By:
Lauren Edmonds
September 14th, 2015
Can I have disaster recovery controls within my SOC 1 test of controls matrix?
FedRAMP | Payment Card Assessments | Federal Assessments
By:
MATT WILGUS
July 9th, 2015
Overview In the last 30 days, the FedRAMP Program Management Office (PMO) has published guidance for both vulnerability scanning and penetration testing. The updated guidance comes on the heels of PCI mandating the enhanced penetration testing requirements within its requirement 11.3 as part of the 3.0, now 3.1, version of the DSS. These augmented PCI requirements, introduced in the fall of 2013, took effect on June 30th. For many cloud service providers this means the requirements for vulnerability scanning and penetration testing are more thorough and will require additional resources for planning, executing and remediating findings. This article will walk through the updates and discuss the differentiation between FedRAMP and the PCI Data Security Standard (DSS).
By:
DEBBIE ZALLER
June 15th, 2015
Is there a SOC certification similar to an ISO 27001 certification?
By:
RYAN MACKIE
February 12th, 2015
In the last 12 months, the Cloud Security Alliance (CSA) has made great strides in enhancing their CSA Security, Trust and Assurance Registry (STAR) Program. In brief, the STAR Program is a publicly available registry designed to recognize assurance requirements and maturity levels of cloud service providers (CSPs). Prior to issuing the guidance for STAR Certification and STAR Attestation, a CSP could only perform a self-assessment, which meant completing the Consensus Assessments Initiative questionnaire (CAIQ) and making the responses publicly available on the CSA Register. The CAIQ was completed in several different ways and the content varied from short answers to full-page responses. It was relevant information but not independently validated. This created a path for the STAR Certification and STAR Attestation Programs.
Payment Card Assessments | PCI DSS | TPRM
By:
Ken Van Allen
December 10th, 2014
The Payment Card Industry Data Security Standard (PCI DSS) is a global security framework designed to safeguard credit card information, protect sensitive authentication data, and minimize the risk of fraud. The PCI Security Standards Council (SSC) released a set of guidelines detailing how to manage third-party service provider (TPSP) relationships and PCI DSS compliance requirements. In this article, we break down everything you need to know about navigating PCI DSS TPSP requirements for PCI compliance.
By:
Jeff Schiess
November 24th, 2014
Organizations take different approaches when it comes to documenting their policies and procedures. Some prioritize keeping them well-documented and easily accessible to employees at all times. Others may only recognize their importance when planning and preparing for an audit as they conduct an extensive review of their existing documentation to determine if they meet audit guideline requirements. Meanwhile, there are companies that overlook or neglect the need for formal policies and procedure documentation altogether.
By:
ERIC SAMPSON
October 3rd, 2014
The media has been filled with stories of high profile credit card breaches, including those from Target, Neiman Marcus, P.F. Chang’s and most recently Home Depot. Details on the Home Depot breach are still emerging, but the details around the Target and Neiman Marcus breaches are well known and causing the public to ask if it will happen again?
By:
MIKE MEYER
August 25th, 2014
With proper design, implementation and maintenance, periodic user access reviews can be an effective tool for service organizations in achieving their security and compliance goals.