Tag controls

SOC Reporting Framework

This post introduces to System and Organization Controls (SOC) reporting framework, in the context of compliance with US American law Sarbanes-Oxley Act (SOX). Regulation Context The Sarbanes-Oxley Act (SOX or Sarbox) is a United States of America federal law. It…

Information Security Controls

This post summarizes information security or cybersecurity control inventories. List of Information Security Control Catalogues Information Security Control Catalogues: ISO/IEC 27002 ISO/IEC 27002 is officially titled “Information security, cybersecurity and privacy protection — Information security controls”, but it can be…