Open in app

Sign In

Write

Sign In

Austin Songer
Austin Songer

606 Followers

Home

About

1 day ago

10 Things To Know Before A SOC 2 Audit

SOC 2 audits are important for organizations that handle customer data and need to ensure that the data is secure and confidential. Such organizations must adhere to specific standards and guidelines set out by the American Institute of Certified Public Accountants (AICPA) in order to protect the data of their…

4 min read

4 min read


Feb 9

SOC 2: Pros and Cons

The SOC 2 framework is a set of standards and guidelines developed by the American Institute of Certified Public Accountants (AICPA) for evaluating the effectiveness of an organization’s controls related to security, availability, processing integrity, confidentiality, and privacy. It is designed to help organizations demonstrate the adequacy of their controls…

Grc

3 min read

Grc

3 min read


Feb 9

ISO 27001: Pros and Cons

The ISO 27001 framework is an internationally recognized standard that provides a set of best practices for establishing, implementing, maintaining, and continually improving an organization’s information security management system (ISMS). …

3 min read

3 min read


Jan 28

SOC 2: Importance of Stakeholders Collaboration

Involving all relevant stakeholders in the SOC 2 implementation process is essential for ensuring that your controls are effective and aligned with your business objectives. …

Grc

6 min read

Grc

6 min read


Jan 15

HIPAA Expected Evidence

Click the link below to be redirected to the spreadsheet HIPAA Expected Evidence SpreadsheetHIPAA ID,Control,Expected Evidence,Standard Hierarchy,Frequency164.308(a)(1)(D),Security Management Process — Information System Activity Review — Implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking …Google Docs

Grc

1 min read

Grc

1 min read


Jan 3

Audit Principles and Concepts

Carve-out method Method of dealing with the services provided by a subservice organization. The nature of the services performed by the subservice Organization is included in section 3, but the relevant related controls are excluded. …

Grc

3 min read

Grc

3 min read


Jan 3

Audit Principles and Concepts

Principle/concept Description Carve-out method Method of dealing with the services provided by a subservice organization. The nature of the services performed by the subservice Organization is included in section 3, but the relevant related controls are excluded. …

Grc

3 min read

Grc

3 min read


Jan 2

Evidence Gathering Recommendation: Adding TimeStamp To Screenshots

Install Timestamp App https://github.com/mzdr/timestamp When Taking Screenshots Remember when taking screenshots for evidence that you will upload to your GRC tool of choice you should add a timestamp in the image. This will allow the auditor will know that the evidence was taken during whatever period that will be auditing for. Please see the screenshot below as an example.

Grc

1 min read

Grc

1 min read


Dec 23, 2022

Mapping Security Controls to the HITRUST framework

Mapping your security controls to the HITRUST Common Security Framework (CSF) is an important step in the process of preparing for a HITRUST audit. The CSF is a comprehensive security framework that provides guidance on the controls and practices needed to protect sensitive healthcare information. Here are a few steps…

Grc

2 min read

Grc

2 min read


Dec 22, 2022

SOC 2: Selecting a SOC 2 Auditor

Selecting a SOC 2 auditor is an important decision for any organization, as the auditor will be responsible for evaluating the effectiveness of your controls related to security, availability, processing integrity, confidentiality, and privacy. Here are a few criteria to consider when selecting a SOC 2 auditor: Independence: It’s important…

Soc2

2 min read

Soc2

2 min read

Austin Songer

Austin Songer

606 Followers

Trusted Veteran | Compassionate. Aspiring. Resourceful.

Following
  • umair haque

    umair haque

  • Jason Yip

    Jason Yip

  • Liza Donnelly

    Liza Donnelly

  • Greg Satell

    Greg Satell

  • GovTrack.us

    GovTrack.us

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech