<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Compliance and GRC on Juan Carlos Munera</title><link>https://cybersecpro.me/categories/compliance-and-grc/</link><description>Recent content in Compliance and GRC on Juan Carlos Munera</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 Juan Carlos Munera</copyright><lastBuildDate>Tue, 28 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://cybersecpro.me/categories/compliance-and-grc/index.xml" rel="self" type="application/rss+xml"/><item><title>What the New PCI DSS to NIST CSF 2.0 Mapping Actually Buys You</title><link>https://cybersecpro.me/posts/pci-dss-v4-nist-csf-2-0-mapping/</link><pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/pci-dss-v4-nist-csf-2-0-mapping/</guid><description>What the new mapping actually buys you, where teams misread it as control equivalence, and how much rework that mistake creates.</description></item><item><title>The PCI DSS Comment Window Just Closed, and AI Was Named in the Ask</title><link>https://cybersecpro.me/posts/pci-dss-rfc/</link><pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/pci-dss-rfc/</guid><description>The Council named future technology and AI innovation in its request for comments. Here&amp;rsquo;s how the RFC process works and what happens next.</description></item><item><title>When Compliance Pulls the Plug: The Fable 5 Shutdown and What It Signals for Defenders</title><link>https://cybersecpro.me/posts/fable5-shutdown/</link><pubDate>Thu, 18 Jun 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/fable5-shutdown/</guid><description>Anthropic disabled two frontier models worldwide to comply with an export directive. The practitioner takeaways on dual-use AI and availability risk.</description></item><item><title>Inside the New Joint Cyber Agency Guidance on Agentic AI</title><link>https://cybersecpro.me/posts/joint-agency-ai-guidance/</link><pubDate>Sun, 03 May 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/joint-agency-ai-guidance/</guid><description>What Careful Adoption of Agentic AI Services means for non-human identity, privilege design, and compliance programs that haven&amp;rsquo;t caught up.</description></item><item><title>The Delve Scandal Proved What Assessors Already Knew</title><link>https://cybersecpro.me/posts/too-sassy-for-compliance-2/</link><pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/too-sassy-for-compliance-2/</guid><description>Two weeks after writing about the structural problems with compliance platforms, the allegations landed. What assessors already knew.</description></item><item><title>Beyond the Dashboard: What SaaS Compliance Tools Can and Can't Do for PCI-DSS</title><link>https://cybersecpro.me/posts/too-saasy-for-compliance/</link><pubDate>Sun, 08 Mar 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/too-saasy-for-compliance/</guid><description>A reality check on compliance automation platforms, the gap between generated evidence and assessed controls, and the questions to ask.</description></item></channel></rss>