search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Text asking compliance with PCI Requirement 1 beside a clipboard checklist with checked boxes.
How to Comply with PCI Requirement 1: Manage Your Firewall
PCI

PCI Requirement 1 deals with setting up and configuring firewalls to protect your business data.

Auditor Tips PCI DSS
Auditor Tips: Requirement 5: Implement And Update Your Anti-Malware
Pulse

PCI DSS requires anti-malware software to be installed on all systems that are commonly affected by malware (e.g., Windows).

Text PCI 4.0 with long blue shadows on a light gray background.
Achieving lift-off with PCI DSS v4.0
PCI Trends

With March 31, 2025 as a target destination, managed security service providers and enterprises from across the digital commerce chain are taking a measured approach to implementing PCI DSS version 4.0.

Three-dimensional blue and white number 40 with shadow on a light gray background.
Changes and Updates to the 4.0 SAQ
PCI Trends

This blog will discuss changes to the PCI DSS 4.0 SAQ questionnaires and is based on our Webinar "PCI DSS 4.0: What's New and How It Affects You."

3D blue number 40 casting a shadow on a light background.
Performing an SAQ P2PE version 4.0 Self-Assessment
PCI Trends

This blog will discuss changes made to the SAQ P2PE version 4.0 and will review the process of performing a self-assessment using the SAQ P2PE.

Multiple copies of a book titled 'SecurityMetrics Guide to PCI DSS Compliance' arranged in a pattern.
PCI DSS 4.0: What is New and How it Affects You Q and A
PCI Trends

Here are some questions participants asked in our webinar, “PCI DSS 4.0: What Is New and How It Affects You.”

Blue credit card labeled CC# and payment terminal with a checkmark on the screen.
PCI DSS v4.0: Future of the PCI Security Standard
PCI Trends

While the PCI v4 standard is not expected to be finalized and released until the end of 2020 or the beginning of 2021, the PCI Security Standards Council has made some information available to the general public on what some of the changes might be.

Abstract numbers 1-5 on white background.
5 Tips to HIPAA Compliant Mobile Devices
HIPAA

By following basic security practices and policies, you can make your devices HIPAA compliant and keep your data safe.

Abstract numbers 1-5 with white background.
5 Blogs to Help You Survive PCI DSS and Prevent Security Breaches This Year
PCI

Here are 5 Blogs to Help You Survive PCI DSS and Prevent Security Breaches This Year. We cover formjacking, penetration tests, PCI DSS checklists, PCI DSS audits, as well as preparing for incident response.

White text reading Auditors Tips on a dark geometric background with a small blue line below.
Auditor Tips: Monitor Your Business Associates’ Compliance
HIPAA Audit

Every covered entity that uses business associates is required to obtain assurances that their business associates treat patient data the way you and HHS require them to.

White text reads Auditor Tips on a dark geometric background with a small blue line below.
Auditor Tips: System Updating and Software Development
HIPAA Audit

System administrators have the responsibility to ensure all system components (e.g., servers, firewalls, routers, workstations) and software are updated with critical security patches within 30 days of when they are released to the public.

White text 'Auditor Tips' on dark geometric background with a small blue underline.
Auditor Tips: Overcome Management’s Budget Concerns
HIPAA Audit

If you are having problems communicating budgetary needs to management, conduct a risk analysis before starting the HIPAA process.

White text 'Auditor Tips' on a dark geometric patterned background with a short blue line beneath text.
Auditor Tips: HIPAA Training Best Practices
HIPAA Audit

Workforce members need to be given specific rules and regular training to know how to protect PHI. Regular training will remind them of the importance of security and keep them up to date with current security policies and practices.

White text 'Auditor Tips' on dark geometric background with a small blue underline.
Auditor Tips: Permanently Delete Files
HIPAA Audit

Most people know how to destroy physical sensitive data, but when it comes to securely destroying electronic data, most healthcare professionals don’t know where to begin.

White text reading 'Auditor Tips' on a dark geometric background with a small blue underline.
Auditor Tips: Healthcare Security And Best Practices
HIPAA Audit

Healthcare security gaps often stem from communication issues. It’s common to see executives and practice leads who aren’t listening to their staff about their current state of compliance and security.

White text reading Auditor Tips on a dark geometric patterned background with a small blue line below.
Auditor Tips: Penetration Testing Best Practices
Penetration Testing

A penetration test will give you a holistic view of what your security system truly looks like. Organizations with poor security practices across their environment leave themselves vulnerable.

White bold text reading 'Auditor Tips' on a dark geometric background with a blue underline.
Auditor Tips: Minimum Necessary Best Practices
HIPAA Audit

The minimum necessary requirement is a key part of the HIPAA Privacy Rule. The goal of this requirement isn’t to encourage organizations to perform the minimum necessary, but rather for organizations to only use and disclose the minimum amount of PHI necessary

White text reading 'Auditor Tips' on a dark geometric patterned background.
Auditor Tips: Regularly Conduct Vulnerability Scans
HIPAA Audit

Regular vulnerability scans are a critical preventative security control as they detect and assess known weaknesses that may be opening up your systems, applications and networks to undue risk of intrusion. Vulnerability scanning is not penetration testing.

White text reading 'Auditor Tips' on a dark textured background with a small blue line underneath.
Auditor Tips: Set Up Your Intrusion Detection/Prevention System
HIPAA Audit

You need a team to choose and manage an IDS/IPS. Whether it’s the responsibility of your IT Security Team,Data Loss Prevention Team, a managed service provider, or a designated co-managed team consisting of security-related department heads.

White text reading Auditor Tips on a dark textured background with a small blue line below the text.
Auditor Tips: Unique ID, Passwords, and Passphrases
HIPAA Audit

More recently, password length, in the form of longer, memorable word strings have proven to be a more important security practice than the use of shorter complex passwords.

White text 'Auditor Tips' on dark background with a small blue underline below the text.
Auditor Tips: Implement Encryption
HIPAA Audit

You should implement encryption to protect PHI any time it is stored.

White text reading Auditor Tips on a dark textured background with a blue underline.
Auditor Tips: Audit Logs and Log Monitoring
HIPAA Audit

Monitoring audit logs for all critical systems and devices in your environment is key to understanding what types of events and actions occur on a daily basis, allowing you to establish a baseline of what is considered normal system activity.

White text 'Auditor Tips' on a dark geometric background with a small blue underline.
Auditor Tips: Secure Remote Access
HIPAA Audit

Remote access to tools and data is essential to employees who work from home or are unable to go into the office for health or other logistical reasons.

White text reading 'Auditor Tips' on a dark geometric background with a small blue underline.
Auditor Tips: System Configuration
HIPAA Audit

Whenever a system is configured make sure you know exactly what is running and also what is necessary to allow the system to perform its intended function.