Compass IT Compliance Blog / Risk Assessment

CISA's K-12 Cybersecurity Guidance: A Roadmap for School Districts

CISA's K-12 Cybersecurity Guidance: A Roadmap for School Districts

On August 12, CISA released the K-12 Cybersecurity Foundations Resource Package, which is a Getting Started Guide, an Implementation Guide, a six-part video series, and quick-reference materials built around eight core objectives: credential protection, device and asset security, back …

Read Story

Which Industries Need Cybersecurity Risk Assessments Most?

Which Industries Benefit Most from Cybersecurity Risk Assessments

Cybersecurity isn't just a concern for tech companies anymore. In today's interconnected world, every organization that handles digital data faces potential threats from hackers, ransomware, phishing attacks, and insider threats. While all businesses should prioritize cybersecurity, c …

Read Story

What is TISAX Assessment Level 2.5 (AL 2.5)?

TISAX Assessment Level 2.5

In the realm of automotive and industrial information security, TISAX (Trusted Information Security Assessment Exchange) plays a vital role in standardizing security assessments among partners and suppliers. One of its unique features is the concept of assessment levels, which determi …

Read Story

SOC 1 vs SOC 2 Reports - What's the Difference?

SOC Reports

As the landscape of modern business shifts, one thing becomes clearer: outsourcing is not just a fleeting trend, but a strategic move adopted by companies across industries. With this increasing reliance on third-party services, there emerges an unprecedented need for more rigorous me …

Read Story

Building a Privacy Culture This Data Privacy Week

Data Privacy

In 2022, data privacy became a hot topic as consumers became more aware of how their data was being tracked and used by companies. This was partly due to the efforts of companies like Apple to educate consumers about their privacy rights.

Read Story

Using the HECVAT to Measure Vendor Risk

Students gather in a lecture hall

Not a day goes by without a conversation about third-party risk management. Our clients are being bombarded in all directions; asked by regulators, auditors, their clients, and customers alike to complete third-party risk assessments (SIG, CAIQ, HECVAT).

Read Story

Subscribe by email