IT Audit & Compliance Blog

The Linford & Company Blog is written by our very own auditors, who are experts in IT audits, information security, and compliance topics. Their auditing experience encompasses a broad spectrum of industries and organizations, and their specialized expertise can help your company or organization make the right decision for your auditing needs. Our specific areas of focus in our IT Audit & Compliance Blog include SOC 1 Audits, SOC 2 Audits, HIPAA Audits, HITRUST Certification, and FedRAMP Assessments, NIST & CMMC, and Penetration Testing.

As I was discussing cloud governance with a client recently, a recurring question came up: “We have ISO 27001, so why do we need ISO 27017?” It’s a fair question. While ISO/IEC 27001 provides the foundational framework for an Information Security Management System (ISMS), the unique risks of cloud environments, including multi-tenancy, shared responsibility, and [...]

A mobile workforce has shifted from a “nice to have” to a critical capability. As employees expect flexibility and organizations rely more on cloud resources, expand globally, and look to reduce overhead, mobility brings both significant benefits and new responsibilities. Whether you’re evaluating a mobile device management (MDM) solution or strengthening or implementing a bring [...]

Having a sound data analytics function within the internal audit department is increasingly critical as the world continues its drive toward digitization. Tools and trends like big data, cloud computing, robotics and automation, machine learning, and artificial intelligence are altering how businesses operate, and internal audits should be no different. The traditional audit approach of [...]

Artificial Intelligence (AI) is no longer a “future state” technology; it’s here and is moving at a breakneck pace. Unless you’re a “frontier” organization, your company isn’t deploying fully autonomous AI systems. However, AI is reshaping your businesses; sometimes through official initiatives, other times through employees quietly adopting tools on their own. It’s driving financial [...]

Imagine an employee at your organization is terminated, but due to a communication gap or manual off-boarding process, their account isn’t disabled. Weeks later, another employee needs access to restricted data but hasn’t yet received approval for such access. Frustrated with delays, this employee uses the former employee’s still-active credentials to access the restricted data. [...]

In today’s market, clients and partners expect more than promises — they expect proof that their data is safe in your hands. Achieving SOC 2 compliance is one of the best ways to demonstrate that commitment. But to stand out, you need more than a checklist approach. You need a security strategy built to withstand [...]

Let’s be honest—when you’re juggling daily priorities and a never-ending to-do list, audit risk probably isn’t the first thing on your mind. And hey, maybe the “out of sight, out of mind” approach feels easier. After all, it doesn’t exactly scream excitement, and there’s always something more urgent to handle. But here’s the thing: while [...]

When I audit small to mid-sized SaaS companies in the healthcare space, there’s one assumption I encounter over and over again: “We’re in the cloud, so compliance is handled.” It’s an easy misconception to fall into. After all, AWS, Azure, and Google Cloud talk extensively about HIPAA and HITRUST capabilities. But here’s the quiet truth—moving [...]

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
I understand and agree to the Linford & Company LLP privacy policy.**