Topic · 8 articles
Governance
Every MacZine article on Governance, newest first - written, reviewed and versioned in the open.
CMMC Consultant, RPO, MSP, or vCISO: Who Owns Your Program?
Hiring a CMMC consultant? An RPO, an MSP, and a vCISO do three different jobs, and none of them can sign for you. What to ask each before you buy.
IBE Decides an AI Agent's Authority Before It Acts
IBE governs what an AI agent may do with no LLM in the decision path - a deterministic autonomy gate that certifies or refuses every action, in writing.
How Many Documents Does CMMC Level 2 Actually Require?
NIST 800-171 names 110 requirements but no document count. Scoping a CMMC Level 2 documentation set is a governance decision - here is what the 110 imply.
MacTech Files Three Provisional Patents Built on Proof, Not Trust
Three provisional patents from MacTech - Trust Codex, IBE, Freehold - on tested systems that prove their claims instead of asking you to trust the operator.
EnclaveWatch: Monitoring a CUI Vault Without Draining It
Continuous monitoring usually means shipping logs somewhere central. Inside a CUI boundary that is the one thing you should not do. EnclaveWatch inverts it.
Who Signs Your Self-Attestation, and What They Are Signing
Self-attestation is not a lighter version of an assessment. It moves the assessment risk onto a named individual - and the False Claims Act is where that lands.
RMF and CMMC Are Not the Same Program. Run Them as One.
RMF authorizes a system, CMMC certifies a contractor. They ask overlapping questions in different vocabularies - and paying twice is the mistake.
Building the Trusted Future: Infrastructure, AI, and MacTech
How MacTech combines infrastructure, security, quality, and governance into systems a defense contractor can trust - and where AI is allowed to decide.