The Linford & Company Blog is written by our very own auditors, who are experts in IT audits, information security, and compliance topics. Their auditing experience encompasses a broad spectrum of industries and organizations, and their specialized expertise can help your company or organization make the right decision for your auditing needs. Our specific areas of focus in our IT Audit & Compliance Blog include SOC 1 Audits, SOC 2 Audits, HIPAA Audits, HITRUST Certification, and FedRAMP Assessments, NIST & CMMC, and Penetration Testing.
A few months ago I got a call from a company that was certain it needed a SOC 1 report. Their largest customer had asked for one, the sales team had promised it, and the CFO wanted to know how fast we could start. Ten minutes into the conversation, I asked the question I ask [...]
A GSA nonfederal Controlled Unclassified Information (CUI) assessment is an independent review of a contractor’s system against the security and privacy requirements the GSA initially published in May 2022, with version 1 adopted in January 2026. If an organization stores, processes, or transmits CUI on a GSA contract, that organization requires a third-party attestation to [...]
HITRUST publishes an annual Trust Report. Last year, my colleague Richard Rieben gave a great breakdown on what could be learned about overall cybersecurity maturity from the 2025 report. 2026, however, has been a complex and revealing year for cybersecurity in general and the assurance space specifically, so I thought it would be good to [...]
In this continuously evolving field of Artificial Intelligence (AI), companies that use AI as part of their daily practices and customers who subscribe to services offered by providers that use AI as part of their business model are voicing concerns about this use of AI. Questions are asked. What data is being used to train [...]
This is your short answer. No federal law regulates your use of artificial intelligence technology; a few states have binding requirements, and some apply even to organizations convinced they are exempt. The state of Illinois has become the first state in the nation to require independent third-party audits of artificial intelligence safety measures, although not [...]
An audit is an independent review and verification of an organization’s assertion or claim. The assertion may be that a company follows applicable standards or rules when performing its operations, that financial statements are presented fairly, that service commitments are being met, etc. If you recently learned that your organization needs an audit, you are [...]
When considering HIPAA compliance, it still feels a bit like the Wild West out there right now. As an auditor, I frequently review the landscape of healthcare data security. I continue to see a significant amount of confusion among organizations of all sizes. The Office of Civil Rights (OCR) enforces fines and sanctions for HIPAA [...]
Security awareness training, also referred to as security training, is a requirement across some of the major IT compliance frameworks. Completing security awareness training may be the only time a non-IT user is reminded of IT threats and what they can do to keep themselves and their place of work safe from bad actors. Since [...]
Imagine using a dial-up modem to stream a 4k movie. This is an antiquated method and would take days of buffering to watch a single movie, which sounds absurd to do in a day with modern high-speed internet. Along those same lines, would you expect HIPAA Security Rule specifications, which were designed over two decades [...]
We use cookies to optimize our website and our service.
"*" indicates required fields