Baden Hughes

Baden Hughes

About Me

I've done "security" for about 30 years, but always as a part of a larger set of responsibilities in product development and/or technology operations.

The last few years I've been more specifically active in security & compliance engineering, both as a leader/manager in a consulting business, and as a hands-on practitioner. Supported customers to implement ISO 27001, SOC 2, NIST CSF, work through audits/attestations/assessments and more. Built a bunch of custom frameworks for GRC automation tools and done lots of data integration and crosswalking.

My more recent work focuses on AWS (as a partner and contracted service provider with a focus on Landing Zone Accelerators - LZA and LZA UC).

I'm currently on a bit of a streak putting out public/free or open-source contributions related to security and compliance standards and frameworks in my home region (Australia/New Zealand) and close by (ASEAN - South East Asia).

Get in Touch

baden.hughes@gmail.com

Specializations

AWSCloud SecurityCompliance AutomationAI Governance

Languages & Tools

OSCALPythonTerraformCloudFormation

Frameworks

CSA STARCSA CCMISO 27001ISO 27017ISO 27018ISO 42001NIST AI RMFNIST CSFNIST RMFSCFAIUC-1AU ISMNZ ISM

Projects

AWS Landing Zone Accelerator and Australia's Information Security Manual (ISM)

Analysis of AWS LZA coverage of Australia's ISM control pack, including AWS Security Blog post and published AWS Artifact report

ISMexplorer

Tool for tracking the evolution of Australia's Information Security Manual (ISM) across quarterly updates

AIUC1explorer.org

Tool for tracking the development of AIUC-1 - the first security and compliance certification for Agentic AI

DitchDistance

Tool for comparing and measuring differences between Australia's Information Security Manual (AUISM) and New Zealand's Information Security Manual (NZISM)

NSIZM OSCAL

Unofficial version of New Zealand's Information Security Manual in OSCAL format

AWS Service Matrix

Unofficial but live, data-driven version of AWS services availability and differences by region

Australian Energy Sector Cybersecurity Framework in OSCAL format

Unofficial but standard-linked expression of AESCSF in OSCAL - full suite: catalog, 3 security profiles x 3 maturity levels, resolved profiles

Singapore ICT&SS Policy Reform (post-IM8) Cybersecurity Controls in OSCAL

Singapore's ICT&SS full and updated Controls Catalog/Profiles/Resolved Profiles in OSCAL Format - synced with current and progressively changing website controls collection rather than one-off IM8 export and including the missing high risk cloud profile

Hong Kong Baseline IT Security Policy [S17] in OSCAL Format

Hong Kong Baseline IT Security Policy [S17] in OSCAL Format

OSCAL version of Thailand's NCSC Cybersecurity Standards for Cloud Systems (BE 2567/2024)

OSCAL version of Thailand's NCSC Cybersecurity Standards for Cloud Systems (BE 2567/2024)

Malaysia's National Cyber Security Baseline (NCSB) — Garis Asas Keselamatan Siber Negara — expressed in OSCAL

Malaysia's National Cyber Security Baseline (NCSB) — Garis Asas Keselamatan Siber Negara — expressed in OSCAL. Includes 3 maturity level profiles based on the Self Assessment Template.