Compass IT Compliance Blog / Compliance (17)

FFIEC Guidance: Revision vs. Update

FFIEC Guidance: Revision vs. Update

When it comes to technology, we hear of terms that are often times confused and interchanged. Some examples of these terms might include Vulnerability Scanning and Penetration Testing. Another example might be the age old debate of Risk Assessment versus Audit. While seemingly similar …

Read Story

IT Security Best Practices: Segregation of Duties

A group of five business professionals celebrate

We hear the phrase “Segregation of Duties” talked about quite a bit when we talk about IT Security. One reason as to why this is such a talked about and ultimately important topic has to do with the fact that the risks associated with Segregation of Duties often go unnoticed until the …

Read Story

The Case for the PCI ROC: When to Perform One Over an SAQ

The Case for the PCI ROC: When to Perform One Over an SAQ

PCI Compliance can be a challenging initiative to take on, especially if this is a new process for your organization. Depending on the level of merchant or service provider you fall under determines the requirements you must complete to become PCI Compliant. This will either take form …

Read Story

FFIEC Guidance: Significant Changes to the Management Booklet

FFIEC Guidance: Significant Changes to the Management Booklet

On November 10th, the Federal Financial Institutions Examination Council (FFIEC) issued a revised Management booklet which is a part of the IT Examination Handbook. This is considered a major revision of the booklet and the first one to take place since 2004. As just a quick overview, …

Read Story

The Top 5 Reasons You Should Have a Vendor Management Program

The Top 5 Reasons You Should Have a Vendor Management Program

Last week we talked about what Vendor Management is and really why you should care about it for your organization. This week we are going to outline the top 5 reasons, in no particular order, of why your organization needs to have a Vendor Management Program implemented and that makes …

Read Story

IT Security vs. Regulatory Compliance: Which One Came First?

IT Security vs. Regulatory Compliance: Which One Came First?

Security or Compliance. Which one should we focus on? On the surface, this almost sounds like the question of which came first, the chicken or the egg. But if we dig deeper, we start to see that while they are similar and have similar goals, they can be very different in how they are …

Read Story

Subscribe by email