<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Muhammad Anwar — Insights</title><description>Cybersecurity, compliance assurance and AI security advisory for Defence, Federal Government and critical infrastructure. ISM, PSPF, NIST SP 800-53, SOCI Act and ISO 42001.</description><link>https://www.muhammad-anwar.com/</link><item><title>ISO 27001 Internal Audit: A Step-by-Step Guide With Checklist</title><link>https://www.muhammad-anwar.com/blog/iso-27001-internal-audit-guide/</link><guid isPermaLink="true">https://www.muhammad-anwar.com/blog/iso-27001-internal-audit-guide/</guid><description>How to plan and run an ISO 27001 internal audit: scope, audit programme, clauses 4 to 10, Annex A sampling, grading findings and closing corrective actions.</description><pubDate>Sun, 11 Oct 2026 00:00:00 GMT</pubDate><category>ISO 27001</category><category>Internal Audit</category><category>ISMS</category></item><item><title>CMMC 2.0 Explained: Levels, Requirements and What It Means for Suppliers</title><link>https://www.muhammad-anwar.com/blog/cmmc-2-explained/</link><guid isPermaLink="true">https://www.muhammad-anwar.com/blog/cmmc-2-explained/</guid><description>CMMC 2.0 explained: the three levels, 110 NIST SP 800-171 requirements, SPRS scoring, POA&amp;M rules and what it means for Australian suppliers.</description><pubDate>Sat, 10 Oct 2026 00:00:00 GMT</pubDate><category>CMMC</category><category>NIST SP 800-171</category><category>Defence</category></item><item><title>How to Conduct a Cyber Security Risk Assessment in 7 Steps</title><link>https://www.muhammad-anwar.com/blog/cyber-security-risk-assessment/</link><guid isPermaLink="true">https://www.muhammad-anwar.com/blog/cyber-security-risk-assessment/</guid><description>How to conduct a cyber security risk assessment step by step: scope, threats, vulnerabilities, a 5x5 risk matrix, appetite and NIST SP 800-53 treatment.</description><pubDate>Fri, 09 Oct 2026 00:00:00 GMT</pubDate><category>Cyber Security Risk Assessment</category><category>Risk Management</category><category>NIST SP 800-30</category></item><item><title>ISM Compliance Explained: A Practical Guide to the Information Security Manual</title><link>https://www.muhammad-anwar.com/blog/ism-compliance-guide/</link><guid isPermaLink="true">https://www.muhammad-anwar.com/blog/ism-compliance-guide/</guid><description>What ISM compliance really means, how the risk-based approach works, and the practical steps to apply the Australian Government Information Security Manual…</description><pubDate>Thu, 08 Oct 2026 00:00:00 GMT</pubDate><category>ISM</category><category>Government Security</category><category>PSPF</category></item><item><title>Third-Party Risk Management: How to Assess Vendors Properly</title><link>https://www.muhammad-anwar.com/blog/third-party-risk-management-guide/</link><guid isPermaLink="true">https://www.muhammad-anwar.com/blog/third-party-risk-management-guide/</guid><description>A practical guide to third-party risk management: tiering vendors, security questionnaires, evidence, scoring, contracts, monitoring and AI questions.</description><pubDate>Thu, 08 Oct 2026 00:00:00 GMT</pubDate><category>Third-Party Risk Management</category><category>Vendor Risk</category><category>TPRM</category></item><item><title>NIST CSF 2.0 Explained: The Six Functions and How to Use Them</title><link>https://www.muhammad-anwar.com/blog/nist-csf-2-explained/</link><guid isPermaLink="true">https://www.muhammad-anwar.com/blog/nist-csf-2-explained/</guid><description>NIST CSF 2.0 explained: the new Govern function, all six functions, categories, profiles and tiers, and how Australian organisations can use it with the ISM.</description><pubDate>Wed, 07 Oct 2026 00:00:00 GMT</pubDate><category>NIST CSF 2.0</category><category>NIST</category><category>Cyber Governance</category></item><item><title>ISO/IEC 42001 for Boards: What an AI Management System Actually Asks of You</title><link>https://www.muhammad-anwar.com/blog/iso-42001-guide-for-boards/</link><guid isPermaLink="true">https://www.muhammad-anwar.com/blog/iso-42001-guide-for-boards/</guid><description>AI governance is moving from principles to auditable systems. Here is what ISO 42001 means in practice — and the five questions every Board should be asking…</description><pubDate>Tue, 06 Oct 2026 00:00:00 GMT</pubDate><category>ISO 42001</category><category>AI Governance</category><category>Board Advisory</category></item><item><title>PSPF Reporting Made Practical: Preparing Your Annual Protective Security Self-Assessment</title><link>https://www.muhammad-anwar.com/blog/pspf-annual-reporting-guide/</link><guid isPermaLink="true">https://www.muhammad-anwar.com/blog/pspf-annual-reporting-guide/</guid><description>A practical guide to the PSPF annual self-assessment: how maturity is judged, the evidence that matters, and how to turn PSPF reporting into genuine…</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>PSPF</category><category>Government Security</category><category>ISM</category></item><item><title>NIST SP 800-53 and the ISM: Building One Control Set for Two Frameworks</title><link>https://www.muhammad-anwar.com/blog/nist-800-53-ism-mapping/</link><guid isPermaLink="true">https://www.muhammad-anwar.com/blog/nist-800-53-ism-mapping/</guid><description>How to map NIST SP 800-53 to the Australian ISM, where the frameworks align and differ, and how a unified control set cuts compliance effort for global and…</description><pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate><category>NIST SP 800-53</category><category>ISM</category><category>Control Mapping</category></item><item><title>How to Write a System Security Plan That Assessors Actually Trust</title><link>https://www.muhammad-anwar.com/blog/system-security-plan-guide/</link><guid isPermaLink="true">https://www.muhammad-anwar.com/blog/system-security-plan-guide/</guid><description>A practical guide to writing a System Security Plan (SSP): structure, what assessors look for, common mistakes and how the SSP, SRMP and Statement of…</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>System Security Plan</category><category>ISM</category><category>IRAP</category></item><item><title>Essential Eight in the Age of AI Agents</title><link>https://www.muhammad-anwar.com/blog/essential-eight-age-ai-agents/</link><guid isPermaLink="true">https://www.muhammad-anwar.com/blog/essential-eight-age-ai-agents/</guid><description>AI agents run code, hold credentials and act on our behalf. Here is how the Essential Eight still applies — and where assessors should be looking harder.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate><category>Essential Eight</category><category>AI Security</category><category>ACSC</category></item><item><title>IRAP Assessment Readiness: 10 Things to Fix Before Your Assessor Arrives</title><link>https://www.muhammad-anwar.com/blog/irap-assessment-readiness/</link><guid isPermaLink="true">https://www.muhammad-anwar.com/blog/irap-assessment-readiness/</guid><description>Preparing for an IRAP assessment? Ten practical readiness steps — from system boundary and SSP quality to evidence and cloud responsibilities — that save…</description><pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate><category>IRAP</category><category>ISM</category><category>Cloud Security</category></item><item><title>SOCI Act CIRMP: A Practical Guide to the Four Hazard Domains</title><link>https://www.muhammad-anwar.com/blog/soci-act-cirmp-guide/</link><guid isPermaLink="true">https://www.muhammad-anwar.com/blog/soci-act-cirmp-guide/</guid><description>A practical guide to the SOCI Act Critical Infrastructure Risk Management Program (CIRMP): the four hazard domains, cyber framework alignment, and preparing…</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><category>SOCI Act</category><category>CIRMP</category><category>Critical Infrastructure</category></item><item><title>AI Supply Chain Risk: The AI Already Inside Your Vendors</title><link>https://www.muhammad-anwar.com/blog/ai-supply-chain-risk/</link><guid isPermaLink="true">https://www.muhammad-anwar.com/blog/ai-supply-chain-risk/</guid><description>Your suppliers are shipping AI features whether you asked for them or not. A practical approach to AI supply chain risk and third-party AI governance for…</description><pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate><category>Third-Party Risk</category><category>AI Security</category><category>SOCI Act</category></item><item><title>AI Security Risks Every Board Should Understand: Prompt Injection, Data Leakage and Excessive Agency</title><link>https://www.muhammad-anwar.com/blog/ai-security-risks-for-boards/</link><guid isPermaLink="true">https://www.muhammad-anwar.com/blog/ai-security-risks-for-boards/</guid><description>The AI security risks that matter most to Boards and executives — prompt injection, sensitive data leakage, excessive agency and supply chain risk — and the…</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>AI Security</category><category>AI Governance</category><category>Board Advisory</category></item><item><title>Cyber Risk Reporting for Boards: KRIs and KCIs That Actually Drive Decisions</title><link>https://www.muhammad-anwar.com/blog/cyber-risk-reporting-for-boards/</link><guid isPermaLink="true">https://www.muhammad-anwar.com/blog/cyber-risk-reporting-for-boards/</guid><description>How to design cyber risk reporting that Boards use: choosing key risk indicators (KRIs) and key control indicators (KCIs), setting thresholds and telling a…</description><pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate><category>Board Advisory</category><category>Risk Management</category><category>GRC</category></item><item><title>Zero Trust for Australian Organisations: Where the ISM Already Points the Way</title><link>https://www.muhammad-anwar.com/blog/zero-trust-australian-organisations/</link><guid isPermaLink="true">https://www.muhammad-anwar.com/blog/zero-trust-australian-organisations/</guid><description>A practical take on zero trust for Australian government and regulated organisations — the core principles, how they align with the ISM, and a realistic…</description><pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate><category>Zero Trust</category><category>ISM</category><category>Identity Security</category></item><item><title>Defence Supply Chain Security: How SMEs Can Prepare for Defence Industry Requirements</title><link>https://www.muhammad-anwar.com/blog/defence-supply-chain-security/</link><guid isPermaLink="true">https://www.muhammad-anwar.com/blog/defence-supply-chain-security/</guid><description>A practical guide for small and medium businesses entering the Defence supply chain: governance, personnel, physical and cyber security expectations, and…</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><category>Defence</category><category>Supply Chain</category><category>Government Security</category></item></channel></rss>