Compass IT Compliance Blog

Guide to Improving Your Security Awareness Training

workshop-2209239_1920

For the past 3 years that I’ve worked at Compass IT Compliance, I’ve had the opportunity to travel the country and meet with various clients ranging from small businesses with less than 10 people to organizations with offices around the world. The main constant that I have noticed wit …

Read Story

Vendor Risk Management: Importance of Service Level Agreements

glass-facade-817732_1920

Every organization, at one point or another, regardless of maturity, complexity, or business vertical, will have a need to work with a vendor, partner, or client to move business goals forward and maintain functional operations. Although vendors, partners, and clients have different r …

Read Story

Deciphering the PCI Testing Requirements of PCI-DSS Requirement 11

wallet-2125548_1920

PCI-DSS Requirement 11: Regularly test security systems and processes As a Qualified Security Assessor (QSA) organization and a security analyst, we receive many questions about meeting the various testing controls outlined within the Payment Card Industry Data Security Standard (PCI- …

Read Story

Controlling the Boot Process of a Suspect System

hard-drive-249412_1920

Retrieving electronic evidence is an imperative part of any forensic investigation. One must follow a strict set of processes in order to ensure the proper extraction of data and to maintain the integrity of the media, establish chain of custody, and document hash values.

Read Story

Vendor Management Programs to Prevent Data Disasters

electrician-1080586_1920

If you’ve read any of my prior blog posts, you will know that my background prior to joining Compass IT Compliance included 21 active duty years in the United States Coast Guard. I seem to talk about it quite a bit. One of the perks, depending on where they are sending you, is getting …

Read Story

Situational Awareness Starts with You!

agreement-2548138_1920

Having situational awareness can get you out of a lot of jams. Let me elaborate on what I mean by that. Have you ever received that annoying phone call from “Macrosoft Support”? This is known as a vishing attack. It’s the practice of eliciting information or attempting to influence ac …

Read Story

Subscribe by email