PCI DSS Compliance: What do PCI SAQ, AoC, and RoC Mean?

by Tori Thurmond / January 8, 2024

The Payment Card Industry Data Security Standard (PCI DSS) is a crucial security framework for businesses that handle cardholder data. Every business that processes, stores, or transmits cardholder data must comply with the framework and undergo an annual PCI DSS assessment to verify it complies.The nature of the assessment ranges from self-assessment to a full on-site PCI DSS audit by a Qualified Security Assessor (QSA). It’s critical that businesses understand…

What is an Audit Scope?

by Joseph Kirkpatrick / December 29, 2023

What is an Audit Scope and How Does it Impact an Audit? Knowing where your assets reside and which controls apply to them are critical for any organization. Why? This is the only way you can manage and secure them from a potential data breach or security incident. During the initial phases of a SOC 1 or SOC 2 audit, an auditor will walk you through defining the scope of…

8 Best Secure Coding Practices

by Tori Thurmond / December 27, 2023

When you hire builders to construct a new home, you expect them to take every precaution to ensure once you move in, you won’t find split beams, foundational errors, or holes in the walls. In the same way, software developers are expected to uphold secure coding practices to ensure they aren’t leaving any vulnerabilities open for hackers to exploit. What is Secure Coding? Secure coding standards govern the coding practices,…

What You Need to Know About OSSTMM

by Hannah Grace Holladay / December 21, 2023

What is the Open Source Security Testing Methodology Manual (OSSTMM)? The Open Source Security Testing Methodology Manual, or OSSTMM, is a peer-reviewed methodology for security testing, maintained by the Institute for Security and Open Methodologies (ISECOM). The manual is updated every six months or so, to remain relevant to the current state of security testing. ISECOM's main goal with the OSSTMM is to offer a scientific method for accurately understanding…

The Top 5 Reasons Why an Internal Audit is Important

by Hannah Grace Holladay / December 20, 2023

People often ask: is an internal audit necessary? What if we're a smaller organization, should we be spending our already limited resources on an internal audit program? If your clients depend on you to provide efficient, compliant, and secure services, then the answer is a resounding "yes". Internal auditing is an important function of any information security and compliance program and is a valuable tool for effectively and appropriately managing…