By:
Schellman
January 17th, 2024
As you may remember, when Tom Sawyer was asked to paint a fence, he ended up outsourcing the job and even got his chosen “vendors” to pay him for the privilege. What was an assigned chore ended up being done by others and turning a profit for Tom.
Assurance / Service Audits | Audit Readiness
By:
Robert Tylka
January 11th, 2024
In the dynamic world of business, where compliance is becoming more important either as requested assurance from customers or a key market differentiator, more and more organizations are turning to assessment firms to help them communicate these advantages. And while some will always look at compliance in the most oversimplified, checkbox manner, many customers and regulators recognize good (and poor) quality of delivery.
By:
Matthew Gierl
January 9th, 2024
ISO 22301 is structured much like other ISO management system standards, featuring introductory clauses (1–3) alongside its core requirement clauses (4–10). Of these, Clause 8 (Operation) is the linchpin of standing up a Business Continuity Management System (BCMS) and achieving ISO 22301 certification.
Cybersecurity Assessments | SchellmanLife
By:
Ryan Ratty
January 4th, 2024
Though perhaps not as prominent as the widely known Certified Information Systems Auditor (CISA) and Certified Information Systems Security Professional (CISSP) certifications, the Certificate of Cloud Security Knowledge (CCSK) can also be helpful to cybersecurity professionals.
SchellmanLife | Audit Readiness
By:
Megan Sajewski
January 2nd, 2024
Benjamin Franklin once said, “By failing to prepare, you are preparing to fail.”
By:
Clint Mueller
December 28th, 2023
If you’re a penetration tester, you know that for any test or phishing campaign, you begin with setting up your infrastructure with a domain name and redirectors. You might also know that this step is straightforward, and many have created walkthroughs on different ways to architect and automate infrastructure deployments.
By:
Todd Connor
December 19th, 2023
In the latest revision of documents pertinent to the ongoing CMMC countdown, NIST SP 800-171 R3 has been released. Though there were only a handful of changes in this new version, there were some significant ones regarding the assessment practices and their presentation that those monitoring the progress of CMMC should know.
By:
Chris Lippert
December 14th, 2023
Since the introduction of the new Data Privacy Framework (DPF) on July 17, 2023, many have begun familiarizing themselves with its seven principles as they ready themselves to comply. However, the DPF also features 16 supplemental principles, two of which—regarding self-certification and verification—also cover particularly important topics.