search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Text reading Auditor Tips PCI DSS on a dark geometric background with a blue underline.
Auditor Tips: Requirement 12: PCI Compliance Basics
Risk Assessment

A risk assessment can be the most important part of your overall security and compliance program, since it helps you identify systems, third parties, business processes, and people that are in scope for PCI compliance.

Text 'Auditor Tips PCI DSS' in white on a dark geometric patterned background.
Auditor Tips: Requirement 9: Improve Your Physical Security
PCI Audit

Once you know what systems you need to protect, put controls in place that can log and restrict access to them.

Text reading Auditor Tips PCI DSS in bold white font on a dark geometric background.
Auditor Tips: Requirement 8: Use Unique ID Credentials
PCI Audit

Requirement 8 is all about using unique ID credentials.

Auditor Tips PCI DSS
Auditor Tips: Requirement 5: Implement And Update Your Anti-Malware
Pulse

PCI DSS requires anti-malware software to be installed on all systems that are commonly affected by malware (e.g., Windows).

Text 'Auditor Tips PCI DSS' on dark background with geometric pattern and blue underline.
Auditor Tips: Requirement 7: Restrict Access
PCI Audit

Cardholder data and card systems should only be accessible to those that need that information to do their jobs. Once you’ve implemented access privileges, make sure to document it.

Text reading Auditor Tips PCI DSS on dark textured background with a blue underline.
Auditor Tips: Requirement 6: System Updating And Software Development
PCI Audit

System administrators have the responsibility to ensure that all system components (e.g., servers, firewalls, routers, workstations) and software are updated with critical security patches within 30 days of public release.

Text reading Auditor Tips PCI DSS on a dark geometric background with a small blue bar.
Auditor Tips: Requirement 4: Sending Data Over Open And Public Networks
PCI

Know exactly where CHD is coming from and being sent to, inside and outside of your organization.

Text reading Auditor Tips PCI DSS on a dark geometric background with blue underline.
Auditor Tips: Requirement 3: Protect Cardholder Data
PCI

It is important to know what data you actually store, process, and/or transmit.

Text reading Auditor Tips PCI DSS on a dark geometric patterned background with a blue underline.
Auditor Tips: PCI DSS Responsibilities and Challenges
PCI

As you implement your cybersecurity program, make sure you understand why a security control is required so you can structure tools and processes around the protection each control offers.

Text reading Auditor Tips PCI DSS on a dark geometric patterned background with a blue underline.
Auditor Tips: Requirement 2: System Configuration
PCI

You are required to use industry-accepted configuration and hardening standards when setting up systems that are part of your PCI scope.

Stone castle gate with two towers symbolizing firewalls in PCI Requirement 1 security concept.
Requirement 1: Establish Secure Firewall Rules
PCI

Make sure to choose firewalls that support the necessary configuration options to protect critical systems and provide segmentation between the CDE and other internal and external networks specific to your organization.

Text reading Auditor Tips PCI DSS on a dark geometric patterned background with a blue underline.
Auditor Tips: PCI DSS Scope
PCI Audit

To discover your PCI scope and what must be included for yourPCI compliance, you need to identify anything that processes, stores, or transmits cardholder data, and then evaluate what people and systems are communicating with your systems.

3D blue outlined text reading PC 4.0 with layered line effects on light gray background.
Performing an SAQ-B Version 4.0 Self-Assessment
PCI Trends

The SAQ B is designed for merchant environments where all cardholder data is processed using standalone Point-of-Interaction (POI) terminals connected via an analog phone line.

Blue outlined 3D text reading 'PCI 4.0' on a light gray background with scattered white shapes.
Performing an SAQ B-IP version 4.0 Self-Assessment
PCI Trends

The Self-Assessment Questionnaire (SAQ) B-IP is intended for payment channels where cardholder data is processed using IP-connected PTS-approved point-of-interaction terminals.

Medical worker working at a computer with blue stripes behind.
5 Steps to Secure Your Healthcare Organization
HIPAA

Securing your healthcare organization should be a priority. Healthcare organizations are especially vulnerable to attacks because they cannot afford to be shut down.

Medical professional with stethoscope standing at a computer workstation focused on the screen.
Everything You Need to Know About How to Manage PHI
HIPAA

Fully understanding all the PHI you have, where it is stored, what processes touch it, and how it is used in your organization is critical to enabling a business to properly manage PHI.

Medical professional in scrubs and glasses using a computer on a mobile workstation.
HIPAA Compliance Best Practices
HIPAA

With over 20 years in the industry, we have found that these HIPAA compliance best practices are most helpful in securing your organization.

Laptop screen filled with binary code and a magnifying glass highlighting part of the code.
2023 Forensic Predictions
Forensics

In 2023, we've got three predictions of cyber attacks that we think will be the most prevalent this year.

Illustration of three spinning gears above a technology device on a white background.
3 Projects to Get You Into InfoSec
Data Security

This blog will discuss 3 infosec projects that are under $100 to get you started in Cybersecurity or Infosecurity by giving you hands-on experience to develop your skills.

Line art of a network switch with three rotating gears above it symbolizing system or network configuration.
How to Maintain HIPAA Compliant Firewalls
HIPAA

Simply installing a firewall on your organization’s network perimeter doesn’t secure your network or make you HIPAA compliant. Proper configuration is critical for HIPAA compliant firewalls.

White text reading Auditors Tips on a dark geometric background with a small blue line below.
Auditor Tips: Monitor Your Business Associates’ Compliance
HIPAA Audit

Every covered entity that uses business associates is required to obtain assurances that their business associates treat patient data the way you and HHS require them to.

White text reads Auditor Tips on a dark geometric background with a small blue line below.
Auditor Tips: System Updating and Software Development
HIPAA Audit

System administrators have the responsibility to ensure all system components (e.g., servers, firewalls, routers, workstations) and software are updated with critical security patches within 30 days of when they are released to the public.

White text 'Auditor Tips' on dark geometric background with a small blue underline.
Auditor Tips: Overcome Management’s Budget Concerns
HIPAA Audit

If you are having problems communicating budgetary needs to management, conduct a risk analysis before starting the HIPAA process.

White text 'Auditor Tips' on a dark geometric patterned background with a short blue line beneath text.
Auditor Tips: HIPAA Training Best Practices
HIPAA Audit

Workforce members need to be given specific rules and regular training to know how to protect PHI. Regular training will remind them of the importance of security and keep them up to date with current security policies and practices.