SOC 2 Type II Evidence: What Auditors Actually Sample
How a SOC 2 Type II auditor samples the observation window: sample size by control frequency, population completeness, and why exceptions happen.
How a SOC 2 Type II auditor samples the observation window: sample size by control frequency, population completeness, and why exceptions happen.
The three references this desk keeps open during a change window. Each one is free, runs in your browser, and needs no account.
Sortable view of the CISA KEV catalog, with the remediation deadline attached to each entry.
Rolling 12-month calendar available in the free tool.
Combined status board across the five providers change teams care about.
A PaperCut NG/MF KEV entry put a 'boring' print server on a 14-day clock. Here is the emergency-change pattern for utility apps nobody tiered as critical.
CISA's BOD 26-04 sets a 16-row deadline table. Here is how a CAB pre-authorizes the ECAB so a 3-day KEV clock never catches you improvising.
Microsoft split a SharePoint RCE chain across two Patch Tuesdays. Here is how a CAB stages a planned emergency change for a fix you know is coming.
How a SOC 2 Type II auditor samples the observation window: sample size by control frequency, population completeness, and why exceptions happen.
PCI DSS 6.4.3 and 11.6.1 have been mandatory since March 2025. Here is how to wire payment-page script authorization into your change process.
You deferred a control and promised a compensating one. Here is the register entry that PCI, SOC 2, and NIST assessors sign off on instead of flagging.
This week's change-risk digest: 4 new CISA KEV entries with two CVSS-10 Cisco flaws, a GitHub P1 outage, PagerDuty's SRE Agent GA, and an RDS patch bug.
A record 970-plus-flaw Patch Tuesday with two exploited zero-days, MikroTik and Citrix NetScaler KEV additions, and Cloudflare Workers wobbles this week.
AI infrastructure hit the CISA KEV catalog hard this week: LiteLLM, Kestra, and JFrog joined nine new exploited CVEs. Plus SonicWall, PaperCut, and DORA.
A timeline of major Azure outages from 2018 to 2026, and why almost every one traces back to a change: a config push, a code deploy, or a key rotation.
Running an external asset view against your internal inventory once a quarter turns shadow assets into a change queue. Here is the exact process.
Metabase, Grafana, Superset and Redash hold credentials to every database they query. A change-managed SOP to get them behind SSO and off the internet.
How Vanta, Drata, and Secureframe handle custom controls, evidence automation, and auditor access — with a named weakness for each GRC platform.
Shodan, Censys, runZero, and cloud-native inventory each answer BOD 26-04's 'is it publicly exposed?' question differently. Here is how they compare.
Your scanner rates asset criticality, your CMDB has a field for it, and NIST has a standard. Here is how the three approaches actually compare.