Compass IT Compliance Blog / IT Audit (3)

IT Security Best Practices: Segregation of Duties

A group of five business professionals celebrate

We hear the phrase “Segregation of Duties” talked about quite a bit when we talk about IT Security. One reason as to why this is such a talked about and ultimately important topic has to do with the fact that the risks associated with Segregation of Duties often go unnoticed until the …

Read Story

The Case for the PCI ROC: When to Perform One Over an SAQ

The Case for the PCI ROC: When to Perform One Over an SAQ

PCI Compliance can be a challenging initiative to take on, especially if this is a new process for your organization. Depending on the level of merchant or service provider you fall under determines the requirements you must complete to become PCI Compliant. This will either take form …

Read Story

FFIEC Guidance: Significant Changes to the Management Booklet

FFIEC Guidance: Significant Changes to the Management Booklet

On November 10th, the Federal Financial Institutions Examination Council (FFIEC) issued a revised Management booklet which is a part of the IT Examination Handbook. This is considered a major revision of the booklet and the first one to take place since 2004. As just a quick overview, …

Read Story

IT Security Policies and Procedures: Why You Need Them

A group of business professionals debate at a meeting

Policies and Procedures are two of the words that most employees dread to hear, especially when it comes to IT Security. Why does this phenomenon occur? Is it because people don’t want to be told what to do? Is it because people feel as though they are being “micromanaged” when they h …

Read Story

IT Auditing and IT Risk Assessment: What's the Difference?

A group of business professionals debate at a meeting

We often hear the terms IT Risk Assessment and IT Audit used in various situations and often times they are used interchangeably. This causes great confusion for people who are trying to determine not only what they are looking for in terms of a service, but also what they can expect …

Read Story

IT Auditing - Why It's a Smart Investment

A group of five business professionals celebrate

We have all heard the term "Audit" and most of the time it makes us cringe. The first thing that we think of is someone in a suit coming into our organization and poking holes in our Technology, People and Processes that we have built based on the needs of our company and business. Ho …

Read Story

Subscribe by email