PUBLIC RESEARCH METHOD
How the Secure AI Playbook is built
Mike Sobiegraj researches, authors, edits, and maintains the Playbook. Interviews, source material, frameworks, regulation, implementation examples, and feedback inform the research; final content and editorial decisions remain with the author.
THE RESEARCH LOOP
Every Playbook stage follows the same research loop
EDITORIAL DEVELOPMENT
Research inputs are synthesized through a single editorial process
Research inputs
Research may include:
- Interviews with CISOs and other relevant professionals
- Regulatory requirements and guidance
- Industry standards and frameworks
- Public research and implementation examples
- Observed differences between organizational environments
- Feedback on Draft elements of the Playbook
Editorial synthesis
The author:
- Interprets the research inputs
- Reconciles conflicting perspectives
- Decides what is relevant to the Playbook
- Writes and structures the published guidance
- Maintains consistency across the complete Playbook
- Publishes changes as Draft or a numbered version
PUBLICATION STATUS AND VERSIONING
How stable is the published guidance?
- Draft
- Actively developed guidance that may change materially as research and editorial work continue.
- v1.0
- The first stable published version of a Playbook element.
- v1.x
- Refinements, clarifications, additions, and compatible improvements.
- v2.0
- A material change to the structure, method, or intended use of the published guidance.
Version numbers communicate publication maturity and change history. They do not claim empirical effectiveness or universal applicability.
INDUSTRY STANDARD ALIGNMENT
Which established frameworks or standards does this element correspond to?
Specific activities, decisions, outputs, controls, or evidence are mapped to named provisions.
Mappings are source-backed and appear as pills beside the relevant Playbook element. Alignment describes correspondence, not proof of effectiveness.
- NIST AI RMF
- ISO/IEC 42001
RECURRING STRUCTURE
What every Playbook stage will contain
| Element | Purpose |
|---|---|
| Stage definition | Stage title and concise description of what the stage does. |
| Input | Independent triggers, records, decisions, or evidence required before the stage begins. |
| Main activities | The minimum actions required to perform the stage and progress to the next decision. |
| Output and evidence | The records, decisions, test results, and other evidence produced by the stage. |
| Tools and templates | Forms, process templates, guides, product lists, and other execution resources supporting the stage. |
| Ownership and responsibilities | The business, technical, security, legal, compliance, privacy, and control responsibilities relevant to the stage. |
| Common blockers | Practical conditions that cause the stage to stall, fail, or become ineffective. |
| Known gaps and open questions | Unresolved questions and areas where the Playbook's current guidance remains incomplete. |
| Publication status and version | Draft or a numbered version indicating the maturity and change history of the published guidance. |
| Last reviewed | The most recent date on which the stage content was materially reviewed. |
| Current focus | The immediate research and development priority for that stage. |
| Industry standard alignment | Source-backed mappings between specific stage elements and named regulatory, framework, or industry-standard provisions. |
| Sources and references | The source material used to support the published guidance and its mappings. |
| Research acknowledgments, where applicable | People who agreed to be named for interviews or Draft reviews that informed the research. |
SHARE FEEDBACK
Test the Playbook against real operating environments
Here’s what would be useful to understand:
- Which Playbook stage do you participate in, and what decision or output must it produce?
- Where does the process stall, fail, or become unclear in your organization?
- Which inputs, evidence, ownership decisions, or handoffs are required to move to the next stage in your organizational context?
- How does your specific cybersecurity-program maturity, industry, regulation, architecture, or operating model align with the Playbook?
Share feedback over email or book a research interview.
Get in touch