Compass IT Compliance Blog / Penetration Testing (3)

Latest Update in Vulnerabilities (SeriousSAM, PrintNightmare)

Latest Update in Vulnerabilities (SeriousSAM, PrintNightmare)

In this week's blog post, Compass IT Compliance Cybersecurity Professional Danielle Corsa analyzes several recent Microsoft vulnerabilities.

Read Story

The Difficulties of Remaining Compliant in the New COVID Landscape

The Difficulties of Remaining Compliant in the New COVID Landscape

If there is one thing that everyone can agree on in these interesting times, it is that COVID-19 has upset the apple cart in lots of different ways. Everything from school to work to social gatherings has been disrupted and changed over the last eight months, and some of these changes …

Read Story

Government Cyber Weaknesses & the Need for White Hats

hacker-1569744_1920

Have White Hat, Will Travel “A young boy, with greasy blonde hair, sitting in a dark room…[T]he weary system cracker telnets to the next faceless .mil site on his hit list.”

Read Story

PCI Compliance - PCI DSS 3.2 By the Numbers

A keyhole within a line of code

PCI DSS 3.2 is coming and that means some changes for Merchants and Service Providers and the steps that they take to mitigate their risk of a breach involving credit and debit cards. While change is inevitable, change can still be difficult,especially when you are talking about all o …

Read Story

The SANS Top 20, A Vulnerability Assessment, and Penetration Testing

The SANS Top 20, A Vulnerability Assessment, and Penetration Testing

The SANS Top 20 Critical Security Controls outline the 20 most critical controls that an organization should implement to ultimately reduce their overall risk of suffering a data breach. These controls were originally developed in 2008 by the NSA at the request of the Office of the Se …

Read Story

IT Risk Assessments and the SANS Top 20

IT Risk Assessments and the SANS Top 20

No matter what industry you are in, conducting a thorough IT Risk Assessment is critical to your organization for a number of reasons. First, it gives you a point in time measurement of how your IT Security posture compares to either various regulations or IT Security Frameworks.

Read Story

Subscribe by email