PCI Requirement 11 – Regularly Test Security Systems & Processes

by Randy Bartels / December 16, 2022

 Regular Testing PCI Requirement 11 is about managing the security of your environment. It states, “Regularly test security systems and processes.” From everything we’ve learned in the PCI DSS so far, we know that it’s required us to: Harden our networks Harden our systems Protect data in storage Protect data in transmission Protect systems against malware Ensure that system and applications are developed securely Restrict access to cardholder data…

PCI DSS Update: Version 3.2.1 Released

by Sarah Harvey / December 16, 2022

On February 1, 2018, nine new PCI DSS requirements went into effect. Four months later, the PCI Security Standards Council (SSC) published a minor revision to the PCI DSS. PCI DSS v3.2.1 replaces v3.2 and addresses effective dates and Secure Socket Layer (SSL)/early Transport Layer Security (TLS) migration deadlines that have passed. Though PCI DSS v3.2.1 does not introduce any new requirements, let’s discuss the minor revisions made, when they…

SOC for Cybersecurity FAQs

by Sarah Harvey / November 20, 2023

What is SOC for Cybersecurity? Because most organizations conduct some portion of their business in cyberspace, they open themselves up to a new level of risk. Who they are, what they do, and what information they possess can make businesses targets for malicious attackers. Reputational damage, disruption of business operations, fines, litigation, and loss of business can all be consequences of a cybersecurity attack. It’s more important than ever to…

Which GDPR Requirements Do You Need to Meet?

by Sarah Harvey / December 16, 2022

GDPR Requirements for Data Controllers and Processors The first step towards GDPR compliance is determining your organization’s data role – are you a data controller or a data processor? Determining your role under GDPR can be challenging because of textual and practical ambiguity, but identifying your role is the starting point for determining which GDPR requirements your organization must follow. What are the responsibilities of data controllers? A data controller determines…

What’s the Difference Between SOC for Cybersecurity and SOC 2?

by Sarah Harvey / June 14, 2023

Newest Addition to the SOC Suite The AICPA recently added a new offering to its SOC suite: SOC for Cybersecurity. The difference between SOC 1, SOC 2, and SOC 3 has always been fairly clear-cut based on factors like internal control over financial reporting, the Trust Services Criteria, and restricted report use. Now, we have a new player in the game. What’s the Difference Between SOC for Cybersecurity and SOC…