<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title/><link>https://sanaamironov.com/</link><atom:link href="https://sanaamironov.com/index.xml" rel="self" type="application/rss+xml"/><description/><generator>HugoBlox Kit (https://hugoblox.com)</generator><language>en</language><lastBuildDate>Mon, 24 Oct 2022 00:00:00 +0000</lastBuildDate><image><url>https://sanaamironov.com/media/sharing.png</url><title/><link>https://sanaamironov.com/</link></image><item><title>About</title><link>https://sanaamironov.com/about/</link><pubDate>Sun, 11 Oct 2026 00:00:00 +0000</pubDate><guid>https://sanaamironov.com/about/</guid><description/></item><item><title>Risk Management Framework for LLM-Enabled Identity Tools: Mapping OWASP LLM Top 10 to NIST CSF 2.0</title><link>https://sanaamironov.com/publications/serim-2026-llm-identity-risk/</link><pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate><guid>https://sanaamironov.com/publications/serim-2026-llm-identity-risk/</guid><description/></item><item><title>Building This Site</title><link>https://sanaamironov.com/blog/building-this-site/</link><pubDate>Wed, 27 May 2026 00:00:00 +0000</pubDate><guid>https://sanaamironov.com/blog/building-this-site/</guid><description>&lt;p&gt;This site is becoming a home for my research, engineering projects, technical writing, and publication materials.&lt;/p&gt;
&lt;p&gt;The goal is to make the work easier to browse than a folder of repositories or a static CV. Each project page can hold the context behind the work: what problem it addresses, what I built, what methods were used, and what artifacts are safe to share publicly.&lt;/p&gt;
&lt;p&gt;I plan to use the blog for shorter notes: research updates, implementation lessons, paper summaries, and reflections from ongoing projects.&lt;/p&gt;</description></item><item><title>LLM-Enabled IAM Risk Mapping</title><link>https://sanaamironov.com/projects/llm-iam-risk-mapping/</link><pubDate>Wed, 27 May 2026 00:00:00 +0000</pubDate><guid>https://sanaamironov.com/projects/llm-iam-risk-mapping/</guid><description>&lt;p&gt;This research project examines how LLM-enabled identity and access management tools introduce new risk patterns across common IAM workflows.&lt;/p&gt;
&lt;p&gt;The project uses the OWASP Top 10 for LLM Applications and NIST Cybersecurity Framework 2.0 as organizing lenses for analyzing use cases such as account recovery, MFA reset, access request triage, provisioning, deprovisioning, policy Q&amp;amp;A, and privileged-access handling.&lt;/p&gt;
&lt;p&gt;The repository includes manuscript materials, experiment artifacts, local-model testing notes, and reproducibility instructions.&lt;/p&gt;
&lt;p&gt;Key themes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Workflow-centered AI risk assessment&lt;/li&gt;
&lt;li&gt;Mapping LLM threat taxonomies to governance frameworks&lt;/li&gt;
&lt;li&gt;Local model testing with open-weight LLMs&lt;/li&gt;
&lt;li&gt;Reproducibility materials for research review&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Next site pass: add the final abstract, paper status, and selected figures.&lt;/p&gt;</description></item><item><title>Teaching Operating Systems with Linux</title><link>https://sanaamironov.com/blog/teaching-operating-systems-with-linux/</link><pubDate>Sun, 24 May 2026 00:00:00 +0000</pubDate><guid>https://sanaamironov.com/blog/teaching-operating-systems-with-linux/</guid><description>&lt;p&gt;Operating systems can feel abstract until students see how the pieces show up in a working environment. Linux gives students a concrete surface for exploring processes, memory, scheduling, filesystems, permissions, and system calls.&lt;/p&gt;
&lt;p&gt;I like teaching systems through workflows students can touch. A command-line trace, a small C program, or a broken permission setting can open a larger conversation about how the OS manages resources and enforces boundaries.&lt;/p&gt;
&lt;p&gt;The goal is not only to memorize concepts. It is to build the confidence to investigate what a system is doing and explain why.&lt;/p&gt;</description></item><item><title>AI Governance as Engineering Work</title><link>https://sanaamironov.com/blog/ai-governance-as-engineering-work/</link><pubDate>Sat, 23 May 2026 00:00:00 +0000</pubDate><guid>https://sanaamironov.com/blog/ai-governance-as-engineering-work/</guid><description>&lt;p&gt;AI governance is often described as policy, oversight, or compliance. Those pieces matter, but governance also has to become engineering work.&lt;/p&gt;
&lt;p&gt;A useful governance process should connect risks to artifacts: model behavior, data quality, system boundaries, logs, prompts, tests, permissions, and human review paths. Without those artifacts, governance becomes a document rather than an operating practice.&lt;/p&gt;
&lt;p&gt;My current interest is in risk mapping that gives teams practical ways to ask better questions: what could fail, what evidence would reveal it, and what controls can reduce the risk before deployment?&lt;/p&gt;</description></item><item><title>Mapping LLM Risks in Identity Workflows</title><link>https://sanaamironov.com/blog/llm-identity-risk-mapping/</link><pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate><guid>https://sanaamironov.com/blog/llm-identity-risk-mapping/</guid><description>&lt;p&gt;Identity workflows are sensitive because they connect people, permissions, access, and institutional trust. When LLMs enter those workflows, the risk surface changes.&lt;/p&gt;
&lt;p&gt;A useful risk mapping does more than list threats. It connects technical failure modes to security outcomes, governance responsibilities, and concrete controls. That is why frameworks such as OWASP LLM Top 10 and NIST CSF 2.0 are useful starting points.&lt;/p&gt;
&lt;p&gt;The goal is not to reject LLM-enabled tools. It is to understand where they can help, where they can fail, and what evidence teams need before trusting them in identity-related decisions.&lt;/p&gt;</description></item><item><title>Ethics Belongs in the Technical Classroom</title><link>https://sanaamironov.com/blog/ethical-issues-in-technology-classroom/</link><pubDate>Tue, 19 May 2026 00:00:00 +0000</pubDate><guid>https://sanaamironov.com/blog/ethical-issues-in-technology-classroom/</guid><description>&lt;p&gt;Ethics in technology is not separate from technical work. Design choices shape access, privacy, safety, power, labor, and accountability.&lt;/p&gt;
&lt;p&gt;In the classroom, I want students to practice ethical reasoning as part of technical reasoning. What assumptions are built into a system? Who benefits? Who is exposed to risk? What evidence would change our mind?&lt;/p&gt;
&lt;p&gt;These questions are not distractions from engineering. They are part of building systems that work responsibly in the world.&lt;/p&gt;</description></item><item><title>Research Artifacts and Reproducibility</title><link>https://sanaamironov.com/blog/research-artifacts-and-reproducibility/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://sanaamironov.com/blog/research-artifacts-and-reproducibility/</guid><description>&lt;p&gt;A research result is easier to trust when the artifacts around it are clear. Code, data descriptions, experiments, logs, configuration, and limitations all help readers understand what was actually done.&lt;/p&gt;
&lt;p&gt;Reproducibility is not only about rerunning a script. It is about making the work inspectable. What inputs were used? What assumptions were made? Which results are stable, and which are sensitive to data or parameter choices?&lt;/p&gt;
&lt;p&gt;I want this website to become a place where projects can show that context instead of hiding it in private notes or scattered repositories.&lt;/p&gt;</description></item><item><title>What Trustworthy Computing Means to Me</title><link>https://sanaamironov.com/blog/what-trustworthy-computing-means-to-me/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://sanaamironov.com/blog/what-trustworthy-computing-means-to-me/</guid><description>&lt;p&gt;Trustworthy computing is not one property. It is a relationship between systems, evidence, people, and decisions.&lt;/p&gt;
&lt;p&gt;For me, the phrase connects several interests: operating systems that can provide evidence, data systems that can represent quality and provenance, AI tools that can be governed responsibly, and interfaces that help people understand when to trust a result.&lt;/p&gt;
&lt;p&gt;The common thread is accountability. A trustworthy system should not merely output an answer. It should help explain the conditions under which that answer should be believed.&lt;/p&gt;</description></item><item><title>Experience</title><link>https://sanaamironov.com/experience/</link><pubDate>Tue, 24 Oct 2023 00:00:00 +0000</pubDate><guid>https://sanaamironov.com/experience/</guid><description/></item></channel></rss>