aletay
Back
Governance, Risk, and Compliance in American
tech

Governance, Risk, and Compliance in American

by XXL boligrafo

36,039 words · 144 min read

"Cyber compliance is a cat and mouse game."

Enjoyed this? Tip the author — it goes straight to them.
Order paperback — from $18 →

$13.12 of this purchase (87.5%) goes directly to XXL boligrafo.

Print editions

Ships to you

Order a physical copy — printed on demand and shipped to you. The author earns a royalty on every copy.

Paperback
from $18
ships free · final total at checkout
6 × 9 in · 215 pages
Order in print →

Printed on demand by our print partner and shipped to your address. Shipping and your total are shown before you pay. The author earns a royalty on every copy.

Sample · opening pages
Free — no signup required
This book is not a dry recitation of standards or a checklist for passing audits—it's a field manual for those who live and breathe the challenges of protecting American digital infrastructure in 2026. When I started my career on the help desk, troubleshooting mundane issues like forgotten passwords and network glitches, I never imagined it would lead to specializing in NIST SP 800-53 assessments for high-stakes environments. But those early days taught me a crucial lesson: Cybersecurity isn't about isolated tools or controls—it's about the interplay of governance, risk management, and compliance (GRC) in a landscape shaped by federal mandates, emerging technologies, and relentless adversaries. From my time as a network engineer configuring Cisco routers to my current role auditing complex systems for fortune 500 companies, I've seen how "nuisances" like varying interpretations of the same framework can derail even the best teams. This book distills those lessons into actionable insights, helping you navigate the American cybersecurity ecosystem with confidence. 6 Part 1 lays the groundwork for GRC, exploring frameworks like NIST CSF 2.0, CMMC, and Zero Trust, while addressing real-world frustrations in compliance and project management. It's designed for ISSOs, ISSMs, SCAs, and professionals entering the field, with bonus chapters on career progression and case studies to make abstract concepts tangible. Part 2 dives deeper for auditors, demystifying IT fundamentals—from networking devices to cloud infrastructure—with a focus on auditing techniques, checklists, and integration under Zero Trust. Whether you're a newcomer building your foundations or a seasoned expert refining your approach, this guide equips you to not just comply, but to excel. In these pages, you'll find the tools to turn compliance from a burden into a strategic advantage.

About the author
X
XXL boligrafo
@writingzombie

"I'm an avid reader building a platform we can all actually enjoy — a place made for the way people really read and write, not the way platforms usually force them to. Right now I'm eighteen feet deep in Part II of the Chronicles of Bass Reeves, and not planning to come up for air anytime soon. My work lives where history meets the impossible: I take the real texture of the past — the dust, the law, the men who carried both — and thread it through fantasy and thriller sequences until you're not

Reader reviews

No reviews yet. Readers who own this book can be the first.