Machine-readable controls
State the subject, the expected condition, the data source, and the test. A machine can then run the check.
Research pillar · Zero Security Theatre
An organisation can hold every certificate its market asks for and still be unable to detect, contain, or recover from an ordinary intrusion. Compliant Insecurity is the name for that condition. This pillar studies how regulatory and contractual obligations move from periodic attestation to continuous operational evidence.
The question
What evidence demonstrates that this requirement is working today?
Active · since 2026 · Zero Security Theatre
hypothesis
HIPAA, SOC 2, HITRUST, NIST frameworks, ISO 27001, CMMC, PCI DSS, GDPR, state privacy laws, customer questionnaires, and contractual security schedules are useful sources of requirements. They tell an organisation what someone believes it should do. They are not evidence that it can survive an attack.
Buyers increasingly ask for the certificate during procurement and live evidence during risk review. This work asks how much of that evidence the running systems can produce automatically.
The framing and much of the source material for this pillar comes from Compliant Insecurity, which collects the pattern in detail.
recommendation
The gap between two audits is where the interesting behaviour happens. Configuration drifts, an exception is granted and forgotten, a vendor changes, a control is disabled during an incident and never restored. Periodic evidence cannot see any of it.
State the subject, the expected condition, the data source, and the test. A machine can then run the check.
Every record says where it came from, when it was collected, and which query produced it. An auditor can run it again.
Continuous comparison of observed state against expected state, with the time between drift and detection as a metric in its own right.
Requirements with no mapped evidence source at all, which are the most common and least reported failure.
Where the platform can enforce a policy, generate the written policy from the enforced rule.
The evidence already exists when the audit starts, so a team does not spend a quarter assembling it.
inference
Continuous evidence helps only when it describes what happened. Operational Truth separates what was intended, reported, recorded, inferred, observed, and independently verified. Without those labels, a clean record can be mistaken for a safe system.
The area uses these six labels from the Operational Truth material.
unknown
The pillar assumes continuous operational evidence predicts outcomes better than periodic compliance evidence.
Put this to work
Use the question “What evidence demonstrates that this requirement is working today?” on a real case and produce a record another person can challenge.
The result is a working analysis. Check it against source evidence and qualified judgment.
Nothing entered here is stored or sent. Review the prompt before sharing confidential, personal, patient, or privileged information.
You can leave any field blank. The prompt will mark it as not provided.
If the record survives your review, send the question, evidence, unknowns, and requested next step.
How many requirements can be answered by a machine today?
When a control is quietly disabled, how long before anyone notices?
Pattern
Store the query, not the screenshot
Keep the source, collection time, and query with the result so a reader can reproduce it. The same record is ready when an audit begins.
Anti-pattern
Presenting a certificate as evidence of resilience
A report describes a negotiated scope, at a point in time, against selected controls, many of which ask only whether a process exists. It is a procurement artifact and a requirement source.
Anti-pattern
Writing a narrative where no data source exists
Requirements with no operational evidence source produce prose, and prose always passes. The absence never appears as a failure in any report.
Organises outcomes across govern, identify, protect, detect, respond, and recover. Used here as a requirement source, not as evidence of effect.
A large control catalogue, useful for mapping requirements to testable statements.
A frequent source of the compliant insecurity pattern, because many requirements ask whether a process exists.
Collected material on organisations that satisfy their frameworks while remaining unable to detect, contain, or recover.
The intended, reported, recorded, inferred, observed, and verified distinction used throughout this area.
Design Patterns
A screenshot is a claim about a moment. A stored query with provenance can be re-run by the reader, which changes what the evidence is worth.
2026-09-15
Operating Theorys
Certification scope is negotiated. A clean report describes the environment that was examined against the controls that were selected, at the time of the examination.
2026-09-15
When requirements are mapped to operational data sources, the largest category is usually requirements that no system can currently answer at all.
2026-09-15