Compliance

penetration testing for SOC 2

Many people wonder: does an SSAE 18 SOC 2 assessment require a penetration test? The answer is a resounding “no.” That being said, there are many good reasons to conduct regular penetration testing. Coordinating that testing with other audit functions promotes economies of scale and may even help with responses to those audits. (NOTE: If …

Does SOC 2 Require a Penetration Test? Not Really. Read More »

SOC 2 type 1 vs type 2

Navigating the SOC audit process can be daunting. There are a few options for audits and while the standards are consistent among auditors, each auditor has their own unique style for conducting the audit. In this article, I’m going to break down the primary distinctions between a SOC 2 Type 1 vs Type 2 audit. …

SOC 2 Type 1 vs Type 2: How to Decide Which is Right Read More »

soc 2 readiness assessment

A SOC 2 readiness assessment, like other kinds of readiness assessments, highlights an organization’s ability to succeed in an assessment against a framework baseline. Readiness assessments are particularly helpful in driving cost savings for assessments, but take time and effort to conduct. In this article, I’ll outline what a SOC 2 readiness assessment is and …

Is a SOC 2 Readiness Assessment Worth It? Comparing Costs & Benefits Read More »

soc 2 certification costs

SOC 2 certifications are a must for many businesses in 2023 and a nice-to-have for many others. It’s become a defacto measure of economic and cybersecurity health because of the quality and extent of the review, and the easy snapshot it provides into organizational, financial, and cybersecurity health. Unfortunately, working out your organization’s potential SOC …

How Much SOC 2 Certification Costs Will Depend on 6 Factors Read More »

Chances are you found this page because you’re a small business owner who heard about PCI compliance. Maybe you were notified by a bank or payment processor that you need to be compliant, or you read somewhere that similar businesses to yours have had to be compliant. In either scenario, you probably weren’t expecting it, …

PCI Compliance for Small Business: How to Avoid Penalties Read More »

It’s common for companies with gaps in their PCI DSS compliance to wonder “How bad could it really be?” Knowing the possible extent of fines for non-compliance and being able to put dollar values on the risk, can help convince board members or executives to allocate the appropriate budget to your firm’s PCI compliance efforts. …

How Bad Can PCI Compliance Fines Get? This Bad Read More »

The worst healthcare data breaches of all time.

There have been a slew of healthcare organizations that have experienced data breaches over the past decade. Some of those are mundane: misprinted and mismailed information or a phone call to the incorrect recipient. However, as healthcare organizations become increasingly sophisticated and use more technology more often to support operations, errors or attacks against that …

The 10 Worst Healthcare Data Breaches of All Time (U.S) Read More »

HITRUST just released its 11th version of HITRUST cybersecurity framework or HITRUST CSF. One of the major changes in version 11 is the removal of the HITRUST bC assessment and its replacement with the new HITRUST e1. Let’s dive into some high-level information about what the HITRUST e1 assessment is, why an organization would pursue …

Understanding the New HITRUST e1 Essentials Certification Read More »

HIPAA Risk Assessment

A HIPAA Risk Assessment, or a HIPAA Security Risk Assessment more precisely, is a mandatory requirement for Covered Entities and Business Associates in their HIPAA Security Rule compliance journey. HIPAA Security Risk Assessments can be straightforward, but it’s critical to understand what to review, how, and against what frameworks. Let’s dive into what a HIPAA …

8 Steps to a Proper HIPAA Risk Assessment in 2023 Read More »

Network Assured on Facebook     Network Assured on Twitter
Copyright © 2022 Network Assured