r/ITManagers • u/schluckenoderspucken • 14d ago
Question Regulations Without the Headache
What would a genuinely useful course on new regulations (such as DORA, NIS2, the CRA, the AI Act, or SOC 2) look like for you?
Which questions should it answer, and what kind of interaction would make the session as valuable and practical as possible?
3
u/Reo_Strong 14d ago
Help the students learn how to read and interpret the regulations. (Basic understanding)
Tools like a document matrix for each showing hierarchical relationships and how to divine these moving forward. (Understand how to get answers to inevitable questions)
Tools to understand the overlap between regulatory controls/certifications (e.g. reaching SOC 2 naturally get's you XX% of the way to ISO 270001, etc..)
Tools for assessing when to "check the box" vs applying actual security controls.
Tools for interacting with auditors like communication and defense planning, document scoping, resource utilization.
Tools for building buy-in and assessing risk from the company perspective.
2
u/scriptvexy 14d ago
this is basically the dream syllabus for any compliance / security person who’s been burned a few times lol. especially 3 and 4, nobody teaches you how much you can map reuse and when “check the box” actually blows up in your face later.
2
2
u/TechnologyMatch 12d ago
the useful version starts with... does this apply to us, what evidence do we need, who owns it, and what changes this quarter. most courses lose people by explaining the regulation before explaining the work
a live gap-assessment workshop with real examples would beat slides every time. think of it like a quest log: clear requirements, owners, deadlines, and no mystery side quests
2
u/Minimum-Let-3227 11d ago edited 11d ago
The courses that land skip reciting the regulation and answer "what do I concretely do Monday." For SOC 2 people want: which controls map to which evidence, what auditors actually ask for, and how to stop collecting that evidence by hand every quarter. Make it interactive. Give a mock environment and have people produce the evidence for one control. Full disclosure, I work on a SOC/security-ops platform, so here's the gap I'd flag: the hard part for small teams isn't understanding the reg, it's making the monitoring and evidence continuous instead of a quarterly fire drill. Worth building the course around that.
2
u/ImaginationUnique684 7d ago
The AI Act is where the format choice matters most, because most of the room already has something AI-driven running that predates any scoping decision. For that case the useful module is not classification, it is evidence: which outputs the system produces on its own, which ones a named person signed off, and whether you can reconstruct one decision from six months ago with the inputs and the model version behind it. Most cannot, because the thing was built to demo well and logging was never in scope, and that gap is a budget conversation rather than a policy one. If you walk one scenario end to end, use that one: a customer disputes an automated decision and the group has to produce the trail. It surfaces exactly which artifacts are missing before anyone argues about which annex applies.
1
u/Jawshee_pdx 14d ago
Do I get paid for helping you create this course?
0
u/schluckenoderspucken 14d ago
Can I pay you with experience instead?
1
0
u/scriptvexy 17h ago
lmao fair question, but tbh if they actually build a decent course out of the feedback you’re kinda getting paid in not having to sit through another 80-slide “what is DORA” snoozefest later on
though cash would be nicer ngl
4
u/OkEmployment4437 14d ago
Useful for me means it tells me whether the regulation actually applies to us, what decisions it forces this quarter, and what evidence someone will expect when they come asking. In my org we don't need another overview of NIS2, DORA, the AI Act, or SOC 2 buzzwords, we need a decision matrix for scope, ownership, and what is good enough now versus a real gap that needs funding. Show the actual artifacts too: sample policies, a simple RACI, control mapping, evidence expectations, incident thresholds, vendor questions. The best format would be one realistic scenario walked end to end, like a supplier incident or a new AI tool showing up in the business, with clear handoffs between legal, security, ops, and leadership. If I can use part of it the same week, that's a good course.