article thumbnail

ISO 27001 Certification Requirements & Standards

Reciprocity

Perform a Gap Analysis. A gap analysis gives you a high-level summary of what needs to be done to attain certification and allows you to examine and compare your organization’s current information security arrangements to the ISO 27001 standards. Third, create a project plan and a project risk register.

Audit 52
article thumbnail

Audit Checklist for SOC 2

Reciprocity

Processing integrity: System processing is complete, valid, accurate, timely, and authorized to meet your service organization’s objectives. Communication and information. Perform a SOC 2 Gap Analysis. Once you’ve completed your audit preparation, you should perform a gap analysis.

Audit 52
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Preparation Continues for the Digital Operational Resilience Act

Fusion Risk Management

Increasingly, financial services supervisory authorities are seeking to ensure that the third parties that are supporting a firm’s important business services meet all resilience requirements. Firms are required to define their TSP risk tolerance based on each financial entity’s unique risk appetite and impact tolerances for TSP disruption.

article thumbnail

5 Steps To Developing A Corporate Compliance Program

Reciprocity

Establish two-way communication at all levels. Set the expectation that workers would communicate proactively and in a timely way, whether it is to ask compliance questions, report difficulties, or address ethical concerns. Make Compliance a Breeze with Reciprocity ROAR.

Audit 52
article thumbnail

The SEPA Cyber Attack a Case Study

Plan B Consulting

Attacks on English local authorities, such as Hackney, I believe have not been paid, but the consequence of this is that three months later they still do not have all their systems back online. It has t aken four to five weeks for SEPA to get their communications and messages sorted out.

article thumbnail

The SEPA Cyber Attack a Case Study

Plan B Consulting

Attacks on English local authorities, such as Hackney, I believe have not been paid, but the consequence of this is that three months later they still do not have all their systems back online. It has t aken four to five weeks for SEPA to get their communications and messages sorted out.