By:
Jon Coffelt
September 17th, 2024
When organizations opt to pursue a new compliance initiative, aside from cost and necessary resources, the first thought is usually regarding what to expect. That’s true for StateRAMP as well, and though many may—correctly—assume that there are some similarities between it and the more popular FedRAMP, there are several very clear deviations by the former from the latter that you know about going in.
Penetration Testing | Federal Assessments
By:
Christian Underkoffler
September 13th, 2024
The release of FedRAMP’s Revision 5 has raised many questions, including those regarding the addition of a red team exercise requirement for those seeking FedRAMP authorization. As the #1 provider of FedRAMP assessments on the Marketplace who have extensive experience in offensive security, we have insight to offer.
By:
AVANI DESAI
September 12th, 2024
As cyber threats continue to grow more complex and difficult to defend against, regulatory cybersecurity requirements are becoming increasingly stringent—the Digital Operational Resilience Act (DORA) is the latest, and it demands your attention. The law comes into full effect in just a few short months—January 2025—and an independent assessment could help ensure you achieve full compliance in time.
By:
Schellman
September 10th, 2024
Maybe you’ve seen the recent headlines—recent ones include “AI’s Energy Demands Are Out Of Control” (Wired), “AI brings soaring emissions for Google and Microsoft” (NPR), “AI emissions are fueling a new doomerism. This time it’s climate change” (Fortune), and “Artificial Intelligence Can Make Companies Greener, but It Also Guzzles Energy” (Wall Street Journal). Given the abundance of such press, it certainly seems as if the growing prevalence of AI across all platforms has sparked some climate controversy.
ISO Certifications | SOC Examinations | SOC 2 | ISO 27001
By:
KRISTEN WILBUR
September 10th, 2024
As they’re now two of the most popular compliance initiatives in the world, many organizations often choose to pursue either SOC 2 or ISO 27001, and others are tackling both. In fact, there are strategic benefits to be gained in undergoing both a SOC 2 examination and achieving ISO 27001 certification, especially as you can do both at the same time.
Payment Card Assessments | PCI DSS
By:
PHIL DORCZUK
September 9th, 2024
Historically, PCI DSS has treated most service accounts as shared administrator accounts that had to be authorized with specific privileges using strong authentication factors. But now, version 4.0 of the PCI DSS has greatly expanded the scope of authentication and authorization requirements—while you’ll still need to secure those administrator accounts, you’ll now also need to implement controls to protect any application and service accounts in your environment.
By:
Josh Tomkiel
September 5th, 2024
For as long as the concept of cybersecurity has been around, much of the focus has centered on sophisticated technical controls—firewalls, password strength, network segmentation, endpoint protection, encryption, etc. And while implementation and regular testing of all these measures does better safeguard your organization, you also need to secure your people. In that, a social engineering campaign can help immensely.
By:
Tim Walsh
September 3rd, 2024
Looking back, December 2023 was a big month for the Department of Defense (DoD). Not only did they release the 32 CFR Part 170 - Cybersecurity Maturity Model Certification (CMMC) Proposed Rule, but they also published a memorandum titled Federal Risk and Authorization Management Program (FedRAMP) Moderate Equivalency for Cloud Service Provider’s (CSP) Cloud Service Offerings (CSOs). The latter, in a huge development, clarified requirements for CSOs that are currently (or will be) storing, processing, or transmitting Covered Defense Information (CDI)—more commonly referred to as Controlled Unclassified Information (CUI)—although there are some nuances that must be understood.