
Filter by Tag
ISO 27001 A.8.2: Privileged Access Rights
ISO 27001 A.8.2 requires that privileged access rights, the elevated permissions that let a person change configuration, read all data, or bypass...
ISO 27001 A.8.32: Change Management
To satisfy ISO 27001 A.8.32, put every change to production systems, applications, and infrastructure through one documented path: a request, a risk...
ISO 27001 A.8.20: Network Security
ISO 27001 A.8.20 requires that the networks carrying an organization's information are secured, managed, and controlled to protect the systems and...
vCISO Services for Mid-Market SaaS: How to Evaluate Fractional Security Leadership in 2026
vCISO services give a mid-market SaaS company senior security leadership on a fractional basis: someone who owns the security program, drives SOC 2...
GRC Software vs a GRC Service for Security Reviews in 2026
GRC software and a security review are different. The software is the tool. The review is the work that helps a B2B SaaS deal move forward.GRC...
Top 8 vCISO Services for Mid-Market SaaS in 2026
The right vCISO service for a mid-market SaaS company is the one that owns and runs the security program end to end, on a fractional basis, the way a...
What Does a Security Architect Do?
A security architect does three jobs: sets security requirements for systems other people design, assesses and reviews those designs, and solutions...
How to Run a Security Assessment Across 90 Applications in 90 Days
When an application portfolio is too large to pen-test, an inquiry-based maturity assessment gets you a defensible, board-ready picture in weeks...
Designing Centralized Identity Across Hybrid Environments: A Security Architecture Walkthrough
Centralizing identity across cloud and on-prem environments is a security architecture problem before it is a tool-selection problem. You start by...
Security Architecture in Practice: The Questions Teams Actually Ask
Security architecture is the practice of designing how people, process, and technology work together to protect an organization's systems. It is not...
EDR vs MDR: The Simple Difference, and Which One You Need
EDR and MDR sound almost identical, and the two terms often get used interchangeably. The short explanation: EDR is the tool, and MDR is the service...
SOC 2 CC7.5: Recovering From Identified Security Incidents
SOC 2 CC7.5 requires a company to identify, develop, and implement the activities that recover the environment after a security incident, and to...
SOC 2 CC7.4: Responding to Security Incidents
SOC 2 CC7.4 requires a company to respond to security incidents through a defined incident-response program that understands, contains, remediates,...
SOC 2 CC7.3: Evaluating Security Events to Identify Incidents
SOC 2 CC7.3 requires a company to evaluate detected security events, decide which of them are incidents, and act on the ones that are. It sits in the...
SOC 2 CC1.2: Board Independence and Oversight
SOC 2 CC1.2 requires that a board of directors, or the body that plays the board's role, stays independent from management and exercises oversight of...
SOC 2 CC5.2: General Controls Over Technology
SOC 2 CC5.2 requires an organization to select and develop general control activities over technology so its systems support the objectives the...
SOC 2 CC2.2: Internal Communication
SOC 2 CC2.2 requires an organization to communicate internal control information, including objectives and responsibilities, to the people inside the...
SOC 2 CC1.5: Accountability for Internal Control
SOC 2 CC1.5 requires an organization to hold individuals accountable for the internal control responsibilities assigned to them. It closes the CC1...
SOC 2 CC6.8: Preventing and Detecting Unauthorized or Malicious Software
SOC 2 CC6.8 requires controls that prevent, or detect and act on, the introduction of unauthorized or malicious software. It sits in the CC6 series...
SOC 2 CC6.7: Restricting the Transmission, Movement, and Removal of Information
SOC 2 CC6.7 requires that information is protected when it is transmitted, moved, or removed, and that only authorized users and processes can do so....
SOC 2 CC6.6: Protecting Against Threats From Outside System Boundaries
SOC 2 CC6.6 requires logical access security measures that protect the system against threats originating outside its boundaries. It sits in the CC6...
SOC 2 CC6.5: Discontinuing Protections Over Disposed Assets
SOC 2 CC6.5 requires that data and software are rendered unrecoverable before an asset loses its protections or leaves the company's control. It sits...
SOC 2 CC3.3: Considering the Potential for Fraud in Risk Assessment
SOC 2 CC3.3 requires an entity to consider the potential for fraud when it assesses risks to its objectives. It sits in the CC3 series (Risk...
SOC 2 CC3.4: Identifying and Assessing Significant Changes
SOC 2 CC3.4 requires an entity to identify and assess changes that could significantly affect its system of internal control. It closes the CC3...
SOC 2 CC5.3: Policies and Procedures
SOC 2 CC5.3 requires an organization to deploy its control activities through policies that state what is expected and procedures that put those...
SOC 2 CC5.1: Selecting and Developing Control Activities
SOC 2 CC5.1 requires an organization to select and develop control activities that reduce its risks to an acceptable level, choosing each control...
SOC 2 CC2.3: External Communication
SOC 2 CC2.3 requires an organization to communicate with external parties about matters that affect how its internal control operates, and to give...
SOC 2 CC3.1: Specifying Objectives With Enough Clarity to Assess Risk
SOC 2 CC3.1 requires an entity to state its objectives clearly enough that the risks to those objectives can be identified and assessed. It opens the...
SOC 2 CC3.2: Identifying and Analyzing Risk to Your Objectives
SOC 2 CC3.2 requires an entity to identify risks to its objectives across the whole organization and to analyze them well enough to decide how each...
SOC 2 CC1.4: Commitment to Competence
SOC 2 CC1.4 requires an organization to attract, develop, and retain people who are competent to carry out their responsibilities, and to hold...



























