Category: Compliance Standards

Staying informed about all of the cyber security compliance standards is essential to keeping your company safe from hackers. Read on to learn about the various steps you can take to stay up to date with your industry’s compliance standards.

  • The Do’s and Don’ts of CMMC Certification

    The Do’s and Don’ts of CMMC Certification

    Technological theft, espionage, and threats to national security are becoming increasingly common concerns for the Department of Defense (DoD). In response to the rising tide of cyberattacks, the DoD has introduced a more stringent compliance framework to protect the Defense Industrial Base (DIB) supply chain. This framework is known as CMMC Certification, the new standard for contractors working with the DoD. CMMC Certification ensures that contractors meet essential cybersecurity requirements, helping safeguard sensitive information and national security.

    In this article, we’ll cover the Do’s and Don’ts of CMMC Certification, starting with a brief introduction to the model. (more…)

  • Basic Patient Data Rights Under HIPAA

    Basic Patient Data Rights Under HIPAA

    The Health Insurance Portability and Accountability Act of 1996 (HIPAA) significantly improved the healthcare industry’s cybersecurity landscape. HIPAA’s impacts went beyond the healthcare practices and associated businesses; there are also several HIPAA patient rights granted to healthcare consumers. At the most basic level, these include reasonable expectations of privacy and access. Let’s take a closer look. (more…)

  • What Is the Difference Between HIPAA vs. FERPA?

    What Is the Difference Between HIPAA vs. FERPA?

    In recent decades, public health agencies and public schools have worked hand in glove, sharing health information about students in order to better understand the broader picture of teens’ overall health. In addition, schools have increasingly sought to give their students more and better health services. Seeing as schools may keep or request sensitive health information from the students or parents, it’s natural to wonder what laws cover the security and privacy of these documents. These days, there are two major privacy laws – HIPAA and FERPA – that may or may not cover a student’s health records. Naturally, whether they do or don’t depends on your particular situation. That said, this article will attempt to wade the convoluted mire, illuminating you as to the differences between HIPAA vs FERPA. Keep reading to discover more! 

    (more…)

  • What Are the Different Levels of Cybersecurity Maturity Model Certification?

    What Are the Different Levels of Cybersecurity Maturity Model Certification?

    In 2020, Department of Defense (DoD) contractors were required to implement robust cybersecurity protocols in response to increasing security breaches. One of the most significant incidents occurred on October 4, 2018, affecting over 30,000 civilian and military contractors. To prevent future breaches, companies that handle Controlled Unclassified Information (CUI) must demonstrate that their networks and systems meet stringent security standards. Achieving this requires compliance with the applicable Cybersecurity Maturity Model Certification (CMMC) levels for the type of data they manage. Before contractors and their partners can obtain certification, they need a clear understanding of the CMMC framework and its five distinct levels.

    (more…)

  • How to Conduct CMMC Employee Training

    How to Conduct CMMC Employee Training

    Cybersecurity is a crucial concern for every business in the world. No matter the kind or size of organization, it’s always imperative to safeguard against cybercrime to prevent loss of sensitive information and other related risks, such as theft and extortion. The threats posed by hackers and other bad actors are even more significant when it comes to matters of national security.

    (more…)

  • What are the Stages of PCI DSS Compliance?

    What are the Stages of PCI DSS Compliance?

    Every organization faces unique cybersecurity challenges, which is why the PCI Compliance Levels framework is designed to provide flexibility while ensuring strong protection of cardholder data. Regardless of size or transaction volume, businesses must follow defined stages of PCI DSS compliance to validate their security posture. These stages outline the key steps every entity must take to achieve and maintain compliance across all PCI compliance levels.

    (more…)

  • Overview of CMMC Level 1 Requirements

    Overview of CMMC Level 1 Requirements

    If your organization works with the US Department of Defense (DoD), understanding the CMMC Level 1 Requirements is essential for meeting basic cybersecurity standards. In this guide, we’ll provide a clear overview of what Level 1 entails and what your team needs to do to stay compliant. This is the first part of our series on the Cybersecurity Maturity Model Certification (CMMC). For details on higher levels, check out our upcoming guides covering Levels 2, 3, 4, and 5. (more…)

  • When will CMMC 2.0 be required for DoD contracts?

    When will CMMC 2.0 be required for DoD contracts?

    CMMC 2.0 provides a robust cybersecurity framework mandated for DoD contractors, consolidating controls from key regulatory texts such as NIST SP 800-171 and SP 800-172. As organizations prepare for its implementation, understanding the distinct requirements of Levels 1 to 3 is crucial.

    While Level 1 targets Federal Contract Information (FCI), Levels 2 and 3 focus on protecting Controlled Unclassified Information (CUI) and advanced threats. Certification, facilitated by Certified Third Party Assessment Organizations (C3PAOs), will be essential for maintaining compliance and bidding on future DoD contracts.

    (more…)

  • Do Dispensaries Share Information With The Government?

    Do Dispensaries Share Information With The Government?

    Ever since California passed Proposition 64, legalizing recreational marijuana, the market has grown rapidly. More dispensaries and farmers are entering the industry, contributing to what Statista forecasts as a steady increase in sales, from $5.62 billion in 2020 to an estimated $6.59 billion by 2025. California’s projected sales account for a large portion of the national growth, which is expected to reach $8.22 billion in 2020. Despite entering the market later than states like Washington, Oregon, and Colorado, California has already surpassed them in annual sales with data privacy protection .

    With a robust medical marijuana market and a rapidly expanding recreational market, many customers are now asking: “Do dispensaries share my personal information with the government?” Understanding data privacy in the legal cannabis industry has never been more important.

    (more…)

  • How to Tell if Your Organization is a HIPAA Covered Entity

    How to Tell if Your Organization is a HIPAA Covered Entity

    If your organization works in or around the healthcare industry, you may fall under the category of a HIPAA Covered Entities,  Determining this is critical because if HIPAA applies, your organization must comply to avoid costly fines and protect patient data.

    Key takeaways:

    • Whether you qualify depends on the type of data your organization collects, stores, or transmits
    • There are three main types of HIPAA covered entities.
    • All covered entities are required to follow specific HIPAA privacy and security rules.

    Frameworks like HITRUST CSF can help organizations streamline and standardize HIPAA compliance.

    (more…)