The SOC Audit Process: Tackling Type I and Type II Reports

by Sarah Harvey / June 13, 2023

So you’ve decided whether you need a SOC 1 or a SOC 2 audit…what’s next? You need to decide where you’ll begin the SOC audit process. With a gap analysis? What are the SOC report types? A Type I? A Type II? Let’s discuss KirkpatrickPrice’s method for completing Type I and Type II audits. SOC Report Types: Type I and Type II FAQs No matter the SOC report types needed…

Security Within Your Development, Staging, and Production Environments

by Sarah Harvey / June 14, 2023

When information security, data security, and cybersecurity measures aren’t followed in development, staging, and production environments, the consequences can be detrimental. We’ve seen that time and time again. Last year, a bug bounty discovered a data breach at Imperva – a leading provider of firewall services. How did it happen? An unauthorized user stole an administrative API key from a production AWS account. What was the mistake behind Uber’s 2016…

Encrypted Backups: What They Are and How to Use Them

by Sarah Harvey / June 14, 2023

Today’s cyber landscape is riddled with advancing threats. From simple phishing attacks to intricate DoS attacks, businesses must ensure that the data they collect, use, store, and transmit is properly and thoroughly secured. After all, the data that companies hold is one of their greatest asset, so being aware of the consequences associated with losing that data is essential. For this reason, we believe that it’s imperative that organizations encrypt…

business people walking

Combining SOC 1 and SOC 2 Audits

by Sarah Harvey / June 13, 2023

We get a lot of questions about SOC 1 and SOC 2 audits. What’s the difference between the two? Should your company do both? Are you able to consolidate multiple audits into one project? KirkpatrickPrice has developed the Online Audit Manager to make it easier to combine multiple audits into one project. Let’s talk through why and how you would take on the project of a combined SOC 1 and…

What is a Secure Software Development Life Cycle

by Sarah Harvey / June 14, 2023

Have you ever worked on a project without a clear direction or guidelines? It can be stressful and pointlessly chaotic. Without structure and task lists, what could have been a basic project turns into a mess of miscommunication. The same principle applies to software development management. In an age when software development is a core function of most organizations, specific and detailed processes need to be in place to ensure…