Compass IT Compliance Blog

CISA's K-12 Cybersecurity Guidance: A Roadmap for School Districts

CISA's K-12 Cybersecurity Guidance: A Roadmap for School Districts

On August 12, CISA released the K-12 Cybersecurity Foundations Resource Package, which is a Getting Started Guide, an Implementation Guide, a six-part video series, and quick-reference materials built around eight core objectives: credential protection, device and asset security, back …

Read Story

What Is a PCI DSS Gap Analysis & What Should You Expect to Find?

What Is a PCI DSS Gap Analysis & What Should You Expect to Find?

Before an organization commits to a full PCI DSS assessment, most experienced QSAs recommend starting with a gap analysis. It is a lower-pressure, exploratory step that tells you where you actually stand before the clock starts on a formal engagement. Here is what a PCI gap analysis i …

Read Story

What Drives SOC 2 Audit Cost: 5 Factors to Know Before You Budget

What Drives SOC 2 Audit Cost: 5 Factors to Know Before You Budget

If a SOC 2 audit quote made you raise an eyebrow, you're not alone. Prices vary widely from firm to firm, sometimes for the same size company in the same industry, and it's easy to assume someone is either overcharging or cutting corners. But before you go shopping for the lowest numb …

Read Story

Breaching a Water Treatment Facility: A Physical Security Test

Breaching a Water Treatment Facility

Most water utilities invest heavily in network penetration testing and web application security, and rightly so. Far fewer test whether someone can simply walk onto the property, badge their way past staff, or climb a fence after dark and reach the equipment that keeps water flowing t …

Read Story

Do You Need a QSA? How to Choose the Right Assessor for Your Firm

Do You Need a QSA How to Choose the Right Assessor for Your Firm

If your business stores, processes, or transmits cardholder data, you have almost certainly come across the term QSA. But whether you actually need to hire one, and how to pick a good one if you do, is not always clear. This guide breaks down what a Qualified Security Assessor does, w …

Read Story

What the Minnesota Water Hack Reveals About OT Security Assessments

What the Minnesota Water Hack Reveals About OT Security Assessments

On July 26 and 27, a coordinated cyberattack hit more than 30 community water systems across Minnesota. Our team is trained in running penetration tests against OT and ICS environments, and when we read the reporting on this one, nothing about it was surprising. That's the part that s …

Read Story

Subscribe by email