Autora: Anwita

Anwita es una apasionada de la ciberseguridad y bloguera veterana. Su amor por todo lo relacionado con la ciberseguridad la impulsó a adentrarse en el mundo del cumplimiento normativo. Con múltiples certificaciones en ciberseguridad, busca simplificar temas complejos relacionados con la seguridad para todo tipo de público. Le encanta leer no ficción, escuchar rock progresivo y ver comedias de situación los fines de semana.
    Gestión del cambio SOC 2
    ,
    Gestión del cambio según SOC 2: Política, proceso y mejores prácticas
    TL,DR: SOC 2 change management establishes policies and procedures for service organizations to implement changes within their IT environment while mitigating risks and meeting audit requirements under Common Criteria 8.1 Organizations must authorize, design, develop, test, approve, and implement changes to data, software, or processes with full documentation including the reason for change, authorizing entity,…
    ISO 27001 para startups
    ,
    Cómo obtener la certificación ISO 27001 para startups (Guía gratuita)
    TL;DR ISO 27001 is not an easy framework to understand, especially for startups new to compliance. It is not quite straightforward and does not provide checklists and examples to make your job easy. But without ISO 27001, startups lose out on a ton of growth opportunities.  To address this, we’ve drafted this article to bridge…
    Cumplimiento con las normas NIST: Una guía completa
    ,
    Cumplimiento con las normas NIST: Una guía completa
    TL,DR: NIST compliance means aligning security practices with standards from the National Institute of Standards and Technology. The article focuses on who needs NIST, common controls, costs, and security expectations. Use it to understand NIST 800-series requirements for federal systems and related programs. NIST asserts significant influence on a number of standards. It provides a…
    PCI DSS compensating controls
    ,
    A Detailed Overview Of PCI DSS Compensating Controls
    If your business handles, stores, transmits, manages, or processes customers’ payment card information, it must comply with PCI DSS (Payment Card Industry Data Security Standard). This is an information security standard that outlines measures and controls for organizations to protect sensitive card details while processing transactions.  Implementing stringent compliance is not a piece of cake…