The subset method
Nobody wants to read eight instruments. Everybody wants the twelve provisions across eight instruments that bear on the problem actually in front of them. That is a page type, and it is the most sellable output this method produces.
create a subset, a graph, of those standards that has just the bits, the controls, and the elements relevant here… You almost recreate a small standard based on this.
What a subset is
A subset takes one real problem and pulls together every provision, from every instrument here, that bears on it — each one cited, each one carrying its own instrument's label and licensing position, and each one linked back to its provision page. It is not a summary of the instruments and it is not a new standard. It is a view over the graph, computed rather than written, which is what makes it maintainable when one of the eight instruments is amended.
| A subset | A summary | |
|---|---|---|
| Is | A view over provisions that exist elsewhere | New text about provisions |
| Each item | Cites a provision, with its address and its instrument's label | Paraphrases several, attributed loosely or not at all |
| When an instrument is amended | The affected item is flagged — the content hash under its positional hash moved | Silently wrong, and looks current |
| Against a paywalled standard | Legitimate — it cites and interprets, it never reproduces | Usually a licence breach wearing a summary's clothes |
Why this page type sidesteps the ISO problem
A subset cites and interprets; it never reproduces. An ISO clause enters a subset as a reference — number, title, and the project's own reading of what it asks for — which is exactly what an ISO folder may legitimately hold. So the instruments that cannot have a folder here can still appear in a subset, and appear usefully. That is not a loophole; it is the difference between citation and reproduction, and it is the same difference a footnote in a book relies on.
What the first subset found
Across eight instruments spanning EU law, US law, ISO standards and security frameworks, the substantive overlap turned out to be small and repetitive:
The throughline across all of them is the same small set of ideas: least privilege, data minimisation, access control, supply-chain and third-party risk, traceable evidence, and accountability.
That is worth publishing for two opposite reasons. It is reassuring — an organisation doing those six things well is in a defensible position under most of them at once. And it is a warning — six shared ideas do not mean six shared obligations, and the differences between how NIS2 and DORA treat third-party risk are precisely where an organisation gets caught. A subset that collapsed the eight into the six would be the merge failure at a larger scale. Bridges, not merges →
Published
Agentic access
What eight instruments require of an organisation that lets an autonomous agent hold credentials and act on real systems. Spanning GDPR, NIST, ISO/IEC 27001, HIPAA, the EU AI Act, NIS2, DORA, and the OWASP/MITRE agentic layer.
Read →The rest
Incident reporting across NIS2, DORA, GDPR and the AI Act is the obvious second — four different clocks, four different addressees, one incident. It does not exist. Neither does anything else.