SOC 1 vs. SOC 2: Which SOC Report Do I Need?

by Sarah Harvey / December 19, 2022

SOC 1 vs. SOC 2 Reports: What's the Difference? As a service organization, you are familiar with audit requests from clients who are required to meet specific compliance and audit requirements, and you have most likely been asked whether your organization is SOC 1 compliant or SOC 2 compliant. We often get asked: What are the differences between a SOC 1 vs. SOC 2 audit? Which SOC report should you…

Mastering the PCI Audit Process Utilizing the Online Audit Manager Approach

by Sarah Harvey / February 5, 2024

It’s no secret that the PCI Data Security Standard is one of the most robust information security standards that exists. With approximately 400 controls, understanding all of the ins and outs of the standard can cause quite the headache without the proper resources and expertise. When selecting a third party Qualified Security Assessor (QSA) to perform your PCI audit, we recommend choosing an auditor that can help with readiness as…

SAS 70 Auditing Standard vs. SSAE 16 Report: What’s the Difference?

by Sarah Harvey / December 19, 2022

What’s the purpose of an SSAE 16 audit and should I pursue one? If you’re new to the world of information security audits, check out this comprehensive guide on the history of SSAE 16, why it replaced the SAS 70, and how becoming SSAE 16 compliant could benefit your business. Outsourcing critical business functions, such as IT or HR, is a common practice among many businesses, today. While outsourcing is…

Road to HIPAA Compliance: Using the NIST Cybersecurity Framework to Protect PHI

by KirkpatrickPrice / December 19, 2022

The NIST Cybersecurity Framework: A Common Language for Cybersecurity Issues The cybersecurity realm is overwhelming – the issues, the regulations, the changes, the threats, the persistence. We’re living in a world where we hear about new breaches every day. None of us can possibly know everything about all cybersecurity issues, and that’s okay. We’re all vulnerable and overwhelmed, but that’s no excuse not to prepare and continually develop your organization’s…

What is an SSAE 18 (SOC 1) Type II Audit Report?

by Sarah Harvey / April 12, 2023

Harvest Strategy Group, Inc. recently completed its 5th annual SSAE 18 SOC I Type II audit in order to reinforce its industry leadership position in regulatory compliance through an extensive evaluation and audit of the internal controls and processes of its vendors and recovery partners. Headquartered in Denver, Colorado, Harvest Strategy Group, Inc. provides comprehensive accounts receivables management services to a variety of creditors, including banks, auto finance lenders, credit…