search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Role Based Access Control for HIPAA Security
HIPAA

Healthcare providers are responsible to make sure those with access to ePHI require that access to adequately do their jobs.

5 Steps to Making a Risk Assessment
Risk Assessment

Making a risk Assessment, or Risk Analysis, is the first step in the Security Rule compliance.

Firewalls 101: 5 Things You Should Know
Data Security

What are firewalls and how do they help protect your business?

5 Tips to Boost Your Business's Physical Security
Data Security

Many businesses don’t often realize how physical security can help protect their card data.

Network Diagrams: Key to Compliance and Security
Data Discovery

If you were to ask network architects and engineers about their favorite part of the job, I doubt any of them will respond with “creating and maintaining network diagrams.”

PCI 4.0 Summary of Changes
PCI Trends

PCI 4.0 summary of changes including new requirements that have been added to the standard.

Scoping for PCI Compliance: What You Need To Know
PCI Audit

Scoping is determining what systems are covered or need to be assessed or included as part of your PCI compliance.

Auditor Tips: Requirement 7: Restrict Access
PCI Audit

Cardholder data and card systems should only be accessible to those that need that information to do their jobs. Once you’ve implemented access privileges, make sure to document it.

How to Test Your Incident Response Plan
Forensics

How to test your incident response plan and conduct tabletop exercises.

Auditor Tips: Requirement 6: System Updating And Software Development
PCI Audit

System administrators have the responsibility to ensure that all system components (e.g., servers, firewalls, routers, workstations) and software are updated with critical security patches within 30 days of public release.

BlogEngine.NET Directory Traversal + Remote Code execution
Data Security

A remote code execution (RCE) vulnerability, CVE-2019-10719, was discovered in BlogEngine 3.3.7 and earlier.

PCI Assessment FAQs
PCI Audit

To address some of the most common questions we receive about PCI assessments, we sat down with Lee Pierce, a PCI assessment expert with over 15 years in the industry.

Auditor Tips: Requirement 10: Audit Logs and Log Monitoring
PCI Audit

It’s critical that you configure the log monitoring solution correctly so that the appropriate directories, files, security controls, and events are being monitored.

Auditor Tips: Requirement 11: Testing Security
Penetration Testing

If your organization is required to be PCI compliant, don’t procrastinate beginning the penetration test process.

PCI DSS 4.0 SAQ Questionnaires Q&A
PCI Trends

PCI DSS 4.0 SAQ Questionnaires Q&A: While future-dated requirements are not mandatory until March 31, 2025, it's recommended to implement them early for enhanced security.

Auditor Tips: Requirement 9: Improve Your Physical Security
PCI Audit

Once you know what systems you need to protect, put controls in place that can log and restrict access to them.

Auditor Tips: Requirement 8: Use Unique ID Credentials
PCI Audit

Requirement 8 is all about using unique ID credentials.

How Much does GDPR Compliance Cost?
GDPR

How much does GDPR compliance cost?

6 Steps to Making an Incident Response Plan
Forensics

Developing and implementing an incident response plan will help your business handle a data breach quickly, efficiently, and with minimal damage done.

Complying with the GDPR: What You Should Know
GDPR

GDPR is regulation that will help unite privacy laws across Europe. Here are some answered questions about GDPR Compliance.

Top 15 ASV Scan Vulnerabilities and How to Fix Them

Vulnerability scans search your network and provide a logged summary of alerts you can review and act on. Here are the top 15 ASV scan vulnerabilities and how to fix them.

Auditor Tips: Requirement 12: PCI Compliance Basics
Risk Assessment

a risk assessment can be the most important part of your overall security and compliance program, since it helps you identify systems, third parties, business processes, and people that are in scope for PCI compliance.

Auditor Tips: Firewall Best Practices
HIPAA

Healthcare organizations of all sizes use firewalls to protect the perimeter of their sensitive networks. Here are some firewall best practices to get you started.