IT Audit & Compliance Blog

The Linford & Company Blog is written by our very own auditors, who are experts in IT audits, information security, and compliance topics. Their auditing experience encompasses a broad spectrum of industries and organizations, and their specialized expertise can help your company or organization make the right decision for your auditing needs. Our specific areas of focus in our IT Audit & Compliance Blog include SOC 1 Audits, SOC 2 Audits, HIPAA Audits, HITRUST Certification, and FedRAMP Assessments, NIST & CMMC, and Penetration Testing.

In the following paragraphs, we’ll discuss what hardening means, the benefits and disadvantages it brings, and where to begin in the process of securing an operating system. Let’s first understand what the hardening process is. The concept of hardening, in relation to computing, is when the system is made more secure through the use of [...]

As I was discussing cloud governance with a client recently, a recurring question came up: “We have ISO 27001, so why do we need ISO 27017?” It’s a fair question. While ISO/IEC 27001 provides the foundational framework for an Information Security Management System (ISMS), the unique risks of cloud environments, including multi-tenancy, shared responsibility, and [...]

A mobile workforce has shifted from a “nice to have” to a critical capability. As employees expect flexibility and organizations rely more on cloud resources, expand globally, and look to reduce overhead, mobility brings both significant benefits and new responsibilities. Whether you’re evaluating a mobile device management (MDM) solution or strengthening or implementing a bring [...]

Having a sound data analytics function within the internal audit department is increasingly critical as the world continues its drive toward digitization. Tools and trends like big data, cloud computing, robotics and automation, machine learning, and artificial intelligence are altering how businesses operate, and internal audits should be no different. The traditional audit approach of [...]

Artificial Intelligence (AI) is no longer a “future state” technology; it’s here and is moving at a breakneck pace. Unless you’re a “frontier” organization, your company isn’t deploying fully autonomous AI systems. However, AI is reshaping your businesses; sometimes through official initiatives, other times through employees quietly adopting tools on their own. It’s driving financial [...]

Imagine an employee at your organization is terminated, but due to a communication gap or manual off-boarding process, their account isn’t disabled. Weeks later, another employee needs access to restricted data but hasn’t yet received approval for such access. Frustrated with delays, this employee uses the former employee’s still-active credentials to access the restricted data. [...]

In today’s market, clients and partners expect more than promises — they expect proof that their data is safe in your hands. Achieving SOC 2 compliance is one of the best ways to demonstrate that commitment. But to stand out, you need more than a checklist approach. You need a security strategy built to withstand [...]

Let’s be honest—when you’re juggling daily priorities and a never-ending to-do list, audit risk probably isn’t the first thing on your mind. And hey, maybe the “out of sight, out of mind” approach feels easier. After all, it doesn’t exactly scream excitement, and there’s always something more urgent to handle. But here’s the thing: while [...]

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
I understand and agree to the Linford & Company LLP privacy policy.**