Skip to content
Digital Bushido

06 / 08 of 8

名誉

06 / Meiyo 名誉

Honour

pronounced may-yoh

Domain: Accountability, governance, audit

Your auditor is not watching. Do it correctly anyway.

The argument

Hold your standard when nobody is watching.

Compliance creates an external requirement. Security governance creates an internal responsibility.

Audits, certifications and regulatory obligations matter. They also create a temptation to optimise for evidence rather than behaviour.

The stronger test is what happens between audits.

Do you patch because the vulnerability is real? Do you review privileged access because the access creates risk? Do you investigate control failures when nobody has asked for the report?

Internal assurance exists to answer these questions.

The failure mode

Compliance theatre performed for the audit window.

When Meiyo is absent, the audit becomes the deadline. Teams fix what the auditor will inspect and defer everything else. Controls exist on paper while their operational state deteriorates.

In practice

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  • Define internal standards

    Set security expectations that are clear and operational.

  • Assign control owners

    Give every important control a responsible owner.

  • Define evidence

    Specify what demonstrates that a control operates.

Show all 5 practices
  • Define control frequency

    State how often important controls must operate or be tested.

  • Record known failures

    Create a visible process for reporting controls that do not work.

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  • Run continuous assurance

    Test important controls throughout the year.

  • Track control degradation

    Monitor controls as systems, ownership and integrations change.

  • Fix internally discovered issues

    Do not wait for an audit or regulator to identify known weaknesses.

Show all 5 practices
  • Review standards

    Update standards when architecture, threats or business processes change.

  • Separate compliance from security

    Track regulatory compliance and internal security objectives separately.

3 / 4 Measured

Verify that the behaviour is happening and that it works.

  • Measure control effectiveness

    Measure whether controls produce the intended result, not only whether they exist.

  • Track overdue assurance

    Monitor controls that have not been tested on schedule.

  • Measure recurring findings

    Identify weaknesses that repeatedly appear in audits and assessments.

Show all 5 practices
  • Report control failures

    Include failed controls in management reporting.

  • Compare internal and external findings

    Identify problems that internal assurance should have found earlier.

4 / 4 Adaptive

Use evidence to improve the behaviour and respond to change.

  • Raise the internal standard

    Increase expectations when the organisation can support them and the risk warrants it.

  • Automate control assurance

    Use technical evidence where possible instead of manual evidence collection.

  • Remove recurring control failures

    Treat repeated findings as process or architecture problems.

Show all 5 practices
  • Challenge accepted weaknesses

    Review whether long-standing accepted risks are still justified.

  • Test before the audit

    Use internal assurance to establish the actual state before external scrutiny arrives.

See the full practice model

Worked examples

Vulnerability remediation

A critical vulnerability is discovered in an internet-facing service.

The SLA is 30 days.

The team fixes it in three days because they understand the exposure.

There is no audit requirement forcing the earlier action.

The standard matters even when the deadline allows more time.

Certificate expiry

A PKI team discovers that several internal certificates are approaching expiry.

The certificates are not currently causing an issue.

They replace them before expiry instead of waiting for an outage.

Operational discipline starts before failure.

Access review

A quarterly privileged-access review identifies several accounts that technically remain justified but are no longer used.

The owners remove them.

There is no audit finding requiring their removal.

Security maturity means reducing unnecessary exposure even when nobody has complained.

Penetration-test findings

A penetration test identifies a medium-risk weakness.

The finding is unlikely to appear in the next audit.

The application team fixes it anyway because the underlying design is wrong.

Do not use the audit scope as the definition of security.

Control failure

A security team discovers that a control has been failing silently for three months.

Nobody has noticed.

The team reports the failure, investigates the cause and accepts the temporary gap openly.

Honour the control by reporting when it does not work.

Mapped controls

Reading: The GOVERN function was added in CSF 2.0, and Meiyo lands on it almost entirely.

NIST Cybersecurity Framework 2.0

MeiyoNIST CSF 2.0. Table scrolls horizontally.
ControlControl titleStrengthWhy it maps
GV.RR-02Roles, responsibilities, and authorities establisheddirectNamed roles and authorities are what make accountability locatable.
GV.OV-01Risk management strategy outcomes revieweddirectReviewing risk-management outcomes is honour as self-scrutiny — checking your own work before an auditor does.

ISO/IEC 27001:2022 — Annex A

MeiyoISO 27001:2022. Table scrolls horizontally.
ControlControl titleStrengthWhy it maps
A.5.1Policies for information securitydirectA stated policy is the standard a team holds itself to unprompted.
A.5.2Information security roles and responsibilitiesdirectAssigned security responsibilities are the structure accountability hangs on.
A.5.35Independent review of information securitydirectIndependent review is the outside check that accountability is real and not self-reported.
A.5.36Compliance with policies, rules and standardsdirectVerifying compliance with the rules you set is honour made routine.