud architecture, infrastructure security, and cloud governance.&lt;/p&gt;

&lt;p&gt;The two perspectives answer different questions.&lt;/p&gt;

&lt;p&gt;ISO 27001: How systematically does the organization manage information security?&lt;/p&gt;

&lt;p&gt;CSA STAR: How does the organization demonstrate assurance around security in its cloud environment?&lt;/p&gt;

&lt;p&gt;Choosing Based on the Architecture and Business Model&lt;/p&gt;

&lt;p&gt;Technology architecture should be considered alongside business requirements.&lt;/p&gt;

&lt;p&gt;A company with limited cloud exposure but significant information assets may primarily require broad information security governance.&lt;/p&gt;

&lt;p&gt;A cloud-native organization delivering services to enterprise customers may have stronger reasons to consider cloud-specific assurance.&lt;/p&gt;

&lt;p&gt;The customer base also matters.&lt;/p&gt;

&lt;p&gt;Enterprise buyers frequently use security certifications as part of supplier evaluation. If a provider's customers operate in regulated sectors, they may expect more detailed evidence around cloud security.&lt;/p&gt;

&lt;p&gt;Why Transparency Matters&lt;/p&gt;

&lt;p&gt;CSA STAR also introduces an additional transparency dimension through the STAR Registry.&lt;/p&gt;

&lt;p&gt;For cloud providers, publicly available assurance information can make it easier for prospective customers to evaluate the provider's security posture.&lt;/p&gt;

&lt;p&gt;This can be commercially relevant when customers compare multiple cloud providers.&lt;/p&gt;

&lt;p&gt;Security assurance is therefore not only a technical issue. It can influence procurement, customer confidence, and market differentiation.&lt;/p&gt;

&lt;p&gt;Final Perspective&lt;/p&gt;

&lt;p&gt;ISO 27001 and CSA STAR should not automatically be treated as competing technologies or certifications.&lt;/p&gt;

&lt;p&gt;ISO 27001 establishes a broad information security management foundation.&lt;/p&gt;

&lt;p&gt;CSA STAR focuses more specifically on cloud security assurance.&lt;/p&gt;

&lt;p&gt;For cloud service providers, particularly those serving European enterprise customers, understanding how the two frameworks relate can lead to a more informed certification strategy.&lt;/p&gt;

&lt;p&gt;In many cases, the strongest approach is not choosing one over the other, but determining how each framework can contribute to the organization's broader security assurance objectives.&lt;/p&gt;

</description>
      <category>cloud</category>
      <category>cybersecurity</category>
      <category>infrastructure</category>
      <category>security</category>
    </item>
    <item>
      <title>Why Energy Data Matters in Industrial Energy Management</title>
      <dc:creator>Chethana M</dc:creator>
      <pubDate>Tue, 06 Oct 2026 09:22:20 +0000</pubDate>
      <link>https://dev.to/chethana_m_cc98dabb42ce46/why-energy-data-matters-in-industrial-energy-management-3h1f</link>
      <guid>https://dev.to/chethana_m_cc98dabb42ce46/why-energy-data-matters-in-industrial-energy-management-3h1f</guid>
      <description>&lt;p&gt;Industrial energy management increasingly depends on the quality of the data available to decision-makers.&lt;/p&gt;

&lt;p&gt;A facility may consume electricity, fuel, steam, compressed air, or other forms of energy across dozens of processes and systems. Production equipment, HVAC, refrigeration, pumps, boilers, lighting, and utilities can all contribute to the overall energy profile.&lt;/p&gt;

&lt;p&gt;The challenge is not simply collecting consumption figures.&lt;/p&gt;

&lt;p&gt;The more important question is whether organizations can use energy information to understand performance and make better operational decisions.&lt;/p&gt;

&lt;p&gt;Energy Data as an Operational Input&lt;/p&gt;

&lt;p&gt;For an industrial organization, energy data can reveal patterns that may otherwise remain difficult to identify.&lt;/p&gt;

&lt;p&gt;A sudden increase in energy consumption may indicate an operational change. A persistent increase could point toward inefficient equipment or processes. Comparing energy performance across different periods can also provide insight into whether specific initiatives are producing the expected results.&lt;/p&gt;

&lt;p&gt;This makes energy measurement relevant beyond sustainability reporting.&lt;/p&gt;

&lt;p&gt;It can become part of the information used to evaluate operational performance.&lt;/p&gt;

&lt;p&gt;ISO 50001 provides a structured framework for this type of energy management. Organizations exploring certification can learn more about &lt;a href="https://www.intercert.com/blogs/iso-50001-energy-management-roi-uae-industrial-firms" rel="noopener noreferrer"&gt;ISO 50001&lt;/a&gt; energy management certification and its requirements for establishing and continually improving an Energy Management System.&lt;/p&gt;

&lt;p&gt;The Role of Energy Performance Indicators&lt;/p&gt;

&lt;p&gt;Energy Performance Indicators, commonly known as EnPIs, are an important concept within ISO 50001.&lt;/p&gt;

&lt;p&gt;Rather than relying only on total energy consumption, organizations can use defined indicators to evaluate energy performance in a more meaningful way.&lt;/p&gt;

&lt;p&gt;This matters because raw consumption figures can sometimes be misleading.&lt;/p&gt;

&lt;p&gt;Production volumes, operating conditions, facility usage, and other factors can influence energy consumption. A structured approach to performance measurement provides a stronger basis for understanding whether energy performance is actually improving.&lt;/p&gt;

&lt;p&gt;Connecting Data With Industrial Decisions&lt;/p&gt;

&lt;p&gt;The technical side of energy management becomes more valuable when the resulting information reaches the right decision-making processes.&lt;/p&gt;

&lt;p&gt;Energy performance information can contribute to decisions involving:&lt;/p&gt;

&lt;p&gt;Production operations&lt;br&gt;
Equipment performance&lt;br&gt;
Maintenance priorities&lt;br&gt;
Energy efficiency initiatives&lt;br&gt;
Facility management&lt;br&gt;
Sustainability objectives&lt;br&gt;
Resource planning&lt;/p&gt;

&lt;p&gt;The objective is not simply to create another dataset.&lt;/p&gt;

&lt;p&gt;The objective is to make energy performance information useful.&lt;/p&gt;

&lt;p&gt;Why This Matters for UAE Industry&lt;/p&gt;

&lt;p&gt;For energy-intensive businesses in the UAE, the financial significance of energy consumption can make this approach particularly relevant.&lt;/p&gt;

&lt;p&gt;Manufacturing facilities, food processors, cement operations, chemical businesses, metals companies, logistics organizations, and other industrial sectors may have multiple significant energy uses that require ongoing monitoring.&lt;/p&gt;

&lt;p&gt;A structured Energy Management System can create greater consistency around how these energy uses are identified, measured, reviewed, and improved.&lt;/p&gt;

&lt;p&gt;From Monitoring to Continual Improvement&lt;/p&gt;

&lt;p&gt;Data has limited value when it is collected but never evaluated.&lt;/p&gt;

&lt;p&gt;Effective energy management requires organizations to review performance, compare results with objectives, identify areas requiring attention, and continue evaluating improvements over time.&lt;/p&gt;

&lt;p&gt;This creates a cycle in which measurement informs decisions and decisions influence future energy performance.&lt;/p&gt;

&lt;p&gt;For organizations considering ISO 50001, this connection between data, operational controls, measurement, and continual improvement is an important part of the broader business case.&lt;/p&gt;

&lt;p&gt;Energy management is therefore not only an environmental or facilities concern. In data-rich industrial environments, it can become an important component of operational intelligence.&lt;/p&gt;

</description>
      <category>analytics</category>
      <category>data</category>
      <category>management</category>
      <category>productivity</category>
    </item>
    <item>
      <title>NIST AI RMF: What Engineering Teams Should Know About AI Risk</title>
      <dc:creator>Chethana M</dc:creator>
      <pubDate>Mon, 05 Oct 2026 11:56:01 +0000</pubDate>
      <link>https://dev.to/chethana_m_cc98dabb42ce46/nist-ai-rmf-what-engineering-teams-should-know-about-ai-risk-2blc</link>
      <guid>https://dev.to/chethana_m_cc98dabb42ce46/nist-ai-rmf-what-engineering-teams-should-know-about-ai-risk-2blc</guid>
      <description>&lt;p&gt;AI engineering does not end when a model performs well in testing.&lt;/p&gt;

&lt;p&gt;Once an AI system enters a real business environment, additional questions emerge. How is the system being used? What data does it depend on? Who owns decisions around it? How are unexpected outputs handled? What happens when the model, data, vendor, or use case changes?&lt;/p&gt;

&lt;p&gt;These questions are part of the wider AI governance problem.&lt;/p&gt;

&lt;p&gt;The NIST AI Risk Management Framework offers a useful structure for thinking about that problem.&lt;/p&gt;

&lt;p&gt;NIST AI RMF 1.0 is a voluntary framework from the U.S. National Institute of Standards and Technology. It is designed to help organizations identify and manage AI risks while promoting trustworthy AI.&lt;/p&gt;

&lt;p&gt;The framework is organized around four functions:&lt;/p&gt;

&lt;p&gt;Govern establishes organizational policies, roles, responsibilities, accountability, and oversight.&lt;/p&gt;

&lt;p&gt;Map focuses on understanding the context of an AI system, including its intended purpose, stakeholders, potential impacts, and risk environment.&lt;/p&gt;

&lt;p&gt;Measure focuses on evaluating risks and system characteristics through appropriate testing, analysis, and monitoring.&lt;/p&gt;

&lt;p&gt;Manage focuses on prioritizing identified risks, determining responses, and monitoring those risks over time.&lt;/p&gt;

&lt;p&gt;For developers and engineering leaders, an important takeaway is that AI risk is broader than application security.&lt;/p&gt;

&lt;p&gt;Depending on the system, engineering teams may need to consider data privacy, reliability, security, explainability, fairness, harmful bias, and unexpected system behavior.&lt;/p&gt;

&lt;p&gt;The framework also recognizes that AI risk changes over time. A model that performs appropriately in one environment may create different risks after its data, users, integrations, or intended purpose changes.&lt;/p&gt;

&lt;p&gt;This makes ongoing monitoring an important part of AI governance.&lt;/p&gt;

&lt;p&gt;NIST AI RMF can also provide useful context when organizations are evaluating how their AI practices connect with other frameworks and standards, including cybersecurity and AI management approaches.&lt;/p&gt;

&lt;p&gt;For a broader introduction to the framework, &lt;a href="https://www.intercert.com/blogs/nist-ai-risk-management-framework-guide-us-enterprises-usa" rel="noopener noreferrer"&gt;NIST AI Risk Management Framework: A Starter Guide for US Enterprises&lt;/a&gt; explains the four functions, key trustworthy-AI characteristics, and practical considerations for organizations adopting NIST AI RMF.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>DPDPA vs GDPR: What Developers and Privacy Teams Should Know</title>
      <dc:creator>Chethana M</dc:creator>
      <pubDate>Mon, 05 Oct 2026 11:10:22 +0000</pubDate>
      <link>https://dev.to/chethana_m_cc98dabb42ce46/dpdpa-vs-gdpr-what-developers-and-privacy-teams-should-know-3d0f</link>
      <guid>https://dev.to/chethana_m_cc98dabb42ce46/dpdpa-vs-gdpr-what-developers-and-privacy-teams-should-know-3d0f</guid>
      <description>&lt;p&gt;Privacy requirements increasingly affect technical decisions.&lt;/p&gt;

&lt;p&gt;Data collection, application architecture, APIs, cloud services, databases, analytics platforms, identity systems, and third-party integrations can all influence how an organization processes personal information.&lt;/p&gt;

&lt;p&gt;For Indian technology companies, the DPDPA introduces an important domestic privacy framework. For businesses serving European users, GDPR may also apply.&lt;/p&gt;

&lt;p&gt;Although both regulations address personal data protection, they should not be treated as interchangeable.&lt;/p&gt;

&lt;p&gt;One important difference is the scope of data covered. DPDPA focuses on digital personal data, while GDPR has a broader concept of personal data and can cover certain manual processing activities.&lt;/p&gt;

&lt;p&gt;This distinction can matter when organizations map data across applications and systems.&lt;/p&gt;

&lt;p&gt;The two frameworks also differ in their approach to lawful processing. GDPR recognizes several lawful bases, including contractual necessity, legal obligations, legitimate interests, and consent. DPDPA relies significantly on consent while also defining specified legitimate uses.&lt;/p&gt;

&lt;p&gt;For technical teams, individual rights can have practical implications as well. Privacy architecture may need to account for processes relating to data access, correction, erasure, and other applicable requests. The exact requirements depend on the regulation and circumstances involved.&lt;/p&gt;

&lt;p&gt;International data flows are another major consideration.&lt;/p&gt;

&lt;p&gt;A modern application may use cloud infrastructure, SaaS platforms, analytics services, or vendors located outside India. If European personal data is involved, GDPR's international transfer requirements may become relevant. DPDPA follows a different approach, with cross-border transfers generally permitted unless specific restrictions are introduced by the Indian government.&lt;/p&gt;

&lt;p&gt;The result is that privacy cannot always be addressed through a single checklist.&lt;/p&gt;

&lt;p&gt;Indian organizations serving multiple markets need to understand the regulatory context around their applications, users, data flows, vendors, and processing activities.&lt;/p&gt;

&lt;p&gt;A useful starting point is a structured comparison of DPDPA vs GDPR, particularly when designing privacy processes for products that operate across India and Europe.&lt;/p&gt;

&lt;p&gt;The article &lt;a href="https://www.intercert.com/blogs/dpdpa-vs-gdpr-key-differences-indian-companies" rel="noopener noreferrer"&gt;DPDPA vs GDPR: Key Differences Every Indian Company Must Understand &lt;/a&gt;explores these differences in greater detail and examines what Indian organizations should consider when determining which privacy obligations apply to their operations.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>technology</category>
    </item>
    <item>
      <title>AI Governance in India: Where ISO/IEC 42001 Fits</title>
      <dc:creator>Chethana M</dc:creator>
      <pubDate>Mon, 05 Oct 2026 10:51:56 +0000</pubDate>
      <link>https://dev.to/chethana_m_cc98dabb42ce46/ai-governance-in-india-where-isoiec-42001-fits-5c5k</link>
      <guid>https://dev.to/chethana_m_cc98dabb42ce46/ai-governance-in-india-where-isoiec-42001-fits-5c5k</guid>
      <description>&lt;p&gt;AI engineering is advancing rapidly, but building an AI system is only one part of operating AI responsibly.&lt;/p&gt;

&lt;p&gt;Organizations developing machine learning applications, generative AI products, recommendation systems, intelligent automation, or AI-enabled SaaS platforms also need to think about governance around those technologies.&lt;/p&gt;

&lt;p&gt;This is where ISO/IEC 42001 becomes relevant.&lt;/p&gt;

&lt;p&gt;ISO/IEC 42001 defines requirements for an Artificial Intelligence Management System (AIMS). It takes an organizational view of AI governance, covering areas such as leadership, risk management, operational processes, performance evaluation, and continual improvement.&lt;/p&gt;

&lt;p&gt;For engineering and technology teams, this creates an important distinction. ISO 42001 is not simply a technical standard for evaluating whether a model produces accurate outputs. It considers the wider organizational environment in which AI is developed and used.&lt;/p&gt;

&lt;p&gt;A practical starting point is building visibility into the AI landscape.&lt;/p&gt;

&lt;p&gt;An organization may have AI in production applications, internal tools, APIs, analytics platforms, third-party services, or employee-facing generative AI tools. Understanding these different uses can influence the scope and governance requirements of the AIMS.&lt;/p&gt;

&lt;p&gt;AI risk management also needs to extend beyond traditional application security. Depending on the system, relevant considerations can include data privacy, bias, fairness, explainability, reliability, cybersecurity, safety, transparency, and legal requirements.&lt;/p&gt;

&lt;p&gt;Another important consideration is lifecycle management. AI governance does not stop when a model reaches production. Changes to models, data, vendors, applications, and intended use can introduce new risks that require ongoing attention.&lt;/p&gt;

&lt;p&gt;From a certification perspective, organizations must also be able to demonstrate that their management system is operating effectively. Performance evaluation, monitoring, reviews, and continual improvement therefore become important parts of the overall system.&lt;/p&gt;

&lt;p&gt;For Indian technology companies, ISO 42001 can provide a recognizable framework for connecting AI engineering practices with broader organizational governance.&lt;/p&gt;

&lt;p&gt;For a more detailed look at how AI-driven organizations can approach certification, see &lt;a href="https://www.intercert.com/blogs/iso-42001-certification-india-first-steps-ai-driven-companies" rel="noopener noreferrer"&gt;ISO 42001 Certification in India: First Steps for AI-Driven Companies&lt;/a&gt;. The article covers the major ISO 42001 requirements, certification stages, common organizational challenges, and the business value of an AIMS.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>ai</category>
    </item>
    <item>
      <title>SOC 2: Understanding the Assurance Standard for Service Organizations</title>
      <dc:creator>Chethana M</dc:creator>
      <pubDate>Mon, 05 Oct 2026 09:16:36 +0000</pubDate>
      <link>https://dev.to/chethana_m_cc98dabb42ce46/soc-2-understanding-the-assurance-standard-for-service-organizations-5gdg</link>
      <guid>https://dev.to/chethana_m_cc98dabb42ce46/soc-2-understanding-the-assurance-standard-for-service-organizations-5gdg</guid>
      <description>&lt;p&gt;As SaaS platforms, cloud services, fintech applications, and other digital services become increasingly connected to customer data, organizations are facing greater expectations around how they protect and manage that information. Customers and enterprise buyers often want more than a security statement—they want credible evidence that relevant controls have been independently evaluated.&lt;/p&gt;

&lt;p&gt;This is where SOC 2 has become particularly relevant for service organizations.&lt;/p&gt;

&lt;p&gt;SOC 2 is an attestation framework developed by the American Institute of Certified Public Accountants (AICPA). It focuses on evaluating controls related to areas such as security, availability, processing integrity, confidentiality, and privacy, depending on the criteria selected for the engagement.&lt;/p&gt;

&lt;p&gt;One important distinction is that SOC 2 is not technically a certification. The outcome is an independent attestation report issued following an examination of the organization's controls. Despite this distinction, terms such as "SOC 2 certification" are frequently used when organizations discuss their assurance efforts with customers and business partners.&lt;/p&gt;

&lt;p&gt;For technology companies selling to enterprise customers, understanding this distinction can make conversations around assurance and vendor due diligence much clearer.&lt;/p&gt;

&lt;p&gt;Why SOC 2 Matters for Technology Companies&lt;/p&gt;

&lt;p&gt;Enterprise customers increasingly evaluate the security practices of their service providers before entering into business relationships. This can involve reviewing security controls, governance practices, risk management processes, and independent assurance reports.&lt;/p&gt;

&lt;p&gt;A SOC 2 report can provide a structured way to demonstrate how an organization's controls address selected Trust Services Criteria.&lt;/p&gt;

&lt;p&gt;For SaaS and cloud providers, this can be particularly valuable because customers may need assurance that information is protected throughout the systems and processes used to deliver the service.&lt;/p&gt;

&lt;p&gt;The relevance of SOC 2 also extends beyond security alone. Depending on the scope of the engagement, organizations may address availability, processing integrity, confidentiality, or privacy as well.&lt;/p&gt;

&lt;p&gt;SOC 2 and Independent Assurance&lt;/p&gt;

&lt;p&gt;A key characteristic of SOC 2 is the role of an independent auditor. Rather than simply relying on an organization's own statements about its controls, the engagement provides an external evaluation of the controls within the defined scope.&lt;/p&gt;

&lt;p&gt;This makes SOC 2 different from an internal security checklist or self-declared compliance statement.&lt;/p&gt;

&lt;p&gt;Organizations preparing for customer due diligence can therefore use SOC 2 as part of a broader assurance strategy, particularly when customers request independent evidence of how security and related controls operate.&lt;/p&gt;

&lt;p&gt;For a more detailed explanation of the SOC 2 definition, Trust Services Criteria, requirements, and audit process, see this SOC 2 overview(&lt;a href="https://www.intercert.com/blogs/what-is-soc-2-definition-requirements-and-audit-process" rel="noopener noreferrer"&gt;https://www.intercert.com/blogs/what-is-soc-2-definition-requirements-and-audit-process&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;What Organizations Should Understand Before Pursuing SOC 2&lt;/p&gt;

&lt;p&gt;SOC 2 is not simply about having security policies in place. The engagement considers the controls within the defined scope and whether they are appropriately designed and, where applicable, operating effectively over the examination period.&lt;/p&gt;

&lt;p&gt;This means organizations should have a clear understanding of:&lt;/p&gt;

&lt;p&gt;Which systems and services fall within scope&lt;br&gt;
Which Trust Services Criteria are relevant&lt;br&gt;
What controls address the selected criteria&lt;br&gt;
What evidence demonstrates control operation&lt;br&gt;
How responsibilities are assigned across teams&lt;br&gt;
How control performance is monitored over time&lt;/p&gt;

&lt;p&gt;A clear understanding of these areas can make discussions with customers, auditors, and other stakeholders more meaningful.&lt;/p&gt;

&lt;p&gt;Building Trust Through Independent Assurance&lt;/p&gt;

&lt;p&gt;For service organizations operating in competitive technology markets, security assurance has increasingly become part of the commercial conversation. Enterprise customers want confidence that their data is being handled through defined and consistently operated controls.&lt;/p&gt;

&lt;p&gt;SOC 2 provides one established mechanism for demonstrating that commitment through an independent attestation report.&lt;/p&gt;

&lt;p&gt;Understanding what SOC 2 actually evaluates—and how the resulting report differs from a certification—can help technology companies communicate their assurance position more accurately to customers and business partners.&lt;/p&gt;

</description>
      <category>soc2</category>
      <category>cybersecurity</category>
    </item>
  </channel>
</rss>
