Posts

SOC 1, SOC 2, and SOC 3 Reports: Type 1, Type 2 or Readiness Assessment?

Image
  SOC reports are gaining in popularity across industries and across the globe. More and more customers are asking for demonstrated SOC compliance, and independent cybersecurity control validation and attestation are becoming necessary to compete for high-priority contracts. Beyond customer demand, SOC reports ensure that controls are properly implemented and used within your organization, greatly reducing potential security threats. For organizations seeking a SOC 1 , SOC 2 , or SOC 3 report, there are two attestation options available: Type 1 and Type 2. Additionally, a readiness assessment can be performed to prepare your organization for the attestation. With so many options, what type is best for your organization to prove compliance? Our experienced assessors break down the options so the path to compliance is clear between SOC 1, SOC 2 and SOC 3. We then dive into the various types of SOC reports: Type 1, Type 2 and a readiness assessment. SOC 1 Report A SOC 1 report foll...

How Does Going Remote Impact My ISO 27001 Certification?

Image
  Over the past two years, many businesses have moved to a hybrid or fully remote environment. While this has become a necessity for many, there are security risks to consider with taking a business remote. Organizations may lack visibility into the security of home networks and must be extra cautious with Bring-Your-Own-Device (BYOD) practices, which are just two examples of areas that require increased security needs. It’s no wonder that information security is top of mind for many leaders at organizations that have shifted to remote work. As such, it’s more important than ever to ensure you have an ISO 27001 certification that confirms your information security management practices are up to snuff and your company is able to protect important information and data. If you already received an ISO/IEC 27001:2013 certification, but recently made changes to the physical environment in which employees work, you may be wondering if you need to update that certification. The short ans...

Federal Compliance 2022: CMMC 2.0, StateRAMP, FedRAMP & Beyond

Image
  With the recent unveiling of CMMC 2.0, the expanded presence of StateRAMP, and new FedRAMP advisory guidelines for external servers, it’s safe to say that 2022 has a lot in store for Federal compliance changes. Tony Bai, A-LIGN’s Federal Practice Lead, and Emily Cummins, Anitian’s Director of Cloud Security, had a chance to sit down and discuss the latest news in federal compliance and what it could mean for your organization. Let’s dive in and get their thoughts on the latest CMMC 2.0 introduction, the new FedRAMP authorization boundary guidance, StateRAMP and more! CMMC 2.0Like everyone else in the world of federal compliance, A-LIGN and Anitian have been closely tracking the Cybersecurity Maturity Model Certification (CMMC) since the U.S. Department of Defense (DoD) shared its initial draft of the model in early 2020. With the release of CMMC 2.0 , three major changes were recently announced: fewer security tiers, removing some third-party assessment requirements, and allo...

HITRUST Assurance Advisory Adds Strategic Scoping Factors

Image
Even though compliance is an on-going process, each individual assessment has its own lifecycle, which begins with a self-assessment of scoping factors. This can be a tedious process to complete for every audit, especially if the same questions get asked more than once, or continue to show up in assessment requirements. Fortunately, HITRUST has introduced a strategic approach to its scoping factors, which it announced in its Assurance Advisory: 2020-003 . HITRUST made multiple changes to its scoping factors, streamlining the audit process by mapping scoping factor questions to assessment requirements – eliminating unrelated requirements. The scoping factor now includes additional context to questions to avoid the typical back-and-forth that could occur during QA of the assessment. This Assurance Advisory is set to minimize unrelated requirements when a scoping factor is marked “no” and to curtail the constant flow of “this is not applicable because…” responses currently captured in H...

How European Companies Can Best Market Compliance Programs

Is your organisation getting maximum value from its compliance program? Each compliance report or certification you possess is more than just a document — it’s an affirmation to your customers, prospects, and partners that your company understands the importance of cybersecurity and is fully capable of safeguarding sensitive information. To spread the word about the assessments that have been completed and what they actually mean, your organisation needs to identify and leverage all available opportunities to market your compliance program and drive new revenue into the business. Whereas companies in the U.S. — especially in the tech industry — can be quite enthusiastic about promoting their various certifications and achievements, organisations in Europe tend to be a bit more subdued when it comes to compliance marketing. Read on to explore the top tips you should be using to market your unique competitive advantage: compliance. Publish a Press Release The press release is a cornersto...

The A-LIGN Advantage: Unify Your Audit Experience

Image
  The emergence of automated security and compliance solutions still leaves organizations with a problem: these point solutions are unable to provide independent third-party certification. Preparation is a key component to a successful audit, but it is only the first step. A-LIGN is transforming how organizations demonstrate compliance by combining its compliance management platform, A‑SCEND, with its years of audit experience through a single-provider approach – from audit readiness to certification, across multiple security frameworks. An audit encompasses readiness, evidence collection, fieldwork, reporting, and certification. Investing into readiness software alone creates a “last mile” problem, meaning that an organization will still need to invest time and money into an additional service provider to complete its audit. There is a management adage that “a failure to plan is planning to fail,” but when a solution is only focused on preparation then an organization may experien...

HITRUST Assurance Advisory Adds Strategic Scoping Factors

Even though compliance is an on-going process, each individual assessment has its own lifecycle, which begins with a self-assessment of scoping factors. This can be a tedious process to complete for every audit, especially if the same questions get asked more than once, or continue to show up in assessment requirements. Fortunately, HITRUST has introduced a strategic approach to its scoping factors, which it announced in its Assurance Advisory: 2020-003. HITRUST made multiple changes to its scoping factors, streamlining the audit process by mapping scoping factor questions to assessment requirements – eliminating unrelated requirements. The scoping factor now includes additional context to questions to avoid the typical back-and-forth that could occur during QA of the assessment. This Assurance Advisory is set to minimize unrelated requirements when a scoping factor is marked “no” and to curtail the constant flow of “this is not applicable because…” responses currently captured in HIT...

Five Best Practices for Compliance Management

Image
As we enter the home stretch of 2021, many organizations are reflecting on this past year and synthesizing lessons learned to inform a more focused and effective business strategy moving forward. Our 2021 Compliance Benchmark Report provided significant insights on how organizations are navigating the current compliance landscape, as well as how they are preparing for the future. By surveying more than 200 cybersecurity, IT, quality assurance, internal audit, finance, and other professionals, we discovered a great deal about what makes compliance programs run smoothly and efficiently, and where there may be areas for improvement for businesses of all sizes and across all industries. Here are five compliance management best practices gleaned from the 2021 Compliance Benchmark Report that you can use to improve your organization’s compliance program. Best Practice #1: Combine Audits for Greater Efficiency One of the standout findings from our Compliance Benchmark Report was the revelat...

3 Compliance Factors Your European Business Should Consider

Image
In 2021, we saw an increase in international expansion and need for compliance certifications, and big changes in the privacy landscape. As we near the end of the year, European organisations should be thinking ahead to the compliance challenges and opportunities that are coming in 2022. It’s always best to be proactive in strategising for future regulations, standards, and policies — even if you feel your business is currently running with all systems fully operational. Here are a few of the changes, trends, and predictions in the world of European business that I believe will make a big difference throughout 2022. GDPR and the New Standard Contractual Clauses (SCCs) Last year’s court ruling that the EU–U.S. Privacy Shield framework is no longer a valid data transfer mechanism under the General Data Protection Regulation (GDPR) brought about new standard contractual clauses (SCCs), which were approved in June 2021. These were introduced to replace the old SCCs (last updated in 2010) ...

The Top Cybersecurity Trends for 2022

Image
When it comes to cybersecurity preparedness, it’s not about “if” but “when” an incident will occur. This illustrates an urgent need for organizations to increase cybersecurity awareness and education to better prepare themselves against an inevitable cybersecurity event. Here are the top three cybersecurity trends we think are worth watching as we approach 2022, and how you can prepare your organization to be ready for the possibility of these threats.  Ransomware Ransomware attacks have made headlines for well over a year at this point, even making an appearance as the lead storyline in various TV shows, for good reason. The ransomware global attack volume increased by 151% for the first six months of 2021 compared to the first six months of 2020. But what exactly is ransomware? Ransomware is a type of malware that encrypts files once inside an organization’s network. Doing so makes the files unusable, as well as the systems that rely on that information to run, enabling malicio...

What You Need to Know About the HIPAA Safe Harbor Act

Image
The HIPAA Safe Harbo r Act was designed to limit the fines associated with a data breach for healthcare organizations that implement “recognized security practices.” Do you have your cybersecurity practices in place? Learn more about how to identify what you need to mitigate risk. Organizations that take proactive steps to implement cybersecurity initiatives to protect their customers and employees are becoming more commonplace. Yet, there are still many examples of organizations falling victim to bad actors’ efforts to steal sensitive information for financial gain. This scenario has become a more common tale within the healthcare industry, especially as malicious players continue to take advantage of the COVID-19 pandemic. In fact, according to the Cybersecurity & Infrastructure Security Agency (CISA), personal health information (PHI) is estimated to be worth 10-20 times the value of credit card data on the dark web. Data breaches targeting PHI are clearly not going away, crea...

What Are the New HITRUST bC and i1 Assessments?

Image
  HITRUST certification just got quicker, more affordable, and less complex. Learn more about HITRUST i1 and why it could be a gamechanger for your organization. The HITRUST Alliance has announced the HITRUST Basic Current State (bC) Assessment and the HITRUST Implemented One-Year (i1) Assessment, two new additions to their portfolio of assessment services that will be released at the end of 2021. While the names bC and i1 may call to mind sleek sports cars or high-powered computer chips, they actually won’t add on a host of new features or added complexity. In fact, it’s what’s not included in these assessments when compared to the standard HITRUST Risk-Based, Two-Year (r2) Assessment (formerly known as the HITRUST CSF Validated Assessment) that makes them appealing. HITRUST i1, in particular, will be a game changer for compliance. Before you can decide if either of these new assessments are a good fit for your organization, let’s take a look at what they are and how they compare...

What is NIST 800-171?

Image
  Your organization can’t afford to lose valuable government contracts. Protect your business by bolstering your organization’s ability to comply with NIST800-171. Government contracts are highly lucrative, but also tough to secure and manage. That’s because the Federal Government deals with a lot of classified and controlled information on a day-to-day basis. Any contractors or subcontractors who wish to work with the Federal government must, therefore, have security procedures in place to protect that sensitive information. National Institute of Standards and Technology (NIST) 800-171 is a mandate that states that federal contractors and subcontractors that handle, transmit, or store controlled unclassified information (CUI) must comply with certain standards to protect that data. Compliance with NIST 800-171 is required under Defense Federal Acquisition Regulation Supplement (DFARS) Clause 252.204-7012. What is Controlled Unclassified Information (CUI)? CUI is information crea...

How Privacy Laws Impact Compliance Programs

Image
  Our 2021 Compliance Benchmark Report found that more than 71% of organizations say that an increasing focus on privacy has impacted their compliance practices and audits. Learn more about what that impact looks like. Privacy is at the forefront of regulators’ minds and therefore, greatly impacting compliance programs across the globe. It’s not just regulators who are taking note of new privacy laws — consumers are concerned about their privacy and data, too. A recent KPMG survey noted that 86% of consumers feel a growing concern about data privacy and 78% are worried about the amount of data being collected about them. With a magnifying glass on privacy concerns — from regulators and consumers — organizations are naturally concerned about their ability to ease consumer fears and avoid massive regulatory fines. In our 2021 Compliance Benchmark Report , we asked more than 200 cybersecurity, IT, quality assurance (QA), internal audit, finance, and other professionals if the increasi...

Powerful New Features Coming Soon to A-SCEND for Security Automation

Image
  We released the A-SCEND development roadmap, announcing powerful new features coming soon! Learn how A-LIGN is investing in product development to deliver new capabilities and services to our clients. The opportunity for new ideas and innovation in the compliance industry is at an all-time high. A-LIGN has always been at the forefront of cybersecurity compliance, relentlessly seeking ways to make audits and assessments more efficient while maintaining a high level of quality. The investments we make in A-SCEND, our end-to-end compliance management platform, allow us to move much faster on new product development and will help us to deliver even more value to our clients. Our customers will be able to experience new capabilities and services through A-SCEND with ease. As we look across the industry, with so many startups trying to ease the burden that compliance puts on resource-constrained security teams, we are proud to build on the experience of our A-LIGN auditors, along with ...

How to Launch and Grow Your Career in Cybersecurity

Image
How did Arti Lalwani, A-LIGN’s Risk Management and Privacy Knowledge Leader, get her start in cybersecurity? To promote Cybersecurity Awareness Month, we sat down with Arti to learn about her career path and advice she has for anyone trying to break into the industry. The world of cybersecurity is fast-paced and rapidly evolving. Current events, such as YouRock 2021 , The Accellion Supply Chain Attack , and The Colonial Pipeline attack , raised new concerns in the industry. Evolutions in frameworks and national or regional regulations, drive the need for new controls, policies, and procedures. And, of course, the last year has been an especially trying time due to the COVID-19 pandemic and the extra steps organizations had to take to ensure compliance when employees are working remotely. While exciting and cutting edge, the cybersecurity industry can be challenging to initially break into due to its rapid rise in popularity and necessity. In honor of Cybersecurity Awareness Month...