---
title: Truvantis Blog | Security Program (7)
description: Security Program | Insights on Cybersecurity, Privacy and Compliance best practices from our industry experts. Topics include Penetration Testing, PCI DSS v4.0.1 Compliance and Risk Management.  (7)
---

[![truvantis-logo-reverse@2x](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-reverse@2x.png?width=1117&height=250&name=truvantis-logo-reverse@2x.png "truvantis-logo-reverse@2x")](https://www.truvantis.com)

[![truvantis-logo-main@2x-1](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-main@2x-1.png?width=1117&height=250&name=truvantis-logo-main@2x-1.png "truvantis-logo-main@2x-1")](https://www.truvantis.com/)

**

# Blog

### Subscribe For Updates

### Recent Posts

#### Related Articles By Topic

[Security Program](https://www.truvantis.com/blog/tag/security-program) [vCISO](https://www.truvantis.com/blog/tag/vciso) [CISO](https://www.truvantis.com/blog/tag/ciso) [PCI DSS](https://www.truvantis.com/blog/tag/pci-dss) [SOC2](https://www.truvantis.com/blog/tag/soc2) [Penetration Testing](https://www.truvantis.com/blog/tag/penetration-testing) [Privacy](https://www.truvantis.com/blog/tag/privacy) [Risk Assessment](https://www.truvantis.com/blog/tag/risk-assessment) [CIS Controls](https://www.truvantis.com/blog/tag/cis-controls) [Red Teaming](https://www.truvantis.com/blog/tag/red-teaming) [HIPAA](https://www.truvantis.com/blog/tag/hipaa) [Threat Intelligence](https://www.truvantis.com/blog/tag/threat-intelligence) [ISO27001](https://www.truvantis.com/blog/tag/iso27001) [CCPA](https://www.truvantis.com/blog/tag/ccpa) [CPRA](https://www.truvantis.com/blog/tag/cpra) [GDPR](https://www.truvantis.com/blog/tag/gdpr) [Ransomware](https://www.truvantis.com/blog/tag/ransomware) [Red Team](https://www.truvantis.com/blog/tag/red-team) [HITRUST](https://www.truvantis.com/blog/tag/hitrust)

### Related Articles By Topic

- [Security Program (76)](https://www.truvantis.com/blog/tag/security-program)
- [vCISO (38)](https://www.truvantis.com/blog/tag/vciso)
- [CISO (35)](https://www.truvantis.com/blog/tag/ciso)
- [PCI DSS (28)](https://www.truvantis.com/blog/tag/pci-dss)
- [SOC2 (28)](https://www.truvantis.com/blog/tag/soc2)
- [Penetration Testing (27)](https://www.truvantis.com/blog/tag/penetration-testing)
- [Privacy (26)](https://www.truvantis.com/blog/tag/privacy)
- [Risk Assessment (19)](https://www.truvantis.com/blog/tag/risk-assessment)
- [CIS Controls (12)](https://www.truvantis.com/blog/tag/cis-controls)
- [Red Teaming (8)](https://www.truvantis.com/blog/tag/red-teaming)
- [HIPAA (7)](https://www.truvantis.com/blog/tag/hipaa)
- [Threat Intelligence (7)](https://www.truvantis.com/blog/tag/threat-intelligence)
- [ISO27001 (6)](https://www.truvantis.com/blog/tag/iso27001)
- [CCPA (5)](https://www.truvantis.com/blog/tag/ccpa)
- [CPRA (2)](https://www.truvantis.com/blog/tag/cpra)
- [GDPR (2)](https://www.truvantis.com/blog/tag/gdpr)
- [Ransomware (2)](https://www.truvantis.com/blog/tag/ransomware)
- [Red Team (2)](https://www.truvantis.com/blog/tag/red-team)
- [HITRUST (1)](https://www.truvantis.com/blog/tag/hitrust)

[See all](https://www.truvantis.com/blog/tag/security-program/page/7#)

[Security Program](https://www.truvantis.com/blog/tag/security-program), [Privacy](https://www.truvantis.com/blog/tag/privacy)

## [Apache Log4j Vulnerabilities vs. Cybersecurity Risk Management](https://www.truvantis.com/blog/apache-log4j-vulnerabilities-vs.-cybersecurity-risk-management)

 Apache Log4j Vulnerabilities vs. GRC On December 10, Apache released details about a Log4j-core vulnerability nicknamed "Log4Shell". It is documented in CVE-2021-44228, and rated a rare 10 out of 10 on the CVSS vulnerability rating scale. Log4j-core is a logging library that can 

[Read More **](https://www.truvantis.com/blog/apache-log4j-vulnerabilities-vs.-cybersecurity-risk-management)

<https://www.truvantis.com/blog/soc-2-compliance-understanding-value> <https://www.truvantis.com/blog/soc-2-compliance-understanding-value>

[SOC2](https://www.truvantis.com/blog/tag/soc2), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [Understanding the Business Value of SOC 2 Compliance](https://www.truvantis.com/blog/soc-2-compliance-understanding-value)

 System and Organizational Controls 2 (SOC 2) is sometimes known as Service Organization Controls. Maintained by the American Institute of Certified Public Accountants (AICPA), SOC 2 is a standard for auditing and reporting on the efficacy of 

[Read More **](https://www.truvantis.com/blog/soc-2-compliance-understanding-value)

<https://www.truvantis.com/blog/bridging-the-gap-between-cisos> <https://www.truvantis.com/blog/bridging-the-gap-between-cisos>

[SOC2](https://www.truvantis.com/blog/tag/soc2), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program), [Risk Assessment](https://www.truvantis.com/blog/tag/risk-assessment)

### [Bridging the gap between CISOs](https://www.truvantis.com/blog/bridging-the-gap-between-cisos)

 Facing the challenges of new cybersecurity and privacy laws, a sharp increase in cybersecurity litigation, and the ceaseless evolution of ransomware and cyberthreats, the role of Chief Information Security Officer (CISO) has become critical to 

[Read More **](https://www.truvantis.com/blog/bridging-the-gap-between-cisos)

<https://www.truvantis.com/blog/combating-ransomware-attacks-through-comprehensive-penetration-testing> <https://www.truvantis.com/blog/combating-ransomware-attacks-through-comprehensive-penetration-testing>

[Penetration Testing](https://www.truvantis.com/blog/tag/penetration-testing), [Security Program](https://www.truvantis.com/blog/tag/security-program), [Risk Assessment](https://www.truvantis.com/blog/tag/risk-assessment)

### [Combating Ransomware Attacks Through Comprehensive Penetration Testing](https://www.truvantis.com/blog/combating-ransomware-attacks-through-comprehensive-penetration-testing)

 Ransomware is still a major threat. In fact, the Tactics, Techniques and Procedures (TTP's) of ransomware gangs have evolved so much that it has created new business models within the darknet where premium services such as Ransomware as a Service 

[Read More **](https://www.truvantis.com/blog/combating-ransomware-attacks-through-comprehensive-penetration-testing)

<https://www.truvantis.com/blog/the-one-reason-to-pen-test-data-backup-systems-ransomware-protection> <https://www.truvantis.com/blog/the-one-reason-to-pen-test-data-backup-systems-ransomware-protection>

[CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Penetration Testing](https://www.truvantis.com/blog/tag/penetration-testing), [HIPAA](https://www.truvantis.com/blog/tag/hipaa), [Security Program](https://www.truvantis.com/blog/tag/security-program), [Risk Assessment](https://www.truvantis.com/blog/tag/risk-assessment)

### [The One Reason to Pen Test Data Backup Systems - Ransomware Protection](https://www.truvantis.com/blog/the-one-reason-to-pen-test-data-backup-systems-ransomware-protection)

 At the heart of your disaster recovery plan, organizations often disregard data backup and recovery systems when it comes to pen testing and maintaining security. Vulnerable backup systems make for an attractive target by ransomware gangs, grief/ 

[Read More **](https://www.truvantis.com/blog/the-one-reason-to-pen-test-data-backup-systems-ransomware-protection)

<https://www.truvantis.com/blog/the-0-day-in-the-room-nobody-is-talking-about-scope> <https://www.truvantis.com/blog/the-0-day-in-the-room-nobody-is-talking-about-scope>

[PCI DSS](https://www.truvantis.com/blog/tag/pci-dss), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Penetration Testing](https://www.truvantis.com/blog/tag/penetration-testing), [HIPAA](https://www.truvantis.com/blog/tag/hipaa), [Security Program](https://www.truvantis.com/blog/tag/security-program), [Risk Assessment](https://www.truvantis.com/blog/tag/risk-assessment), [Red Teaming](https://www.truvantis.com/blog/tag/red-teaming)

### [The 0-day in the Room Nobody is Talking About: Scope](https://www.truvantis.com/blog/the-0-day-in-the-room-nobody-is-talking-about-scope)

 Scope is an important shaping tool that, when leveraged properly, can help enhance engagement outcomes during penetration testing, red team and other security operations. Like any tool, however, when used incorrectly it can have devastating 

[Read More **](https://www.truvantis.com/blog/the-0-day-in-the-room-nobody-is-talking-about-scope)

<https://www.truvantis.com/blog/do-you-have-apis-how-do-you-test-them> <https://www.truvantis.com/blog/do-you-have-apis-how-do-you-test-them>

[Penetration Testing](https://www.truvantis.com/blog/tag/penetration-testing), [Security Program](https://www.truvantis.com/blog/tag/security-program), [CCPA](https://www.truvantis.com/blog/tag/ccpa), [ISO27001](https://www.truvantis.com/blog/tag/iso27001)

### [Do you have APIs? How do you test them?](https://www.truvantis.com/blog/do-you-have-apis-how-do-you-test-them)

 Application Program Interfaces (APIs) have changed in nature in recent years and are increasingly (and sometimes inadvertently) being made available to users of web services, the “Apps” (applications) on mobile devices, and internally for the web 

[Read More **](https://www.truvantis.com/blog/do-you-have-apis-how-do-you-test-them)

<https://www.truvantis.com/blog/using-a-vciso-service-to-achieve-and-retain-a-soc2-certification> <https://www.truvantis.com/blog/using-a-vciso-service-to-achieve-and-retain-a-soc2-certification>

[SOC2](https://www.truvantis.com/blog/tag/soc2), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [Using a vCISO Service to Achieve and Retain a SOC 2 Certification](https://www.truvantis.com/blog/using-a-vciso-service-to-achieve-and-retain-a-soc2-certification)

 CSO Online, which knows plenty about what goes into ensuring security, makes a strong case for hiring a virtual Chief Information Security Officer (vCISO). It notes that fulltime CISOs “can be hard to come by, often stay in their job for two years 

[Read More **](https://www.truvantis.com/blog/using-a-vciso-service-to-achieve-and-retain-a-soc2-certification)

<https://www.truvantis.com/blog/11-steps-to-achieve-soc-2-compliance> <https://www.truvantis.com/blog/11-steps-to-achieve-soc-2-compliance>

[SOC2](https://www.truvantis.com/blog/tag/soc2), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [Video | 11 Steps to Achieve SOC 2 Compliance](https://www.truvantis.com/blog/11-steps-to-achieve-soc-2-compliance)

 Are you looking to start your SOC 2 Audit for this year? Here is a video that will guide you through your first SOC 2 audit using 11 steps. Overview Your customers have probably asked for your SOC 2 report, or it may be required to seal the deal on 

[Read More **](https://www.truvantis.com/blog/11-steps-to-achieve-soc-2-compliance)

<https://www.truvantis.com/blog/using-cyber-security-to-enable-sales> <https://www.truvantis.com/blog/using-cyber-security-to-enable-sales>

[SOC2](https://www.truvantis.com/blog/tag/soc2), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program), [Privacy](https://www.truvantis.com/blog/tag/privacy)

### [Using Cyber Security to Enable Sales](https://www.truvantis.com/blog/using-cyber-security-to-enable-sales)

 Information security and privacy programs are generally about managing risk, but they can also impact your sales team by either slowing down or speeding up deals. 

[Read More **](https://www.truvantis.com/blog/using-cyber-security-to-enable-sales)

[Previous](https://www.truvantis.com/blog/tag/security-program/page/6) [Next](https://www.truvantis.com/blog/tag/security-program/page/8)

<https://www.truvantis.com/blog/apache-log4j-vulnerabilities-vs.-cybersecurity-risk-management> <https://www.truvantis.com/blog/apache-log4j-vulnerabilities-vs.-cybersecurity-risk-management>

[Security Program](https://www.truvantis.com/blog/tag/security-program), [Privacy](https://www.truvantis.com/blog/tag/privacy)

### [1 Apache Log4j Vulnerabilities vs. Cybersecurity Risk Management](https://www.truvantis.com/blog/apache-log4j-vulnerabilities-vs.-cybersecurity-risk-management)

 Apache Log4j Vulnerabilities vs. GRC On December 10, Apache released details about a Log4j-core vulnerability nicknamed "Log4Shell". It is ... 

[Read More **](https://www.truvantis.com/blog/apache-log4j-vulnerabilities-vs.-cybersecurity-risk-management)

<https://www.truvantis.com/blog/soc-2-compliance-understanding-value> <https://www.truvantis.com/blog/soc-2-compliance-understanding-value>

[SOC2](https://www.truvantis.com/blog/tag/soc2), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [2 Understanding the Business Value of SOC 2 Compliance](https://www.truvantis.com/blog/soc-2-compliance-understanding-value)

 System and Organizational Controls 2 (SOC 2) is sometimes known as Service Organization Controls. Maintained by the American Institute of ... 

[Read More **](https://www.truvantis.com/blog/soc-2-compliance-understanding-value)

<https://www.truvantis.com/blog/bridging-the-gap-between-cisos> <https://www.truvantis.com/blog/bridging-the-gap-between-cisos>

[SOC2](https://www.truvantis.com/blog/tag/soc2), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program), [Risk Assessment](https://www.truvantis.com/blog/tag/risk-assessment)

### [3 Bridging the gap between CISOs](https://www.truvantis.com/blog/bridging-the-gap-between-cisos)

 Facing the challenges of new cybersecurity and privacy laws, a sharp increase in cybersecurity litigation, and the ceaseless evolution of ... 

[Read More **](https://www.truvantis.com/blog/bridging-the-gap-between-cisos)

<https://www.truvantis.com/blog/combating-ransomware-attacks-through-comprehensive-penetration-testing> <https://www.truvantis.com/blog/combating-ransomware-attacks-through-comprehensive-penetration-testing>

[Penetration Testing](https://www.truvantis.com/blog/tag/penetration-testing), [Security Program](https://www.truvantis.com/blog/tag/security-program), [Risk Assessment](https://www.truvantis.com/blog/tag/risk-assessment)

### [4 Combating Ransomware Attacks Through Comprehensive Penetration Testing](https://www.truvantis.com/blog/combating-ransomware-attacks-through-comprehensive-penetration-testing)

 Ransomware is still a major threat. In fact, the Tactics, Techniques and Procedures (TTP's) of ransomware gangs have evolved so much that it has ... 

[Read More **](https://www.truvantis.com/blog/combating-ransomware-attacks-through-comprehensive-penetration-testing)

<https://www.truvantis.com/blog/the-one-reason-to-pen-test-data-backup-systems-ransomware-protection> <https://www.truvantis.com/blog/the-one-reason-to-pen-test-data-backup-systems-ransomware-protection>

[CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Penetration Testing](https://www.truvantis.com/blog/tag/penetration-testing), [HIPAA](https://www.truvantis.com/blog/tag/hipaa), [Security Program](https://www.truvantis.com/blog/tag/security-program), [Risk Assessment](https://www.truvantis.com/blog/tag/risk-assessment)

### [5 The One Reason to Pen Test Data Backup Systems - Ransomware Protection](https://www.truvantis.com/blog/the-one-reason-to-pen-test-data-backup-systems-ransomware-protection)

 At the heart of your disaster recovery plan, organizations often disregard data backup and recovery systems when it comes to pen testing and ... 

[Read More **](https://www.truvantis.com/blog/the-one-reason-to-pen-test-data-backup-systems-ransomware-protection)

<https://www.truvantis.com/blog/the-0-day-in-the-room-nobody-is-talking-about-scope> <https://www.truvantis.com/blog/the-0-day-in-the-room-nobody-is-talking-about-scope>

[PCI DSS](https://www.truvantis.com/blog/tag/pci-dss), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Penetration Testing](https://www.truvantis.com/blog/tag/penetration-testing), [HIPAA](https://www.truvantis.com/blog/tag/hipaa), [Security Program](https://www.truvantis.com/blog/tag/security-program), [Risk Assessment](https://www.truvantis.com/blog/tag/risk-assessment), [Red Teaming](https://www.truvantis.com/blog/tag/red-teaming)

### [6 The 0-day in the Room Nobody is Talking About: Scope](https://www.truvantis.com/blog/the-0-day-in-the-room-nobody-is-talking-about-scope)

 Scope is an important shaping tool that, when leveraged properly, can help enhance engagement outcomes during penetration testing, red team and ... 

[Read More **](https://www.truvantis.com/blog/the-0-day-in-the-room-nobody-is-talking-about-scope)

<https://www.truvantis.com/blog/do-you-have-apis-how-do-you-test-them> <https://www.truvantis.com/blog/do-you-have-apis-how-do-you-test-them>

[Penetration Testing](https://www.truvantis.com/blog/tag/penetration-testing), [Security Program](https://www.truvantis.com/blog/tag/security-program), [CCPA](https://www.truvantis.com/blog/tag/ccpa), [ISO27001](https://www.truvantis.com/blog/tag/iso27001)

### [7 Do you have APIs? How do you test them?](https://www.truvantis.com/blog/do-you-have-apis-how-do-you-test-them)

 Application Program Interfaces (APIs) have changed in nature in recent years and are increasingly (and sometimes inadvertently) being made ... 

[Read More **](https://www.truvantis.com/blog/do-you-have-apis-how-do-you-test-them)

<https://www.truvantis.com/blog/using-a-vciso-service-to-achieve-and-retain-a-soc2-certification> <https://www.truvantis.com/blog/using-a-vciso-service-to-achieve-and-retain-a-soc2-certification>

[SOC2](https://www.truvantis.com/blog/tag/soc2), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [8 Using a vCISO Service to Achieve and Retain a SOC 2 Certification](https://www.truvantis.com/blog/using-a-vciso-service-to-achieve-and-retain-a-soc2-certification)

 CSO Online, which knows plenty about what goes into ensuring security, makes a strong case for hiring a virtual Chief Information Security ... 

[Read More **](https://www.truvantis.com/blog/using-a-vciso-service-to-achieve-and-retain-a-soc2-certification)

<https://www.truvantis.com/blog/11-steps-to-achieve-soc-2-compliance> <https://www.truvantis.com/blog/11-steps-to-achieve-soc-2-compliance>

[SOC2](https://www.truvantis.com/blog/tag/soc2), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [9 Video | 11 Steps to Achieve SOC 2 Compliance](https://www.truvantis.com/blog/11-steps-to-achieve-soc-2-compliance)

 Are you looking to start your SOC 2 Audit for this year? Here is a video that will guide you through your first SOC 2 audit using 11 steps. ... 

[Read More **](https://www.truvantis.com/blog/11-steps-to-achieve-soc-2-compliance)

<https://www.truvantis.com/blog/using-cyber-security-to-enable-sales> <https://www.truvantis.com/blog/using-cyber-security-to-enable-sales>

[SOC2](https://www.truvantis.com/blog/tag/soc2), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program), [Privacy](https://www.truvantis.com/blog/tag/privacy)

### [10 Using Cyber Security to Enable Sales](https://www.truvantis.com/blog/using-cyber-security-to-enable-sales)

 Information security and privacy programs are generally about managing risk, but they can also impact your sales team by either slowing down or ... 

[Read More **](https://www.truvantis.com/blog/using-cyber-security-to-enable-sales)

[Previous](https://www.truvantis.com/blog/tag/security-program/page/6) [All posts](https://www.truvantis.com/blog/all) [Next](https://www.truvantis.com/blog/tag/security-program/page/8)

[![truvantis-logo-white@2x-1](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-white@2x-1.png?width=1117&height=250&name=truvantis-logo-white@2x-1.png "truvantis-logo-white@2x-1")](https://www.truvantis.com/)

[info@truvantis.com](mailto:info@truvantis.com)

+1 (415) 422-9844

<https://www.facebook.com/truvantis> <https://www.linkedin.com/company/truvantis> <https://twitter.com/truvantis?lang=en>

© 2024 Truvantis, Inc All Rights Reserved.

[Privacy Policy](https://www.truvantis.com/privacy-policy)    [Terms of Service ](https://www.truvantis.com/terms-of-service)

![](https://px.ads.linkedin.com/collect/?pid=2614233&fmt=gif) ![](https://ws.zoominfo.com/pixel/dnjpprEKcMtv41HRInFR)

```json
{
  "@context" : "https://schema.org",
  "@type" : "VideoObject",
  "caption" : {
    "@type" : "MediaObject",
    "contentUrl" : "https://www.truvantis.com/media-transcripts/39272429473/en.vtt",
    "inLanguage" : "en",
    "name" : "en Captions"
  },
  "contentUrl" : "https://4366475.fs1.hubspotusercontent-na2.net/hubfs/4366475/Podcasts%20or%20Vlogs/SOC%202%20(2).mov",
  "dateModified" : "2026-06-03T18:35:19.008Z",
  "description" : "",
  "duration" : "PT4M46.153S",
  "height" : 1080,
  "name" : "SOC 2 (2)",
  "thumbnailUrl" : "https://api-na2.hubspot.com/filemanager/api/v3/files/thumbnail-redirect/39272429473?portalId=4366475&size=medium",
  "uploadDate" : "2020-12-28T19:28:58.131Z",
  "width" : 1920
}
```