<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_001.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_001.png</image:loc>
      <image:title>Principle 001: Crisis Decision Hierarchy — Executive Governance Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Organisations do not lose systems first. They lose decision authority — then everything else follows. Principle 001/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Executive Governance.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_002.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_002.png</image:loc>
      <image:title>Principle 002: Board-Survivable Cyber Architecture™ — Executive Governance Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Boards do not buy cyber technology. They buy the absence of unrecoverable downside. Principle 002/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Executive Governance.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_003.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_003.png</image:loc>
      <image:title>Principle 003: Evidence Chain Model™ — Evidence &amp; Regulation Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>If the evidence chain breaks before the regulator opens the file, the control was never a control. Principle 003/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Evidence &amp; Regulation.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_004.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_004.png</image:loc>
      <image:title>Principle 004: Decision Rights Architecture™ — Executive Governance Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Authority that cannot be exercised under pressure is decorative. Document it as theatre or redesign it as power. Principle 004/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Executive Governance.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_005.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_005.png</image:loc>
      <image:title>Principle 005: Recoverability Mandate™ — Resilience &amp; Recovery Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Recovery is not a phase. It is the discipline that proves whether the programme is real. Principle 005/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Resilience &amp; Recovery.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_006.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_006.png</image:loc>
      <image:title>Principle 006: Contract Control Matrix™ — Contracts &amp; Suppliers Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Every clause your counterparty would not sign on incident day must be removed or rewritten today. Principle 006/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Contracts &amp; Suppliers.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_007.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_007.png</image:loc>
      <image:title>Principle 007: AI Accountability Stack™ — AI Governance Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Autonomy without accountability is liability dressed as innovation. Govern both with the same instrument. Principle 007/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. AI Governance.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_008.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_008.png</image:loc>
      <image:title>Principle 008: Operational Defensibility — Evidence &amp; Regulation Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Time-to-defensible is the only metric your supervisor, board, and insurer will ever agree on. Principle 008/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Evidence &amp; Regulation.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_009.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_009.png</image:loc>
      <image:title>Principle 009: Doctrine Durability — Doctrine &amp; Talent Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Control posture survives leadership turnover only when doctrine outlives the doctrine's author. Principle 009/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Doctrine &amp; Talent.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_010.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_010.png</image:loc>
      <image:title>Principle 010: Asymmetric Disclosure Doctrine™ — Disclosure &amp; Crisis Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Counterparties forgive incidents. They do not forgive the second disclosure that contradicts the first. Principle 010/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Disclosure &amp; Crisis.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_011.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_011.png</image:loc>
      <image:title>Principle 011: Third-Party Liability Inversion™ — Suppliers &amp; Liability Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Your supplier's weakest control becomes your strongest liability when the regulator names you together. Principle 011/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Suppliers &amp; Liability.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_012.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_012.png</image:loc>
      <image:title>Principle 012: Cyber Insurance Renegotiation Principle™ — Insurance &amp; Claims Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>The pre-incident premium is tuition. The renewal is the exam your control posture sits in writing. Principle 012/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Insurance &amp; Claims.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_013.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_013.png</image:loc>
      <image:title>Principle 013: Identity-as-Perimeter Doctrine™ — Identity &amp; Access Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>There is no boundary left to harden. Identity is the control plane and every assertion is an audit contract. Principle 013/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Identity &amp; Access.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_014.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_014.png</image:loc>
      <image:title>Principle 014: Crypto-Agility Mandate™ — Quantum &amp; Crypto Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Quantum-resilient cryptography is not research. It is next decade's audit finding written today. Principle 014/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Quantum &amp; Crypto.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_015.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_015.png</image:loc>
      <image:title>Principle 015: Operational Resilience Threshold™ — Resilience &amp; Continuity Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>The hour you cannot operate degraded is the hour your continuity plan becomes evidence against you. Principle 015/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Resilience &amp; Continuity.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_016.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_016.png</image:loc>
      <image:title>Principle 016: Model Risk Governance Doctrine™ — AI Governance Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Every AI decision touching a customer leaves a paper trail. Write it before the regulator does. Principle 016/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. AI Governance.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_017.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_017.png</image:loc>
      <image:title>Principle 017: Sovereign Risk Geometry™ — Data Sovereignty Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Data residency is not policy. It is the geometry of who can compel disclosure and from where. Principle 017/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Data Sovereignty.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_018.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_018.png</image:loc>
      <image:title>Principle 018: Zero Trust Engineering Admission™ — Zero Trust Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Zero Trust is not a product line. It is the admission that inherited trust was already wrong. Principle 018/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Zero Trust.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_019.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_019.png</image:loc>
      <image:title>Principle 019: First Call Hierarchy™ — Crisis Command Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>The first call after breach is not legal. It is the executive who owns the consequence. Principle 019/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Crisis Command.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_020.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_020.png</image:loc>
      <image:title>Principle 020: Vendor Concentration Trap™ — Supplier Concentration Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>A single-provider stack is efficiency until the regulator calls it concentration risk. Principle 020/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Supplier Concentration.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_021.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_021.png</image:loc>
      <image:title>Principle 021: Insider Threat Realism™ — Insider Risk Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>The insider does not merely appear in the threat model. The insider often builds it. Govern accordingly. Principle 021/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Insider Risk.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_022.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_022.png</image:loc>
      <image:title>Principle 022: SBOM Provenance Mandate™ — Software Supply Chain Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Code you cannot enumerate is risk you cannot disclose. The SBOM is the receipt for every signature. Principle 022/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Software Supply Chain.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_023.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_023.png</image:loc>
      <image:title>Principle 023: Run-Time Truth Doctrine™ — Runtime Assurance Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Build-time guarantees expire when the workload starts. Runtime evidence is what regulators accept. Principle 023/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Runtime Assurance.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_024.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_024.png</image:loc>
      <image:title>Principle 024: Defaults-Become-Decisions Doctrine™ — Configuration Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Every configuration you did not change is a decision you signed without reading. Principle 024/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Configuration.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_025.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_025.png</image:loc>
      <image:title>Principle 025: Critical Skill Concentration Risk™ — Talent Concentration Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>When the one engineer who understands the control leaves, the control leaves with them. Principle 025/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Talent Concentration.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_026.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_026.png</image:loc>
      <image:title>Principle 026: Programme Discipline — Programme Discipline Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>A programme that cannot state its next decision in one sentence is not a programme. It is a process. Principle 026/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Programme Discipline.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_027.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_027.png</image:loc>
      <image:title>Principle 027: Operating Tempo Doctrine — Operating Model Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Tempo is the only governance metric that compounds. Improve it and every other metric follows. Principle 027/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Operating Model.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_028.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_028.png</image:loc>
      <image:title>Principle 028: Single-Threaded Authority — Authority Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Distributed authority is theatre. Real authority is single-threaded, accountable, and revocable. Principle 028/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Authority.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_029.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_029.png</image:loc>
      <image:title>Principle 029: Threat Intelligence Hierarchy — Threat Intelligence Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Intelligence that does not change a decision is content. Intelligence that does is doctrine. Principle 029/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Threat Intelligence.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_030.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_030.png</image:loc>
      <image:title>Principle 030: Crown-Jewel Inversion Principle — Crown Jewels Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Crown jewels are not where value sits. They are where consequence collapses if compromised. Principle 030/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Crown Jewels.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_031.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_031.png</image:loc>
      <image:title>Principle 031: Detection Engineering Mandate — Detection Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Every detection that triggers without an owned response is a notification, not a control. Principle 031/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Detection.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_032.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_032.png</image:loc>
      <image:title>Principle 032: Forensic Readiness Discipline — Forensics Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>If your incident investigation begins after the incident, you have already lost it. Principle 032/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Forensics.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_033.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_033.png</image:loc>
      <image:title>Principle 033: Encryption Decree — Encryption Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Encryption without key custody is decorative. Custody without rotation is fossilised. Principle 033/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Encryption.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_034.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_034.png</image:loc>
      <image:title>Principle 034: Public-Cloud Sovereignty Test — Cloud Sovereignty Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Sovereignty in cloud is measured in keys you hold and clauses you signed — nothing else. Principle 034/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Cloud Sovereignty.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_035.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_035.png</image:loc>
      <image:title>Principle 035: Configuration Drift Doctrine — Configuration Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Configuration drift is the slowest, costliest breach. It has no perimeter and no headline. Principle 035/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Configuration.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_036.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_036.png</image:loc>
      <image:title>Principle 036: Patch Cadence Realism — Vulnerability Management Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Patch cadence is published as policy and audited as legend. Reconcile or remove. Principle 036/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Vulnerability Management.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_037.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_037.png</image:loc>
      <image:title>Principle 037: Vulnerability Triage Hierarchy — Vulnerability Management Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Severity ratings sort vulnerabilities. Exploitability decides which ones move you out of bed. Principle 037/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Vulnerability Management.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_038.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_038.png</image:loc>
      <image:title>Principle 038: Logging Sufficiency Test — Logging Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Logs that cannot reconstruct the timeline within minutes are storage costs, not security. Principle 038/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Logging.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_039.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_039.png</image:loc>
      <image:title>Principle 039: Identity Lifecycle Discipline — Identity Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Joiners, movers, leavers: the boring loop that decides whether identity is governance or theatre. Principle 039/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Identity.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_040.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_040.png</image:loc>
      <image:title>Principle 040: Privileged Access Minimum — Privileged Access Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Standing privileged access is liability dressed as convenience. Default it to ephemeral. Principle 040/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Privileged Access.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_041.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_041.png</image:loc>
      <image:title>Principle 041: Shadow IT Recognition — Shadow IT Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Shadow IT is not policy failure. It is a measurement of how easily the organisation can be told no. Principle 041/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Shadow IT.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_042.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_042.png</image:loc>
      <image:title>Principle 042: Vendor Onboarding Mandate — Supplier Onboarding Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>A vendor onboarded without evidence becomes a vendor offboarded under provable loss. Principle 042/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Supplier Onboarding.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_043.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_043.png</image:loc>
      <image:title>Principle 043: Contractual Asymmetry Principle — Contracts Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Every clause not actively negotiated is a clause negotiated for someone else. Principle 043/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Contracts.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_044.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_044.png</image:loc>
      <image:title>Principle 044: Procurement Cyber Gate — Procurement Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Procurement that skips cyber pre-qualification is procurement that bypasses governance. Principle 044/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Procurement.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_045.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_045.png</image:loc>
      <image:title>Principle 045: Insurance Underwriting Realism — Insurance Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Cyber underwriters price what they can see. Make sure it survives forensic review. Principle 045/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Insurance.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_046.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_046.png</image:loc>
      <image:title>Principle 046: Claim-Defensibility Doctrine — Claims Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>A control that cannot defend a claim is a control that will become an exclusion. Principle 046/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Claims.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_047.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_047.png</image:loc>
      <image:title>Principle 047: Quantification Sobriety — Risk Quantification Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Quantification is useful only when it changes a decision. Otherwise, it is performance. Principle 047/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Risk Quantification.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_048.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_048.png</image:loc>
      <image:title>Principle 048: Risk Appetite Coherence — Risk Appetite Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Risk appetite means nothing until exceeded. Put the tripwires in before the breach. Principle 048/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Risk Appetite.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_049.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_049.png</image:loc>
      <image:title>Principle 049: Risk-Register Realism — Risk Register Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>A risk register without owners, dates, and money is a literature review. Principle 049/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Risk Register.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_050.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_050.png</image:loc>
      <image:title>Principle 050: Audit Findings Discipline — Audit Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>An audit finding without a board-approved remediation date is a finding the board does not own. Principle 050/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Audit.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_051.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_051.png</image:loc>
      <image:title>Principle 051: Continuous Assurance Mandate — Assurance Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Annual attestation is a snapshot. Continuous assurance is a contract. Principle 051/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Assurance.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_052.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_052.png</image:loc>
      <image:title>Principle 052: Three-Lines Operational Truth — Governance Lines Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Three lines of defence collapse to one when only the first knows what is happening. Principle 052/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Governance Lines.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_053.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_053.png</image:loc>
      <image:title>Principle 053: Internal-Audit Independence Test — Internal Audit Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Audit independence is measured by what the auditor may write to the board. Principle 053/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Internal Audit.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_054.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_054.png</image:loc>
      <image:title>Principle 054: Whistleblower Doctrine — Ethics Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>If anomaly-to-accountability runs through command, it is not a route. It is a filter. Principle 054/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Ethics.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_055.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_055.png</image:loc>
      <image:title>Principle 055: Crisis Communications Mandate — Crisis Comms Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Crisis communications drafted during crisis confess that there was no plan. Principle 055/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Crisis Comms.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_056.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_056.png</image:loc>
      <image:title>Principle 056: Forensic Custody Chain — Forensics Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Chain of custody preserved badly is chain of custody not preserved at all. Principle 056/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Forensics.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_057.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_057.png</image:loc>
      <image:title>Principle 057: Tabletop Exercise Realism — Exercises Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Tabletop exercises that do not end in a board decision are calendar entries. Principle 057/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Exercises.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_058.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_058.png</image:loc>
      <image:title>Principle 058: Restoration-Tested Backups — Backups Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Backups that have not been restored are not backups. They are encrypted hope. Principle 058/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Backups.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_059.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_059.png</image:loc>
      <image:title>Principle 059: Recovery-Time Honesty — Recovery Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Recovery-time objectives unverified by drills are aspirations the board should reject. Principle 059/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Recovery.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_060.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_060.png</image:loc>
      <image:title>Principle 060: Operational-Resilience Inversion — Resilience Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Resilience is not what technology does. It is what the institution does when technology does not. Principle 060/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Resilience.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_061.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_061.png</image:loc>
      <image:title>Principle 061: Severance &amp; Liability Doctrine — Liability Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Liability that cannot be transferred, insured, or absorbed must be reduced. There is no fourth option. Principle 061/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Liability.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_062.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_062.png</image:loc>
      <image:title>Principle 062: Data Sovereignty Discipline — Data Sovereignty Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Data sovereignty is decided at the contract, not at the data centre. Principle 062/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Data Sovereignty.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_063.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_063.png</image:loc>
      <image:title>Principle 063: Cross-Border Transfer Mandate — Cross-Border Data Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Every cross-border transfer is a contract. Absence of one is a breach in waiting. Principle 063/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Cross-Border Data.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_064.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_064.png</image:loc>
      <image:title>Principle 064: Privacy-by-Design Realism — Privacy Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Privacy retrofitted is privacy lost. Build it in or rebuild around it. Principle 064/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Privacy.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_065.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_065.png</image:loc>
      <image:title>Principle 065: Subject-Rights Operating Model — Data Rights Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Subject-rights requests test the operating model. If you fail at scale, fix the model. Principle 065/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Data Rights.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_066.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_066.png</image:loc>
      <image:title>Principle 066: Data Minimisation Mandate — Data Minimisation Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Every field you do not collect is a breach you do not suffer. Discipline shows in what is absent. Principle 066/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Data Minimisation.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_067.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_067.png</image:loc>
      <image:title>Principle 067: Retention Mandate — Retention Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Data kept past purpose becomes evidence in someone else's case. Retention is governance, not storage. Principle 067/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Retention.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_068.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_068.png</image:loc>
      <image:title>Principle 068: Cyber-Physical Engineering Mandate — OT / ICS Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>OT cyber is engineering, not IT. Apply IT thinking and the plant teaches you the difference. Principle 068/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. OT / ICS.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_069.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_069.png</image:loc>
      <image:title>Principle 069: Safety-Cyber Convergence — Safety Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Safety integrity and cyber integrity now share a budget, regulator, and failure mode. Principle 069/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Safety.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_070.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_070.png</image:loc>
      <image:title>Principle 070: ICS Patch Doctrine — ICS Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>ICS patching is a maintenance window, a safety case, and a vendor negotiation — in that order. Principle 070/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. ICS.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_071.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_071.png</image:loc>
      <image:title>Principle 071: Critical-Infrastructure Inversion — Critical Infrastructure Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Critical infrastructure is critical until incident. After incident it is public consequence. Principle 071/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Critical Infrastructure.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_072.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_072.png</image:loc>
      <image:title>Principle 072: National-Resilience Mandate — Essential Services Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Operators of essential services answer to two regimes: the supervisor's and the public's. Principle 072/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Essential Services.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_073.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_073.png</image:loc>
      <image:title>Principle 073: Geopolitical Cyber Realism — Geopolitics Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Your threat model is your geography. Update it as the map changes. Principle 073/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Geopolitics.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_074.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_074.png</image:loc>
      <image:title>Principle 074: Sanctions Compliance Mandate — Sanctions Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Sanctions compliance is a cyber control. Treat it as one and your blast radius shrinks. Principle 074/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Sanctions.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_075.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_075.png</image:loc>
      <image:title>Principle 075: State-Aligned Threat Doctrine — State Threats Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>State-aligned threats are now baseline threats. Architecting around them is architecting for everyone. Principle 075/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. State Threats.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_076.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_076.png</image:loc>
      <image:title>Principle 076: Quantum-Risk Time Horizon — Quantum Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Quantum risk is a 2026 problem because 2030 data is being copied today. Principle 076/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Quantum.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_077.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_077.png</image:loc>
      <image:title>Principle 077: Post-Quantum Migration Mandate — Post-Quantum Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Crypto migration is a multi-year programme. Start it the day you classify the data. Principle 077/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Post-Quantum.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_078.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_078.png</image:loc>
      <image:title>Principle 078: Cipher Inventory Discipline — Crypto Inventory Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>If you cannot list every cipher in your estate, you cannot migrate any of them. Principle 078/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Crypto Inventory.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_079.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_079.png</image:loc>
      <image:title>Principle 079: Hardware Trust Doctrine — Hardware Trust Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Hardware roots of trust are policy, supply chain, and physics. Lose one and you lose the root. Principle 079/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Hardware Trust.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_080.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_080.png</image:loc>
      <image:title>Principle 080: Firmware Governance Mandate — Firmware Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Firmware is the controlled substance of cyber. Track it like one or expect the breach equivalent. Principle 080/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Firmware.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_081.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_081.png</image:loc>
      <image:title>Principle 081: SBOM Mandate — SBOM Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>If your supplier cannot produce an SBOM, you cannot produce a defence. Principle 081/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. SBOM.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_082.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_082.png</image:loc>
      <image:title>Principle 082: Open-Source Stewardship — Open Source Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Open source is a dependency, not a gift. Govern it as a supplier with no SLA. Principle 082/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Open Source.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_083.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_083.png</image:loc>
      <image:title>Principle 083: AI Provenance Mandate — AI Provenance Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Every AI decision must be traceable to data, weights, and authority. Lose one and accountability collapses. Principle 083/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. AI Provenance.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_084.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_084.png</image:loc>
      <image:title>Principle 084: Model Drift Discipline — Model Drift Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Models drift. Decisions drift with them. Govern drift or stop calling it governance. Principle 084/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Model Drift.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_085.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_085.png</image:loc>
      <image:title>Principle 085: Training-Data Custody — Training Data Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Training data is a regulated asset. Treat it as one or watch it become evidence. Principle 085/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Training Data.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_086.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_086.png</image:loc>
      <image:title>Principle 086: Prompt-Injection Realism — Prompt Injection Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Prompt injection is the new SQL injection. The lesson is unchanged: trust no input. Principle 086/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Prompt Injection.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_087.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_087.png</image:loc>
      <image:title>Principle 087: Agentic-Autonomy Test — Agentic AI Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Every autonomous action your system can take must have a named human accountable for its outcome. Principle 087/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Agentic AI.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_088.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_088.png</image:loc>
      <image:title>Principle 088: AI-Assisted Decision Provenance — AI Decisions Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>If you cannot explain why the AI agreed, you cannot defend why you did. Principle 088/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. AI Decisions.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_089.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_089.png</image:loc>
      <image:title>Principle 089: Bias-Audit Mandate — Bias Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Bias audited annually is bias governed. Bias audited at incident is bias litigated. Principle 089/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Bias.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_090.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_090.png</image:loc>
      <image:title>Principle 090: Disinformation Operational Test — Disinformation Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Operational disinformation is now cyber risk. Reputation is an attack surface. Principle 090/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Disinformation.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_091.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_091.png</image:loc>
      <image:title>Principle 091: Insider Threat Realism Update — Insider Risk Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Insider threat is no longer the disgruntled employee. It is the privileged identity used by anyone. Principle 091/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Insider Risk.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_092.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_092.png</image:loc>
      <image:title>Principle 092: Talent Concentration Inversion — Talent Risk Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Talent that cannot be cross-trained becomes risk. Talent that cannot be retained becomes liability. Principle 092/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Talent Risk.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_093.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_093.png</image:loc>
      <image:title>Principle 093: Hiring-Pipeline Discipline — Hiring Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>A hiring pipeline is governance infrastructure. Underfund it and audit findings repeat. Principle 093/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Hiring.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_094.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_094.png</image:loc>
      <image:title>Principle 094: Skills-Currency Mandate — Skills Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Skills lapse faster than certifications. Audit currency, not credentials. Principle 094/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Skills.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_095.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_095.png</image:loc>
      <image:title>Principle 095: Doctrine-Author Continuity — Doctrine Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Doctrine that depends on its author ends with its author. Codify or expect collapse. Principle 095/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Doctrine.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_096.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_096.png</image:loc>
      <image:title>Principle 096: Knowledge-Capture Discipline — Knowledge Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Tribal knowledge is a fault line. Convert it to doctrine before the senior leaver takes production with them. Principle 096/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Knowledge.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_097.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_097.png</image:loc>
      <image:title>Principle 097: Board-Reporting Honesty — Board Reporting Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Board reports that omit what went wrong are confidence trades. Eventually one fails. Principle 097/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Board Reporting.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_098.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_098.png</image:loc>
      <image:title>Principle 098: Materiality Calibration — Materiality Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Materiality is decided by the board before the incident — or by the regulator after. Principle 098/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Materiality.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_099.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_099.png</image:loc>
      <image:title>Principle 099: Disclosure-Timing Discipline — Disclosure Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Disclosure timing is a board-level decision. Push it down and it will land on the news cycle. Principle 099/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Disclosure.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_100.html</loc>
    <lastmod>2026-05-19</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_100.png</image:loc>
      <image:title>Principle 100: Doctrine Closing Principle — Institutional Architecture Doctrine Card by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>A doctrine that survives twenty years and three regulators is no longer doctrine. It is institutional architecture. Principle 100/100 from 100 Cyber Doctrine Principles by Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University. Institutional Architecture.</image:caption>
    </image:image>
  </url>




<!-- KIE-IMAGE-SITEMAP-101-200-START -->
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_101.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_101.png</image:loc>
      <image:title>Principle 101: Doctrine Closing Principle | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 101: Doctrine Closing Principle — Institutional Architecture doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_102.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_102.png</image:loc>
      <image:title>Principle 102: Algorithmic Liability Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 102: Algorithmic Liability Doctrine™ — AI Liability doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_103.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_103.png</image:loc>
      <image:title>Principle 103: Invisible Breach Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 103: Invisible Breach Doctrine™ — Shadow AI doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_104.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_104.png</image:loc>
      <image:title>Principle 104: AI Act Horizon Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 104: AI Act Horizon Doctrine™ — AI Act doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_105.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_105.png</image:loc>
      <image:title>Principle 105: Silent Drift Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 105: Silent Drift Doctrine™ — Model Drift doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_106.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_106.png</image:loc>
      <image:title>Principle 106: Upstream Threat Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 106: Upstream Threat Doctrine™ — Upstream Data doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_107.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_107.png</image:loc>
      <image:title>Principle 107: Semantic Firewall Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 107: Semantic Firewall Doctrine™ — Prompt Injection doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_108.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_108.png</image:loc>
      <image:title>Principle 108: Machine Decision Evidence™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 108: Machine Decision Evidence™ — AI Evidence doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_109.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_109.png</image:loc>
      <image:title>Principle 109: Intimate Data Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 109: Intimate Data Doctrine™ — Biometrics doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_110.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_110.png</image:loc>
      <image:title>Principle 110: Unguided Weapon Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 110: Unguided Weapon Doctrine™ — Autonomous Systems doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_111.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_111.png</image:loc>
      <image:title>Principle 111: Sentient Inventory Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 111: Sentient Inventory Doctrine™ — Algorithm Inventory doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_112.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_112.png</image:loc>
      <image:title>Principle 112: Negligence Trap Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 112: Negligence Trap Doctrine™ — Board Liability doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_113.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_113.png</image:loc>
      <image:title>Principle 113: Reporting Line Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 113: Reporting Line Doctrine™ — CISO Reporting doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_114.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_114.png</image:loc>
      <image:title>Principle 114: Asymmetric Warfare Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 114: Asymmetric Warfare Doctrine™ — Cyber Budget doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_115.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_115.png</image:loc>
      <image:title>Principle 115: Tolerable Threshold Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 115: Tolerable Threshold Doctrine™ — Risk Appetite doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_116.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_116.png</image:loc>
      <image:title>Principle 116: Compliance Illusion Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 116: Compliance Illusion Doctrine™ — Compliance Ceiling doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_117.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_117.png</image:loc>
      <image:title>Principle 117: Digital Asset Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 117: Digital Asset Doctrine™ — Balance Sheet doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_118.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_118.png</image:loc>
      <image:title>Principle 118: Actionable Signal Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 118: Actionable Signal Doctrine™ — Metric Discipline doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_119.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_119.png</image:loc>
      <image:title>Principle 119: False Comfort Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 119: False Comfort Doctrine™ — Cyber Insurance doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_120.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_120.png</image:loc>
      <image:title>Principle 120: Reality Check Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 120: Reality Check Doctrine™ — Crisis Simulation doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_121.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_121.png</image:loc>
      <image:title>Principle 121: Canary Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 121: Canary Doctrine™ — Safe Reporting doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_122.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_122.png</image:loc>
      <image:title>Principle 122: Hidden Chain Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 122: Hidden Chain Doctrine™ — Supply Chain doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_123.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_123.png</image:loc>
      <image:title>Principle 123: Single-Point Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 123: Single-Point Doctrine™ — Cloud Concentration doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_124.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_124.png</image:loc>
      <image:title>Principle 124: Right-to-Audit Reality™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 124: Right-to-Audit Reality™ — Audit Rights doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_125.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_125.png</image:loc>
      <image:title>Principle 125: Trojan Horse Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 125: Trojan Horse Doctrine™ — Vendor Onboarding doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_126.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_126.png</image:loc>
      <image:title>Principle 126: Unpaid Maintainer Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 126: Unpaid Maintainer Doctrine™ — Open-Source Stewardship doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_127.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_127.png</image:loc>
      <image:title>Principle 127: Data Fragmentation Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 127: Data Fragmentation Doctrine™ — SaaS Sprawl doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_128.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_128.png</image:loc>
      <image:title>Principle 128: Forgotten Door Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 128: Forgotten Door Doctrine™ — API Perimeter doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_129.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_129.png</image:loc>
      <image:title>Principle 129: Cascading Impact Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 129: Cascading Impact Doctrine™ — Vendor Ransomware doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_130.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_130.png</image:loc>
      <image:title>Principle 130: Continuity Illusion Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 130: Continuity Illusion Doctrine™ — Source Escrow doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_131.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_131.png</image:loc>
      <image:title>Principle 131: Lingering Ghost Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 131: Lingering Ghost Doctrine™ — Vendor Offboarding doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_132.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_132.png</image:loc>
      <image:title>Principle 132: Resilience Shift Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 132: Resilience Shift Doctrine™ — DORA doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_133.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_133.png</image:loc>
      <image:title>Principle 133: Essential Entity Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 133: Essential Entity Doctrine™ — NIS2 Essential doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_134.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_134.png</image:loc>
      <image:title>Principle 134: 24-Hour Squeeze Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 134: 24-Hour Squeeze Doctrine™ — Notification Window doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_135.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_135.png</image:loc>
      <image:title>Principle 135: Sovereign Perimeter Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 135: Sovereign Perimeter Doctrine™ — Data Sovereignty doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_136.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_136.png</image:loc>
      <image:title>Principle 136: Cryptographic Proof Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 136: Cryptographic Proof Doctrine™ — Evidence Chain doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_137.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_137.png</image:loc>
      <image:title>Principle 137: Revenue Impact Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 137: Revenue Impact Doctrine™ — Revenue Fine doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_138.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_138.png</image:loc>
      <image:title>Principle 138: Personal Exposure Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 138: Personal Exposure Doctrine™ — Executive Liability doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_139.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_139.png</image:loc>
      <image:title>Principle 139: First-Hour Classification™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 139: First-Hour Classification™ — Incident Classification doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_140.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_140.png</image:loc>
      <image:title>Principle 140: Interlocking Rules Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 140: Interlocking Rules Doctrine™ — Regulatory Coherence doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_141.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_141.png</image:loc>
      <image:title>Principle 141: Strictest-Regime Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 141: Strictest-Regime Doctrine™ — Strictest Regime doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_142.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_142.png</image:loc>
      <image:title>Principle 142: Baseline Survival Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 142: Baseline Survival Doctrine™ — Recoverability doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_143.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_143.png</image:loc>
      <image:title>Principle 143: Last-Line Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 143: Last-Line Doctrine™ — Backup Isolation doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_144.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_144.png</image:loc>
      <image:title>Principle 144: Scorched-Earth Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 144: Scorched-Earth Doctrine™ — Destructive Attack doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_145.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_145.png</image:loc>
      <image:title>Principle 145: Operational Truth Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 145: Operational Truth Doctrine™ — Recovery Testing doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_146.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_146.png</image:loc>
      <image:title>Principle 146: Physical Chasm Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 146: Physical Chasm Doctrine™ — True Air Gap doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_147.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_147.png</image:loc>
      <image:title>Principle 147: Monday-Morning Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 147: Monday-Morning Doctrine™ — Failover Truth doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_148.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_148.png</image:loc>
      <image:title>Principle 148: Graceful Degradation Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 148: Graceful Degradation Doctrine™ — Graceful Failure doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_149.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_149.png</image:loc>
      <image:title>Principle 149: Mirrored Flaw Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 149: Mirrored Flaw Doctrine™ — Mirrored Production doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_150.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_150.png</image:loc>
      <image:title>Principle 150: Unknown Dependency Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 150: Unknown Dependency Doctrine™ — Dependency Mapping doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_151.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_151.png</image:loc>
      <image:title>Principle 151: Unreachable Archive Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 151: Unreachable Archive Doctrine™ — Cyber Vault doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_152.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_152.png</image:loc>
      <image:title>Principle 152: Default Stance Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 152: Default Stance Doctrine™ — Zero Trust Default doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_153.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_153.png</image:loc>
      <image:title>Principle 153: Shifting Boundary Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 153: Shifting Boundary Doctrine™ — Perimeter Identity doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_154.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_154.png</image:loc>
      <image:title>Principle 154: Human Limit Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 154: Human Limit Doctrine™ — MFA Fatigue doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_155.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_155.png</image:loc>
      <image:title>Principle 155: Silent Majority Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 155: Silent Majority Doctrine™ — Non-Human Identity doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_156.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_156.png</image:loc>
      <image:title>Principle 156: Janitor's Keys Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 156: Janitor's Keys Doctrine™ — Lateral Movement doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_157.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_157.png</image:loc>
      <image:title>Principle 157: Active Session Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 157: Active Session Doctrine™ — Continuous Auth doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_158.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_158.png</image:loc>
      <image:title>Principle 158: Orphaned Access Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 158: Orphaned Access Doctrine™ — Leaver Process doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_159.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_159.png</image:loc>
      <image:title>Principle 159: Ephemeral Key Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 159: Ephemeral Key Doctrine™ — JIT Privilege doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_160.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_160.png</image:loc>
      <image:title>Principle 160: Deepfake Threat Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 160: Deepfake Threat Doctrine™ — Biometric Spoof doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_161.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_161.png</image:loc>
      <image:title>Principle 161: Phishing-Starvation Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 161: Phishing-Starvation Doctrine™ — Passwordless doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_162.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_162.png</image:loc>
      <image:title>Principle 162: Fog-of-War Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 162: Fog-of-War Doctrine™ — First Hour doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_163.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_163.png</image:loc>
      <image:title>Principle 163: Secure Channel Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 163: Secure Channel Doctrine™ — Out-of-Band Comms doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_164.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_164.png</image:loc>
      <image:title>Principle 164: Truth Deficit Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 164: Truth Deficit Doctrine™ — Denial Discipline doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_165.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_165.png</image:loc>
      <image:title>Principle 165: Morality Play Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 165: Morality Play Doctrine™ — Ransom Ethics doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_166.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_166.png</image:loc>
      <image:title>Principle 166: Silent Partner Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 166: Silent Partner Doctrine™ — LE Coordination doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_167.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_167.png</image:loc>
      <image:title>Principle 167: Contaminated Scene Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 167: Contaminated Scene Doctrine™ — Forensic Integrity doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_168.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_168.png</image:loc>
      <image:title>Principle 168: Double-Edged Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 168: Double-Edged Doctrine™ — Legal Privilege doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_169.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_169.png</image:loc>
      <image:title>Principle 169: Double-Dip Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 169: Double-Dip Doctrine™ — Exfil Recovery doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_170.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_170.png</image:loc>
      <image:title>Principle 170: Victim-Blaming Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 170: Victim-Blaming Doctrine™ — Post-Breach doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_171.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_171.png</image:loc>
      <image:title>Principle 171: True-Cost Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 171: True-Cost Doctrine™ — Lessons Learned doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_172.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_172.png</image:loc>
      <image:title>Principle 172: Global Exposure Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 172: Global Exposure Doctrine™ — Cloud Exposure doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_173.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_173.png</image:loc>
      <image:title>Principle 173: Amplified Risk Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 173: Amplified Risk Doctrine™ — Multi-Cloud Risk doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_174.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_174.png</image:loc>
      <image:title>Principle 174: Data Border Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 174: Data Border Doctrine™ — Geopolitical Data doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_175.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_175.png</image:loc>
      <image:title>Principle 175: Air-Gap Myth Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 175: Air-Gap Myth Doctrine™ — OT/IT Convergence doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_176.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_176.png</image:loc>
      <image:title>Principle 176: Technical Debt Bomb™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 176: Technical Debt Bomb™ — Legacy Systems doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_177.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_177.png</image:loc>
      <image:title>Principle 177: Scalable Flaw Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 177: Scalable Flaw Doctrine™ — IaC Misconfig doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_178.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_178.png</image:loc>
      <image:title>Principle 178: Untethered Device Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 178: Untethered Device Doctrine™ — Edge Device doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_179.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_179.png</image:loc>
      <image:title>Principle 179: Hidden Payload Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 179: Hidden Payload Doctrine™ — Container Supply doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_180.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_180.png</image:loc>
      <image:title>Principle 180: Silent Drain Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 180: Silent Drain Doctrine™ — Cryptojacking doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_181.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_181.png</image:loc>
      <image:title>Principle 181: Abdication Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 181: Abdication Doctrine™ — Shared Responsibility doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_182.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_182.png</image:loc>
      <image:title>Principle 182: Harvest-Now Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 182: Harvest-Now Doctrine™ — PQC Harvest doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_183.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_183.png</image:loc>
      <image:title>Principle 183: Seamless Swap Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 183: Seamless Swap Doctrine™ — Crypto Agility doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_184.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_184.png</image:loc>
      <image:title>Principle 184: Digital Trust Rebuild™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 184: Digital Trust Rebuild™ — PQC Rebuild doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_185.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_185.png</image:loc>
      <image:title>Principle 185: Market Manipulation Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 185: Market Manipulation Doctrine™ — Deepfake Markets doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_186.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_186.png</image:loc>
      <image:title>Principle 186: Orbital Attack Surface™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 186: Orbital Attack Surface™ — Space Systems doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_187.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_187.png</image:loc>
      <image:title>Principle 187: Drone-Strike Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 187: Drone-Strike Doctrine™ — AI Defence doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_188.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_188.png</image:loc>
      <image:title>Principle 188: Silicon Threat Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 188: Silicon Threat Doctrine™ — Hardware Trust doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_189.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_189.png</image:loc>
      <image:title>Principle 189: Perpetual Zero-Day Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 189: Perpetual Zero-Day Doctrine™ — Unpatched Known doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_190.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_190.png</image:loc>
      <image:title>Principle 190: Unchangeable Secret Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 190: Unchangeable Secret Doctrine™ — Biometric Irrevocable doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_191.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_191.png</image:loc>
      <image:title>Principle 191: Aging Standard Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 191: Aging Standard Doctrine™ — Deprecated Protocols doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_192.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_192.png</image:loc>
      <image:title>Principle 192: Value-at-Risk Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 192: Value-at-Risk Doctrine™ — Risk Quantification doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_193.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_193.png</image:loc>
      <image:title>Principle 193: Security Poverty Line Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 193: Security Poverty Line Doctrine™ — SMB Supply Chain doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_194.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_194.png</image:loc>
      <image:title>Principle 194: Umbrella-in-Hurricane Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 194: Umbrella-in-Hurricane Doctrine™ — War Exclusion doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_195.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_195.png</image:loc>
      <image:title>Principle 195: Invisible Return Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 195: Invisible Return Doctrine™ — Cyber ROI doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_196.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_196.png</image:loc>
      <image:title>Principle 196: First-Line Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 196: First-Line Doctrine™ — Secure by Design doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_197.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_197.png</image:loc>
      <image:title>Principle 197: Free-Market Vulnerability™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 197: Free-Market Vulnerability™ — Bug Bounty doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_198.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_198.png</image:loc>
      <image:title>Principle 198: Burnout Factor Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 198: Burnout Factor Doctrine™ — Analyst Burnout doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_199.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_199.png</image:loc>
      <image:title>Principle 199: Zero-Day Economy Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 199: Zero-Day Economy Doctrine™ — Zero-Day Economy doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_200.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_200.png</image:loc>
      <image:title>Principle 200: Attacker Advantage Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 200: Attacker Advantage Doctrine™ — Defender Economics doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
<!-- KIE-IMAGE-SITEMAP-101-200-END -->
<!-- KIE-IMAGE-SITEMAP-201-300-START -->
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_201.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_201.png</image:loc>
      <image:title>Principle 201: Final Doctrine™ | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 201: Final Doctrine™ — Institutional Architecture doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_202.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_202.png</image:loc>
      <image:title>Principle 202: Sovereign Stack Defensibility | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 202: Sovereign Stack Defensibility — Sovereign Tech doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_203.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_203.png</image:loc>
      <image:title>Principle 203: Reachability Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 203: Reachability Doctrine — Sovereign Tech doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_204.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_204.png</image:loc>
      <image:title>Principle 204: Export-Control Surface | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 204: Export-Control Surface — Geopolitics doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_205.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_205.png</image:loc>
      <image:title>Principle 205: Coercion Cartography | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 205: Coercion Cartography — Geopolitics doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_206.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_206.png</image:loc>
      <image:title>Principle 206: Secondary-Sanctions Posture | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 206: Secondary-Sanctions Posture — Sanctions doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_207.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_207.png</image:loc>
      <image:title>Principle 207: GPAI Tier Discipline | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 207: GPAI Tier Discipline — AI Act Enforcement doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_208.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_208.png</image:loc>
      <image:title>Principle 208: Substantial Modification Threshold | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 208: Substantial Modification Threshold — AI Act Enforcement doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_209.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_209.png</image:loc>
      <image:title>Principle 209: Agent Autonomy Ceiling | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 209: Agent Autonomy Ceiling — Agentic AI Control doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_210.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_210.png</image:loc>
      <image:title>Principle 210: Model Recall Discipline | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 210: Model Recall Discipline — AI Incident Response doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_211.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_211.png</image:loc>
      <image:title>Principle 211: Right to Human Review | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 211: Right to Human Review — AI Redress doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_212.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_212.png</image:loc>
      <image:title>Principle 212: Provenance-or-Penalty Principle | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 212: Provenance-or-Penalty Principle — AI Training Data doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_213.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_213.png</image:loc>
      <image:title>Principle 213: Vector Database Trust Boundary | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 213: Vector Database Trust Boundary — AI Supply Chain doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_214.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_214.png</image:loc>
      <image:title>Principle 214: Eval-as-Control | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 214: Eval-as-Control — AI Evaluation doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_215.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_215.png</image:loc>
      <image:title>Principle 215: BYOAI Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 215: BYOAI Doctrine — Shadow AI doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_216.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_216.png</image:loc>
      <image:title>Principle 216: Prompt-as-Exfiltration-Surface | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 216: Prompt-as-Exfiltration-Surface — GenAI Leakage doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_217.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_217.png</image:loc>
      <image:title>Principle 217: Authentic-or-Accountable Principle | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 217: Authentic-or-Accountable Principle — AI Watermarking doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_218.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_218.png</image:loc>
      <image:title>Principle 218: Harvest-Now Decrypt-Later Inventory | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 218: Harvest-Now Decrypt-Later Inventory — Post-Quantum Migration doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_219.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_219.png</image:loc>
      <image:title>Principle 219: Cipher-Suite Reversibility Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 219: Cipher-Suite Reversibility Doctrine — Cryptographic Agility doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_220.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_220.png</image:loc>
      <image:title>Principle 220: Hybrid-Mode Inheritance | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 220: Hybrid-Mode Inheritance — PQC Suppliers doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_221.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_221.png</image:loc>
      <image:title>Principle 221: Service-Account Sprawl | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 221: Service-Account Sprawl — Non-Human Identity doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_222.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_222.png</image:loc>
      <image:title>Principle 222: Trust-Federation Blast Radius | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 222: Trust-Federation Blast Radius — Identity Federation doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_223.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_223.png</image:loc>
      <image:title>Principle 223: Token-Theft Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 223: Token-Theft Doctrine — Session Hijack doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_224.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_224.png</image:loc>
      <image:title>Principle 224: Standing-Privilege Abolition | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 224: Standing-Privilege Abolition — JIT Access doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_225.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_225.png</image:loc>
      <image:title>Principle 225: Concentration-of-Common-Mode | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 225: Concentration-of-Common-Mode — Cascading Failure doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_226.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_226.png</image:loc>
      <image:title>Principle 226: Active-Active Authority | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 226: Active-Active Authority — Multi-Region doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_227.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_227.png</image:loc>
      <image:title>Principle 227: Manual-Operating-Mode Continuity | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 227: Manual-Operating-Mode Continuity — Cyber-Physical doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_228.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_228.png</image:loc>
      <image:title>Principle 228: Validated-Recovery Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 228: Validated-Recovery Doctrine — RTO/RPO Discipline doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_229.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_229.png</image:loc>
      <image:title>Principle 229: Production-Chaos Mandate | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 229: Production-Chaos Mandate — Chaos Engineering doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_230.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_230.png</image:loc>
      <image:title>Principle 230: RPKI Hygiene | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 230: RPKI Hygiene — BGP Resilience doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_231.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_231.png</image:loc>
      <image:title>Principle 231: DNS Single-Provider Risk | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 231: DNS Single-Provider Risk — DNS Resilience doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_232.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_232.png</image:loc>
      <image:title>Principle 232: Attack-Cost Asymmetry | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 232: Attack-Cost Asymmetry — DDoS Economics doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_233.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_233.png</image:loc>
      <image:title>Principle 233: Fourth-Party Concentration | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 233: Fourth-Party Concentration — Nth-Party Risk doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_234.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_234.png</image:loc>
      <image:title>Principle 234: Runtime SBOM Reconciliation | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 234: Runtime SBOM Reconciliation — SBOM Runtime doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_235.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_235.png</image:loc>
      <image:title>Principle 235: Maintainer-of-One Risk | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 235: Maintainer-of-One Risk — Open-Source Stewardship doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_236.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_236.png</image:loc>
      <image:title>Principle 236: Acquisition-Risk Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 236: Acquisition-Risk Doctrine — Vendor Acquisition doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_237.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_237.png</image:loc>
      <image:title>Principle 237: M&A Diligence Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 237: M&A Diligence Doctrine — Cyber Due Diligence doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_238.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_238.png</image:loc>
      <image:title>Principle 238: Indemnity-Sized Findings | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 238: Indemnity-Sized Findings — Closing Conditions doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_239.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_239.png</image:loc>
      <image:title>Principle 239: 100-Day Cyber Integration | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 239: 100-Day Cyber Integration — Integration Window doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_240.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_240.png</image:loc>
      <image:title>Principle 240: Clean-Carve Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 240: Clean-Carve Doctrine — Divestiture doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_241.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_241.png</image:loc>
      <image:title>Principle 241: Syndicate Drift Risk | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 241: Syndicate Drift Risk — Insurance Syndicate doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_242.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_242.png</image:loc>
      <image:title>Principle 242: Subrogation-Anticipation Drafting | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 242: Subrogation-Anticipation Drafting — Subrogation doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_243.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_243.png</image:loc>
      <image:title>Principle 243: Carrier-Mandated Control Set | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 243: Carrier-Mandated Control Set — Insurer Leverage doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_244.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_244.png</image:loc>
      <image:title>Principle 244: Form 8-K Materiality | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 244: Form 8-K Materiality — SEC Rule doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_245.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_245.png</image:loc>
      <image:title>Principle 245: Director Liability Discipline | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 245: Director Liability Discipline — NIS2 Liability doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_246.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_246.png</image:loc>
      <image:title>Principle 246: Cross-Regulator Triage | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 246: Cross-Regulator Triage — Regulator Coordination doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_247.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_247.png</image:loc>
      <image:title>Principle 247: Press-Release-as-Disclosure | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 247: Press-Release-as-Disclosure — Crisis Comms doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_248.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_248.png</image:loc>
      <image:title>Principle 248: Material Cyber Loss Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 248: Material Cyber Loss Doctrine — Investor Relations doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_249.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_249.png</image:loc>
      <image:title>Principle 249: Cyber-Literate Board Discipline | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 249: Cyber-Literate Board Discipline — Board Fluency doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_250.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_250.png</image:loc>
      <image:title>Principle 250: Risk-Committee Charter Update | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 250: Risk-Committee Charter Update — Committee Charter doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_251.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_251.png</image:loc>
      <image:title>Principle 251: Three-Lines Coherence | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 251: Three-Lines Coherence — Three Lines doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_252.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_252.png</image:loc>
      <image:title>Principle 252: C-Suite Crisis Rehearsal | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 252: C-Suite Crisis Rehearsal — Tabletop Discipline doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_253.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_253.png</image:loc>
      <image:title>Principle 253: Audit-Fatigue Reduction | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 253: Audit-Fatigue Reduction — Control Fatigue doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_254.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_254.png</image:loc>
      <image:title>Principle 254: Evidence-Cost Ratio | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 254: Evidence-Cost Ratio — Evidence Economics doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_255.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_255.png</image:loc>
      <image:title>Principle 255: Attestation-as-Code | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 255: Attestation-as-Code — Continuous Attestation doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_256.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_256.png</image:loc>
      <image:title>Principle 256: Security-Debt Amortisation | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 256: Security-Debt Amortisation — Security Debt doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_257.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_257.png</image:loc>
      <image:title>Principle 257: Detection-as-Code | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 257: Detection-as-Code — Detection Engineering doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_258.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_258.png</image:loc>
      <image:title>Principle 258: Log-Retention Discipline | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 258: Log-Retention Discipline — Telemetry Economics doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_259.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_259.png</image:loc>
      <image:title>Principle 259: Observability-as-Witness | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 259: Observability-as-Witness — Observability Trust doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_260.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_260.png</image:loc>
      <image:title>Principle 260: Detection-to-Containment Gap | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 260: Detection-to-Containment Gap — MTTR Honesty doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_261.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_261.png</image:loc>
      <image:title>Principle 261: Immutability-or-Insolvency | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 261: Immutability-or-Insolvency — Immutable Backups doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_262.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_262.png</image:loc>
      <image:title>Principle 262: Restore-Rehearsal Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 262: Restore-Rehearsal Doctrine — Tested Restore doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_263.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_263.png</image:loc>
      <image:title>Principle 263: Integrity-as-the-First-CIA | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 263: Integrity-as-the-First-CIA — Data Integrity doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_264.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_264.png</image:loc>
      <image:title>Principle 264: Concentration-Risk in Hiring | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 264: Concentration-Risk in Hiring — Cyber Talent Market doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_265.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_265.png</image:loc>
      <image:title>Principle 265: Operator Sustainability | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 265: Operator Sustainability — Burnout Doctrine doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_266.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_266.png</image:loc>
      <image:title>Principle 266: Distributed Security Function | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 266: Distributed Security Function — Security Champions doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_267.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_267.png</image:loc>
      <image:title>Principle 267: Departure-Risk Window | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 267: Departure-Risk Window — Insider Risk doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_268.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_268.png</image:loc>
      <image:title>Principle 268: Whistleblower-Friendly Reporting | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 268: Whistleblower-Friendly Reporting — Whistleblower doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_269.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_269.png</image:loc>
      <image:title>Principle 269: Designated-Entity Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 269: Designated-Entity Doctrine — Critical Infrastructure doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_270.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_270.png</image:loc>
      <image:title>Principle 270: Clinical Continuity Threshold | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 270: Clinical Continuity Threshold — Healthcare doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_271.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_271.png</image:loc>
      <image:title>Principle 271: Impact-Tolerance Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 271: Impact-Tolerance Doctrine — FS Operational Resilience doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_272.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_272.png</image:loc>
      <image:title>Principle 272: Smart-Building Attack Surface | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 272: Smart-Building Attack Surface — Real Estate Cyber doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_273.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_273.png</image:loc>
      <image:title>Principle 273: Citizen-Trust Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 273: Citizen-Trust Doctrine — Public Sector doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_274.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_274.png</image:loc>
      <image:title>Principle 274: Cost-to-Attacker Modelling | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 274: Cost-to-Attacker Modelling — Adversary Economics doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_275.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_275.png</image:loc>
      <image:title>Principle 275: Pay-or-Not Decision Architecture | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 275: Pay-or-Not Decision Architecture — Ransomware Economics doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_276.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_276.png</image:loc>
      <image:title>Principle 276: Triple-Extortion Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 276: Triple-Extortion Doctrine — Multi-Stage Extortion doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_277.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_277.png</image:loc>
      <image:title>Principle 277: Carve-Out Discipline | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 277: Carve-Out Discipline — Liability doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_278.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_278.png</image:loc>
      <image:title>Principle 278: Live-Audit-Rights Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 278: Live-Audit-Rights Doctrine — Audit Rights doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_279.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_279.png</image:loc>
      <image:title>Principle 279: Sub-Processor Veto | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 279: Sub-Processor Veto — Data Processing doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_280.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_280.png</image:loc>
      <image:title>Principle 280: Annex-as-Architecture | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 280: Annex-as-Architecture — MSA Cyber Annex doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_281.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_281.png</image:loc>
      <image:title>Principle 281: Cyber-Force-Majeure Reckoning | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 281: Cyber-Force-Majeure Reckoning — Force Majeure doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_282.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_282.png</image:loc>
      <image:title>Principle 282: External-Attack-Surface Discipline | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 282: External-Attack-Surface Discipline — Attack Surface doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_283.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_283.png</image:loc>
      <image:title>Principle 283: Tasked Intelligence Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 283: Tasked Intelligence Doctrine — Threat Intel Tasking doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_284.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_284.png</image:loc>
      <image:title>Principle 284: Adversary-Emulation Rhythm | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 284: Adversary-Emulation Rhythm — Red Team doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_285.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_285.png</image:loc>
      <image:title>Principle 285: Continuous-Validation Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 285: Continuous-Validation Doctrine — Breach Simulation doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_286.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_286.png</image:loc>
      <image:title>Principle 286: Collection-as-Liability | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 286: Collection-as-Liability — Data Minimisation doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_287.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_287.png</image:loc>
      <image:title>Principle 287: Egress-Tax Discipline | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 287: Egress-Tax Discipline — Cross-Border Egress doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_288.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_288.png</image:loc>
      <image:title>Principle 288: Granular-Consent Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 288: Granular-Consent Doctrine — Consent Architecture doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_289.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_289.png</image:loc>
      <image:title>Principle 289: DSR-as-Operational-Discipline | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 289: DSR-as-Operational-Discipline — Data-Subject Rights doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_290.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_290.png</image:loc>
      <image:title>Principle 290: Egress-Lock-In Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 290: Egress-Lock-In Doctrine — Cloud Egress doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_291.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_291.png</image:loc>
      <image:title>Principle 291: Multi-Cloud-as-Insurance | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 291: Multi-Cloud-as-Insurance — Multi-Cloud doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_292.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_292.png</image:loc>
      <image:title>Principle 292: Infrastructure-as-Code-as-Evidence | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 292: Infrastructure-as-Code-as-Evidence — IaC Trust doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_293.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_293.png</image:loc>
      <image:title>Principle 293: Permission Drift Discipline | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 293: Permission Drift Discipline — Cloud IAM doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_294.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_294.png</image:loc>
      <image:title>Principle 294: Roadmap-Survivability | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 294: Roadmap-Survivability — Programme Conviction doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_295.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_295.png</image:loc>
      <image:title>Principle 295: FAIR-Aligned Risk Speech | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 295: FAIR-Aligned Risk Speech — Risk Quantification doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_296.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_296.png</image:loc>
      <image:title>Principle 296: Cost-of-Cyber-Curve | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 296: Cost-of-Cyber-Curve — Cyber Economics doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_297.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_297.png</image:loc>
      <image:title>Principle 297: Maturity-as-Marketing | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 297: Maturity-as-Marketing — Maturity Models doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_298.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_298.png</image:loc>
      <image:title>Principle 298: Irreversible-Action Doctrine | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 298: Irreversible-Action Doctrine — Irreversibility doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_299.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_299.png</image:loc>
      <image:title>Principle 299: Governance-Debt Reckoning | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 299: Governance-Debt Reckoning — Governance Debt doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://kieranupadrasta.com/principle-cards/principle_300.html</loc>
    <image:image>
      <image:loc>https://kieranupadrasta.com/principle-cards/principle_300.png</image:loc>
      <image:title>Principle 300: Doctrine-as-Continuity | Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University</image:title>
      <image:caption>Principle 300: Doctrine-as-Continuity — Institutional Memory doctrine. Professor Kieran Upadrasta, CISSP CISM CRISC, Schiphol University.</image:caption>
    </image:image>
  </url>
<!-- KIE-IMAGE-SITEMAP-201-300-END -->
</urlset>
