<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Secantra — Resources</title><description>Articles and guides on DORA, NIS2 and ISO 27001 programmes: how requirements become scope, how scope becomes evidence, and what auditors actually ask for.</description><link>https://www.secantra.com</link><language>en</language><item><title>What a new framework version changes — and what it must never touch</title><link>https://www.secantra.com/blog/what-a-framework-version-update-changes</link><guid isPermaLink="true">https://www.secantra.com/blog/what-a-framework-version-update-changes</guid><description>A framework pack gets a new version. Which applicability decisions carry over, which need review, which are gone — and why the old adoption must stay frozen.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>Framework versions</category><category>Applicability</category><category>Audit trail</category><category>Annex A</category><category>Curated packs</category><author>Secantra editorial</author></item><item><title>ISO 27001 clause 9 without the slide deck: internal audit and management review on a derived posture</title><link>https://www.secantra.com/blog/iso-27001-clause-9-derived-posture</link><guid isPermaLink="true">https://www.secantra.com/blog/iso-27001-clause-9-derived-posture</guid><description>Clause 9 asks for monitoring, internal audit and management review. When posture is computed from records, the review is a delta between two frozen snapshots.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>ISO 27001</category><category>Clause 9</category><category>Internal audit</category><category>Management review</category><category>Posture</category><author>Secantra editorial</author></item><item><title>NIS2 incident reporting: the 24-hour, 72-hour and one-month path as a runbook, not a policy</title><link>https://www.secantra.com/blog/nis2-incident-reporting-24-72-one-month</link><guid isPermaLink="true">https://www.secantra.com/blog/nis2-incident-reporting-24-72-one-month</guid><description>Article 23 sets three deadlines and asks different questions at each. Who decides &quot;significant&quot;, who notifies whom, and which records the answers come from.</description><pubDate>Sun, 30 Aug 2026 00:00:00 GMT</pubDate><category>NIS2</category><category>Article 23</category><category>Incident reporting</category><category>Runbook</category><category>CSIRT</category><author>Secantra editorial</author></item><item><title>A backup restore drill is evidence — if you record it like one</title><link>https://www.secantra.com/blog/backup-restore-drill-is-evidence</link><guid isPermaLink="true">https://www.secantra.com/blog/backup-restore-drill-is-evidence</guid><description>DORA, NIS2 and ISO 27001 ask whether you can restore, not whether you back up. What turns a restore test into evidence: date, scope, control, the gap it found.</description><pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate><category>Evidence</category><category>Backup</category><category>Restore testing</category><category>DORA</category><category>NIS2</category><category>ISO 27001</category><author>Secantra editorial</author></item><item><title>The DORA register of information in 30 minutes: a walkthrough of the checklist</title><link>https://www.secantra.com/blog/register-of-information-in-30-minutes</link><guid isPermaLink="true">https://www.secantra.com/blog/register-of-information-in-30-minutes</guid><description>Run the register-of-information checklist with three people in half an hour: which records to open first, what &quot;Partly&quot; usually means, and what to do next.</description><pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate><category>DORA</category><category>Register of information</category><category>Third parties</category><category>Checklist</category><category>Walkthrough</category><author>Secantra editorial</author></item><item><title>Four-eyes per flow: what a second approver actually changes — and when a single-admin tenant may switch it off</title><link>https://www.secantra.com/blog/four-eyes-per-flow</link><guid isPermaLink="true">https://www.secantra.com/blog/four-eyes-per-flow</guid><description>Segregation of duties is only real when the system refuses a self-approval. Which three flows carry it, what an approver may do, how an exception is audited.</description><pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate><category>Four-eyes</category><category>Segregation of duties</category><category>Governance documents</category><category>Risk acceptance</category><category>Audit trail</category><author>Secantra editorial</author></item><item><title>Evidence recency: why &quot;twelve months&quot; is not a rule, and what to measure instead</title><link>https://www.secantra.com/blog/evidence-recency-twelve-months-is-not-a-rule</link><guid isPermaLink="true">https://www.secantra.com/blog/evidence-recency-twelve-months-is-not-a-rule</guid><description>Auditors do not ask how old evidence is; they ask whether it still shows the control operating. Measure recency per control against its own review period.</description><pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate><category>Evidence</category><category>Recency</category><category>Controls</category><category>Posture</category><category>Audit</category><author>Secantra editorial</author></item><item><title>Provider → service → function: the three links most third-party obligations read back to</title><link>https://www.secantra.com/blog/provider-service-function</link><guid isPermaLink="true">https://www.secantra.com/blog/provider-service-function</guid><description>DORA Art. 28, NIS2 Art. 21(2)(d) and ISO 27001 supplier controls all assume you know which provider delivers which service to which function. Model it once.</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>Third parties</category><category>DORA</category><category>NIS2</category><category>Supply chain</category><category>CMDB</category><category>Register of information</category><author>Secantra editorial</author></item><item><title>Applicability has five scopes — and &quot;tenant-wide&quot; is usually the wrong first answer</title><link>https://www.secantra.com/blog/applicability-has-five-scopes</link><guid isPermaLink="true">https://www.secantra.com/blog/applicability-has-five-scopes</guid><description>A requirement rarely applies to a whole organisation. Deciding applicability per asset, IT service, business solution or process makes &quot;not applicable&quot; hold up.</description><pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate><category>Applicability</category><category>Scope</category><category>CMDB</category><category>Statement of Applicability</category><category>Evidence</category><author>Secantra editorial</author></item><item><title>The DORA testing programme is a scoping problem before it is a testing problem</title><link>https://www.secantra.com/blog/dora-resilience-testing-programme</link><guid isPermaLink="true">https://www.secantra.com/blog/dora-resilience-testing-programme</guid><description>DORA Article 24 asks for a yearly, risk-based testing programme. The hard part is not the test: it is deriving scope from the inventory and closing every gap.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>DORA</category><category>Resilience testing</category><category>TLPT</category><category>Findings</category><category>CMDB</category><author>Secantra editorial</author></item><item><title>Why a compliance percentage should never be typed into a box</title><link>https://www.secantra.com/blog/why-a-compliance-percentage-should-never-be-typed</link><guid isPermaLink="true">https://www.secantra.com/blog/why-a-compliance-percentage-should-never-be-typed</guid><description>A posture number somebody typed is a slide, not a fact. What deriving posture from adoption, applicability, coverage and evidence means — and why you freeze it.</description><pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate><category>Posture</category><category>Evidence</category><category>Applicability</category><category>Management reporting</category><author>Secantra editorial</author></item><item><title>The Statement of Applicability is a decision log, not a checklist</title><link>https://www.secantra.com/blog/statement-of-applicability-is-a-decision-log</link><guid isPermaLink="true">https://www.secantra.com/blog/statement-of-applicability-is-a-decision-log</guid><description>ISO/IEC 27001 asks for the one thing most SoAs lack: the reason. Keeping applicability, justification and implementation status as records that outlive audits.</description><pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate><category>ISO 27001</category><category>Statement of Applicability</category><category>Annex A</category><category>Evidence</category><category>Applicability</category><author>Secantra editorial</author></item><item><title>NIS2 Article 21: ten measure areas, one inventory — where to start when the deadline has already passed</title><link>https://www.secantra.com/blog/nis2-article-21-where-to-start</link><guid isPermaLink="true">https://www.secantra.com/blog/nis2-article-21-where-to-start</guid><description>NIS2 Article 21 lists ten measure areas but never says which system they protect. Start from the inventory and the management-body decision, not a policy pack.</description><pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate><category>NIS2</category><category>Article 21</category><category>CMDB</category><category>Risk management</category><category>Management body</category><author>Secantra editorial</author></item><item><title>The DORA register of information: what the ESAs actually ask for, and where the data has to come from</title><link>https://www.secantra.com/blog/the-dora-register-of-information</link><guid isPermaLink="true">https://www.secantra.com/blog/the-dora-register-of-information</guid><description>The DORA register is a prescribed template, not a product feature. Which linked records — providers, services, functions — must exist to fill it with no sheet.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate><category>DORA</category><category>Third parties</category><category>CMDB</category><category>Register of information</category><author>Secantra editorial</author></item></channel></rss>