<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cybersecurity Governance on Christa Burger</title><link>https://christaburger.com/tags/cybersecurity-governance/</link><description>Recent content in Cybersecurity Governance on Christa Burger</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 03 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://christaburger.com/tags/cybersecurity-governance/index.xml" rel="self" type="application/rss+xml"/><item><title>Give AI a Job Description Before Giving It Access</title><link>https://christaburger.com/blog/give-ai-a-job-description-before-access/</link><pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate><guid>https://christaburger.com/blog/give-ai-a-job-description-before-access/</guid><description>&lt;p&gt;Before giving AI more access, give it a job description.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;What is it responsible for?&lt;/li&gt;
&lt;li&gt;What should it ignore?&lt;/li&gt;
&lt;li&gt;What does good output look like?&lt;/li&gt;
&lt;li&gt;What tools can it use?&lt;/li&gt;
&lt;li&gt;When should it escalate?&lt;/li&gt;
&lt;li&gt;What should it never decide?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This sounds obvious.&lt;/p&gt;
&lt;p&gt;It is apparently not.&lt;/p&gt;
&lt;p&gt;People will give AI access to meaningful workflows with less role clarity than they would give an intern named Brayden who starts Monday and says &amp;ldquo;for sure&amp;rdquo; too much.&lt;/p&gt;</description></item><item><title>Accountability Should Not Require Archaeology</title><link>https://christaburger.com/blog/accountability-should-not-require-archaeology/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://christaburger.com/blog/accountability-should-not-require-archaeology/</guid><description>&lt;p&gt;If accountability requires archaeology, the system is under-designed.&lt;/p&gt;
&lt;p&gt;People should not need to dig through inboxes, Slack threads, meeting notes, and the memory of whoever was least distracted at the time.&lt;/p&gt;
&lt;p&gt;That is not a process.&lt;/p&gt;
&lt;p&gt;That is a scavenger hunt with legal exposure.&lt;/p&gt;
&lt;p&gt;AI should make this better.&lt;/p&gt;
&lt;p&gt;Every meaningful AI-assisted workflow should be able to answer:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;What did it do?&lt;/li&gt;
&lt;li&gt;What inputs did it use?&lt;/li&gt;
&lt;li&gt;What changed?&lt;/li&gt;
&lt;li&gt;What did it recommend?&lt;/li&gt;
&lt;li&gt;What did a human approve?&lt;/li&gt;
&lt;li&gt;Where is the evidence?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This is not just a security or compliance concern.&lt;/p&gt;</description></item><item><title>"I Think We Talked About This" Is Not a Control</title><link>https://christaburger.com/blog/i-think-we-talked-about-this-is-not-a-control/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://christaburger.com/blog/i-think-we-talked-about-this-is-not-a-control/</guid><description>&lt;p&gt;The worst time to document a decision is after something goes wrong.&lt;/p&gt;
&lt;p&gt;Everyone is calm. Everyone remembers clearly. No one is searching email for &amp;ldquo;final_final_ACTUAL_USE_THIS_ONE_v7.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;Obviously.&lt;/p&gt;
&lt;p&gt;AI can help us stop doing this.&lt;/p&gt;
&lt;p&gt;It can capture decisions as they happen:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;What was known?&lt;/li&gt;
&lt;li&gt;What was decided?&lt;/li&gt;
&lt;li&gt;Who decided it?&lt;/li&gt;
&lt;li&gt;What changed later?&lt;/li&gt;
&lt;li&gt;What evidence existed at the time?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;That is incredibly valuable.&lt;/p&gt;
&lt;p&gt;But only if we design for it.&lt;/p&gt;
&lt;p&gt;Otherwise AI just helps us create more outputs with less traceability.&lt;/p&gt;</description></item><item><title>Human-in-the-Loop AI Is Not Enough</title><link>https://christaburger.com/blog/human-in-the-loop-is-not-enough/</link><pubDate>Wed, 29 Apr 2026 00:00:00 +0000</pubDate><guid>https://christaburger.com/blog/human-in-the-loop-is-not-enough/</guid><description>&lt;p&gt;&amp;ldquo;Human in the loop&amp;rdquo; has become one of those phrases we say to make everyone feel better.&lt;/p&gt;
&lt;p&gt;Like &amp;ldquo;cross-functional alignment.&amp;rdquo; Or &amp;ldquo;quick sync.&amp;rdquo; Or &amp;ldquo;this should be straightforward.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;The issue is not whether a human is somewhere in the loop.&lt;/p&gt;
&lt;p&gt;The issue is whether the human is in the &lt;strong&gt;right place&lt;/strong&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Before the AI acts?&lt;/li&gt;
&lt;li&gt;After it drafts?&lt;/li&gt;
&lt;li&gt;When risk is detected?&lt;/li&gt;
&lt;li&gt;When money is involved?&lt;/li&gt;
&lt;li&gt;When customer trust is at stake?&lt;/li&gt;
&lt;li&gt;When a decision needs authority?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;That matters.&lt;/p&gt;</description></item><item><title>What AI Governance Actually Means (And Why Most Organizations Get It Wrong)</title><link>https://christaburger.com/blog/what-ai-governance-actually-means/</link><pubDate>Sat, 28 Mar 2026 00:00:00 +0000</pubDate><guid>https://christaburger.com/blog/what-ai-governance-actually-means/</guid><description>&lt;p&gt;When most organizations hear &amp;ldquo;AI governance,&amp;rdquo; they think one of two things: a policy document nobody reads, or a legal team saying no to everything.&lt;/p&gt;
&lt;p&gt;Neither is governance. Both are avoidance.&lt;/p&gt;
&lt;p&gt;Real AI governance is the architecture through which an organization makes decisions about AI — consistently, accountably, and in alignment with its values. It answers three fundamental questions:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Who decides?&lt;/strong&gt; When an AI system affects employees, customers, or communities — who has authority over that decision? Who can challenge it? Who is accountable when it goes wrong?&lt;/p&gt;</description></item></channel></rss>