PCI DSS Gap Analysis: A Complete Guide to Identifying and Closing Compliance Gaps

PCI Compliance

Meeting PCI DSS requirements starts with understanding where your organization stands today. That’s where a PCI DSS gap analysis comes in. It’s a diagnostic process that pinpoints which controls are already in place, which ones are missing, and what actions are needed to achieve full compliance. If your organization stores, processes, or transmits payment card … Read more

Mastering a Risk Assessment

Mastering a Risk Assessment

In light of the recent news of the data breach at Anthem Blue Cross/Blue Shield, risk assessment is our theme today. We welcome this guest post from our partner, KirkpatrickPrice….   Performing a Risk Assessment is a critical component of any Information Security Program. It’s mandated by several frameworks (SSAE 16, SOC 2, PCI DSS, … Read more

HIPAA Audit Programs: What Covered Entities and Business Associates Need to Know

Confident African American female doctor looking at the tablet.

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) is continuing its efforts to enforce HIPAA compliance through periodic and proactive audit programs. These audits are designed to assess how well Covered Entities and Business Associates are meeting their obligations under the HIPAA privacy, security, and breach notification standards. With … Read more

Public Cloud vs VPS

Public cloud vs VPS

When it comes to virtualized environments, we’re often asked: What’s the difference between a Virtual Private Server (VPS) and a public cloud? Both leverage virtualization, that is, creating virtual rather than physical computing resources, but they serve distinct purposes. Confusion arises because they share this virtual foundation. Let’s break it down, starting with the basics … Read more