<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: CSFaaS</title>
    <description>The latest articles on DEV Community by CSFaaS (@csfaas).</description>
    <link>https://dev.to/csfaas</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4086952%2Fa0c9d421-a9dd-4177-9841-242a278b5f8c.png</url>
      <title>DEV Community: CSFaaS</title>
      <link>https://dev.to/csfaas</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/csfaas"/>
    <language>en</language>
    <item>
      <title>Back to Basics: Risk Appetite &amp; Risk Tolerance</title>
      <dc:creator>CSFaaS</dc:creator>
      <pubDate>Sun, 20 Sep 2026 14:29:37 +0000</pubDate>
      <link>https://dev.to/csfaas/back-to-basics-risk-appetite-risk-tolerance-fdb</link>
      <guid>https://dev.to/csfaas/back-to-basics-risk-appetite-risk-tolerance-fdb</guid>
      <description>&lt;p&gt;&lt;strong&gt;Risk appetite and risk tolerance are core concepts in risk management and GRC, helping organisations connect strategic intent with risk decision-making. And sometimes, going back to basics is exactly what we need.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A simple distinction:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Risk appetite sets the overall direction.&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Risk tolerance makes that direction usable for specific decisions.&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In this article, I look at where these concepts come from, how &lt;strong&gt;COSO, ISO and NIST&lt;/strong&gt; frame them, and how they connect governance with practical risk decisions.&lt;/p&gt;

&lt;p&gt;The key question is not simply whether an organisation has a risk appetite statement.&lt;/p&gt;

&lt;p&gt;It is whether that statement can actually guide &lt;strong&gt;risk acceptance, treatment, exceptions, escalation and reporting&lt;/strong&gt;.&lt;/p&gt;

&lt;h1&gt;
  
  
  Where do these concepts come from?
&lt;/h1&gt;

&lt;p&gt;The modern concepts of risk appetite and risk tolerance developed through financial risk management, corporate governance and Enterprise Risk Management, before being incorporated into international risk management standards.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Turnbull Guidance (1999):&lt;/strong&gt; helped frame the underlying governance question by asking boards to consider the extent and categories of risk acceptable for the company to bear.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;COSO ERM (2004):&lt;/strong&gt; formalised the distinction more explicitly. Risk appetite was positioned at the broader enterprise level, while risk tolerance described the acceptable variation relative to achieving specific objectives.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;COSO ERM (2017):&lt;/strong&gt; further integrated risk appetite with strategy and performance. Subsequent COSO guidance describes tolerance in terms of acceptable variation in performance relative to objectives, reinforcing the link between risk-taking, strategy and execution.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;ISO Guide 73:2009:&lt;/strong&gt; incorporated both risk appetite and risk tolerance into the ISO risk management vocabulary. Its successor, &lt;strong&gt;ISO 31073:2022&lt;/strong&gt;, retains both concepts, defining risk appetite as the amount and type of risk an organisation is willing to pursue or retain, and risk tolerance as the organisation's or an interested party's readiness to bear residual risk in order to achieve its objectives.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;FSB Principles for an Effective Risk Appetite Framework (2013):&lt;/strong&gt; following the global financial crisis, connected risk capacity, appetite, limits and risk profile with strategy and board oversight.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The terminology differs across frameworks.&lt;/p&gt;

&lt;p&gt;COSO emphasises acceptable variation around objectives and performance, while ISO expresses tolerance in terms of readiness to bear residual risk.&lt;/p&gt;

&lt;p&gt;Despite those differences, both seek to translate an organisation's attitude toward risk into guidance for decision-making.&lt;/p&gt;

&lt;h1&gt;
  
  
  One picture, two concepts
&lt;/h1&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Froki3f3yr1ktqm57yoy3.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Froki3f3yr1ktqm57yoy3.webp" alt="Illustrative performance over time: appetite is a narrow range, tolerance a wider range with review zones, and the risk universe spans the best and worst outcomes." width="799" height="375"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Illustrative relationship between expected performance, risk appetite, risk tolerance and the broader risk universe.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Source&lt;/em&gt; &lt;a href="https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161r1-upd1.pdf#page=282" rel="noopener noreferrer"&gt;&lt;em&gt;NIST SP 800-161 Rev. 1 Update 1, Figure 16&lt;/em&gt;&lt;/a&gt;&lt;em&gt;, printed page 268 (PDF page 282).&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The diagram places expected performance within a broader &lt;strong&gt;risk universe&lt;/strong&gt;, ranging from the best to the worst possible outcomes.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Risk appetite&lt;/strong&gt; represents the range within which the organisation intends to operate.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Risk tolerance&lt;/strong&gt; may establish wider boundaries, providing some flexibility around that appetite.&lt;/p&gt;

&lt;p&gt;Between the two lies the &lt;strong&gt;review zone&lt;/strong&gt;: a departure from appetite that remains within tolerance, but warrants attention and review.&lt;/p&gt;

&lt;p&gt;In simple terms:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Appetite provides the direction.&lt;br&gt;&lt;br&gt;
Tolerance establishes the boundaries around that direction.&lt;/strong&gt;&lt;/p&gt;

&lt;h1&gt;
  
  
  From governance to decisions
&lt;/h1&gt;

&lt;p&gt;A simple way to view the relationship is:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Objectives → Risk Appetite → Risk Tolerance → Risk Decisions&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Risk appetite provides overarching guidance about the risks an organisation is prepared to take in pursuit of its objectives.&lt;/p&gt;

&lt;p&gt;Risk tolerance translates that direction into more specific boundaries.&lt;/p&gt;

&lt;p&gt;Together, they help communicate risk expectations, support consistent decision-making, and determine when a risk may require treatment, acceptance, exception or escalation.&lt;/p&gt;

&lt;p&gt;Those boundaries should remain aligned with senior leadership direction and take into account applicable legal, regulatory and contractual requirements.&lt;/p&gt;

&lt;h1&gt;
  
  
  What it looks like in practice
&lt;/h1&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fg3jcmbz0f1ugjmt2wicd.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fg3jcmbz0f1ugjmt2wicd.png" width="800" height="514"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Illustrative examples from NIST SP 800-221, Table 3.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Take the government agency example.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The appetite establishes the direction: &lt;strong&gt;mission-critical systems should be protected from known ICT vulnerabilities.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The corresponding tolerance makes that direction actionable by defining a &lt;strong&gt;14-day remediation boundary for critical vulnerabilities&lt;/strong&gt; on systems designated as mission-critical.&lt;/p&gt;

&lt;p&gt;The academic institution example shows that tolerance can also be conditional.&lt;/p&gt;

&lt;p&gt;Some loss of student devices is expected and accepted, while there is &lt;strong&gt;no appetite for the loss of sensitive institutional information&lt;/strong&gt;. The tolerance therefore applies only if sensitive information is prohibited from being stored on those devices.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The thresholds themselves are illustrative, not universal.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A 14-day remediation period, a four-hour outage or a particular loss threshold should not become an organisational tolerance simply because it appears in guidance.&lt;/p&gt;

&lt;p&gt;What matters is that the tolerance is specific enough to make the broader appetite usable in governance and decision-making.&lt;/p&gt;

&lt;h1&gt;
  
  
  In a GRC context
&lt;/h1&gt;

&lt;p&gt;Risk appetite and tolerance should not exist as isolated statements.&lt;/p&gt;

&lt;p&gt;They should inform the organisation's broader GRC mechanisms, including &lt;strong&gt;risk assessment and acceptance criteria, policies, controls, exceptions, remediation, escalation and reporting&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;This connection is explicit in &lt;strong&gt;NIST CSF 2.0&lt;/strong&gt;, where GV.RM-02 expects risk appetite and risk tolerance statements to be established, communicated and maintained.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;ISO/IEC 27001&lt;/strong&gt; also requires organisations to establish information security risk acceptance criteria. It does not define risk appetite or tolerance itself, but those concepts can help inform how such criteria are established.&lt;/p&gt;

&lt;p&gt;This is ultimately what makes appetite and tolerance useful: they connect strategic risk direction with the way risk is governed across the organisation.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Risk appetite sets the direction.&lt;br&gt;&lt;br&gt;
Risk tolerance makes that direction usable for governance and decision-making.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final" rel="noopener noreferrer"&gt;NIST SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://csrc.nist.gov/pubs/sp/800/221/final" rel="noopener noreferrer"&gt;NIST SP 800-221, Enterprise Impact of Information and Communications Technology Risk: Governing and Managing ICT Risk Programs Within an Enterprise Risk Portfolio&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.coso.org/critical-to-success" rel="noopener noreferrer"&gt;COSO – Risk Appetite: Critical to Success (2020)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.iso.org/standard/79637.html" rel="noopener noreferrer"&gt;ISO 31073:2022, Risk management — Vocabulary&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
    </item>
    <item>
      <title>Building a More Complete GRC Platform — The Latest CSFaaS Updates</title>
      <dc:creator>CSFaaS</dc:creator>
      <pubDate>Sun, 23 Aug 2026 20:31:16 +0000</pubDate>
      <link>https://dev.to/csfaas/building-a-more-complete-grc-platform-the-latest-csfaas-updates-3om3</link>
      <guid>https://dev.to/csfaas/building-a-more-complete-grc-platform-the-latest-csfaas-updates-3om3</guid>
      <description>&lt;p&gt;&lt;strong&gt;While many are taking a summer break, we have been doing what we love: building for you.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Since late July, &lt;strong&gt;55 issues have moved to Done across CSFaaS&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Some introduced new capabilities. Others fixed edge cases, tightened workflows, improved auditability, improved usability, or hardened the platform underneath.&lt;/p&gt;

&lt;p&gt;Taken together, they tell an important story: &lt;strong&gt;CSFaaS is becoming a more mature, reliable and operational GRC platform, release after release.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Here is a snapshot of what has kept the team busy over the past few weeks.&lt;/p&gt;

&lt;h1&gt;
  
  
  AI prompts and automation
&lt;/h1&gt;

&lt;p&gt;One of the most important additions is the new ability to &lt;strong&gt;create, store and manage reusable AI prompts directly in CSFaaS&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;These prompts are designed to help teams automate and standardize recurring GRC activities.&lt;/p&gt;

&lt;p&gt;They can be used, for example, to:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;review controls and evidence;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;document or assess risks;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;check framework implementation status;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;generate summaries;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;produce recommendations;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;support audit preparation;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;standardize recurring analysis and review activities.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Instead of rewriting the same instructions every time, teams can now turn their own methodologies and best practices into &lt;strong&gt;reusable AI workflows&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;This is also a natural extension of CSFaaS' MCP architecture.&lt;/p&gt;

&lt;p&gt;The objective is not to place an AI chatbot next to the platform.&lt;/p&gt;

&lt;p&gt;It is to make AI available &lt;strong&gt;throughout the GRC operating model&lt;/strong&gt;, connected to the information already managed inside CSFaaS: frameworks, controls, risks, policies, evidence, audits and related workflows.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;AI is no longer a separate assistant sitting next to the GRC platform. It becomes part of the way the GRC platform operates.&lt;/strong&gt;&lt;/p&gt;

&lt;h1&gt;
  
  
  MCP hardening
&lt;/h1&gt;

&lt;p&gt;The MCP layer has also received significant attention over the past few weeks.&lt;/p&gt;

&lt;p&gt;Several issues were fixed around write operations, usage reliability and restricted permissions. We also improved the way PDF evidence can be read and added protections to prevent internal application codes from being unintentionally modified.&lt;/p&gt;

&lt;p&gt;These may sound like technical details, but they become critical when AI agents are allowed to interact directly with governance data.&lt;/p&gt;

&lt;p&gt;Launching an MCP server is relatively easy to announce.&lt;/p&gt;

&lt;p&gt;Making it reliable enough for real operational use is a different challenge.&lt;/p&gt;

&lt;p&gt;A failed write is inconvenient.&lt;/p&gt;

&lt;p&gt;An incorrect write can affect traceability.&lt;/p&gt;

&lt;p&gt;An accidentally modified identifier can affect data integrity.&lt;/p&gt;

&lt;p&gt;As AI becomes more deeply integrated into GRC processes, the reliability of the MCP layer increasingly becomes part of the reliability of the platform itself.&lt;/p&gt;

&lt;h1&gt;
  
  
  CyFun integration
&lt;/h1&gt;

&lt;p&gt;CyFun has been another major area of work.&lt;/p&gt;

&lt;p&gt;Seven workstreams were completed around the &lt;strong&gt;CyberFundamentals Framework (CyFun®)&lt;/strong&gt;, including:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;support for both Documentation maturity and Implementation maturity;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;a dedicated summary page;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;import from the official self-assessment workbook;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;export back to the official workbook format;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;support for Key Measures and Management Aspects;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;version-handling improvements;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;broader integration into the CSFaaS framework architecture.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The important point is not simply that CSFaaS supports another framework.&lt;/p&gt;

&lt;p&gt;The objective is to integrate CyFun into the same underlying GRC model already used for other standards and regulations.&lt;/p&gt;

&lt;p&gt;That means avoiding unnecessary duplication.&lt;/p&gt;

&lt;p&gt;Controls, risks, evidence, policies and implementation work should be reusable wherever possible across multiple frameworks.&lt;/p&gt;

&lt;p&gt;For us, adding another framework should not mean adding another compliance silo.&lt;/p&gt;

&lt;h1&gt;
  
  
  Risk and Demand workflows
&lt;/h1&gt;

&lt;p&gt;A substantial amount of work also went into improving risk and demand workflows.&lt;/p&gt;

&lt;p&gt;Recent changes include the ability to create Risk Demands on behalf of another user, cumulative edit permissions for requests and remediation plans, fixes around response rounds, improvements following the &lt;strong&gt;Request Information&lt;/strong&gt; step, and locking certain review parameters once a risk response has been submitted.&lt;/p&gt;

&lt;p&gt;These are the kinds of changes that rarely make release headlines.&lt;/p&gt;

&lt;p&gt;But they determine whether a workflow remains reliable once multiple people, roles and review cycles are involved.&lt;/p&gt;

&lt;p&gt;A workflow that works during a demonstration is one thing.&lt;/p&gt;

&lt;p&gt;A workflow that remains consistent when responsibilities change, information is incomplete, reviews are reopened and multiple stakeholders are involved is another.&lt;/p&gt;

&lt;p&gt;That is where product maturity starts to show.&lt;/p&gt;

&lt;h2&gt;
  
  
  Auditability and framework usability
&lt;/h2&gt;

&lt;p&gt;We also continued improving the experience around frameworks, controls and audits.&lt;/p&gt;

&lt;p&gt;Recent changes include the addition of an &lt;strong&gt;Audit Conclusion&lt;/strong&gt; tab to audit framework elements, clearer &lt;strong&gt;Finding Register&lt;/strong&gt; and &lt;strong&gt;Actions Register&lt;/strong&gt; views, support for a &lt;strong&gt;Partially implemented&lt;/strong&gt; applicability status, improved control progression behaviour and several fixes affecting maturity and target maturity displays.&lt;/p&gt;

&lt;p&gt;We also corrected smaller usability issues, such as evidence names not appearing correctly in drawers and visual inconsistencies in applicability statuses.&lt;/p&gt;

&lt;p&gt;Individually, these are small changes.&lt;/p&gt;

&lt;p&gt;During a real audit or assessment, however, small inconsistencies quickly become visible.&lt;/p&gt;

&lt;p&gt;A GRC platform should reduce ambiguity, not create it.&lt;/p&gt;

&lt;p&gt;The more the platform is used as a system of record, the more important this level of detail becomes.&lt;/p&gt;

&lt;h1&gt;
  
  
  Permissions and activity visibility
&lt;/h1&gt;

&lt;p&gt;Permissions and traceability also continued to evolve.&lt;/p&gt;

&lt;p&gt;We extended role-based access in several areas, improved activity log access configuration and refined permissions around requests and remediation plans.&lt;/p&gt;

&lt;p&gt;These changes are important because GRC platforms are collaborative by nature.&lt;/p&gt;

&lt;p&gt;Different people need different levels of access, but the platform still has to preserve accountability, ownership and traceability.&lt;/p&gt;

&lt;p&gt;The challenge is not simply to restrict access.&lt;/p&gt;

&lt;p&gt;It is to provide enough flexibility for organisations without weakening governance.&lt;/p&gt;

&lt;h1&gt;
  
  
  Platform, scale and monitoring
&lt;/h1&gt;

&lt;p&gt;Some of the work happened deeper in the architecture.&lt;/p&gt;

&lt;p&gt;This included event-plane storage improvements designed for scale, as well as export capabilities for MCP and API activity monitoring.&lt;/p&gt;

&lt;p&gt;These changes are less visible in the user interface, but they matter as the platform grows.&lt;/p&gt;

&lt;p&gt;Operational monitoring, activity traceability and scalable storage are not optional once a GRC platform becomes part of day-to-day security and compliance operations.&lt;/p&gt;

&lt;h1&gt;
  
  
  Product experience
&lt;/h1&gt;

&lt;p&gt;We also continued refining the broader CSFaaS experience.&lt;/p&gt;

&lt;p&gt;That included dashboard fixes, navigation improvements, contextual help for Risk Profiling, terminology improvements, framework display refinements and changes to how certain views behave.&lt;/p&gt;

&lt;p&gt;Again, none of these improvements is revolutionary by itself.&lt;/p&gt;

&lt;p&gt;But users do not experience a product as a list of features.&lt;/p&gt;

&lt;p&gt;They experience the accumulation of hundreds of interactions.&lt;/p&gt;

&lt;p&gt;Every unnecessary click, unclear label, broken navigation path or inconsistent result creates friction.&lt;/p&gt;

&lt;p&gt;Removing that friction is part of building the product.&lt;/p&gt;

&lt;h1&gt;
  
  
  Education
&lt;/h1&gt;

&lt;p&gt;The last few weeks were not limited to the application itself.&lt;/p&gt;

&lt;p&gt;We launched the new &lt;strong&gt;CSFaaS Education Program&lt;/strong&gt; page.&lt;/p&gt;

&lt;p&gt;The Education Program is particularly important to us.&lt;/p&gt;

&lt;p&gt;Our goal is to make professional GRC tooling more accessible to universities, schools and training programs, so that students can work with the same concepts and workflows they will encounter in real organisations.&lt;/p&gt;

&lt;h1&gt;
  
  
  Website
&lt;/h1&gt;

&lt;p&gt;We also launched a &lt;strong&gt;fully redesigned CSFaaS homepage&lt;/strong&gt;, with clearer positioning, updated messaging and a better overview of the platform and its capabilities.&lt;/p&gt;

&lt;p&gt;We would genuinely like your feedback.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Take a look at the new homepage and tell us what you think — what is clear, what is missing, and what we could improve.&lt;/strong&gt;&lt;/p&gt;

&lt;h1&gt;
  
  
  The accumulation matters
&lt;/h1&gt;

&lt;p&gt;There is no single feature that defines these four weeks.&lt;/p&gt;

&lt;p&gt;And that is probably the most interesting part.&lt;/p&gt;

&lt;p&gt;A mature GRC platform is not built only through large launches.&lt;/p&gt;

&lt;p&gt;It is built through the accumulation of improvements across workflows, permissions, auditability, integrations, reliability, AI, infrastructure and user experience.&lt;/p&gt;

&lt;p&gt;The small things matter because GRC itself is built on consistency.&lt;/p&gt;

&lt;p&gt;When someone runs an audit, reviews a risk, checks evidence, assigns responsibility, maps a framework or lets an AI agent interact with governance data, the platform has to behave predictably.&lt;/p&gt;

&lt;p&gt;That is what the last few weeks have been about.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;55 issues shipped since late July.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;And there is more coming in the next few days, with several major new capabilities that will take CSFaaS another step closer to becoming &lt;strong&gt;one of the most complete GRC platforms on the market&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Welcome to the leading edge of GRC.&lt;/strong&gt;&lt;/p&gt;

</description>
    </item>
    <item>
      <title>AI Content Watermarking: Claude Starts Marking AI-Generated Content</title>
      <dc:creator>CSFaaS</dc:creator>
      <pubDate>Fri, 21 Aug 2026 11:03:01 +0000</pubDate>
      <link>https://dev.to/csfaas/ai-content-watermarking-claude-starts-marking-ai-generated-content-2407</link>
      <guid>https://dev.to/csfaas/ai-content-watermarking-claude-starts-marking-ai-generated-content-2407</guid>
      <description>&lt;p&gt;Anthropic has announced plans to &lt;strong&gt;mark content generated or processed by Claude&lt;/strong&gt; as part of its commitments under the &lt;strong&gt;EU AI Act&lt;/strong&gt; and the Code of Practice on Transparency of AI-Generated Content.&lt;/p&gt;

&lt;p&gt;For new Claude models launched in the EU on or after &lt;strong&gt;August 2, 2026&lt;/strong&gt;, Anthropic says marking will be supported from launch.&lt;/p&gt;

&lt;p&gt;The approach relies on two complementary mechanisms: &lt;strong&gt;embedded watermarks in text&lt;/strong&gt; and &lt;strong&gt;signed provenance metadata for files&lt;/strong&gt;.&lt;/p&gt;

&lt;h1&gt;
  
  
  An Invisible Watermark Embedded in Text
&lt;/h1&gt;

&lt;p&gt;This is perhaps the most interesting part of the announcement.&lt;/p&gt;

&lt;p&gt;When a supported Claude model generates text, Anthropic says it will embed an &lt;strong&gt;imperceptible watermark directly into the text&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;This is not simply a visible “Generated by AI” label. According to Anthropic, the watermark travels with the text when it is copied and pasted and may remain detectable after some editing.&lt;/p&gt;

&lt;p&gt;How is that possible?&lt;/p&gt;

&lt;p&gt;Anthropic has not yet published the technical details of its implementation and says further technical documentation will follow.&lt;/p&gt;

&lt;p&gt;One possible approach to this type of watermarking is to introduce a &lt;strong&gt;statistical signal during text generation&lt;/strong&gt;. A model can favor certain token choices or formulations among several possible alternatives, creating a statistical pattern that can later be detected across a sufficiently large sample of text.&lt;/p&gt;

&lt;p&gt;Such an approach would explain why a watermark could survive limited editing while becoming increasingly difficult to detect after substantial rewriting.&lt;/p&gt;

&lt;h1&gt;
  
  
  Copying the Text May Not Remove the Mark
&lt;/h1&gt;

&lt;p&gt;This has an important consequence.&lt;/p&gt;

&lt;p&gt;A simple copy and paste preserves the text and may therefore preserve the watermark.&lt;/p&gt;

&lt;p&gt;Limited modifications may also leave enough of the signal intact for detection.&lt;/p&gt;

&lt;p&gt;However, Anthropic explicitly acknowledges several limitations. Heavy editing, paraphrasing, translation or combining the content with other text may make the watermark undetectable.&lt;/p&gt;

&lt;p&gt;Very short passages may also contain too little information to provide a reliable signal.&lt;/p&gt;

&lt;p&gt;A text watermark should therefore be considered &lt;strong&gt;a provenance signal rather than absolute proof of authorship&lt;/strong&gt;.&lt;/p&gt;

&lt;h1&gt;
  
  
  C2PA Provenance Metadata for Files
&lt;/h1&gt;

&lt;p&gt;For supported files, Anthropic is taking a different approach.&lt;/p&gt;

&lt;p&gt;Claude will attach &lt;strong&gt;signed provenance metadata&lt;/strong&gt; to supported file types such as SVG, PNG and JPEG.&lt;/p&gt;

&lt;p&gt;This metadata follows &lt;strong&gt;C2PA (Coalition for Content Provenance and Authenticity)&lt;/strong&gt;, an open industry standard designed to provide verifiable information about the origin and history of digital content.&lt;/p&gt;

&lt;p&gt;When signed provenance metadata is present, it can indicate that a file was processed by Claude and help detect whether it has subsequently been altered.&lt;/p&gt;

&lt;p&gt;This approach is particularly interesting for images and other digital assets because it moves the discussion beyond simple AI detection toward broader &lt;strong&gt;content traceability and provenance&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;It also has limitations. Metadata can disappear when files are converted, re-saved, screenshotted or processed by systems that do not preserve it.&lt;/p&gt;

&lt;h1&gt;
  
  
  “Processed by Claude” Does Not Mean “Created by Claude”
&lt;/h1&gt;

&lt;p&gt;This is probably the most important distinction in Anthropic’s announcement.&lt;/p&gt;

&lt;p&gt;Detecting a Claude mark does not necessarily mean that Claude originally created the content.&lt;/p&gt;

&lt;p&gt;Consider a simple example.&lt;/p&gt;

&lt;p&gt;A person writes an entire article and then asks Claude:&lt;/p&gt;

&lt;p&gt;“Correct the spelling and improve the style slightly.”&lt;/p&gt;

&lt;p&gt;The resulting text may carry a Claude mark even though the ideas and original content came from a human author.&lt;/p&gt;

&lt;p&gt;The same applies to translation, summarization, proofreading or file conversion.&lt;/p&gt;

&lt;p&gt;It would therefore be incorrect to interpret a detected mark automatically as:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;“This content was written by AI.”&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A more accurate conclusion would be:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;“This content may have been processed by Claude.”&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That distinction matters.&lt;/p&gt;

&lt;h1&gt;
  
  
  No Watermark Does Not Mean “Human”
&lt;/h1&gt;

&lt;p&gt;The opposite is equally important.&lt;/p&gt;

&lt;p&gt;The absence of a detectable watermark does not prove that content was created by a human.&lt;/p&gt;

&lt;p&gt;Anthropic identifies several situations where Claude-generated or Claude-processed content may no longer carry a detectable mark:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;it was generated by a model that did not yet support marking;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;the text was heavily edited or paraphrased;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;it was translated;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;it was combined with other content;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;the passage is too short;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;file metadata was removed;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;the platform, feature or file format did not support a particular marking mechanism.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This highlights a fundamental limitation of AI-content detection.&lt;/p&gt;

&lt;p&gt;These mechanisms can provide &lt;strong&gt;signals&lt;/strong&gt;, but those signals should not be treated as definitive proof.&lt;/p&gt;

&lt;h1&gt;
  
  
  From AI Detection to Content Provenance
&lt;/h1&gt;

&lt;p&gt;This development is particularly interesting because it may gradually change the question we ask about digital content.&lt;/p&gt;

&lt;p&gt;Today, the common question is:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;“Was this text or image created by AI?”&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;But that distinction is becoming increasingly difficult to establish — and increasingly less meaningful.&lt;/p&gt;

&lt;p&gt;Content can be:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;written by a human and corrected by AI;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;generated by AI and extensively rewritten by a human;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;translated by AI;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;summarized by AI;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;assembled from multiple human and AI-generated sources;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;or processed successively by several AI systems.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A simple &lt;strong&gt;Human vs. AI&lt;/strong&gt; classification quickly reaches its limits.&lt;/p&gt;

&lt;p&gt;We are therefore gradually moving from:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;“Is this AI?”&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;to:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;“What is the provenance of this content?”&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That is a much more meaningful question.&lt;/p&gt;

&lt;h1&gt;
  
  
  A New Dimension of AI Governance
&lt;/h1&gt;

&lt;p&gt;For organizations, this development goes far beyond identifying AI-written articles on the Internet.&lt;/p&gt;

&lt;p&gt;As generative AI becomes integrated into business processes, organizations will increasingly need to understand — and in some cases demonstrate:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;which AI systems were used;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;which content was generated or transformed;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;where human intervention occurred;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;what modifications were made;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;what provenance evidence is available.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In other words, &lt;strong&gt;traceability is becoming an important component of AI governance&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;This is a familiar principle in cybersecurity and GRC. Organizations cannot rely solely on statements that a process is controlled. They increasingly need evidence showing how processes operate and, where necessary, the ability to trace what happened.&lt;/p&gt;

&lt;p&gt;Technologies such as watermarking and C2PA can contribute to that traceability, although they cannot provide the entire solution on their own.&lt;/p&gt;

&lt;h1&gt;
  
  
  An Important Step, but Not a Perfect Solution
&lt;/h1&gt;

&lt;p&gt;Anthropic’s initiative represents an interesting step toward greater transparency around AI-generated content.&lt;/p&gt;

&lt;p&gt;But its limitations are just as important as the technology itself.&lt;/p&gt;

&lt;p&gt;A watermark can become undetectable.&lt;/p&gt;

&lt;p&gt;Metadata can be removed.&lt;/p&gt;

&lt;p&gt;Marked content may originally have been created by a human.&lt;/p&gt;

&lt;p&gt;And unmarked content may still have been generated by AI.&lt;/p&gt;

&lt;p&gt;The real objective may therefore not be to build a universal detector capable of answering &lt;strong&gt;“human or AI?”&lt;/strong&gt; with certainty.&lt;/p&gt;

&lt;p&gt;Instead, the challenge is to develop an &lt;strong&gt;ecosystem of provenance, traceability and governance for digital content&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;As the EU AI Act progressively takes effect, this topic is likely to become increasingly important — both for AI model providers and for the organizations using these systems.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;AI content watermarking: a real step forward for transparency, or a measure that will ultimately be easy to circumvent?&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02024R1689-20260727" rel="noopener noreferrer"&gt;EU AI Act (OJ L, 2024/1689, 12.7.2024)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content?ref=hackernoon.com" rel="noopener noreferrer"&gt;How Claude marks AI-generated content&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>ai</category>
      <category>claude</category>
      <category>llm</category>
      <category>news</category>
    </item>
  </channel>
</rss>
