From Paperwork to Proof: Automating Cyber Compliance
Cyber compliance has long been defined by documents, manual reviews, and one-off assessments—but that model is buckling under the speed and complexity of modern technology. In “From Paperwork to Proof,” host Josh Brickman explores how automation, machine-readable standards, and AI could transform compliance into a continuous, evidence-driven practice.
Pirooz Javan, CTO and co-founder of Easy Dynamics, explains the promise of OSCAL, intelligent automation, and a common language for communicating cybersecurity posture—while emphasizing why organizations cannot permanently outsource ownership of compliance. Members of the Common Criteria Users Forum Management Group preview their upcoming work in Rome and discuss how vendors, laboratories, and governments can improve international product assurance. Eric Crusius, Partner at Hunton Andrews Kurth brings us up to date on CMMC. Former NSA NIAP director Jonathan Rolf reflects on four decades of cybersecurity change and examines the tensions surrounding EUCC, mutual recognition, protection profiles, software supply chains, and post-quantum cryptography.
Plus, Josh and producer Bill Rutledge unpack recent developments involving AI-assisted cryptanalysis, the CMVP backlog, AI and PQ, ENISA’s PQ plans, and critical-infrastructure threats.