The History of SOC 2 Reports

by Sarah Harvey / December 19, 2022

    In order to understand the purpose of a Service Organization Control (SOC) 2 Report, it’s important to understand the background and history of how the SOC 2 came in to existence as a way for service organizations to manage the risks associated with outsourcing services. The original standard was known as SAS 70 and was a way service organizations could demonstrate the effectiveness of internal controls at their…

What is PCI and DSS Compliance?

by Sarah Harvey / April 12, 2023

What is PCI and DSS Compliance? This is a question KirkpatrickPrice, as a PCI QSA, is frequently asked. Let’s start with what it stands for. PCI stands for the Payment Card Industry. When we talk about compliance, we’re talking about the PCI DSS, or Payment Card Industry Data Security Standard. The PCI DSS originated from efforts by major credit card brands (Visa, MasterCard, American Express, Discover, and JCB) to encourage…

Road to HIPAA Compliance: Managing Business Associate Compliance

by KirkpatrickPrice / December 19, 2022

Why Does Business Associate Compliance Matter? The goal for this session is to identify the importance of the relations between covered entities and business associates, and to identify the issues that business associates and covered entities must navigate. This webinar is not designed just to benefit the covered entities. If you are a business associate, it will be beneficial to learn the issues that covered entities are dealing with and…

Understanding Data Breaches with Benjamin Wright

by Benjamin Wright / December 19, 2022

It’s become quite common to see reports in the headlines about data security breaches as different types of organizations are targeted every day. The types of information or data that is stolen as a result of a breach are things like social security numbers, credit card numbers, Protected Health Information (PHI), and Personally Identifiable Information (PII), trade secrets, or intellectual property. The most important thing to consider when it comes…

Man working on computer

Assessing Your Defenses: Penetration Testing for Beginners

by Sarah Harvey / December 19, 2022

What is Penetration Testing? Penetration testing is a form of permission-based ethical hacking in which a certified penetration tester attempts to gain access to an organization's system, network, or web application(s). The purpose of penetration testing is to find vulnerabilities that could potentially be exploited by a malicious hacker as part of a routine security check. This form of security testing allows organizations to find the vulnerabilities in their security…