TL,DR: FedRAMP requires cloud service providers to achieve authorization through independent third-party assessment organizations (3PAOs) before serving U.S. federal agencies, with 3 impact levels: Low (125 controls), Moderate (325 controls), and High (421 controls) Authorization follows 2 paths: Agency Authorization sponsored by a specific federal agency, or JAB Provisional Authorization reviewed by the Joint Authorization…
On May 2023, a disgruntled Tesla ex-employee used his privileges as a service technician to gain access to data of 75,735 employees, including personal details and financial information. The breach attracted a $3.3 billion fine under GDPR. While breaches due to external and unknown factors are not under an organization’s control, such incidents can be…
TL,DR: The EU-U.S. Data Privacy Framework replaces Privacy Shield and governs secure transfer of EU residents’ personal data to U.S. organizations through self-certification with the U.S. Department of Commerce The framework is built on 7 core principles: notice, choice, accountability for onward transfer, security, data integrity and purpose limitation, access, and recourse/enforcement/liability for violations Non-adherence…
TL,DR: Mixing compliance consulting and auditing creates a direct conflict of interest because auditors reviewing their own consulting work cannot objectively assess the controls they helped design or recommend The “self-review threat” means consultants turned auditors are psychologically inclined to validate earlier recommendations rather than identify genuine compliance gaps in the organization Independent auditing is…