IT Audit & Compliance Blog

The Linford & Company Blog is written by our very own auditors, who are experts in IT audits, information security, and compliance topics. Their auditing experience encompasses a broad spectrum of industries and organizations, and their specialized expertise can help your company or organization make the right decision for your auditing needs. Our specific areas of focus in our IT Audit & Compliance Blog include SOC 1 Audits, SOC 2 Audits, HIPAA Audits, HITRUST Certification, and FedRAMP Assessments, NIST & CMMC, and Penetration Testing.

An audit is an independent review and verification of an organization’s assertion or claim. The assertion may be that a company follows applicable standards or rules when performing its operations, that financial statements are presented fairly, that service commitments are being met, etc. If you recently learned that your organization needs an audit, you are [...]

When considering HIPAA compliance, it still feels a bit like the Wild West out there right now. As an auditor, I frequently review the landscape of healthcare data security. I continue to see a significant amount of confusion among organizations of all sizes. The Office of Civil Rights (OCR) enforces fines and sanctions for HIPAA [...]

Security awareness training, also referred to as security training, is a requirement across some of the major IT compliance frameworks. Completing security awareness training may be the only time a non-IT user is reminded of IT threats and what they can do to keep themselves and their place of work safe from bad actors. Since [...]

In 2025, the California Privacy Protection Agency (CPPA) adopted regulations that implemented requirements, under the California Consumer Privacy Act (CCPA), for certain businesses to perform annual cybersecurity audits. Those regulations went into effect on January 1, 2026. This blog breaks down the CCPA cybersecurity audit regulation and highlights the core requirements that must be met. [...]

Historically, an IT compliance audit involved a physical component. An auditor would visit your company headquarters, test the weight of the server room doors, look for security cameras, and verify badge readers. But what happens when your company is 100% remote? If there are no physical doors to lock and no office buildings to secure, [...]

Many U.S. companies receive what, until recently, were called SAS 70 audit reports from certain types of vendors. These reports come out once a year, typically in the late Fall. While most organizations do a good job of recognizing the need to request these reports, often they are not properly reviewed and evaluated when received. [...]

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
I understand and agree to the Linford & Company LLP privacy policy.**