Tag
Audit
4 articles tagged “Audit”.
-
The Compensating Controls Register Auditors Accept
You deferred a control and promised a compensating one. Here is the register entry that PCI, SOC 2, and NIST assessors sign off on instead of flagging.
-
Risk-Based Patching: How to Defend It to an Auditor
You skipped a Critical CVSS because EPSS said low-risk. Here is the evidence trail that keeps a PCI, SOC 2, or SOX auditor satisfied.
-
SOC 2 Change Management Controls and Real Audit Questions
SOC 2 change management under CC8.1, CC7.1, and CC6: what auditors actually ask, what evidence to keep, and where automation falls short.
-
SOX Change Control Checklist Mapped to Your ITSM Workflow
What SOX §404 and ITGC actually require for IT change control, mapped field-by-field to ServiceNow and Jira Service Management tickets.