Mike Somody is an ISO Senior Associate with Schellman. Prior to joining Schellman in 2022, Mike worked as a Senior, Business Consultant at a Big 4 Accounting firm, specializing in Technology Risk (SOX 404/ITGC compliance). Mike also led and supported various other projects, including SDLC Implementation Evaluations, Application Controls Testing, and other Internal and External IT audits. Mike additionally has experience with CSA STAR and TISAX assessments. Mike has over 6 years of experience comprised of serving clients in various industries, including Healthcare, Industrial Products, Consumer Goods, and Real Estate. Mike is now focused on ISO 27001, 9001, and 22301 certifications, as well as CSA STAR and TISAX reporting for organizations across various industries.
Cloud Computing | CSA STAR Program
By:
Mike Somody
February 16th, 2026
The Cloud Security Alliance (CSA) created the Security, Trust, Assurance, and Risk (STAR) program in August of 2011 to improve transparency and security within cloud computing. This program was built upon the Cloud Controls Matrix (CCM), a selection of cloud controls designed to secure cloud service providers and customers, and is mapped to major standards like ISO 27001.
Artificial Intelligence | ISO 42001
By:
Mike Somody
September 8th, 2025
Organizations are under increasing pressure to secure and govern their AI systems responsibly. Fortunately, industry frameworks are stepping in to help, including the Cloud Security Alliance (CSA) Artificial Intelligence Controls Matrix (AICM), which maps to the ISO 42001 standard for AI management systems. Together, these frameworks provide a powerful roadmap for aligning AI governance with established security and compliance practices.
By:
Mike Somody
April 3rd, 2025
A critical component of the ISO 27001 framework is the internal audit defined in Clause 9.2. The internal audit is designed to evaluate the effectiveness and compliance of your Information Security Management System (ISMS).