Resources
Written to be used, not filed.
The assessment instrument we score identity risk with, published in full, plus the regulatory changes that actually reach access — both mapped to controls you can implement rather than frameworks you can cite.
The Regulated IAM Assessment Guide
The instrument we score identity risk with, published in full — a weighted ten-category taxonomy, a 0–4 scoring model, a US–Canada control crosswalk with an evidence query for every line, and the artifacts assessors sample first.
Published in 3 sector editions · 10 shared categories · pick your sector on the download form
Get the guide → Always growingvaultKEY
Unlocking the essential IAM news that matters — what replaced the FFIEC CAT, HIPAA Section 164.312 evidence kits, NHI ownership models, NYDFS-to-Entra MFA mappings, and the US–Canada crosswalk. Written to be implemented, not skimmed.
What changed, what it means for IAM, and what it takes to implement
Read vaultKEY →The Assessment Guide is published in three sector editions because the ten risk categories are shared but the weights, instruments and artifacts are not. You choose yours on the download form — or read what separates the three first.