Compliance Perspectives

Troy Fine on Data Security Standards Audits [Podcast]


Listen Later

By Adam Turteltaub

With enhanced concerns and vigilance over cybersecurity has come an increasing number of yardsticks that organizations much measure themselves against. As Troy Fine, Director, Risk and Compliance at Drata explains, in addition to legal requirements such as the European General Data Protection Regulation (GDPR), HIPAA and the California Consumer Privacy Act (CCPA) two key standards have emerged:

* SOC2: This standard was developed by the accounting body ISACA and is primarily of import to US-based technology companies and startups. Audits are performed by CPA firms on internal controls related to security
* ISO27001: More popular in Europe, it is a certification on information security management systems, examining how risks are identified and mediated and what control plans are in place

To prepare for an audit he recommends first getting a good understanding of the relevant standard so you understand all the elements it requires and what it will take to meet those requirements. Next determine when you will need the certification in hand and start building a timeline backwards to determine when you need to start. Calculate, too, what it will cost in terms of time, people and everything else, including the price of the audit.

How you work with the auditor will depend largely on which audit you pursue. He explains that SOC2 audits allow for more consultation than ISO27001 does.

When hiring an auditor, it can be tempting to use the one with the lowest price. He recommends, though, being careful before going down that route since the auditor is likely to have less time to give.

Be sure also to ensure that the auditor has the necessary expertise to be able to evaluate your technology. Some may not be as well versed on various elements, including cloud services, as they should.

Once the audit begins, compliance teams can be helpful by ensuring that all the data and people the auditor needs are available. And, he advises, be transparent, even about your gaps.

Listen in to learn more about having a successful data security standard audit.
...more
View all episodesView all episodes
Download on the App Store

Compliance PerspectivesBy SCCE

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

34 ratings


More shows like Compliance Perspectives

View all
The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

229,674 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,687 Listeners

Wait Wait... Don't Tell Me! by NPR

Wait Wait... Don't Tell Me!

38,950 Listeners

Making Sense with Sam Harris by Sam Harris

Making Sense with Sam Harris

26,380 Listeners

Pivot by New York Magazine

Pivot

9,724 Listeners

FCPA Compliance Report by Thomas Fox

FCPA Compliance Report

20 Listeners

Up First from NPR by NPR

Up First from NPR

56,944 Listeners

Stay Tuned with Preet by Preet Bharara

Stay Tuned with Preet

32,354 Listeners

Corruption Crime & Compliance by Michael Volkov

Corruption Crime & Compliance

43 Listeners

GZERO World with Ian Bremmer by GZERO Media

GZERO World with Ian Bremmer

837 Listeners

Compliance into the Weeds by Tom Fox

Compliance into the Weeds

12 Listeners

Daily Compliance News by Tom Fox

Daily Compliance News

7 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

16,525 Listeners

On with Kara Swisher by Vox Media

On with Kara Swisher

3,538 Listeners

The Mel Robbins Podcast by Mel Robbins

The Mel Robbins Podcast

20,222 Listeners