3 hours ago · Tech · hide · 0 comments

I have been writing about the limitations of audits and compliance systems for several years. In Accountability and Transparency in Modern Systems, I wrote about systems producing evidence continuously rather than assembling it periodically for an auditor. In First Principles for Root Store Management, I looked back at the decision to require WebTrust for publicly trusted CAs and argued that, if we were designing the system today, much more of the trust decision should be based on continuously verifiable behavior. That led to The Limitations of Audits, Rethinking Compliance, and Compliance at the Speed of Code. The common thread was that the systems we are trying to assure change much faster than the mechanisms we use to understand them. Over the last year, I have spent considerably more time on this problem, both thinking about it and building systems intended to work differently. That work convinced me that the problem is deeper than periodicity alone. I have pulled that thinking…

No comments yet. Log in to reply on the Fediverse. Comments will appear here.