Category Index

8 primary categories.

Use categories for a higher-level view than tags or series.

ai

Category
ATO for AI Systems

How AI models actually get authorized in the DoD — the Assess Only construct, the coming NIST 800-53 AI overlays, and the re-authorization trigger problem nobody has solved.

architecture

Category
CDAO, Swarms, and the Kill Chain as Microservices

Why the kill chain is decomposing into services on a data fabric — what Replicator's dissolution into DAWG reveals, how Open DAGIR works as an API contract, and where the microservices metaphor breaks.

System Design 101

A practical index of system design concepts, patterns, and real-world architecture references.

cybersecurity

Category
Army RMF 2.0: How the Updated Framework Works

How Army RMF 2.0 (Project Sentinel) restructured control selection, inheritance, and monitoring — and how it maps onto the DoD's new five-phase Cybersecurity Risk Management Construct.

SBOM in the Defense Industrial Base

A practical breakdown of SBOM requirements, format standards, toolchain options, and where DIB contractors consistently fall short when the contracting officer asks for one.

CMMC 2.0 in Practice

A practical breakdown of CMMC 2.0 levels, NIST SP 800-171 control domains, and what contractors must demonstrate to pass a C3PAO assessment.

Zero Trust Meets the AI Stack

Why your ZT architecture must now account for AI systems, model workflows, and the 2026 National Cyber Strategy

delivery

Category

development

Category

devsecops

Category
Secrets Management in Defense CI/CD

How defense CI/CD pipelines handle secrets without embedding credentials in code — covering dynamic brokers, secrets-as-code, operator patterns, and wiring rotation into continuous authorization evidence.

The Defense DevSecOps Toolkit

A curated index of the policy documents, NIST publications, Platform One services, pipeline tools, and compliance resources that defense software teams actually use.

Continuous ATO in Practice

A technical breakdown of Continuous ATO — what it actually requires, how OSCAL enables machine-readable evidence, and where most DoD programs fail to sustain it.

finance

Category

gitops

Category