Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # TrustCommunity: The #1 Community for Security, Privacy, and GRC Professionals ## Sitemaps [XML Sitemap](https://community.trustcloud.ai/sitemap_index.xml): Includes all crawlable and indexable pages. ## Forums - [Welcome](https://community.trustcloud.ai/tcf/forum/welcome/): Welcome to TrustCommunity! - [TrustCloud Q&A](https://community.trustcloud.ai/tcf/forum/trustcloud/) - [GRC Q&A](https://community.trustcloud.ai/tcf/forum/grc/) ## Topics - [Requesting to add a few systems and platforms](https://community.trustcloud.ai/tcf/topic/requesting-to-add-a-few-systems-and-platforms/): 1. We need to be able to add DigitalOcean and Hetzner as cloud providers. - [Excluded controls](https://community.trustcloud.ai/tcf/topic/excluded-controls/): Is it possible to exclude controls from the scope of a SOC-2 assessment? If so, how and where would I find these excluded controls? (I'm aware that you can assign a control as planned.) - [Buildkite Issues](https://community.trustcloud.ai/tcf/topic/buildkite-issues/): Buildkite Integration broken. Has anyone reported or had any luck integrating this into trustcloud ? - [How to add exception in case of automated test which is bound to fail?](https://community.trustcloud.ai/tcf/topic/how-to-add-exception-in-case-of-automated-test-which-is-bound-to-fail/): I have an automated test for Microsoft Entra ID regarding "Minimum password length" that is currently showing as Failed. The test report itself acknowledges this is a known platform limitation, stating: " The test always fails, because Azure AD password policies default setting is 8 for password minimum length, that cannot be changed, so test never meet the password minimum 12 length criteria." How do I properly document this in Trustcloud? I need to: Add an exception/compensating controls for this test Upload evidence showing our compensating controls (MFA, Conditional Access, Password Protection, etc.) Change the status from "Failed" to "Risk Accepted" or similar I cannot leave this as a failing test for my SOC2 audit when it's an acknowledged Microsoft platform limitation. What I need to know: Where in the Trustcloud interface can I add an exception for this automated test? What is the proper workflow for documenting compensating controls? Can automated tests be marked as "Accepted Risk with Compensating Controls"? Do I need to upload specific evidence files, or is there a form to fill out? Please advise on the recommended approach for handling automated tests that fail due to third-party platform limitations beyond our control. Thank you! - [Requesting an app integreation](https://community.trustcloud.ai/tcf/topic/requesting-an-app-integreation/): It would be great to add a linear integration that automates tasks the same as jira. Letting you know this would be a high value app. - [GCP integration doesn’t follow best practices](https://community.trustcloud.ai/tcf/topic/gcp-integration-doesnt-follow-best-practices/): We're testing out trustcloud. It looks like a good option for us. We're on GCP and when I went to follow TrustCloud's integration instructions and GCP and ran into my first big issue. - [SOC 2 Type 1 Minimum Requirements](https://community.trustcloud.ai/tcf/topic/soc-2-type-1-minimum-requirements/): We are a small startup with <10 employees requiring SOC 2 Type 1 in the coming year. We are using the free service to obtain this certification. I see the list in my portal showing what is needed for SOC 2 but it does not seem to be divided into what is required to meet just SOC 2 Type 1. Has anyone encountered this and can point me in the right direction? It's my first time working in this space. - [OpenAPI/swagger JSON](https://community.trustcloud.ai/tcf/topic/openapi-swagger-json/): Hello, - [Adding a system](https://community.trustcloud.ai/tcf/topic/adding-a-system/): Hi all. I'm trying to add a new system for my stack - one that isn't already on Trustcloud. How long does it take for these to pull through? I'm keen to press on with using Trustcloud, but am reluctant to invest time if it cannot be done. For interest, the two services are AWS Bedrock and AssemblyAI. Thanks - [Uncategorized system: TrustCloud](https://community.trustcloud.ai/tcf/topic/uncategorized-system-trustcloud/): Hi there, I'm setting up controls and tests for each of my policies for the first time, and it seems that most tests show a fail on TrustCloud as an uncategorized system. Great if someone can explain why I only see this problem with TrustCloud, and what I should do to correct the situation. Thanks! - [Removing an integration](https://community.trustcloud.ai/tcf/topic/removing-an-integration/): How do I remove an integration that is no longer applicable? - [Organization Page Greyed Out](https://community.trustcloud.ai/tcf/topic/organization-page-greyed-out/): The organisation page won't let me define my organisation's structure. Is this a glitch, or am I missing something? - [Delete Group](https://community.trustcloud.ai/tcf/topic/delete-group/): How can I delete group ? - [Add employee](https://community.trustcloud.ai/tcf/topic/add-employee/): How to add many employee at once ? Platform only allows to add single employee at times. Please guide. - [Compliance program and sales – correlation](https://community.trustcloud.ai/tcf/topic/compliance-program-and-sales-correlation/): How can having a compliance program help my sales team? - [Changing the company name in TrustCloud](https://community.trustcloud.ai/tcf/topic/changing-the-company-name-in-trustcloud/): How can I change my company's name in TrustCloud? - [Roles and access rights to configure integrations](https://community.trustcloud.ai/tcf/topic/roles-and-access-rights-to-configure-integrations/): What type of access do you need to configure integrations? - [Maintaining accurate and up-to-date compliance records](https://community.trustcloud.ai/tcf/topic/maintaining-accurate-and-up-to-date-compliance-records/): How does TrustOps help in maintaining accurate and up-to-date compliance records? - [Responding to security questionnaires from enterprise clients quickly](https://community.trustcloud.ai/tcf/topic/responding-to-security-questionnaires-from-enterprise-clients-quickly/): As a vendor, how can we streamline the process of responding to security questionnaires from enterprise clients without slowing down deals? - [Assess and monitor high-risk vendors](https://community.trustcloud.ai/tcf/topic/assess-and-monitor-high-risk-vendors/): How can I assess and monitor high-risk vendors, ensuring compliance and minimizing potential security threats? - [Importing an existing risk register into TrustRegister](https://community.trustcloud.ai/tcf/topic/importing-an-existing-risk-register-into-trustregister/): What are the best practices for importing an existing risk register into TrustRegister, and how can I ensure that all risk details, such as categories and mitigation plans, are accurately mapped during the transition? - [AUP template](https://community.trustcloud.ai/tcf/topic/aup-template/): Could you share a template for Acceptable Use Policy? - [Background checks](https://community.trustcloud.ai/tcf/topic/background-checks/): Does TrustCloud facilitate background checks? - [Information security policy](https://community.trustcloud.ai/tcf/topic/information-security-policy/): Does every vendor need an information security policy that is documented? Where can one find it? - [ISO 27001 vs SOC 2](https://community.trustcloud.ai/tcf/topic/iso-27001-vs-soc-2/): Can I achieve everything that I can with ISO 27001 with SOC 2 as well? - [How does TrustCloud manage vendor risks?](https://community.trustcloud.ai/tcf/topic/how-does-trustcloud-manage-vendor-risks/): How does TrustCloud manage vendor risks? - [Test exclusion in TrustOps](https://community.trustcloud.ai/tcf/topic/test-exclusion-in-trustops/): What does test exclusion do? - [Version history of Policies](https://community.trustcloud.ai/tcf/topic/version-history-of-policies/): Can I view version history of policies? - [Exporting my risk register](https://community.trustcloud.ai/tcf/topic/exporting-my-risk-register/): Can I export my risk register? - [Controls with monthly frequency that doesn’t make much sense](https://community.trustcloud.ai/tcf/topic/controls-with-monthly-frequency-that-doesnt-make-much-sense/): Hi! - [SOC 2 checklist vs. Trust Cloud documentation](https://community.trustcloud.ai/tcf/topic/soc-2-checklist-vs-trust-cloud-documentation/): What is the relationship between the SOC 2 checklist you provided and the online information we compile in Trust Cloud? See: https://community.trustcloud.ai/docs/grc-launchpad/soc-2/successful-soc-2-program-checklist. Do we need to provide answers to each item in the check-list in a separate document? - [Where to identify people, processes, and technology for SOC Type 1](https://community.trustcloud.ai/tcf/topic/where-to-identify-people-processes-and-technology-for-soc-type-1/): Where to identify people, processes, and technology for SOC Type 1? People: We have assigned people and groups to policies, systems, and vendors, and have an org chart on our Notion page. Is there anything else we need to do? Processes: We have policies that document our processes, and documented processes on our Notion wiki. Do we need to link these in the policy os is this sufficient? Technology: We have identified all our systems in the TC inventory, that's sufficient, correct? - [Ability to view SOC 2 controls by criteria](https://community.trustcloud.ai/tcf/topic/ability-to-view-soc-2-controls-by-criteria/): We would like to focus on SOC 2 controls for 3 trust criteria: Security, Privacy, and Confidentiality. But it looks like Security and Privacy are grouped together and Confidentiality sits in the optional bucket. Is there a way to see what is involved in each category so we can prioritize our work? How do we select the three criteria: Security, Privacy, and Confidentiality. - [Bitbucket Integration Giving Error While Running Role Based Access Control](https://community.trustcloud.ai/tcf/topic/bitbucket-integration-giving-error-while-running-role-based-access-control-2/): Can anyone assist? - [Controls failing when data is correct](https://community.trustcloud.ai/tcf/topic/controls-failing-when-data-is-correct/): Hello, - [Free Trust Center](https://community.trustcloud.ai/tcf/topic/free-trust-center/): Why is the Trust Center offered for free? Are there any limitations to the free offering? - [GMail and HIPAA Compliance](https://community.trustcloud.ai/tcf/topic/hipaa-compliance/): Is Gmail HIPAA compliant? - [Financial institutions against AI-related risks](https://community.trustcloud.ai/tcf/topic/financial-institutions-against-ai-related-risks/): What steps can financial institutions take to safeguard against AI-related risks? - [HITRUST and R2](https://community.trustcloud.ai/tcf/topic/hitrust-and-r2/): Does your support for HITRUST include R2? If not, is that on your roadmap for 2025? - [Policy update and re-approval](https://community.trustcloud.ai/tcf/topic/policy-update-and-re-approval/): If any changes are made to the existing policy and are published, does it need to be re-approved? - [TrustShare collaborator role](https://community.trustcloud.ai/tcf/topic/trustshare-collaborator-role/): How do I invite a new user with the "TrustShare Collaborator" role? I can only add "TrustShare Admin" from the Teams -> "Platform Administration" -> "Roles Setting" page. Is it because I have a "Compliance Admin" role? - [Integration with vulnerability scanning tools](https://community.trustcloud.ai/tcf/topic/integration-with-vulnerability-scanning-tools/): How does TrustCloud help integration with vulnerability scanning tools to automate vulnerability identification, prioritization, and remediation tracking? - [Effective cybersecurity measures with data centers](https://community.trustcloud.ai/tcf/topic/effective-cybersecurity-measures-with-data-centers/): How can data centers implement effective cybersecurity measures in a multi-cloud environment? - [Customizable corporate branding with TrustCloud](https://community.trustcloud.ai/tcf/topic/customizable-corporate-branding-with-trustcloud/): What customizable configurations does TrustCloud provide to compliance administrators for aligning with corporate branding? - [Risk Assessment Report](https://community.trustcloud.ai/tcf/topic/risk-assessment-report/): What is a risk assessment report? What information should it include? - [Remove an Integration](https://community.trustcloud.ai/tcf/topic/remove-an-integration/): I cannot find a way to remove an integration that was added. I mistakenly added an integration we do not have and now it's just hanging out, waiting to be integrated. Also, if we no longer are using a service, I'd imagine we'd have to remove in those cases as well. - [How do managed service providers ensure data security and compliance?](https://community.trustcloud.ai/tcf/topic/how-do-managed-service-providers-ensure-data-security-and-compliance/): I can be a security officer inside a particular company or I can be a third-party that is operating security operations on behalf of my clients, how can both of them ensure the digital assets are well secured. - [Add wasabi.com system please](https://community.trustcloud.ai/tcf/topic/add-wasabi-com-system-please/): We've requested adding Wasabi (https://wasabi.com/) a while back and this still has not happened. Can someone from TrustCloud look into this? Thank you - [Getting leadership to support new budget / procedure to reduce risk](https://community.trustcloud.ai/tcf/topic/getting-leadership-to-support-new-budget-procedure-to-reduce-risk/): Any advice on how I can get a buy in from leadership to support new budget / procedure to reduce risk - [Standards for third-party risk management platforms](https://community.trustcloud.ai/tcf/topic/standards-for-third-party-risk-management-platforms/): What are the new standards for third-party risk management platforms? - [How to link to my privacy policy or ToS from TrustShare](https://community.trustcloud.ai/tcf/topic/how-to-link-to-my-privacy-policy-or-tos-from-trustshare/): I've uploaded my privacy policy and ToS but how can I share a link? A reviewer is asking to see it. - [Audit readiness for multiple infosec and data security standards](https://community.trustcloud.ai/tcf/topic/audit-readiness-for-multiple-infosec-and-data-security-standards/): What are the benefits of achieving audit readiness for multiple infosec and data security standards simultaneously? - [Implementation and gap analysis of controls](https://community.trustcloud.ai/tcf/topic/implementation-and-gap-analysis-of-controls/): How does TrustOps simplify the implementation and gap analysis of controls? - [Expert advice on helping with evidence](https://community.trustcloud.ai/tcf/topic/expert-advice-on-helping-with-evidence/): If I need more information on what evidence is relevant, can I get an expert to help me? - [Systems and scope of audit](https://community.trustcloud.ai/tcf/topic/systems-and-scope-of-audit/): How do I know what systems should be brought into scope for my audit? - [Consequences of non-compliance](https://community.trustcloud.ai/tcf/topic/consequences-of-non-compliance/): What are the consequences of non-compliance, and how can I avoid them? - [TrustShare – what do the green lights indicate?](https://community.trustcloud.ai/tcf/topic/trustshare-what-do-the-green-lights-indicate/): What are the green lights meant to indicate? We see a lot of green lights even for things that we haven't completed yet so it doesn't show that we're "in compliance". How can we make it such that the dashboard will show the controls and other aspects that we've already completed/comply with? Many thanks! - [Accelerate compliance certifications](https://community.trustcloud.ai/tcf/topic/accelerate-compliance-certifications/): I noticed my compliance program has several controls around risk management. Will TrustRegister automate some of these controls? - [Residual risk calculation](https://community.trustcloud.ai/tcf/topic/residual-risk-calculation/): How is residual risk calculated? - [Number of frameworks in my TrustOps](https://community.trustcloud.ai/tcf/topic/number-of-frameworks-in-my-trustops/): How many frameworks can I have in my TrustOps? - [Exporting controls](https://community.trustcloud.ai/tcf/topic/exporting-controls/): How do I export my controls to a file? - [Change user role](https://community.trustcloud.ai/tcf/topic/change-user-role/): I have a current collaborator that is assigned as a group owner but I need to change to a Compliance Admin. How do I do this? - [Implementing custom frameworks](https://community.trustcloud.ai/tcf/topic/implementing-custom-frameworks/): When should I consider implementing custom frameworks? - [How long does it take for new systems to be added?](https://community.trustcloud.ai/tcf/topic/how-long-does-it-take-for-new-systems-to-be-added/): Hi there, - [How much does an ISO 27001 audit cost?](https://community.trustcloud.ai/tcf/topic/how-much-does-an-iso-27001-audit-cost/): How much does an ISO 27001 audit cost? - [Linking my TrustShare to my website](https://community.trustcloud.ai/tcf/topic/linking-my-trustshare-to-my-website/): How can I link my TrustShare to my website? - [Why HR-9 and HR-20 are duplicated?](https://community.trustcloud.ai/tcf/topic/why-hr-9-and-hr-20-are-duplicated/): I am trying to complete the parameters of the HR-9 Board of Directors and HR-20 Board Oversight controls and I see that they are the same even the documentation of both is just a copy. - [Rename a user account](https://community.trustcloud.ai/tcf/topic/rename-a-user-account/): I made a mistake when creating an account. Before the user accepted the invitatio, I removed the account and recreated it with the correct name (using the original email address). However, the old name still appeared when I made that person the owner of a policy. Is there a way to correct this? - [How do I change the user email that is used for login?](https://community.trustcloud.ai/tcf/topic/how-do-i-change-the-user-email-that-is-used-for-login/): How do I change the user email that is used for login? - [Inability to customize automated tests?](https://community.trustcloud.ai/tcf/topic/inability-to-customize-automated-tests/): Unlike other platforms, Trustcloud does not seem to have the ability to create custom tests, or modify existing ones, unless I am missing it... - [Inconsistent and inflexible mapping of controls to systems](https://community.trustcloud.ai/tcf/topic/inconsistent-and-inflexible-mapping-of-controls-to-systems/): This seems a major flaw, which is a pity as I like most of Trustcloud over other systems I am evaluating... - [Backup region replication test for DynamoDB confusion](https://community.trustcloud.ai/tcf/topic/backup-region-replication-test-for-dynamodb-confusion/): What exactly does the "Backup region replication" test for DynamoDB tests? - [No AUTH-17 control?](https://community.trustcloud.ai/tcf/topic/no-auth-17-control/): I am just getting into Trustcloud, for SOC2. Some systems I added - e.g. Carta, for Cap table management, you have listed as a service, but when I classify them as "Company restricted", I get absolutely no controls mapped to them, and hence no tests, not even manual attestations. Which is not very useful. - [Render system](https://community.trustcloud.ai/tcf/topic/render-system/): Is your Render system for Render.com PaaS? It's missing an icon! Do you plan adding integrations for it like for Heroku? - [re: MDMs, Miradore.com](https://community.trustcloud.ai/tcf/topic/re-mdms-miradore-com/): How do we integrate our MDM into TrustCloud for asset management? We use Miradore (https://www.miradore.com/platforms/macos-management/) - [re: Heroku Postgres Backups vs. Continuous Protection](https://community.trustcloud.ai/tcf/topic/re-heroku-postgres-backups-vs-continuous-protection/): Heroku Postgres provides "Continuous Protection" which is better than backups: - [Having multiple policy owners](https://community.trustcloud.ai/tcf/topic/having-multiple-policy-owners/): Can I have multiple Policy owners? - [re: Heroku integrations](https://community.trustcloud.ai/tcf/topic/re-heroku-integrations/): I see that for Heroku we have to do self-assessments. Is the Heroku integration on your roadmap so that some or all tests can be automated? - [Test Name: Single sign-on configuration](https://community.trustcloud.ai/tcf/topic/test-name-single-sign-on-configuration/): NEED HELP HOW TO SET THIS UP WE ARE USING AZURE CLOUD AND NEED TO PASS THIS SELF ASSESSMENT FOR AZURE AD/ MICROSOFT ENTRA ID ON TRUSTCLOUD - [Servers that are not AWS/Google/Azure Cloud](https://community.trustcloud.ai/tcf/topic/servers-that-are-not-aws-google-azure-cloud/): Hello, - [NEED HELP WITH TEST OF MINIMUM PASSWORD LENGHT](https://community.trustcloud.ai/tcf/topic/need-help-with-test-of-minimum-password-lenght/): What does this test do? The test always fail, because Azure AD password policies default setting is 8 for password minimum length, that cannot be changed, so test never meet the password minimum 12 length criteria. - [Multiple documents uploaded as evidence](https://community.trustcloud.ai/tcf/topic/multiple-documents-uploaded-as-evidence/): I have multiple documents to upload as evidence for one control when I created a bucket using >TrustOps>Program>Documents>+Add Document all of the items uploaded did not save nor add to the system as new document. How can I add multiple documents under one control as evidence? - [NIST-CSF and CMMC](https://community.trustcloud.ai/tcf/topic/nist-csf-and-cmmc/): How do I choose between NIST-CSF and CMMC? How can I determine which one is a better fit for my organization? - [Do I need to review controls regularly?](https://community.trustcloud.ai/tcf/topic/do-i-need-to-review-controls-regularly/): Do I need to review controls regularly? - [Do you have FAIR on your roadmap?](https://community.trustcloud.ai/tcf/topic/do-you-have-fair-on-your-roadmap/): Do you have FAIR on your roadmap? - [exporting report as CSV or sheets](https://community.trustcloud.ai/tcf/topic/exporting-report-as-csv-or-sheets/): Can I export reports or data from TrustCloud as CSV or Sheets to use them for business purposes?" - [History of tests](https://community.trustcloud.ai/tcf/topic/history-of-tests/): Can I view the history of tests? - [TrustCloud is not asking to attach evidence on any of these – just an approval](https://community.trustcloud.ai/tcf/topic/policies/): While I read and get all the policies approved, there is no evidence been asked on the portal. - [Question on integrations in Trustcloud](https://community.trustcloud.ai/tcf/topic/question-on-integrations-in-trustcloud/): i went to trustops and in Programs>systems - added all systems that we are currently using. However, i was able to integrate only a few like Azure, Deel, Github, etc. - [Common risks](https://community.trustcloud.ai/tcf/topic/common-risks/): What are some of the most common risks to look out for when first starting a risk management program? - [Trust Cloud’s own info-sec compliance](https://community.trustcloud.ai/tcf/topic/trust-clouds-own-info-sec-compliance/): Very much appreciate your thoughts. Best, Elizabeth - [Popular tools we use don’t seem to be in your catalog](https://community.trustcloud.ai/tcf/topic/popular-tools-we-use-dont-seem-to-be-in-your-catalog/): Additionally, we run (Apache) DevLake and Firebase without underlying systems, so how do I upload these without selecting an underlying option? - [ISO 27001 to NIST 800-53 mapping – common criteria](https://community.trustcloud.ai/tcf/topic/iso-27001-to-nist-800-53-mapping-common-criteria/): What are the common criteria for ISO 27001 to NIST 800-53 mapping? - [What kind of permissions does TrustCloud need to set up integrations?](https://community.trustcloud.ai/tcf/topic/what-kind-of-permissions-does-trustcloud-need-to-set-up-integrations/): What kind of permissions does TrustCloud need to set up integrations? - [Google Workspace integration not importing list of employees?](https://community.trustcloud.ai/tcf/topic/google-workspace-integration-not-importing-list-of-employees/): Thank you! - [ISO 27001 2013 to ISO 27001 2022](https://community.trustcloud.ai/tcf/topic/iso-27001-2013-to-iso-27001-2022/): When are you planning on transitioning from ISO 27001 2013 to 2022? - [Managing people / employees](https://community.trustcloud.ai/tcf/topic/managing-people-employees/): I have two questions regarding managing employees When adding company employees, is the 'date joined' to be the date of hire or the date added into TrustCloud? Is there a way to edit employees once they have been added or a way to remove them if they are no longer employed? - [Vendor Agreements](https://community.trustcloud.ai/tcf/topic/vendor-agreements/): Hey, the system asks me to get a Master Service Agreements for google and mongodb atlas. How do I get those documents? - [HITRUST support](https://community.trustcloud.ai/tcf/topic/hitrust-support/): Does TrustCloud support HITRUST? - [CMMC vs NIST](https://community.trustcloud.ai/tcf/topic/cmmc-vs-nist/): What are the biggest differences between CMMC and NIST-CSF? - [How do I complete an ISO 27001 self assessment?](https://community.trustcloud.ai/tcf/topic/how-do-i-complete-an-iso-27001-self-assessment/): Can you provide a template or questionnaire for me to complete my ISO 27001 self-assessment? - [Controls prioritization](https://community.trustcloud.ai/tcf/topic/controls-prioritization/): How do you prioritize which controls you should implement first? - [Roadmap to achieve audit readiness](https://community.trustcloud.ai/tcf/topic/roadmap-to-achieve-audit-readiness/): I've been tasked to design a roadmap for our team to achieve "audit readiness" by August. Our team is me, a marketer (with a little experience responding to security questionnaires in sales deals), our director of engineering, a scrum master). How would I assign areas of responsibility to each person and how much personal time would you expect each contributor to invest? Also, is there a logical flow to get the job done? - [AI compliance](https://community.trustcloud.ai/tcf/topic/ai-compliance/): Hi there, we are committed to conduct a SOC2 readiness assessment in Summer. As an AI-powered B2B SaaS application, I would love to know what policies and controls you offer or are now developing to support our compliance with the new The EU AI Act. Also, and if you are not supporting this compliance avenue, how would we incorporate that compliance work on your platform. - [Integrations vs Connected apps](https://community.trustcloud.ai/tcf/topic/integrations-vs-connected-apps/): What is the difference between Integrations and Connected Apps? - [European Cloud Provider](https://community.trustcloud.ai/tcf/topic/european-cloud-provider/): Hello, Our software uses European cloud provider Hetzner.com. Is it possible to add it as our cloud provider in any way? - [Tasks section is not available?](https://community.trustcloud.ai/tcf/topic/tasks-section-is-not-available/): Documentation says that Tasks are located in TrustOps but I only see Audits, Groups, Programs, Gap Analysis, Frameworks. We're running on the startup edition, which I had assumed was close to feature parity as the Growth license. Are Tasks only available in the paid version? Or is my tenant (or me) missing something? - [Default Trustcloud Automated Test – Not able to upload evidence](https://community.trustcloud.ai/tcf/topic/default-trustcloud-automated-test-not-able-to-upload-evidence/): For some controls, for example CUST-11, release notifications, TrustCloud is listed as an automated test as the system. When this is the case, I'm unable to upload evidence, and I'm unsure of what exactly the automated test is. - [View Policies button on dashboard no longer works.](https://community.trustcloud.ai/tcf/topic/view-policies-button-on-dashboard-no-longer-works/): The View Policies button on my dashboard previously took me to the Policies page, but now it doesn't. I tried refreshing the page several times and also tried signing out and back in again. - [How to upload SOC2 reports in TrustShare and enable request access for customers](https://community.trustcloud.ai/tcf/topic/how-to-upload-soc2-reports-in-trustshare-and-enable-request-access-for-customers/): I want to to create request access link that can be provided to customers and when they get an access they should be able to download SOC2 type1 and type2 reports, can you please share steps to enable this? - [Unable to upload Risk Register onto TrustRegister](https://community.trustcloud.ai/tcf/topic/unable-to-upload-risk-register-onto-trustregister/): I have downloaded and completed the template. When I upload the document, it says "File Successfully Uploaded" but when I click "Upload Risk Register", nothing has happened on the TrustRegister site. Can you please help me? This is causing my Risk Register control to fail. Thanks - [Unable to integrate with Google Cloud Platform](https://community.trustcloud.ai/tcf/topic/unable-to-integrate-with-google-cloud-platform/): I follow the instructions here https://flightschool.trustcloud.ai/docs/trustops/integrations/google-cloud-platform/ and it's giving me an error that it can't connect to Google Cloud: There was an error while testing the connection credentials. Please contact support. Error: Project(s) not exists or not active. Has anyone else run into this issue? - [Inventory is not up to date](https://community.trustcloud.ai/tcf/topic/inventory-is-not-up-to-date/): I've integrated AWS and in the inventory section I'm seeing a list of users with their access to the AWS account. In which I don't see all the users I have in my AWS account. Any specific reason for it? How can I refresh and get all the users details into the inventory so that I can submit evidences from here. - [Bitbucket Integration Giving Error While Running Role Based Access Control](https://community.trustcloud.ai/tcf/topic/bitbucket-integration-giving-error-while-running-role-based-access-control/): Hi I am trying to run test on my Bitbucket account for Role Based Access Control, but I am getting error that says "An Error was encountered when running the test". Please help. - [Skipping evidence before it is outdated](https://community.trustcloud.ai/tcf/topic/skipping-evidence-before-it-is-outdated/): Can I skip evidence before it is outdated? - [Identifying impact from industry events](https://community.trustcloud.ai/tcf/topic/identifying-impact-from-industry-events/): How is your team identifying impact from industry events, such as SVB failure? - [Reviewing evidence for an ISO 27001 audit](https://community.trustcloud.ai/tcf/topic/reviewing-evidence-for-an-iso-27001-audit/): When do you start reviewing evidence for your ISO 27001 audit? - [Salesforce Integration Error: A problem occurred while connecting to Salesforce:](https://community.trustcloud.ai/tcf/topic/salesforce-integration-error-a-problem-occurred-while-connecting-to-salesforce/): When I attempt to integrate Salesforce, I click the button to connect, which brings up my Salesforce login. When I login to Salesforce, I'm redirected back to TrustCloud, where I get the error in red: A problem occurred while connecting to Salesforce: authentication failure. Any ideas? - [How can I add a custom control?](https://community.trustcloud.ai/tcf/topic/how-can-i-add-a-custom-control/): How can I add a custom control? - [Cyber Insurance](https://community.trustcloud.ai/tcf/topic/cyber-insurance/): Is Cyber Insurance Required and is there a minimum limit? - [Auditor data access](https://community.trustcloud.ai/tcf/topic/auditor-data-access/): What all does my Auditor have access to? - [ISO auditor selection](https://community.trustcloud.ai/tcf/topic/iso-auditor-selection/): What should I look for when searching for an ISO 27001 Auditor? - [Privacy controls in trustcloud](https://community.trustcloud.ai/tcf/topic/privacy-controls-in-trustcloud/): We are about to kick off Audit and found Privacy review is another area we can focus on when customers do ask for that, if we want that to be addressed our auditors asked ask to enable/add privacy specific controls in trustcloud which can be reviewed by them. Currently I see 82 controls in total, How can I get it added in trustcloud? - [Possible to Restore Excluded Automated Tests?](https://community.trustcloud.ai/tcf/topic/possible-to-restore-excluded-automated-tests/): As per title. I tried moving to planned, then back to adopted but the tests stay excluded. The tests are HR-9 Board of Directors and HR-20. I also tried "Reset to Original State". I know they can be added back as self-assessments but I'm not sure if they were linked to any policies. They were, however, linked to BOD Meeting Agenda and Board Members Profile in the Documents section but don't see a way to Link those. - [If someone has 80% of ISO27001 done, how hard is it for them to get SOC 2?](https://community.trustcloud.ai/tcf/topic/if-someone-has-80-of-iso27001-done-how-hard-is-it-for-them-to-get-soc-2/): If someone has 80% of ISO27001 done, how hard is it for them to get SOC 2? Many of the controls can carry over right? But do they need all new policies? - [AUTH-11 Password Configurations](https://community.trustcloud.ai/tcf/topic/auth-11-password-configurations/): Azure Active Directory will not allow admin to change the password length. So how can I pass this automated test? - [Salesforce app not displaying in companies](https://community.trustcloud.ai/tcf/topic/salesforce-app-not-displaying-in-companies/): I configured the connected app with Salesforce and have a green light. In Salesforce I have an opportunity and account but nothing displays to select in TrustShare. Am I missing something? - [What is the total timeline to be ISO27001 + SOC 2 certified with TrustCloud?](https://community.trustcloud.ai/tcf/topic/what-is-the-total-timeline-to-be-iso27001-soc-2-certified-with-trustcloud/): What is the total timeline to be ISO27001 + SOC 2 certified with TrustCloud? - [What kind of ISO 27001 audit is the standard one to be certified?](https://community.trustcloud.ai/tcf/topic/what-kind-of-iso-27001-audit-is-the-standard-one-to-be-certified/): What kind of ISO 27001 audit is the standard one to be certified? Internal, surveillance or stage 1& 2? - [How to satisfy EC2 security groups Rulesets for default security groups](https://community.trustcloud.ai/tcf/topic/how-to-satisfy-ec2-security-groups-rulesets-for-default-security-groups/): How do I satisfy EC2 security groups Rulesets for default security groups so the test is green. - [What are the repercussions if a data breach happens while trying to achieve SOC2](https://community.trustcloud.ai/tcf/topic/what-are-the-repercussions-if-a-data-breach-happens-while-trying-to-achieve-soc2/): What are legal implications if data breach happens. Are there fines associated with SOC2 and data breaches - [Pen Testing and Audit](https://community.trustcloud.ai/tcf/topic/pen-testing-and-audit/): Is Pen testing mandatory for my Prod workload to pass SOC2? If yes, which Pen test I should perform for e.g. Whitebox, Blackbox, Graybox ...? Do I need to select only partners from the TrustCloud list for Pen testing and even for audit? - [Changing an ISO auditor](https://community.trustcloud.ai/tcf/topic/changing-an-iso-auditor/): How can I change my ISO auditor? - [Filtering tasks that are assigned to me](https://community.trustcloud.ai/tcf/topic/filtering-tasks-that-are-assigned-to-me/): How can I filter "All Tasks" for only tasks that are assigned to me? - [TrustCloud controls in terms of HR, Leadership, Board](https://community.trustcloud.ai/tcf/topic/trustcloud-controls-in-terms-of-hr-leadership-board/): As a small startup heavily reliant on contractors and lacking a complete board setup, should we be concerned about the absence of an employee handbook? How might the typical controls over employees, their workstations, and the board apply to our unique situation? Are there strategies to establish these controls even if we don't have anything, or should we explore potential exclusions given our startup's specific structure and dynamics? - [SOC 2 Cyber Insurance](https://community.trustcloud.ai/tcf/topic/soc2-cyber-insurance/): Is it mandatory to have cyber insurance for SOC2, or I can exclude it - [Non-conformity](https://community.trustcloud.ai/tcf/topic/non-conformity/): What is the difference between a major and minor non-conformity - [Process for bringing in a custom framework in TrustCloud](https://community.trustcloud.ai/tcf/topic/process-for-bringing-in-a-custom-framework-in-trustcloud/): What is the process for bringing in a custom framework in TrustCloud? - [What is the easiest way to show our leadership team how we are tracking towards](https://community.trustcloud.ai/tcf/topic/what-is-the-easiest-way-to-show-our-leadership-team-how-we-are-tracking-towards/): The Audit Dashboard view is perfect for displaying progress towards current audit work. Additionally, the Gap Analysis view is great for showing progress towards other audits or standards you are thinking of pursuing in the future. Our Gap Analysis will show your readiness percentage against any of the other standards we support based on the work you have already done for any current audits. - [What is Gap Analysis?](https://community.trustcloud.ai/tcf/topic/what-is-gap-analysis/): What is Gap Analysis? - [Who should be a policy owner?](https://community.trustcloud.ai/tcf/topic/who-should-be-a-policy-owner/): Who should be a policy owner? - [Vulnerability management solutions](https://community.trustcloud.ai/tcf/topic/vulnerability-management-solutions/): What solutions do you use for vulnerability management? - [User access controls – best practices](https://community.trustcloud.ai/tcf/topic/user-access-controls-best-practices/): What are best practices for completing user access controls? - [What is AuditLens?](https://community.trustcloud.ai/tcf/topic/what-is-auditlens/): What is AuditLens? - [Watermarking individual documents in TrustShare](https://community.trustcloud.ai/tcf/topic/watermarking-individual-documents-in-trustshare/): Can I watermark individual documents in TrustShare? - [Utilizing TrustShare to answer online or web-portal security questionnaires](https://community.trustcloud.ai/tcf/topic/utilizing-trustshare-to-answer-online-or-web-portal-security-questionnaires/): How can I utilize TrustShare to answer online or web-portal security questionnaires? - [What is a risk register?](https://community.trustcloud.ai/tcf/topic/what-is-a-risk-register/): What is a risk register? - [TrustCloud user limits](https://community.trustcloud.ai/tcf/topic/trustcloud-user-limits/): How many users can I invite in TrustCloud? - [TrustCloud data hosting](https://community.trustcloud.ai/tcf/topic/trustcloud-data-hosting/): Where is TrustCloud hosting my data? - [TrustCloud control vs custom control](https://community.trustcloud.ai/tcf/topic/trustcloud-control-vs-custom-control/): What is the difference between a TrustCloud control and a custom control? - [TrustCloud API working](https://community.trustcloud.ai/tcf/topic/trustcloud-api-working/): How does the TrustCloud API work? - [TrustCloud API and workflows](https://community.trustcloud.ai/tcf/topic/trustcloud-api-and-workflows/): What are some ways you have used TrustCloud's API to further streamline your workflows - [Trust Service Criteria](https://community.trustcloud.ai/tcf/topic/trust-service-criteria/): How do I know which Trust Service Criteria should be in scope for my SOC2 audit? - [Test exclusion vs resource exclusion](https://community.trustcloud.ai/tcf/topic/test-exclusion-vs-resource-exclusion/): What is the difference between a test exclusion and a resource exclusion? - [Tracking customer commitments in TrustCloud](https://community.trustcloud.ai/tcf/topic/tracking-customer-commitments-in-trustcloud/): How can I track customer commitments in TrustCloud? - [Systems vs Vendors](https://community.trustcloud.ai/tcf/topic/systems-vs-vendors/): What is the difference between Systems and Vendors page? - [Switching between apps in TrustCloud](https://community.trustcloud.ai/tcf/topic/switching-between-apps-in-trustcloud/): How do I switch between different apps in TrustCloud? - [Surveillance audit](https://community.trustcloud.ai/tcf/topic/surveillance-audit/): What is a surveillance audit? - [Support from the board for compliance efforts](https://community.trustcloud.ai/tcf/topic/support-from-the-board-for-compliance-efforts/): How have you successfully gotten support from the board for compliance efforts? - [Supported Risk frameworks](https://community.trustcloud.ai/tcf/topic/supported-risk-frameworks/): What risk frameworks do you support? - [Supported framework not visible in TrustOps](https://community.trustcloud.ai/tcf/topic/supported-framework-not-visible-in-trustops/): What if I don't see a supported framework within TrustOps? - [Start with SOC 2 or ISO 27001](https://community.trustcloud.ai/tcf/topic/start-with-soc-2-or-iso-27001/): As an international company, is it better to start off with SOC 2 or ISO 27001? - [SOC 2 Type 1 and Type 2 audit frequency](https://community.trustcloud.ai/tcf/topic/soc-2-type-1-and-type-2-audit-frequency/): Do I need to do a SOC 2 Type 1 & a SOC 2 Type 2 audit every year? - [SOC 2 type 2 audit observation period](https://community.trustcloud.ai/tcf/topic/soc-2-type-2-audit-observation-period/): What is the least and maximum range for an observation period for my SOC 2 type 2 audit? - [Sharing password protected documents](https://community.trustcloud.ai/tcf/topic/sharing-password-protected-documents/): Can I uploaded and share password protected documents? - [SOC 2 audit cost](https://community.trustcloud.ai/tcf/topic/soc-2-audit-cost/): How much does a SOC 2 audit cost? - [SOC 2 order of Type 1 and Type 2](https://community.trustcloud.ai/tcf/topic/soc-2-order-of-type-1-and-type-2/): This is the first time I am undergoing a SOC 2 audit. Is there a requirement to do a Type 1 first and then do a Type 2 or can I straight go to a type 2? - [Segregation of duties](https://community.trustcloud.ai/tcf/topic/segregation-of-duties/): What solutions do you use for segregation of duties? - [Sharing documents safely with prospects or clients](https://community.trustcloud.ai/tcf/topic/sharing-documents-safely-with-prospects-or-clients/): How can I safely share documents with specific clients or prospects? - [Setting up NDA wrapping for TrustShare](https://community.trustcloud.ai/tcf/topic/setting-up-nda-wrapping-for-trustshare/): How can I set up NDA wrapping for TrustShare? - [Review compliance procedures](https://community.trustcloud.ai/tcf/topic/review-compliance-procedures/): How often do I need to review and update my compliance procedures? - [Risks that should be a part of my Risk Register](https://community.trustcloud.ai/tcf/topic/risks-that-should-be-a-part-of-my-risk-register/): How do I know what risks should be on my Risk Register? - [Reviewing evidence for a SOC 2 audit](https://community.trustcloud.ai/tcf/topic/reviewing-evidence-for-a-soc-2-audit/): When do you start reviewing evidence for your SOC 2 audit? - [Qualified and unqualified reports](https://community.trustcloud.ai/tcf/topic/qualified-and-unqualified-reports/): What are qualified and unqualified reports? - [Preview of controls automated from a particular integration](https://community.trustcloud.ai/tcf/topic/preview-of-controls-automated-from-a-particular-integration/): Can I see a preview of controls automated from a particular integration? - [Private documents vs Data Room documents](https://community.trustcloud.ai/tcf/topic/private-documents-vs-data-room-documents/): What is the difference between Private documents and Data Room document access levels in TrustShare? - [Planned vs Adopted controls](https://community.trustcloud.ai/tcf/topic/planned-vs-adopted-controls/): What is the difference between a planned and adopted control? - [Pen testing requirement for SOC 2](https://community.trustcloud.ai/tcf/topic/pen-testing-requirement-for-soc-2/): Is Pen testing a requirement for SOC 2? - [Outlining controls in a policy document](https://community.trustcloud.ai/tcf/topic/outlining-controls-in-a-policy-document/): Do all controls have to be outlined in the policy documents? - [Number of prospects or customers that can be invited into my TrustShare](https://community.trustcloud.ai/tcf/topic/number-of-prospects-or-customers-that-can-be-invited-into-my-trustshare/): How many prospects or customers can I invite into my TrustShare? - [Number of questions that the AI will be able to respond to](https://community.trustcloud.ai/tcf/topic/number-of-questions-that-the-ai-will-be-able-to-respond-to/): How many questions will the AI be able to respond to? - [Number of risks in my Risk Register](https://community.trustcloud.ai/tcf/topic/number-of-risks-in-my-risk-register/): How many risks can I have in my Risk Register? - [Managing risks within policies](https://community.trustcloud.ai/tcf/topic/managing-risks-within-policies/): How do you manage risks within policies? - [Managing my risks with TrustCloud](https://community.trustcloud.ai/tcf/topic/managing-my-risks-with-trustcloud/): How can I manage my risks with TrustCloud? - [Manually uploading evidence for a test](https://community.trustcloud.ai/tcf/topic/manually-uploading-evidence-for-a-test/): How do I manually upload evidence for a test? - [No terminations or new hires within my SOC 2 observation period](https://community.trustcloud.ai/tcf/topic/no-terminations-or-new-hires-within-my-soc-2-observation-period/): What do I do if I do not have any terminations or new hires within my SOC 2 observation period? Will this lead to an exception/finding in my report? - [ISO 27001 internal audit](https://community.trustcloud.ai/tcf/topic/iso-27001-internal-audit/): Who can do an internal audit to meet the ISO 27001 requirement? - [ISO 27001 audit readiness timeframe](https://community.trustcloud.ai/tcf/topic/iso-27001-audit-readiness-timeframe/): How long does it take customers to get audit ready for ISO 27001? Also, how long does the audit process itself take? - [Is Slack HIPAA Compliant?](https://community.trustcloud.ai/tcf/topic/is-slack-hipaa-compliant/): Is Slack HIPAA Compliant? - [Inviting my auditor to TrustCloud](https://community.trustcloud.ai/tcf/topic/inviting-my-auditor-to-trustcloud/): How can I invite my auditor into TrustCloud or turn on an audit? - [Importance of the deal value while filling out a security questionnaire](https://community.trustcloud.ai/tcf/topic/importance-of-the-deal-value-while-filling-out-a-security-questionnaire/): Why is the deal value important when filling out a security questionnaire? - [Importing security questionnaires](https://community.trustcloud.ai/tcf/topic/importing-security-questionnaires/): What is the process to import a security questionnaire? - [Impact of skipping an evidence refresh task](https://community.trustcloud.ai/tcf/topic/impact-of-skipping-an-evidence-refresh-task-2/): What happens if I skip an evidence refresh task? Does this impact my audit? - [Gap analysis and how this help my business](https://community.trustcloud.ai/tcf/topic/gap-analysis-and-how-this-help-my-business/): What is a gap analysis and how could this help my business? - [How often are my controls tested?](https://community.trustcloud.ai/tcf/topic/how-often-are-my-controls-tested/): How often are my controls tested? - [External auditors and controls](https://community.trustcloud.ai/tcf/topic/external-auditors-and-controls/): What controls have your external auditors focused on? - [Exporting security questionnaires into their original format](https://community.trustcloud.ai/tcf/topic/exporting-security-questionnaires-into-their-original-format/): Can I export security questionnaires into their original format? - [Finding an auditor](https://community.trustcloud.ai/tcf/topic/finding-an-auditor/): Where do I start to find an auditor? - [Descriptive content visible for few controls when linked to a policy](https://community.trustcloud.ai/tcf/topic/descriptive-content-visible-for-few-controls-when-linked-to-a-policy/): How come for some controls, when I link them to my TrustCloud policy, I can see the descriptive content as well but for some, I do not. - [Email notifications if a team member assigns me as the question owner](https://community.trustcloud.ai/tcf/topic/email-notifications-if-a-team-member-assigns-me-as-the-question-owner/): Do I get email notifications if a team member assign's me as the question owner? - [Editing previous answers in TrustShare](https://community.trustcloud.ai/tcf/topic/editing-previous-answers-in-trustshare/): Can I edit previous answers on TrustShare? - [Customizing a control](https://community.trustcloud.ai/tcf/topic/customizing-a-control/): Can I customize a control? - [Custom Frameworks in TrustCloud](https://community.trustcloud.ai/tcf/topic/custom-frameworks-in-trustcloud/): What is considered a Custom Framework in TrustCloud? - [Creating tickets on behalf of a customer](https://community.trustcloud.ai/tcf/topic/creating-tickets-on-behalf-of-a-customer/): Can my CSM (Customer Success Manager) create a support ticket on my behalf? - [Controls and tests automated with each integration](https://community.trustcloud.ai/tcf/topic/controls-and-tests-automated-with-each-integration/): How many controls and tests are automated with each integration? - [Control status vs Test status](https://community.trustcloud.ai/tcf/topic/control-status-vs-test-status/): What is control status and how is it different from test status? - [Control frequency logic](https://community.trustcloud.ai/tcf/topic/control-frequency-logic/): Based on what can I change the frequency of controls? - [Control compliance software](https://community.trustcloud.ai/tcf/topic/control-compliance-software/): What's your favorite software for helping with various control compliance efforts? - [Communicating controls to stakeholders](https://community.trustcloud.ai/tcf/topic/communicating-controls-to-stakeholders/): How does your team go about communicating controls to stakeholders? - [Communicating compliance posture to your board](https://community.trustcloud.ai/tcf/topic/communicating-compliance-posture-to-your-board/): How do you report / communicate compliance posture to your board? - [Choosing an auditor](https://community.trustcloud.ai/tcf/topic/choosing-an-auditor/): What are some things to look for when choosing an auditor? - [Bringing my own Risk Register](https://community.trustcloud.ai/tcf/topic/bringing-my-own-risk-register/): Can I bring my own risk register into TrustRegister? - [BAA and vendors](https://community.trustcloud.ai/tcf/topic/baa-and-vendors/): Do I need a BAA in place with all my vendors or just the vendors that touch PHI Data? - [Automated tests vs Self assessment tests](https://community.trustcloud.ai/tcf/topic/automated-tests-vs-self-assessment-tests/): What is the difference between an automated and a self assessment test? - [Audit readiness progress tracking](https://community.trustcloud.ai/tcf/topic/audit-readiness-progress-tracking/): How do I track the progress within the program? - [Audit preparation time](https://community.trustcloud.ai/tcf/topic/audit-preparation-time/): How much time do you give yourself to prepare for an audit? - [Adopting controls and leaving controls as planned](https://community.trustcloud.ai/tcf/topic/adopting-controls-and-leaving-controls-as-planned/): Do I have to adopt all controls? or can I leave controls as planned? How will those affect the completeness of the SOC 2 or ISO program? - [Adopting a new framework](https://community.trustcloud.ai/tcf/topic/adopting-a-new-framework/): What does your team consider when thinking about adopting a new framework? How do you perform that evaluation? - [Adding my own system](https://community.trustcloud.ai/tcf/topic/adding-my-own-system/): Can I add my own system? - [Adding my own policies](https://community.trustcloud.ai/tcf/topic/adding-my-own-policies/): Can I add my own polices? - [Adding additional accounts to my integrations](https://community.trustcloud.ai/tcf/topic/adding-additional-accounts-to-my-integrations/): 40Can I add additional accounts to my integrations? - [Adding a custom policy](https://community.trustcloud.ai/tcf/topic/adding-a-custom-policy/): Can I add a Custom Policy? - [Welcome to TrustCommunity](https://community.trustcloud.ai/tcf/topic/welcome-to-trustcommunity/): Welcome to TrustCommunity! This is your central hub for connecting with like-minded peers, sharing knowledge, and collaborating to enhance your TrustCloud experience. We're excited to have you on board as we cultivate a vibrant and supportive community for GRC professionals. - [Code of Conduct](https://community.trustcloud.ai/tcf/topic/code-of-conduct/): The TrustCommunity’s mission is to showcase, celebrate, and provide added value to GRC professionals. To uphold the community’s mission and maintain a safe and transparent environment, TrustCloud requires that all members agree to and follow a code of conduct that will ensure constructive, professional interactions for all members.  ## Replies - [Reply To: TrustCloud controls in terms of HR, Leadership, Board](https://community.trustcloud.ai/tcf/reply/7580/): Good question - [Reply To: SOC 2 Cyber Insurance](https://community.trustcloud.ai/tcf/reply/7227/): Thank you! - [Reply To: SOC 2 Cyber Insurance](https://community.trustcloud.ai/tcf/reply/7199/): yes, they will want you to make progressive improvements to your program and will want to see in the next review evidence of cyber insurance. - [Reply To: SOC 2 Cyber Insurance](https://community.trustcloud.ai/tcf/reply/7172/): Thanks for the reply, in the last sentence you mentioned Auditor will recommend having insurance prior to the next audit. does that mean, prior to the renewal of SOC2. - [Reply To: SOC 2 Cyber Insurance](https://community.trustcloud.ai/tcf/reply/7158/): Hi Pratik, the SOC 2 framework doesn't explicitly require cyber insurance. It requires the organization to invest in risk mitigation and one of the ways to do that is through cyber insurance. You could exclude it for now, but I believe your prospects and customers will require you to have it to ensure business continuity in the event of a cyber attack. Additionally, your auditors might dive into this and will recommend to have an insurance prior to the next audit. - [Reply To: Non-conformity](https://community.trustcloud.ai/tcf/reply/6560/): A major non-conformity is a serious deviation from a requirement or standard that could potentially result in the failure of the product or service or pose a significant risk to the customer or end-user. Major non-conformities typically require immediate corrective action and may lead to suspension or withdrawal of certification until the issue is resolved. - [Reply To: Process for bringing in a custom framework in TrustCloud](https://community.trustcloud.ai/tcf/reply/6563/): We have a custom framework feature in our TrutOps product that allows you bring in or create any custom frameworks and map your controls to our TCCCF. That said, we also offer implementation services you can select from depending on your needs. For more information on implementation services please reach out to your Customer Success Manager or contact sales@trustcloud.ai. - [Reply To: Importing security questionnaires](https://community.trustcloud.ai/tcf/reply/5441/): There are three options when importing a security questionnaire: white-glove import, self-import, or importing a standardized questionnaire (CAIQ, SIG, etc.) using one of our templates! - [Reply To: What is AuditLens?](https://community.trustcloud.ai/tcf/reply/4814/): AuditLens is a tool that the auditor uses to conduct an audit. It allows them only the necessary view into a customers compliance program. - [Reply To: What is Gap Analysis?](https://community.trustcloud.ai/tcf/reply/4771/): Users can view any available Gap Analysis to gain an understanding of their progress and gaps towards other potential frameworks or standards. Gap Analysis offer a educational primer on the selected standard, an overview of main sections, progress percentages towards the selected standard, and a detailed view of gaps as it relates to controls and policies in your program. The only gap analysis that is not readily available in TrustOps is for any privacy standards. If you would like to see a gap analysis for a privacy standard please reach out to your Customer Success Manager. - [Reply To: Who should be a policy owner?](https://community.trustcloud.ai/tcf/reply/4643/): Whoever needs final approval on that policy - [Reply To: Vulnerability management solutions](https://community.trustcloud.ai/tcf/reply/4628/): Check out our page on Vulnerability Management to see what tools our customers use. https://community.trustcloud.ai/docs/trustops/controls/vulnerability-management/ - [Reply To: User access controls – best practices](https://community.trustcloud.ai/tcf/reply/4615/): User access controls are very dependent upon the system in play, the HR structure, and the departmental decisioning on appropriateness of access. - [Reply To: TrustCloud user limits](https://community.trustcloud.ai/tcf/reply/4709/): We believe that compliance is a team sport. You should invite all or as many team members as you need to contribute towards your compliance program. - [Reply To: Watermarking individual documents in TrustShare](https://community.trustcloud.ai/tcf/reply/4797/): Yes! You can change your default watermark setting to on/off, and can change the individual document's watermark setting if needed. It is important to note that encrypted documents and any documents set to 'public' access cannot be watermarked. - [Reply To: Utilizing TrustShare to answer online or web-portal security questionnaires](https://community.trustcloud.ai/tcf/reply/4795/): TrustShare offers a Chrome Extension for a streamlined experience when answering security questionnaires in a web-portal! Simply install the extension to your Chrome browser, log in, and gain access to TrustShare no matter where your security questionnaire lives! - [Reply To: What is a risk register?](https://community.trustcloud.ai/tcf/reply/4641/): A risk management tool that helps your company to identify risk's before they become a problem, streamline risk related workflows, assess impact/ align stakeholders, & build programs that grow your business - [Reply To: TrustCloud user limits](https://community.trustcloud.ai/tcf/reply/4708/): You can invite as many users as you'd like. There is no fee or extra charge per user - [Reply To: TrustCloud data hosting](https://community.trustcloud.ai/tcf/reply/4702/): We use AWS as our cloud provider to securely manage your data - [Reply To: TrustCloud control vs custom control](https://community.trustcloud.ai/tcf/reply/4725/): A TrustCloud control is a control that is generated as part of our Common Control Framework. TrustCloud's Common Control Framework is standard agnostic, meaning that our controls and policies map to a variety of different standards. If you have multiple security or privacy standards that you are looking to adhere to this is great because you are doing the work once but doing it across many different standards. A custom control is a control that is created by you when selecting + Add Custom Control or via our Custom Frameworks feature. The great thing about leveraging both of these features is that you can map your custom control to any of our controls. - [Reply To: TrustCloud API working](https://community.trustcloud.ai/tcf/reply/4706/): The TrustCloud API is an API designed to empower organizations in managing and monitoring their Trust Program effectively. Click this link to get started https://community.trustcloud.ai/docs/trustcloud-api/getting-started/ - [Reply To: TrustCloud API and workflows](https://community.trustcloud.ai/tcf/reply/4698/): Currently TrustCloud's API is primarily being used to retrieve compliance data from TrustCloud to leverage in other systems and automate the submission of evidence. For more information on our API checkout this article: https://community.trustcloud.ai/docs/trustcloud-api/ - [Reply To: Test exclusion vs resource exclusion](https://community.trustcloud.ai/tcf/reply/4748/): A test exclusion will exclude at the test level. See question #158 for more details on test exclusions. A resource exclusion excludes at the resource level. For example, you may have a MFA enforce test that does not apply to a service account that you set up for an integration. In this case, we recommend excluding this resource (the service account) from that test to ensure more accurate test status. - [Reply To: Tracking customer commitments in TrustCloud](https://community.trustcloud.ai/tcf/reply/4729/): On the TrustOps Controls page there is an Impact view that allows you to track all of your customer commitments and their respective controls. Our Impact view is pulling customer commitments from any contracts uploaded to controls (select any control and click on Impact toggle) and your TrustShare activities. - [Reply To: Trust Service Criteria](https://community.trustcloud.ai/tcf/reply/4679/): This varies greatly by organization but an easy way to tell if you need to add a Trust Service Criteria beyond Security (this one is mandatory) is reviewing any customer comittments or contractual obligations your business may have made around any of the Trust Service Criteria (Security, Confidentiality, Processing Integrity, and Privacy). https://community.trustcloud.ai/docs/compliance-launchpad/soc-2/ For more information on SOC2 Trust Service Criteria checkout Audit Dashboard and Gap Analysis in TrustOps. - [Reply To: Systems vs Vendors](https://community.trustcloud.ai/tcf/reply/4733/): The Systems page is a list of all of the systems you use that are in scope for your audit. This usually includes third-party systems and in-house developed systems. You can leverage your Systems page to define data sensitivity across your systems and run tests to verify your systems are in compliance with your controls and policies. The Vendors page is a list of all of the vendors you are currently engaged with but can also include vendors that may not necessarily be in scope. You can leverage your Vendors page to track important details about your vendors and help consolidate your vendor assessment efforts. A list of your vendors is automatically generated based on your Systems page but you can add additional vendors to this page as well. - [Reply To: Switching between apps in TrustCloud](https://community.trustcloud.ai/tcf/reply/4713/): Click on the 4 small boxes in the top left corner of your platform. This takes you to the page to switch between apps - [Reply To: Surveillance audit](https://community.trustcloud.ai/tcf/reply/4653/): Surveillance Audits are an ISO term. An ISO 27001 audit is done on a 3 year cycle. The first year, is what is called a full audit, wherein the ISO auditor will review and test the effectiveness of all ISO 27001 controls. The second and the third year are called the "surveillance audits" as the auditor looks at a subset of controls from the ISO 27001 framework. - [Reply To: Support from the board for compliance efforts](https://community.trustcloud.ai/tcf/reply/4632/): Boards and leaders are predominately looking to answer the question "what is the business impact of compliance efforts?". Showcasing how GRC can reduce the cost of audit readiness, accelerate and increase revenue, as well as reduce financial liability and risk has proven to be an effective approach - [Reply To: Supported Risk frameworks](https://community.trustcloud.ai/tcf/reply/4783/): We support a number of risk frameworks including asset and risk based approaches. Checkout this article for details: https://community.trustcloud.ai/docs/trustregister/overview/#supported-compliance-standards - [Reply To: Supported framework not visible in TrustOps](https://community.trustcloud.ai/tcf/reply/4767/): If you do not see a supported framework in TrustOps you can create a Custom Framework or reach out to your Customer Success Manager to discuss options for supporting other frameworks. For more information checkout Custom Frameworks: https://community.trustcloud.ai/docs/trustops/custom-frameworks/ - [Reply To: Start with SOC 2 or ISO 27001](https://community.trustcloud.ai/tcf/reply/4754/): ISO 27001 is recognized internationally, where as SOC 2 is purely relevant to America. - [Reply To: SOC 2 order of Type 1 and Type 2](https://community.trustcloud.ai/tcf/reply/4669/): It usually depends on what your customers are asking for. If they are wanting a SOC 2 Type 1 then you should go right ahead and do a Type 1. Same with Type 2. - [Reply To: SOC 2 Type 1 and Type 2 audit frequency](https://community.trustcloud.ai/tcf/reply/4666/): You do not need a Type 1 every year as it can only be done once. However, to stay SOC 2 Type 2 compliant it needs it be done every year. - [Reply To: SOC 2 Type 1 and Type 2 audit frequency](https://community.trustcloud.ai/tcf/reply/4665/): A SOC 2 Type 1 is done only for the first time. After that, you can continue with only the SOC 2 Type 2. - [Reply To: SOC 2 type 2 audit observation period](https://community.trustcloud.ai/tcf/reply/4663/): The observation range is 3-6 months. Typically closer to 3 months - [Reply To: SOC 2 type 2 audit observation period](https://community.trustcloud.ai/tcf/reply/4662/): The minimum duration for an observation period is 3 months and maximum is for 12 months. That said, we recommend going for a window of at least 6 months if you are a small organization so that the auditors will be able to test for controls around new hire access provisioning, access terminations. For a small size company who do not have a high velocity of hiring or terminations, the auditor will not be able to effectively test these controls. Within the report the auditor will mark those controls as "Not tested - as no new hires occured within the observation period." This will likely be the same for Disaster Recovery testing, Incident response testing, penetration testing and therefore will not be enough to provide assurance to your customers. - [Reply To: Sharing password protected documents](https://community.trustcloud.ai/tcf/reply/4799/): Yes, you can. Keep in mind those documents cannot be watermarked as we are unable to edit password protected documents - [Reply To: SOC 2 audit cost](https://community.trustcloud.ai/tcf/reply/4675/): This generally varies by the auditor, the type of audit being performed, and the scope of your audit. Another factor most auditors will take into consideration when giving you pricing is whether or not you have a GRC tool in place that can help accelerate their evidence review process. For more details on pricing feel free to checkout our Compliance Launchpad for up-front pricing from our audit partners. https://community.trustcloud.ai/docs/compliance-launchpad/ - [Reply To: SOC 2 order of Type 1 and Type 2](https://community.trustcloud.ai/tcf/reply/4668/): There is no requirement that you have to do a SOC 2 Type 1 first prior to a SOC 2 Type 2. A type 1 audit is a point in time test and only looks at a sample of one for testing of controls. For ex. the audtor will look at your change management policies and test one change to ensure that the change management policy was followed. Wheeras for a Type 2, they will pick a sample of changes, typically 25 changes and test to ensure that the change management policies were followed for each of those changes. The only reason a Type 1 is done to ensure that the organization is ready for the rigors of a SOC 2 Type 2. If an organization feels confident for a type 2 audit - they can straight away begin a SOC2 Type 2. - [Reply To: Segregation of duties](https://community.trustcloud.ai/tcf/reply/4626/): There are various tools and software solutions available that can assist in implementing and enforcing segregation of duties within an organization. Here are some tools you might consider: - [Reply To: Sharing documents safely with prospects or clients](https://community.trustcloud.ai/tcf/reply/4807/): If you would like to share certain documents with specific people or groups of people, you can take advantage of TrustShare Data Rooms! The document(s) stored within a Data Room are only viewable by users that have been invited into that Data Room! - [Reply To: Setting up NDA wrapping for TrustShare](https://community.trustcloud.ai/tcf/reply/4789/): To set up NDA click-wrap, you will simply navigate to the "Settings" page of "Manage my TrustShare". Here, you will find the "Add NDA" section that allows you to upload a generic, signed (by your Company) copy of your NDA! You can then assign the e-mail address that should receive an executed copy of each contract, and a welcome message for your invited TrustShare viewers! - [Reply To: Review compliance procedures](https://community.trustcloud.ai/tcf/reply/4611/): As a general rule, compliance procedures should be reviewed and updated regularly, at least once a year, or whenever there are significant changes in the regulatory environment that affect the business. - [Reply To: Risks that should be a part of my Risk Register](https://community.trustcloud.ai/tcf/reply/4781/): There are several techniques you can use to identify risks. These include SWOT analysis, PESTEL analysis, Scenario Analysis, and others. System based risk identification is a good way to determine cyber risks as it involves assessing the threats and vulnerability for each system. The best approach is using a combination of techniques as it will provide a more comprehensive list of potential risks. - [Reply To: Reviewing evidence for a SOC 2 audit](https://community.trustcloud.ai/tcf/reply/4673/): SOC 2 readiness can be daunting -- but the earlier and more frequently you obtain and collect information from your stakeholders, the easier it is to get started. Depending on the size of your environment, you can typically get started with collecting information about 6 weeks prior to the start of your audit. - [Reply To: Pen testing requirement for SOC 2](https://community.trustcloud.ai/tcf/reply/4660/): It depends on your auditors – In general, penetration testing is required for SOC 2, however some audit firms would make an exception for the Type 1 and allow companies to skip this requirement or demonstrate an “intention” to have a pen testing done at some point in the near future. Regardless, any company doing a SOC 2 would eventually do a type 2 which absolutely requires a penetration test. As such, its advisable to err on the side of caution and get one. On top of that, SOC 2 or not, all organizations should conduct pen testing at least every year to see how vulnerable they are. - [Reply To: Qualified and unqualified reports](https://community.trustcloud.ai/tcf/reply/4657/): An unqualified opinion doesn't have any kind of adverse comments and it doesn't include any disclaimers about any clauses or the audit process. This type of report indicates that the auditors are satisfied with testing of the controls. A qualified contains some exceptions that the auditors uncovered during their testing These exceptions will have the organizations's response as well as any additional steps that the auditors tool to gain reasonable assurance on the efficacy of the controls. - [Reply To: Preview of controls automated from a particular integration](https://community.trustcloud.ai/tcf/reply/4744/): Yes, You can see a preview of all the different criteria and mappings of each integration on the available integration tab on your TrustCloud - [Reply To: Private documents vs Data Room documents](https://community.trustcloud.ai/tcf/reply/4787/): Private documents will be made available to all authenticated users. Data room documents will only be accessible to users invited into the Data Room(s) that the document is stored in. - [Reply To: Planned vs Adopted controls](https://community.trustcloud.ai/tcf/reply/4769/): Controls within TrustOps are categorized as either ""Adopted"" or ""Planned."" Adopted controls refer to those that you have thoroughly reviewed and accepted as part of your program. These controls are actively implemented and integrated into your compliance framework. On the other hand, Planned controls are recommendations from our end, suggesting controls that we advise you to implement based on best practices and industry standards. These controls are yet to be implemented in your program. - [Reply To: Pen testing requirement for SOC 2](https://community.trustcloud.ai/tcf/reply/4659/): Pen testing is not a requirement for SOC 2 Type I but it is a requirement for SOC 2 Type II - [Reply To: Outlining controls in a policy document](https://community.trustcloud.ai/tcf/reply/4613/): Ideally, they can be. At TrustCloud we have linked the most relevant controls within the policy by default. However, you have the ability to link additional controls as well as edit the documentation to reflect how the controls are implemented within your organization. - [Reply To: Number of prospects or customers that can be invited into my TrustShare](https://community.trustcloud.ai/tcf/reply/4809/): There is no limit to the amount of users that can view the public facing information on your TrustShare page. However, the number of authenticated users (by invitation or access request) is limited based on your pricing plan. - [Reply To: Number of questions that the AI will be able to respond to](https://community.trustcloud.ai/tcf/reply/4805/): The number of questions that TrustShare AI can respond to is really dependent on the information within your TrustCloud. The controls, policies, and past answers within your program all play a role in how much of your security questionnaire TrustCloud AI can answer. As TrustCloud AI learns, you will see an increase in the work that it does for you. - [Reply To: Number of risks in my Risk Register](https://community.trustcloud.ai/tcf/reply/4777/): You can have as many risks as you'd like but do keep in mind the amount of risks you can add vary between your subscription level. Reach out to your CSM to know exactly how many risks you are allotted. - [Reply To: Managing risks within policies](https://community.trustcloud.ai/tcf/reply/4746/): One way you con manage risks associated with your policies is by linking controls to your policies. Linking controls to policies makes them testable and allows TrustCloud to generate a Risk Score for your policies. TrustCloud's auto-generated policies already come with linked controls but you can further customize these. For any custom policies you will also have the ability to link any controls from your program. - [Reply To: Managing my risks with TrustCloud](https://community.trustcloud.ai/tcf/reply/4779/): Traditionally, companies have tracked risks in spreadsheets or across siloed systems. TrustCloud customers can leverage TrustRegister to programmatically identify risks across their organization and streamline risk management activities with business-wise compliance efforts. For more information on TrustRegister checkout this article or reach out to your Customer Success Manager. https://community.trustcloud.ai/docs/trustregister/overview/ - [Reply To: Manually uploading evidence for a test](https://community.trustcloud.ai/tcf/reply/4761/): Here's a step-by-step guide on how to add evidence in TrustOps: - [Reply To: No terminations or new hires within my SOC 2 observation period](https://community.trustcloud.ai/tcf/reply/4671/): It will not lead to any exceptions within your report. However, the opinion for this control will be noted as "N/A - could not test the effectiveness of this control as no users were hired within the observation period." - [Reply To: ISO 27001 audit readiness timeframe](https://community.trustcloud.ai/tcf/reply/4818/): The audit will take around 2-3 weeks. - [Reply To: Is Slack HIPAA Compliant?](https://community.trustcloud.ai/tcf/reply/4649/): To our knowledge, Slack only supports HIPAA-compliant communications. The platform is not HIPAA-compliant by default. For more information on how to make your Slack communications HIPAA-compliant checkout this article: https://www.salesforce.com/company/legal/slack-guide-for-hipaa-entities/ - [Reply To: Importing security questionnaires](https://community.trustcloud.ai/tcf/reply/4819/): To upload your questionnaire, you will need to log into the TrustShare application and then navigate to "Questionnaires". From there, you can select the "New Questionnaire" button to begin the upload process! - [Reply To: Inviting my auditor to TrustCloud](https://community.trustcloud.ai/tcf/reply/4816/): To turn on an audit go to Audits on your TrustOps menu and select the framework or standard that will be in scope for your audit. Once you have selected a framework you should see a button that says Create Audit. Once you have created an audit you will be prompted to invite your auditors or you can skip this step and invite them from your Account Summary page (make sure to assign them the Auditor role). - [Reply To: Importance of the deal value while filling out a security questionnaire](https://community.trustcloud.ai/tcf/reply/4811/): Logging deal value is crucial for financial tracking, performance evaluation, forecasting, sales pipeline management, decision making, and comprehensive reporting and analysis. It provides a holistic view of sales activities related to security reviews and enables businesses to make informed decisions, optimize sales performance, and drive growth. - [Reply To: ISO 27001 internal audit](https://community.trustcloud.ai/tcf/reply/4655/): Internal audit needs to be performed by a person who is not in change of the implementation or maintenance of the ISMS. This can be an internal resource with knowledge of the ISO 27001 or an external consultant as well. - [Reply To: ISO 27001 audit readiness timeframe](https://community.trustcloud.ai/tcf/reply/4651/): Checkout this article for details on ISO 27001 and general readiness timeline. https://community.trustcloud.ai/docs/compliance-launchpad/iso-27001/ For more details on how long it will take you to get ready go to your Gap Analysis in TrustOps to find out your readiness status. - [Reply To: External auditors and controls](https://community.trustcloud.ai/tcf/reply/4634/): Auditors focus on all controls relevant to the framework being audited. Each framework have requirements and for each requirements, controls have been created. The auditor will focus on all the controls in order to confirm that an organization is complying with the framework. - [Reply To: Impact of skipping an evidence refresh task](https://community.trustcloud.ai/tcf/reply/4736/): Skipping an evidence task will allow you to override the evidence refresh task for a control verification test. However, we advise against doing this to avoid inconsistencies in your control testing and potentially putting at risk the results of your audit. Rather than skipping evidence refresh tasks you should consider changing the evaluation frequency of a control prior to your audit. Once you have kicked-off your audit you should not make any changes to your evaluation frequency. - [Reply To: How often are my controls tested?](https://community.trustcloud.ai/tcf/reply/4723/): Depends on the control, but most are tested quarterly or annually - [Reply To: Gap analysis and how this help my business](https://community.trustcloud.ai/tcf/reply/4731/): The Gap Analysis tool has been developed with the intention of providing you valuable insights into compliance standards and identifying any existing gaps in your organization's adherence to these standards. This tool serves as an excellent resource, particularly if you are considering the pursuit of additional standards, as it enables you to assess the level of effort that may be required from your team in meeting these requirements. TrustOps offers you the convenience of accessing a real-time Gap Analysis for various standards standards. - [Reply To: Exporting security questionnaires into their original format](https://community.trustcloud.ai/tcf/reply/4791/): Yes! When exporting your security questionnaire, you will be presented with two options: export to original format or export without formatting. Exporting to the original format will be handled by our white-glove service and can take anywhere from 1-48 hours depending on the complexity and amount of export requests received. If you prefer to transfer the information to the original format yourself, you can do so by downloading without formatting and then transferring the information back to the original file! - [Reply To: Finding an auditor](https://community.trustcloud.ai/tcf/reply/4677/): Checkout our Compliance Launchpad for information on our trusted audit partners (select on the audit or standard you are looking to pursue). https://community.trustcloud.ai/docs/compliance-launchpad/ You can take a look at our partner network and request a connection from this link as well: https://www.trustcloud.ai/partners/ - [Reply To: Descriptive content visible for few controls when linked to a policy](https://community.trustcloud.ai/tcf/reply/4715/): The most common and relevant controls are linked to the policy and have the descriptive content by default. For the more nuanced controls, you always have the ability to link those to the policy as well as add the descriptive content to reflect how that policy is implemented in your organization. - [Reply To: Email notifications if a team member assigns me as the question owner](https://community.trustcloud.ai/tcf/reply/4801/): Yes, make sure you have your notification settings to all email notifications - [Reply To: Editing previous answers in TrustShare](https://community.trustcloud.ai/tcf/reply/4793/): Users can go back to certain security questionnaires and modify or re-submit responses. - [Reply To: Customizing a control](https://community.trustcloud.ai/tcf/reply/4750/): We understand that every business is distinct and may already have established security and privacy programs. With this understanding, we have prioritized control customization as a fundamental aspect of our platform, ensuring a seamless process for tailoring controls to your specific needs. In TrustOps, you can easily customize controls on the control details page. This allows you to modify control statement language, policy mappings, and control frequency, enabling you to accurately align the controls with your unique business practices. By offering this level of flexibility, we empower you to enhance the effectiveness and relevance of your security and privacy measures within our platform. - [Reply To: Controls and tests automated with each integration](https://community.trustcloud.ai/tcf/reply/4738/): That depends with your program and controls that you have adopted. You can see a preview of all the different criteria and mappings of each integration on the available integration tab on your TrustCloud - [Reply To: Custom Frameworks in TrustCloud](https://community.trustcloud.ai/tcf/reply/4727/): A custom framework is a framework that has been uploaded or created in TrustOps that is not natively supported by TrustCloud. - [Reply To: Creating tickets on behalf of a customer](https://community.trustcloud.ai/tcf/reply/4704/): We always recommend the customer to create the support tickets so our support team can directly communicate with you on any support related inquiries to ensure you get the response quickly as possible. - [Reply To: Control status vs Test status](https://community.trustcloud.ai/tcf/reply/4775/): Control status is the adoption status of a control. In other words, is the control Adopted or Planned. Adopted controls are any controls that are considered in-scope for your audit and Planned controls are considered out-of-scope, but are potential controls you can implement in the future. - [Reply To: Control compliance software](https://community.trustcloud.ai/tcf/reply/4624/): Control compliance started out with spreadsheets which allowed for infinite customizability. Biggest challenge was keeping all this data manually updated across a growing tech stack - [Reply To: Communicating controls to stakeholders](https://community.trustcloud.ai/tcf/reply/4617/): As a part of best practice, stakeholder engagement is critical to adoption of a cohesive compliance program. - [Reply To: Control frequency logic](https://community.trustcloud.ai/tcf/reply/4645/): You may have compliance or regulatory requirments that require you to follow defined control testing frequencies or your auditor define these for you. Generally, all controls need to be tested at least once a year, but depnding on the type of standard you are looking to adhere to this may vary. It is best practice to set more frequent testing frequencies for controls tied to higher risks. For example, any controls related to mitagating unauthorized access will likely need to be tested more frequently than a control associated with updating your org chart. Another factor that can determine frequency is the maturity of your business and internal cycles. For example, you may want to test your hiring and recruitments controls if your company is consistantly growing its team but if you do not plan to hire many people for the forseeable future then testing this once will probably be sufficient. If you are still unsure on what is the best frequency for your controls please reach out to your Customer Success Manager or Trust Advisor. - [Reply To: Communicating compliance posture to your board](https://community.trustcloud.ai/tcf/reply/4630/): We use TrustShare, an application within TrustCloud that displays our compliance posture in real time! - [Reply To: Bringing my own Risk Register](https://community.trustcloud.ai/tcf/reply/4785/): Yes. Checkout this article for step-by-step instructions on how to upload your risk register in TrustRegister. If you require further assistance please contact support or your Customer Success Manager. https://community.trustcloud.ai/docs/trustregister/getting-started/#step-by-step-guide-to-create-your-account - [Reply To: BAA and vendors](https://community.trustcloud.ai/tcf/reply/4647/): According to the requirements of the Health Insurance Portability and Accountability Act (HIPAA), you are only required to have a Business Associate Agreement (BAA) in place with vendors or service providers who will have access to or handle Protected Health Information (PHI) on behalf of your organization. - [Reply To: Choosing an auditor](https://community.trustcloud.ai/tcf/reply/4639/): This varies by organization but a few things we like to share up front about our audit partners are: cost, breadth of services, team size, turn around time, availability, and location. - [Reply To: Audit preparation time](https://community.trustcloud.ai/tcf/reply/4622/): While audit readiness can be achieved in as little as 4 - 6 weeks, we typically recommend that clients start the audit readiness process 3 - 6 months prior to wanting to complete the audit. - [Reply To: Audit readiness progress tracking](https://community.trustcloud.ai/tcf/reply/4711/): Using Audit Dashboard. You can read more here: https://community.trustcloud.ai/docs/trustops/audit-dashboard/ - [Reply To: Automated tests vs Self assessment tests](https://community.trustcloud.ai/tcf/reply/4763/): Once your integrations are in place, you can take full advantage of the benefits offered by automated tests in TrustOps. These tests are designed to run automatically at the defined evaluation frequency for each control. When an automated test is executed, the corresponding evidence for that control is fetched automatically, streamlining the assessment process. - [Reply To: Adopting a new framework](https://community.trustcloud.ai/tcf/reply/4620/): When adopting a new framework, it's important to consider the business objectives you are trying to accomplish. Most B2B companies will require reports such as a SOC 2 or ISO certification as a starting point, while B2C companies may need to consider PCI. - [Reply To: Adopting controls and leaving controls as planned](https://community.trustcloud.ai/tcf/reply/4717/): The controls required to meet the SOC 2 and ISO 27001 requirements come in as adopted when your program is created. That said, you also have access to other controls that you can adopt to show the maturity of your program. You are not required to adopt all, but if you are implementing those controls, go ahead and adopt them. - [Reply To: Adding my own system](https://community.trustcloud.ai/tcf/reply/4773/): To add a system in TrustOps, follow these step-by-step instructions. First, locate the Systems page in the left panel of the screen. Click on the "+ Add System" button. - [Reply To: Adding my own policies](https://community.trustcloud.ai/tcf/reply/4765/): TrustCloud provides a comprehensive selection of pre-configured policies to cater to various needs. However, there might be specific use cases where additional policies are required. If you find yourself in such a scenario, we recommend reaching out to our support team for assistance. They will be able to verify the policies already included in your plan and guide you accordingly. - [Reply To: Adding additional accounts to my integrations](https://community.trustcloud.ai/tcf/reply/4742/): Yes, you can add additional accounts by going into the My integrations tab on your TrustCloud and clicking on the integration configured to add another account - [Reply To: Adding a custom policy](https://community.trustcloud.ai/tcf/reply/4740/): Yes, you can bring your own policy and also can add a new policy which is located on the Policies tab in your Program. ## Glossary - [Fair Labor Standards Act (FLSA)](https://community.trustcloud.ai/glossary/fair-labor-standards-act-flsa/): The Fair Labor Standards Act (FLSA) is a U.S. law establishing minimum wage, overtime pay, and child labor protections. Employers must comply with its requirements to avoid penalties and lawsuits. - [Insider Threat](https://community.trustcloud.ai/glossary/insider-threat/): Insider threat is a risk posed by employees or contractors who misuse their access to harm an organization. Mitigating this requires strict access controls and monitoring mechanisms. - [Operational Risk](https://community.trustcloud.ai/glossary/operational-risk/): Operational risk is the risk of loss due to inadequate or failed internal processes, people, or systems. Compliance teams work to minimize such risks through audits and monitoring. - [Benchmarking](https://community.trustcloud.ai/glossary/benchmarking/): Benchmarking is the practice of comparing an organization's processes or performance metrics to industry standards or competitors. It helps identify compliance gaps and opportunities for improvement. - [Data Subject](https://community.trustcloud.ai/glossary/data-subject/): A data subject is an individual whose personal data is collected, processed, or stored by an organization, as defined under regulations like GDPR. - [Data Governance](https://community.trustcloud.ai/glossary/data-governance/): Data governance is about policies and practices ensuring data is managed securely, accurately, and responsibly throughout its lifecycle. - [Cybersecurity compliance](https://community.trustcloud.ai/glossary/cybersecurity-compliance/): Cybersecurity compliance is about adherence to laws, policies, and standards that protect systems, networks, and data from cyber threats. - [Adverse Action](https://community.trustcloud.ai/glossary/adverse-action/): Adverse action is a decision that negatively impacts an individual or entity, such as denying credit or employment. It often triggers specific compliance requirements, such as providing reasons under the Fair Credit Reporting Act (FCRA). - [Corporate Social Responsibility (CSR)](https://community.trustcloud.ai/glossary/corporate-social-responsibility-csr/): Corporate Social Responsibility (CSR) is a company’s commitment to ethical behavior, environmental sustainability, and community well-being beyond legal requirements. - [Compliance Framework](https://community.trustcloud.ai/glossary/compliance-framework/): Compliance Framework is a structured set of guidelines and practices that help organizations meet legal, regulatory, and operational requirements. - [Anti-Money Laundering](https://community.trustcloud.ai/glossary/anti-money-laundering/): Anti-Money Laundering (AML) regulations and procedures aimed at preventing criminals from disguising illegally obtained funds as legitimate income. - [Accreditation](https://community.trustcloud.ai/glossary/accreditation/): Accreditation is a formal recognition that an organization meets certain standards, often granted by an external body. - [Whistleblowing](https://community.trustcloud.ai/glossary/whistleblowing/): Whistleblowing is the act of reporting unethical, illegal, or unsafe practices within an organization to internal or external authorities to ensure accountability and corrective action. - [Code of Conduct](https://community.trustcloud.ai/glossary/code-of-conduct/): A code of conduct is a set of rules outlining the social norms, ethical principles, and responsibilities of individuals within an organization. - [Trust Services Criteria](https://community.trustcloud.ai/glossary/trust-services-criteria/): The SOC Trust Services Criteria (TSC) are a set of standards developed by the AICPA (American Institute of Certified Public Accountants) to evaluate how well an organization safeguards data in a SOC 2 or SOC 3 audit. - [Information Security Policy](https://community.trustcloud.ai/glossary/information-security-policy/): Information Security Policy is a formal document outlining an organization’s approach to protecting its information assets. - [Global Compliance](https://community.trustcloud.ai/glossary/global-compliance/): Global compliance is the practice of adhering to regulatory requirements across multiple jurisdictions. - [Digital Certificate](https://community.trustcloud.ai/glossary/digital-certificate/): A digital certificate is an electronic document that verifies the identity of individuals or devices using public key infrastructure (PKI). - [Asset Tagging](https://community.trustcloud.ai/glossary/asset-tagging/): Asset tagging helps in monitoring the life cycle of IT resources and ensuring security controls are enforced. - [Zero Trust Architecture](https://community.trustcloud.ai/glossary/zero-trust-architecture/): Zero trust requires continuous verification and monitoring of all access requests to reduce the risk of insider threats and external attacks. - [Whaling](https://community.trustcloud.ai/glossary/whaling/): Whaling is a type of phishing attack that specifically targets high-profile individuals within an organization, such as executives. - [Vendor Risk Management](https://community.trustcloud.ai/glossary/vendor-risk-management/): Vendor Risk Management (VRM) is the process of identifying, assessing, and mitigating risks associated with third-party vendors. - [Third-Party Risk Assessment](https://community.trustcloud.ai/glossary/third-party-risk-assessment/): Third-Party Risk Assessment is a process of evaluating the security, privacy, and compliance practices of external vendors, suppliers, and partners. - [Supply Chain Risk Management](https://community.trustcloud.ai/glossary/supply-chain-risk-management/): Supply Chain Risk Management (SCRM) is the process of identifying and mitigating risks associated with the supply chain, including third-party vendors and service providers. - [Software as a Service](https://community.trustcloud.ai/glossary/software-as-a-service/): Software as a Service (SaaS) is a cloud computing model where applications are hosted by a service provider and made available to customers over the internet. - [Role-Based Access Control](https://community.trustcloud.ai/glossary/role-based-access-control/): Role-Based Access Control (RBAC) is a method for restricting system access based on the roles of individual users within an organization. - [Data minimization](https://community.trustcloud.ai/glossary/data-minimization/): Data minimization is a privacy principle that encourages collecting only the data necessary for a specific purpose. - [CRL](https://community.trustcloud.ai/glossary/crl/): CRL stands for Certificate Revocation List. A list of digital certificates that have been revoked before their expiration date by the certificate authority (CA). - [Identity Federation](https://community.trustcloud.ai/glossary/identity-federation/): Identity Federation is a system that allows users to authenticate and access multiple systems or applications across different organizations using a single set of credentials - [Backup and Recovery](https://community.trustcloud.ai/glossary/backup-and-recovery/): Backup and recovery is the process of creating and storing copies of data that can be restored in case of data loss. - [Application Security](https://community.trustcloud.ai/glossary/application-security/): Application security is the practice of protecting software applications from security threats throughout the development lifecycle. - [Virtual Private Network](https://community.trustcloud.ai/glossary/virtual-private-network/): Virtual Private Network (VPN) is a service that encrypts internet traffic and routes it through a secure server, providing privacy and anonymity online. - [Third-Party Due Diligence](https://community.trustcloud.ai/glossary/third-party-due-diligence/): Third-Party Due Diligence is a comprehensive evaluation of a third-party vendor or service provider's security, financial, and operational practices before engaging in a business relationship. - [Spoofing](https://community.trustcloud.ai/glossary/spoofing/): Spoofing is a cyberattack where an attacker disguises themselves as a trusted entity to gain access to sensitive information. - [Governance Framework](https://community.trustcloud.ai/glossary/governance-framework/): Governance Framework is a structured approach to managing and overseeing an organization's IT systems, processes, and risks. - [Security Incident Response](https://community.trustcloud.ai/glossary/security-incident-response/): Security Incident Response is the coordinated effort to detect, investigate, and respond to a security breach or attack. - [Data Leakage Prevention](https://community.trustcloud.ai/glossary/data-leakage-prevention/): Data Leakage Prevention (DLP) is a strategy or tool designed to prevent unauthorized transmission of sensitive information outside the corporate network. - [Public Key Infrastructure](https://community.trustcloud.ai/glossary/public-key-infrastructure/): Public Key Infrastructure (PKI) is a framework for creating, distributing, and managing digital certificates that verify identities and encrypt communications. - [Social Engineering](https://community.trustcloud.ai/glossary/social-engineering/): Social engineering is a type of cyberattack that relies on manipulating individuals into divulging confidential information or performing actions that compromise security. - [Service Level Agreement](https://community.trustcloud.ai/glossary/service-level-agreement/): Service Level Agreement (SLA) is a contract between a service provider and a customer that defines the level of service expected. - [Security Operations Center](https://community.trustcloud.ai/glossary/security-operations-center/): The Security Operations Center (SOC) is a centralized team responsible for monitoring, detecting, and responding to security incidents within an organization. - [Data Exfiltration](https://community.trustcloud.ai/glossary/data-exfiltration/): Data exfiltration is the unauthorized transfer of data from a network or system. - [DNS Spoofing](https://community.trustcloud.ai/glossary/dns-spoofing/): DNS spoofing is a type of attack where an attacker corrupts the DNS cache or alters DNS records to redirect traffic from legitimate websites to malicious ones. - [Geofencing](https://community.trustcloud.ai/glossary/geofencing/): Geofencing is a location-based security technique that restricts access to systems, networks, or devices based on geographic location. - [Honeypot](https://community.trustcloud.ai/glossary/honeypot/): Honeypot is a decoy system designed to attract attackers and study their methods while appearing as a legitimate target. - [Malware-as-a-Service](https://community.trustcloud.ai/glossary/malware-as-a-service/): Malware-as-a-Service (MaaS) is a business model where cybercriminals provide malware tools and services to other attackers for a fee. - [QR Code Phishing](https://community.trustcloud.ai/glossary/qr-code-phishing/): QR Code Phishing is a type of phishing attack where attackers use malicious QR codes to trick users into visiting fraudulent websites or downloading malware. - [Multifactor Authentication](https://community.trustcloud.ai/glossary/multifactor-authentication/): Multifactor Authentication (MFA) is a security mechanism that requires users to provide two or more forms of verification before accessing a system or service. - [Data Integrity](https://community.trustcloud.ai/glossary/data-integrity/): Data integrity ensures that data remains accurate, consistent, and unaltered during storage, processing, or transmission. - [Application Whitelisting](https://community.trustcloud.ai/glossary/application-whitelisting/): Application whitelisting is a security control that allows only approved or trusted applications to execute on a system. - [Ransomware-as-a-Service (RaaS)](https://community.trustcloud.ai/glossary/ransomware-as-a-service-raas/): Ransomware-as-a-Service (RaaS) is a model where cybercriminals offer ransomware tools and services to other attackers in exchange for a share of the ransom payment. - [Internet of Things (IoT) Security](https://community.trustcloud.ai/glossary/internet-of-things-iot-security/): Internet of Things (IoT) security is the practice of securing connected devices and sensors that interact over the internet, such as smart home devices, industrial systems, and medical equipment. - [Threat Intelligence](https://community.trustcloud.ai/glossary/threat-intelligence/): Threat intelligence is the collection and analysis of information about potential or existing cyber threats. - [Tokenization](https://community.trustcloud.ai/glossary/tokenization/): Tokenization is a security technique that replaces sensitive data, such as credit card numbers, with unique tokens that cannot be used outside of the system. - [Role-Based Access Control (RBAC)](https://community.trustcloud.ai/glossary/role-based-access-control-rbac/): Role-Based Access Control, or RBAC, is a method for restricting system access based on the roles of individual users within an organization. - [Data Retention](https://community.trustcloud.ai/glossary/data-retention/): Data retention refers to the policies and practices regarding how long data is stored and when it is deleted. - [Vulnerability Assessment](https://community.trustcloud.ai/glossary/vulnerability-assessment/): Vulnerability assessment is the process of identifying, quantifying, and prioritizing vulnerabilities in systems, networks, and applications. - [Data encryption](https://community.trustcloud.ai/glossary/data-encryption/): Data encryption is the process of converting plaintext data into a coded form to prevent unauthorized access. - [Incident Playbook](https://community.trustcloud.ai/glossary/incident-playbook/): The incident playbook is a predefined set of actions and responses for handling specific types of security incidents. - [Dynamic Data Masking](https://community.trustcloud.ai/glossary/dynamic-data-masking/): Dynamic Data Masking is a security technique that obscures sensitive information in real-time as it is accessed by non-privileged users while keeping the underlying data unchanged. Dynamic data masking allows users to interact with data without exposing sensitive details, reducing security risks. - [Advanced Persistent Threat (APT)](https://community.trustcloud.ai/glossary/advanced-persistent-threat-apt/): Advanced Persistent Threat (APT) is a sophisticated cyberattack where an unauthorized user gains access to a system and remains undetected for a prolonged period. - [EDR](https://community.trustcloud.ai/glossary/edr/): EDR solutions help organizations quickly identify and mitigate endpoint threats. - [Zero-Day Exploit](https://community.trustcloud.ai/glossary/zero-day-exploit/): Zero-day exploits are highly dangerous, as attackers can exploit the vulnerability before it is detected and addressed. - [WAF](https://community.trustcloud.ai/glossary/waf/): Web Application Firewall (WAF) is a security tool that monitors and filters HTTP traffic between a web application and the internet. - [Risk Assessment](https://community.trustcloud.ai/glossary/risk-assessment/): Risk Assessment is the process of identifying, evaluating, and prioritizing risks to organizational assets. - [DLP](https://community.trustcloud.ai/glossary/dlp/): DLP solutions monitor and control data transfers, ensuring that confidential information does not leave the organization’s boundaries. - [Shadow IT](https://community.trustcloud.ai/glossary/shadow-it/): Shadow IT is the use of information technology systems, devices, or software without explicit approval from an organization's IT department. Shadow IT can introduce security vulnerabilities and compliance risks, as these systems may not adhere to the organization's security policies. - [Phishing](https://community.trustcloud.ai/glossary/phishing/): Phishing attacks are often carried out through emails or fake websites. - [Patch Management](https://community.trustcloud.ai/glossary/patch-management/): Patch Management is the process of regularly applying software updates to fix vulnerabilities, improve functionality, and enhance security. - [IP Whitelisting](https://community.trustcloud.ai/glossary/ip-whitelisting/): IP Whitelisting is a security technique that allows only trusted IP addresses to access a network or system. - [Email Spoofing](https://community.trustcloud.ai/glossary/email-spoofing/): Email Spoofing is the practice of forging the sender's address in an email to make it appear as though it is from a trusted source. - [CASB](https://community.trustcloud.ai/glossary/casb/): CASBs help organizations manage cloud security risks, such as data loss, unauthorized access, and regulatory compliance. - [Cyber Hygiene](https://community.trustcloud.ai/glossary/cyber-hygiene/): Cyber Hygiene are the routine practices and behaviors that help maintain the security of information systems. - [UTM](https://community.trustcloud.ai/glossary/utm/): Unified Threat Management (UTM) is a security solution that combines multiple security features, such as firewalls, intrusion detection, and antivirus protection, into a single platform. - [2FA](https://community.trustcloud.ai/glossary/2fa/): 2FA enhances security by combining something the user knows (e.g., a password) with something the user has (e.g., a phone or security token). - [Encryption Key Rotation](https://community.trustcloud.ai/glossary/encryption-key-rotation/): Encryption Key Rotation is the process of periodically changing encryption keys to reduce the risk of them being compromised. Key rotation is essential for maintaining the security of encrypted data and is often part of a broader key management strategy. - [Cyber Insurance](https://community.trustcloud.ai/glossary/cyber-insurance/): Cyber insurance helps mitigate the financial impact of security events, but organizations must still maintain robust security controls. - [Botnet](https://community.trustcloud.ai/glossary/botnet/): A network of compromised devices (bots) controlled remotely by attackers to perform malicious activities, such as launching DDoS attacks or sending spam. Botnets pose a significant threat to organizations by allowing attackers to harness distributed computing power for large-scale attacks. - [Behavior-Based Detection](https://community.trustcloud.ai/glossary/behavior-based-detection/): Behavior-Based Detection is a security approach that identifies potential threats based on deviations from normal behavior rather than relying solely on known attack patterns. - [KRI](https://community.trustcloud.ai/glossary/kri/): KRIs help organizations proactively monitor and manage potential threats to their operations or security. - [DES](https://community.trustcloud.ai/glossary/des/): DES or Data Encryption Standard is a symmetric-key encryption algorithm used to protect sensitive information. - [SQL Injection](https://community.trustcloud.ai/glossary/sql-injection/): SQL Injection is a code injection technique used by attackers to exploit vulnerabilities in web applications that use SQL databases. - [Single Sign-On (SSO)](https://community.trustcloud.ai/glossary/single-sign-on-sso/): Single Sign-On (SSO) is an authentication process that allows users to access multiple applications with one set of login credentials. SSO simplifies the user experience while enhancing security by reducing the number of passwords a user must manage. - [Security Information and Event Management (SIEM)](https://community.trustcloud.ai/glossary/security-information-and-event-management-siem/): A system that collects, analyzes, and reports on security events from multiple sources in real-time. SIEM tools help organizations detect and respond to security threats by providing a centralized view of potential incidents. - [Data Classification](https://community.trustcloud.ai/glossary/data-classification/): Data classification is the process of categorizing data based on its sensitivity and value to the organization. - [Data Breach](https://community.trustcloud.ai/glossary/data-breach/): A data breach occurs when unauthorized individuals access or steal sensitive data. Breaches can result from hacking, insider threats, or weak security controls. - [Cybersecurity](https://community.trustcloud.ai/glossary/cybersecurity/): Cybersecurity refers to the practice of protecting systems, networks, and data from cyberattacks. - [Cloud Security](https://community.trustcloud.ai/glossary/cloud-security/): Cloud security involves the policies, controls, and technologies that protect cloud-based systems, data, and infrastructure. - [Business Continuity Plan (BCP)](https://community.trustcloud.ai/glossary/business-continuity-plan-bcp/): A BCP outlines procedures and processes to ensure that critical business functions can continue during and after a disaster. A well-prepared BCP minimizes downtime and protects the organization’s reputation during crises. - [Audit Trail](https://community.trustcloud.ai/glossary/audit-trail/): An audit trail is a record of all user activities and transactions within a system. - [Asset Management](https://community.trustcloud.ai/glossary/asset-management/): Asset management is the process of tracking and managing an organization’s IT and information resources. - [Access Control](https://community.trustcloud.ai/glossary/access-control/): Access control ensures only authorized users can access specific systems, resources, or data. - [TrustLens](https://community.trustcloud.ai/glossary/trustlens/): Application that provides a comprehensive vendor risk management solution that simplifies the assessment process for businesses. By creating assessment templates or uploading existing questionnaires, users can efficiently gather the necessary information from vendors. - [AUP](https://community.trustcloud.ai/glossary/aup/): An Acceptable Use Policy (AUP) is a set of rules and guidelines that outline how users are permitted to use a company's or organization's resources, including networks, websites, and IT systems. - [PII](https://community.trustcloud.ai/glossary/pii/): Personally Identifiable Information (PII) refers to data that can be used to identify an individual, such as names, addresses, Social Security numbers, or biometric records. - [AICPA](https://community.trustcloud.ai/glossary/aicpa/): AICPA stands for the American Institute of Certified Public Accountants. SOC audit and reporting standards that define the criteria for managing customer information were designed by this member association. - [TrustOps](https://community.trustcloud.ai/glossary/trustops/): Application that enables continuous compliance automation. TrustOps empowers teams to manage their internal trust operations and achieve one or more security and privacy compliance standards such as SOC 2, HIPAA, ISO 27001, etc. - [Due Diligence](https://community.trustcloud.ai/glossary/due-diligence/): Due diligence is the thorough investigation and evaluation of potential risks, compliance obligations, and the integrity of business partners. - [Disclosure](https://community.trustcloud.ai/glossary/disclosure/): Disclosure is an act of revealing relevant information, particularly regarding compliance, risks, and governance, to stakeholders or authorities. - [Protocol](https://community.trustcloud.ai/glossary/protocol/): A protocol is a set of predefined procedures governing the conduct of activities, particularly in risk and compliance contexts. - [Vigilance](https://community.trustcloud.ai/glossary/vigilance/): Vigilance is the continuous and proactive effort to identify, assess, and respond to risks, incidents, and compliance challenges. - [Penalty](https://community.trustcloud.ai/glossary/penalty/): A penalty is a punishment or fine imposed for violating laws, regulations, or internal policies, serving as a deterrent to non-compliance. - [Liability](https://community.trustcloud.ai/glossary/liability/): Liability is a legal responsibility for the consequences of actions or inactions, particularly concerning compliance and governance. - [Inspection](https://community.trustcloud.ai/glossary/inspection/): Inspection is a formal review or examination of processes, systems, or records to verify compliance with regulations and standards. - [Fraud](https://community.trustcloud.ai/glossary/fraud/): Fraud is an intentional deception or misrepresentation for personal or financial gain, often resulting in legal and compliance issues. - [Detection](https://community.trustcloud.ai/glossary/detection/): Detection is the identification of potential risks, incidents, or non-compliance issues. - [Privacy](https://community.trustcloud.ai/glossary/privacy/): Privacy is about the protection of personal or sensitive information from unauthorized access or disclosure. - [Incident Management](https://community.trustcloud.ai/glossary/incident-management/): Incident management is the process of identifying, managing, and mitigating incidents that could harm an organization’s operations. - [Control Framework](https://community.trustcloud.ai/glossary/control-framework/): A control framework is a structured approach to managing risks by implementing controls across an organization. - [Data Privacy](https://community.trustcloud.ai/glossary/data-privacy/): Data privacy involves the proper handling of personal information, ensuring it is protected from unauthorized access. Privacy regulations like GDPR and CCPA require organizations to implement policies and procedures to safeguard personal data. Maintaining data privacy helps build trust with customers and avoids costly fines. - [Regulatory Compliance](https://community.trustcloud.ai/glossary/regulatory-compliance/): Regulatory compliance is about ensuring that an organization follows external laws, regulations, and guidelines applicable to its business. - [Internal Audit](https://community.trustcloud.ai/glossary/internal-audit/): An internal audit is an independent, objective assurance and consulting activity designed to add value and improve an organization’s operations. - [Forensics](https://community.trustcloud.ai/glossary/forensics/): Forensics is the application of scientific methods to investigate and gather evidence from digital systems. Forensics is used in GRC to analyze breaches, identify perpetrators, and support legal actions. - [Response](https://community.trustcloud.ai/glossary/response/): Response is the action taken by an organization to address an incident, breach, or other disruptive event. Effective response plans are critical for minimizing damage and restoring normal operations. - [Encryption](https://community.trustcloud.ai/glossary/encryption/): Encryption is the process of converting information into a code to prevent unauthorized access. Encryption is a fundamental aspect of data security, ensuring that sensitive information is protected. - [Assurance](https://community.trustcloud.ai/glossary/assurance/): Assurance is the confidence that a system, process, or control is operating as intended. Assurance activities, such as audits and assessments, help verify the effectiveness of GRC measures. - [Continuity](https://community.trustcloud.ai/glossary/continuity/): Continuity is the planning and preparation to ensure that an organization can continue its critical operations in the event of a disruption. Business continuity planning is vital for resilience and risk management. - [Strategy](https://community.trustcloud.ai/glossary/strategy/): Strategy is a plan of action designed to achieve long-term or overall objectives. In GRC, strategies guide how organizations manage risks, ensure compliance, and achieve their governance goals. - [Remediation](https://community.trustcloud.ai/glossary/remediation/): Remediation is the process of addressing and correcting deficiencies, vulnerabilities, or non-compliance issues. Remediation is essential for maintaining the effectiveness of controls and minimizing risk. - [Sanction](https://community.trustcloud.ai/glossary/sanction/): Sanction is a penalty or corrective action imposed for non-compliance with regulations, policies, or standards. Sanctions serve as a deterrent against violations and encourage adherence to rules. - [Escalation](https://community.trustcloud.ai/glossary/escalation/): Escalation is the process of moving an issue or incident to a higher level of authority for resolution. Escalation is used when an issue cannot be resolved at the current level and requires additional attention. - [Notification](https://community.trustcloud.ai/glossary/notification/): Notification is the process of informing relevant stakeholders about a significant event, such as a security breach or policy change. Timely notification is critical for effective response and management. - [Benchmark](https://community.trustcloud.ai/glossary/benchmark/): A benchmark is a standard or point of reference against which things can be compared or assessed. Benchmarks help organizations gauge their performance and identify areas for improvement. - [Accountability](https://community.trustcloud.ai/glossary/accountability/): Accountability is the obligation of individuals or organizations to accept responsibility for their actions and decisions. Accountability is fundamental in the GRC for ensuring transparency and trust. - [Oversight](https://community.trustcloud.ai/glossary/oversight/): Oversight is the process of supervising and monitoring activities to ensure they comply with established policies and standards. Oversight is crucial for accountability and effective governance. - [Ethics](https://community.trustcloud.ai/glossary/ethics/): Ethics are the moral principles that govern an organization’s behaviour and decision-making. Ethics in GRC ensures that actions are not only legal but also morally sound. - [Evaluation](https://community.trustcloud.ai/glossary/evaluation/): Evaluation is the systematic assessment of the effectiveness, efficiency, and relevance of policies, procedures, or controls. Evaluation helps organizations make informed decisions and improve their practices. - [Enforcement](https://community.trustcloud.ai/glossary/enforcement/): Enforcement is the process of ensuring compliance with laws, regulations, or policies. Enforcement may involve penalties, fines, or other corrective actions against those who violate the rules. - [Monitoring](https://community.trustcloud.ai/glossary/monitoring/): Monitoring is the continuous observation and tracking of systems, processes, or activities to ensure they are functioning as intended. Monitoring is essential for detecting issues early and maintaining compliance. - [Procedure](https://community.trustcloud.ai/glossary/procedure/): A procedure is a specific, step-by-step set of instructions for carrying out a particular task or operation. Procedures ensure tasks are completed correctly and consistently. - [Standard](https://community.trustcloud.ai/glossary/standard/): A standard is a set of criteria or benchmarks established by authoritative bodies that organizations must follow to ensure consistency and quality. Standards help align processes and improve efficiency. - [Regulation](https://community.trustcloud.ai/glossary/regulation/): Regulation is a rule or directive made and maintained by an authority to govern conduct within an organization or industry. Compliance with regulations is mandatory and often carries legal obligations. - [Confidentiality](https://community.trustcloud.ai/glossary/confidentiality/): Confidentiality ensures that sensitive information is accessible only to those authorized to view it. It is a key principle of information security, protecting data from unauthorized disclosure. Encryption, access control, and data masking are common methods used to maintain confidentiality. Confidentiality is essential to protect personal, financial, and business data. - [Integrity](https://community.trustcloud.ai/glossary/integrity/): Integrity is about ensuring that data and systems are accurate, complete, and unaltered by unauthorized parties. Integrity is a cornerstone of information security and is vital for trustworthy operations. - [Resilience](https://community.trustcloud.ai/glossary/resilience/): Resilience is the ability of an organization to withstand and recover quickly from disruptive events. Resilience involves not only the capacity to absorb shocks but also to adapt to changing conditions. - [Threat](https://community.trustcloud.ai/glossary/threat/): Threat is any circumstance or event with the potential to cause harm to an organization’s operations, assets, or individuals. Threats can be internal or external, and they must be managed to protect the organization. - [Vulnerability](https://community.trustcloud.ai/glossary/vulnerability/): A vulnerability is a weakness or gap in a security program that can be exploited by threats. Identifying and addressing vulnerabilities is crucial to minimizing risk. - [Assessment](https://community.trustcloud.ai/glossary/assessment/): Assessment is the process of evaluating risks, controls, or compliance to determine effectiveness. Assessments can be qualitative or quantitative and are essential for identifying areas of improvement. - [Breach](https://community.trustcloud.ai/glossary/breach/): A breach is an incident where unauthorized access, disclosure, or destruction of data occurs. Breaches can lead to significant financial and reputational damage for organizations. - [Incident](https://community.trustcloud.ai/glossary/incident/): An incident is an event that disrupts normal operations and may have negative consequences for an organization. Incidents can include security breaches, system failures, or compliance violations. - [Framework](https://community.trustcloud.ai/glossary/framework/): A framework is a structured approach or system used to organize and guide processes, practices, and decisions within an organization. GRC frameworks help ensure comprehensive risk management and compliance. - [Mitigation](https://community.trustcloud.ai/glossary/mitigation/): Actions taken to reduce the severity or likelihood of a risk. Mitigation strategies may include implementing controls, transferring risk, or avoiding certain actions altogether. - [Governance](https://community.trustcloud.ai/glossary/governance/): The system by which organizations are directed and controlled. It involves establishing policies and monitoring their proper implementation to ensure organizational objectives are met. - [TPRA](https://community.trustcloud.ai/glossary/tpra/): Third-party risk assessments (TPRA) provide insights into the potential risks posed by your vendors. - [TCCCF](https://community.trustcloud.ai/glossary/tcccf/): The TCCCF is a set of comprehensive controls that were developed based on common requirements from various industry security and privacy frameworks such as NIST, ISO, SOC, and HITRUST. - [PHI](https://community.trustcloud.ai/glossary/phi/): PHI is any personal health information that potentially identifies an individual that was created, used, or disclosed in the course of providing healthcare services, including, but not limited to: Names, Addresses, Date of birth, Social security number, Payment or billing information and, Medical records (electronic or paper) - [Protected Health Information](https://community.trustcloud.ai/glossary/protected-health-information/): PHI is any personal health information that potentially identifies an individual that was created, used, or disclosed in the course of providing healthcare services, including, but not limited to: Names, Addresses, Date of birth, Social security number, Payment or billing information and, Medical records (electronic or paper) - [Compliance Program](https://community.trustcloud.ai/glossary/compliance-program/): A compliance program is a company's set of internal artifacts (controls, policies, systems, etc.) put into place in order to comply with laws, rules, and regulations or to uphold the business's reputation. - [Risk Management](https://community.trustcloud.ai/glossary/risk-management/): Risk management is the process of identifying, assessing, and mitigating potential risks that could negatively impact an organization's objectives, goals, or projects. The objective of risk management is to minimize the likelihood and impact of risks by developing and implementing proactive measures to mitigate them - [Subservice Organization](https://community.trustcloud.ai/glossary/subservice-organization/): If a vendor’s controls, in combination with your organization’s controls, are necessary to achieve your service commitments and system requirements, to meet your SOC 1 objectives, or to fulfill applicable SOC 2 trust services criteria, then the vendor is classified as a “subservice organization". Subservice organizations are critical to the success of the service organization. - [Third-Party Vendor](https://community.trustcloud.ai/glossary/third-party-vendor/): A third party vendor is a person or company that provides services for another company (or that company's customers). - [Security Posture](https://community.trustcloud.ai/glossary/security-posture/): An organization's security posture (or cybersecurity posture) is the collective security status of all software, hardware, services, networks, information, vendors and service providers.  - [Security Questionnaire](https://community.trustcloud.ai/glossary/trustshare/security-questionnaire/): Security questionnaires are lists of often complex and technical questions, usually compiled by IT teams, to determine a company's security and compliance posture. - [Vendor](https://community.trustcloud.ai/glossary/vendor/): A company that builds and ships a system. For example, Microsoft is the vendor for systems like Azure AD, Confluence, Office 365 etc. - [User](https://community.trustcloud.ai/glossary/user/): An individual who uses TrustCloud, identified with their email ID. A user may be part of a single team, or multiple teams. Most users belong to a single team. - [TrustRegister](https://community.trustcloud.ai/glossary/trustregister/): Predictive intelligence to eliminate manual, unreliable processes and optimize your risk management program. TrustRegister helps you identify risks, streamline remediation, and assess business impact so you can maintain a proactive program - good riddance to that pesky spreadsheet - [TrustShare](https://community.trustcloud.ai/glossary/trustshare/): An automatically generated, interactive website that TrustCloud customers use as a single place for all trust communication with their prospects and customers. TrustShare confidently showcases your company’s security and compliance hygiene to help you bi-pass completing security questionnaires! - [TrustHQ](https://community.trustcloud.ai/glossary/trusthq/): TrustHQ enables companies to engage their employees in meeting their trust obligations to the company. Employees can understand, and periodically attest to their obligations to the company - such as reading and acknowledging company policies, declaring their use of third-party software systems, completing training etc. - [Trust Assurance](https://community.trustcloud.ai/glossary/trust-assurance/): Trust Assurance is a brand new approach. Trust Assurance is a crafted, consumer-grade user experience that demystifies compliance. It pairs machine learning with intuitive design to do most of the work for you; embedding accurate testability into every workflow to reduce your risk and ensure truth in compliance. Trust Assurance enables teams of all maturity and experience levels to understand, generate, measure and manage compliance programs with confidence and ease. - [Trust Champion](https://community.trustcloud.ai/glossary/trust-champion/): The person who helps their organization measure and meet its internal compliance obligations. Their actions support revenue-generating activities, protect their organization from legal and contractual liabilities, and enable the organization to confidently and transparently showcase an intentional, robust, and differentiated culture of trust. - [Test](https://community.trustcloud.ai/glossary/test/): A test checks for a single requirement in a control. All controls contain one or more tests, each of which checks for a specific requirement of the control. - [Team (or “Account”)](https://community.trustcloud.ai/glossary/team-or-account/): A single customer’s instance of TrustCloud. “Team” roughly equates to a company, or an Organization Unit within a company. - [System](https://community.trustcloud.ai/glossary/system/): A piece of software, either built by the company or purchased from a third-party. All the cloud-based tools that employees use on a daily basis, typically qualify as systems. For example → Salesforce, Slack, JIRA, Miro, AWS S3, Gusto, etc. are all systems. - [Subcontractor](https://community.trustcloud.ai/glossary/subcontractor/): A Subcontractor is an entity to whom a Business Associate delegates a function, activity, or service, other than in the capacity of a member of the workforce of the Business Associate.  - [SOC Trust Services Criteria (TSC)](https://community.trustcloud.ai/glossary/soc-trust-services-criteria-tsc/): There are five Trust Service Criteria (TSC) or Trust Service Principles (TSP) within the SOC 2 framework. All organizations, independent of size, industry, or customer needs pursuing a SOC 2 have to include the Security Criteria. The others are optional and guided by the business and customer requirements. - [SOC 2 Type II Report](https://community.trustcloud.ai/glossary/soc-2-type-ii-report/): SOC 2 Type II reports assess the efficacy of an entity’s security and other applicable criteria since the last SOC 2 audit. Most SOC 2 reports are renewed annually. However, it is up to the company to decide to go under audit earlier if there is a necessity. - [SOC 2 Type I Report](https://community.trustcloud.ai/glossary/soc-2-type-i-report/): A SOC 2 Type I report examines the controls that govern an entity’s security and other applicable criteria at a point in time. This involves an auditor performing a walkthrough of your processes to understand and attest to the design of your internal controls. Therefore, it would usually be the first-ever SOC 2 report for a company. - [SOC 2 Report](https://community.trustcloud.ai/glossary/soc-2-report/): An audit report done by an objective, third-party firm that would be responsible for assessing your cybersecurity practices. All companies that hold customer information throughout their operation should consider scheduling and go through an audit. Depending on the maturity of the company, the intended audience for the report, and the scope, there are two types of SOC 2 reports to choose from: SOC 2 Type 1 and SOC 2 Type 2. - [SOC 2 Audit Firm](https://community.trustcloud.ai/glossary/soc-2-audit-firm/): SOC 2 audit firms are regulated by the AICPA, and they are required to be independent CPAs. The SOC 2 auditor you choose to work with will examine your controls (which will include evidence collection) to determine whether they are functioning properly. - [Security Rule (HIPAA)](https://community.trustcloud.ai/glossary/security-rule-hipaa/): The Security Rule protects a subset of information covered by the privacy rule, and sets the standard for the protection of electronically stored and transmitted PHI (ePHI). It does so by requiring the implementation of administrative, technical, and physical safeguards. - [TrustShare Questionnaires](https://community.trustcloud.ai/glossary/trustshare-questionnaires/): TrustShare feature that uses Machine Learning to auto-generate accurate answers to security questionnaires. - [Program](https://community.trustcloud.ai/glossary/program/): A compliance program is a company's set of internal artifacts (controls, policies, systems, etc.) put into place in order to comply with laws, rules, and regulations or to uphold the business's reputation. - [Privacy Rule](https://community.trustcloud.ai/glossary/privacy-rule-hipaa/): The Privacy Rule was developed to: Ensure that organizations that create and store health information take appropriate steps to protect this information from misuse or wrongful disclosure. - [Omnibus Rule](https://community.trustcloud.ai/glossary/omnibus-rule/): The HIPAA Omnibus Rule, which became effective in 2013, contains modifications and edits to the Security, Privacy, Breach Notification Rules and their enforcement. These modifications are intended to enhance confidentiality and security in data sharing, and strengthen the protection of protected health information, especially in electronic form. - [ISO 27701](https://community.trustcloud.ai/glossary/iso-27701/): ISO 27701 is a management standard that was published in 2019 in response to the growing need for a global data privacy framework. ISO (the International Organization for Standardization) and the IEC (the International Electrotechnical Commission) developed ISO 27701 as an addition to the popular ISO 27000 family of information security standards to provide much-needed guidance on how to comply with global privacy standards such as the California Consumer Privacy Act (CCPA), the EU GDPR (General Data Protection Regulation), and the New York SHIELD Act. - [HIPAA Violation](https://community.trustcloud.ai/glossary/hipaa-violation/): A HIPAA violation is the failure to comply with any of the standards outlined in the rules. Even after you’ve successfully completed an audit, there is a possibility that you may violate one of the HIPAA rules.  - [HIPAA Rules](https://community.trustcloud.ai/glossary/hipaa-rules/): There are four rules designed to keep PHI safe and secure, and to properly notify affected parties in case of a data breach: Privacy, Security, Breach Notification, and Omnibus. - [GDPR](https://community.trustcloud.ai/glossary/gdpr/): This is known to be the toughest privacy and security law. Approved in 2016, and enforced in May 2018 by the EU, it made the already strict European legal environment even more challenging for businesses. It imposes uniform data security on organizations that deal with the private information of EU citizens. - [Evidence](https://community.trustcloud.ai/glossary/evidence/): Each piece of evidence provides proof that a company is adhering to its controls. Auditors (and sometimes customers) require a company to provide evidence, so that they can validate that the company is actually meeting the compliance obligations it claims. - [Data Rooms](https://community.trustcloud.ai/glossary/data-rooms/): Securely Invite customers: By using the Data Rooms feature in TrustShare, sales and security teams now have full control over what documents get shared with each customer, by creating a data room for each customer, where specific documents that need to be accessible to that customer can be added. - [Covered Entities](https://community.trustcloud.ai/glossary/covered-entities/): If you are a Covered Entity, you are subject to, and legally required to, comply with all the standards set forth by HIPAA. - [Compliance Standard](https://community.trustcloud.ai/glossary/compliance-standard/): A set of requirements defined by a law, or by an authority, that is widely accepted as a standard for demonstrating your trust to your customers. - [CCPA](https://community.trustcloud.ai/glossary/ccpa/): A statewide data privacy law, effective from January 1, 2020, that reinforced individuals’ rights by strengthening company laws around the use of personal information. CCPA is said to be a model of GDPR and is sometimes called the “GDPR light”. However, some don’t agree with this, for they can be different in terms of who it applies to and how they define certain terms. - [Business Associate](https://community.trustcloud.ai/glossary/business-associate/): A Business Associate is an entity that provides services to, or performs certain functions involving the use or disclosure of PHI on behalf of, a Covered Entity. - [Breach Notification Rule](https://community.trustcloud.ai/glossary/breach-notification-rule-hipaa/): Any PHI usage or disclosure that isn’t permitted under the Privacy Rule is considered a breach. When a breach occurs, Covered Entities are required to notify affected individuals. - [AuditLens](https://community.trustcloud.ai/glossary/auditlens/): Application built for auditors to externally evaluate a company’s compliance program and assess it for adherence to a standard. - [HIPAA](https://community.trustcloud.ai/glossary/hipaa/): Regulated by the United States Department of Health and Human Services’ Office for Civil Rights (OCR), the Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law that established national standards to protect sensitive patient health information from being disclosed without the patient’s consent or knowledge. - [SOC 2](https://community.trustcloud.ai/glossary/soc-2/): SOC 2 is a comprehensive framework applicable to all service providers who store any kind of client data in the cloud or on-prem. Moreover, SOC 2 is the most widely adopted and requested compliance certification for SaaS vendors in the United States. - [GRC](https://community.trustcloud.ai/glossary/grc/): Governance, Risk and Compliance (GRC) is the integrated collection of capabilities that enable an organization to reliably achieve objectives, address uncertainty and act with integrity. ## - [Security Awareness Training – S](https://community.trustcloud.ai/?p=22114) ## ## ## ## ## - [Certificate](https://community.trustcloud.ai/?p=8516): &nbsp; ## - [Test 17Jan25](https://community.trustcloud.ai/?p=21858) ## Articles - [Security ratings are flawed! Here’s how to use them without getting burned](https://community.trustcloud.ai/article/security-ratings-are-flawed-heres-how-to-use-them-without-getting-burned/): Security ratings were supposed to simplify third-party risk management. - [Data fabric architecture for GRC: How to finally eliminate risk data silos](https://community.trustcloud.ai/article/data-fabric-architecture-for-grc-how-to-finally-eliminate-risk-data-silos/): Technical guide to building a data fabric connecting ERM, compliance, audit, and finance data covering metadata management and AI readiness scoring. - [Why 87% of organizations now list AI vulnerabilities as their top cyber risk](https://community.trustcloud.ai/article/why-87-of-organizations-now-list-ai-vulnerabilities-as-their-top-cyber-risk/): Security leaders are realizing that AI introduces a completely new attack surface, one that traditional cybersecurity strategies were never designed to handle. That’s why recent industry surveys show that 87% of organizations now rank AI vulnerabilities as their top cyber risk. The concern is no longer hypothetical. Businesses are already seeing real-world incidents tied to AI misuse, data leakage, model manipulation, and unauthorized AI access. - [ESG compliance is now a cyber risk problem: What every GRC team needs to know](https://community.trustcloud.ai/article/esg-compliance-is-now-a-cyber-risk-problem-what-every-grc-team-needs-to-know/): Connects ESG reporting mandates (CSRD, SEC climate rules) to information security controls with a cross-function compliance framework. - [The insider threat nobody budgets for: human risk in the age of GenAI](https://community.trustcloud.ai/article/the-insider-threat-nobody-budgets-for-human-risk-in-the-age-of-genai/): Human risk in the age of GenAI is evolving rapidly, making it essential for organizations to identify emerging threats before they cause significant damage. As businesses increasingly adopt artificial intelligence tools, cybercriminals and negligent insiders are finding new ways to exploit vulnerabilities. Risks such as unsecured remote work practices, deepfake-enabled fraud, and unmonitored third-party vendor activities are becoming more common and sophisticated. - [7 ways UEBA and AI are improving risk scoring accuracy for enterprises](https://community.trustcloud.ai/article/7-ways-ueba-and-ai-are-improving-risk-scoring-accuracy-for-enterprises/): In the rapidly changing cybersecurity landscape, enterprises must stay ahead of emerging threats while keeping their digital assets secure. For beginners in cybersecurity, concepts like User and Entity Behavior Analytics (UEBA) and artificial intelligence (AI) might seem advanced, yet they are becoming fundamental to improving risk scoring accuracy. This blog post provides an accessible, detailed guide for those with little to no prior experience in these areas, exploring seven distinct ways that UEBA and AI help enterprises refine and improve their cybersecurity risk assessments. - [Unlock the power of security automation with XDR and AI in 2026](https://community.trustcloud.ai/article/unlock-the-power-of-security-automation-with-xdr-and-ai-in-2026/): As cyber threats continue to evolve in complexity and scale, cybersecurity managers are in a constant race to outpace adversaries and secure organizational assets. One of the emerging trends in modern security has been the integration of extended detection and response (XDR) with machine learning capabilities. With 2026 on the horizon, understanding how XDR and machine learning converge is crucial for those looking to leverage security automation and AI in high-stakes defense strategies. This article will dive deep into the role of machine learning within XDR solutions, elucidate the benefits, and outline challenges while providing a forward-looking perspective for security leaders. - [How AI-powered SOAR tools cut incident response time by 70%](https://community.trustcloud.ai/article/how-ai-powered-soar-tools-cut-incident-response-time-by-70-2/): Discover how AI-powered SOAR tools slash incident response time by 70%, streamline cybersecurity operations, and boost efficiency. Learn key benefits, real-world examples, and implementation tips for faster threat mitigation today. - [MFA vs. SSO: Which identity solution best supports your zero-trust strategy?](https://community.trustcloud.ai/article/mfa-vs-sso-which-identity-solution-best-supports-your-zero-trust-strategy/): Zero-trust used to sound like a buzzword you’d only hear in vendor decks and security keynotes. Today, it’s the reality check for every team that’s tired of treating the corporate network like a magical safe zone. If users are logging in from everywhere, on every kind of device, and your most critical apps live in the cloud, then identity has quietly become your new perimeter. And that’s exactly where the “MFA vs. SSO” debate shows up: do you double down on stronger authentication or make access simpler and more centralized? - [The essential guide to IAM: Building access controls in a zero-trust world](https://community.trustcloud.ai/article/the-essential-guide-to-iam-building-access-controls-in-a-zero-trust-world/): Discover how to build secure, zero-trust access controls with IAM. Learn practical steps to protect identities, reduce risk, and boost compliance. - [Data governance in 2026: Essential strategies for enterprise compliance and innovation](https://community.trustcloud.ai/article/data-governance-in-2025-what-enterprises-need-to-know-today/): As enterprises march towards an AI-driven, hyper-connected digital future, the strategic importance of data governance is more critical than ever. In 2025, data will no longer just be an asset—it will be the foundation of trust, innovation, and resilience. Yet many organizations still treat data governance as a compliance checkbox rather than a competitive differentiator. - [Securing multi-cloud architectures: Best practices for AWS, Azure, and GCP](https://community.trustcloud.ai/article/securing-multi-cloud-architectures-best-practices-for-aws-azure-and-gcp/): Discover proven best practices to secure AWS, Azure, and GCP multi-cloud environments. Strengthen your cloud security and boost resilience today. - [How to perform a cloud security risk assessment: Step-by-step approach](https://community.trustcloud.ai/article/how-to-perform-a-cloud-security-risk-assessment-step-by-step-approach/): Learn a proven step-by-step approach to perform cloud security risk assessments. Identify, reduce, and manage your cloud security risks effectively. - [The complete guide to AWS, Azure, and GCP shared responsibility models](https://community.trustcloud.ai/article/the-complete-guide-to-aws-azure-and-gcp-shared-responsibility-models/): Understand how AWS, Azure, and GCP shared responsibility models divide security and compliance duties so you can protect data, avoid gaps, and stay audit-ready. - [FFIEC compliance: What it is, who it applies to, and how to meet it in 2026](https://community.trustcloud.ai/article/what-is-ffiec-compliance/): The primary purpose of the FFIEC is to establish uniformity and consistency in the supervision and examination of financial institutions. - [Unlock powerful HIPAA compliance trends 2026](https://community.trustcloud.ai/article/powerful-hipaa-compliance-and-enforcement-top-7-emerging-trends/): Discover 2026's top HIPAA compliance trends: $3M+ risk analysis fines, ransomware surge, AI compliance, and OCR's BAA crackdown. Master enforcement shifts, avoid multimillion penalties, and build audit-ready defenses with proven strategies. - [Powerful 2026 cybersecurity compliance changes ahead](https://community.trustcloud.ai/article/powerful-2026-cybersecurity-compliance-changes-ahead/): Discover the most important 2026 cybersecurity compliance changes and learn how to turn new regulations into a powerful advantage for your business security strategy. - [10 critical SaaS security risks and how to mitigate them in 2026](https://community.trustcloud.ai/article/10-critical-saas-security-risks-and-how-to-mitigate-them-in-2025/): Explore the top 10 SaaS security risks in 2025 and learn effective strategies to mitigate them. Strengthen your SaaS defenses with this essential guide. - [Unlock CCPA compliance with powerful consumer insights](https://community.trustcloud.ai/article/consumer-rights-under-ccpa-understanding-and-implementing-compliance/): Learn how to comply with CCPA by understanding consumer rights. Gain clear steps to boost trust, ensure compliance, and strengthen data privacy practices. - [GDPR vs. CCPA: Key differences in data privacy laws every security team should know](https://community.trustcloud.ai/article/gdpr-vs-ccpa-key-differences-in-data-privacy-laws-every-security-team-should-know/): Over the past decade, privacy laws have shifted from being a secondary issue for businesses to a prime matter of strategic planning. With incidents of data breaches and unauthorized data access frequently in the news, the evolution of data privacy laws remains a top-of-mind concern, especially for security teams. In this article, we will dive into the detailed differences between the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) while providing clarity on their unique approaches to privacy protection. Whether you are a security professional or part of a management team tasked with ensuring regulatory compliance, understanding these differences is essential for navigating today’s complex landscape of privacy laws. - [Cybersecurity governance made simple: A powerful, positive guide to managing risk](https://community.trustcloud.ai/article/cybersecurity-governance-made-simple-a-powerful-positive-guide-to-managing-risk/): Every business and organization, regardless of size, faces cybersecurity challenges. With breaches and data leaks making headlines, the need for a clear, effective, and approachable cybersecurity governance strategy is more urgent than ever. In this guide, we explore the fundamentals of cybersecurity governance, share practical tips for managing risk, and offer insights into creating a safer digital environment for your organization. - [Global Privacy Control (GPC): What it means for your business in 2026](https://community.trustcloud.ai/article/global-privacy-control-gpc-what-it-means-for-your-business-in-2025/): Understand what Global Privacy Control (GPC) means in 2025. Discover how it affects compliance, user rights, and your company’s privacy strategy—all in one simple guide. - [Top 10 emerging malware threats of 2026](https://community.trustcloud.ai/article/top-10-emerging-malware-threats-of-2026/): Discover the top 10 emerging malware threats of 2026 and get practical tips security teams can use now to stay protected and confidently reduce risk. - [NIST password guidelines 2026: 15 rules to follow](https://community.trustcloud.ai/article/nist-password-guidelines-2025-15-rules-to-follow/): Let's delve into the 15 rules outlined in the NIST Password Guidelines 2026. - [Spot sophisticated phishing campaigns before breaches](https://community.trustcloud.ai/article/spot-sophisticated-phishing-campaigns-before-breaches/): The cybersecurity landscape continues to evolve as threat actors become more creative in executing cyberattacks that slip past basic filters, targeting your network with precision. Early detection saves businesses from massive losses and reputational damage. Among these techniques, sophisticated phishing campaigns remain a persistent threat to enterprise networks. - [The ultimate guide to zero-day vulnerabilities: How threat intelligence prevents attacks in 2026](https://community.trustcloud.ai/article/the-ultimate-guide-to-zero-day-vulnerabilities-how-threat-intelligence-prevents-attacks-in-2025/): Discover how to stay ahead of zero-day vulnerabilities in 2026. Learn how real-time threat intelligence empowers businesses to prevent breaches before they happen. - [The mental health toll of being a CISO in 2026](https://community.trustcloud.ai/article/the-mental-health-toll-of-being-a-ciso-in-2025/): Explore the real mental health toll on CISOs in 2026 and learn practical, resilient strategies leaders and organizations can use to reduce burnout and protect well-being. - [Revolutionizing GRC: How AI is reshaping 2026 strategies](https://community.trustcloud.ai/article/artificial-intelligence-the-role-in-enhancing-grc-strategies-in-2024/): Discover how AI enhances GRC strategies by improving risk management, compliance, and decision-making processes in 2025. - [Data privacy in 2026: What lies ahead? Trends and predictions](https://community.trustcloud.ai/article/data-privacy-in-2025-what-lies-ahead-trends-and-predictions/): Data privacy, at its core, involves the handling, processing, consent, and regulatory obligations concerning personal information. - [Top 5 data privacy trends in 2026 from top security experts](https://community.trustcloud.ai/article/top-5-data-privacy-trends-in-2025-from-top-security-experts/): In 2026, organizations will become more aware of data privacy and more transparent about their data practices, giving individuals more control over their data. - [Revolutionizing cybersecurity: The future of the common security framework](https://community.trustcloud.ai/article/revolutionizing-cybersecurity-the-future-of-the-common-security-framework/): Cybersecurity is more than an IT concern; it has become a top priority for organizations around the globe. As cyber threats grow in sophistication and frequency, the need for a proactive, unified approach to security becomes undeniable. The common security framework (CSF) emerges as a groundbreaking strategy that consolidates best practices from various established cybersecurity models into one cohesive, effective approach. - [Unlock success: ISO 27001 vs SOC 2 – the ultimate security guide](https://community.trustcloud.ai/article/iso-27001-vs-soc-2-key-differences-and-which-one-your-business-needs/): Discover the key differences between ISO 27001 and SOC 2. Learn which framework fits your business needs for trusted and effective data security today. - [Unlock successful PCI DSS compliance: Powerful steps for easy AOC](https://community.trustcloud.ai/article/understanding-the-requirements-of-pci-dss-to-successfully-navigate-the-attestation-of-compliance-aoc-process/): Learn proven strategies to easily satisfy PCI DSS requirements and smoothly navigate the AOC process. Follow these expert tips to achieve compliance and protect your business. - [Unlock HIPAA compliance success: Proven strategies for healthcare privacy](https://community.trustcloud.ai/article/mastering-hipaa-compliance-essential-strategies-for-healthcare-privacy-in-2025/): Explore essential HIPAA compliance strategies for 2025. Learn practical privacy tactics to protect patient data, avoid penalties, and confidently meet healthcare regulations. - [Mastering ISMS [yy]: Ultimate guide to secure your business now](https://community.trustcloud.ai/article/mastering-isms-essential-guide-to-information-security-management-systems-in-2025/): Discover powerful ISMS strategies to protect your business in %currentyear%. Learn essential info security management systems for lasting success. Start today! - [A deep dive into TPRA (Third Party Risk Assessment)](https://community.trustcloud.ai/article/a-deep-dive-into-tpra-third-party-risk-assessment/): TPRA assists organizations in meeting regulatory requirements by evaluating the security measures and privacy practices of their third-party partners. - [Essential guide to powerful compliance management systems](https://community.trustcloud.ai/article/understanding-compliance-management-systems-key-components-best-practices/): Explore key components and best practices of compliance management systems. Build a strong, effective framework for ongoing success and regulatory alignment. - [Powerful guide to KYC compliance: Simplify customer verification](https://community.trustcloud.ai/article/kyc-compliance-demystified-a-practical-guide-to-know-your-customer-regulations/): Discover how to simplify KYC compliance with this practical guide. Learn key regulations, best practices, and tools to strengthen your customer verification process. - [Master GDPR compliance: A powerful guide for businesses to build trust & avoid penalties](https://community.trustcloud.ai/article/gdpr-compliance-a-comprehensive-guide-for-businesses/): GDPR compliance represents a landmark in global data protection, empowering individuals and reshaping the way businesses handle personal data. - [Powerful cybersecurity tools for stronger threat protection](https://community.trustcloud.ai/article/top-18-cybersecurity-tools-of-2025-essential-solutions-for-modern-threats/): Explore the top 18 cyber security tools of 2024 to bolster your defenses against modern threats. Stay ahead with the latest in digital protection. - [5 essential penetration testing tools for robust cybersecurity](https://community.trustcloud.ai/article/top-5-penetration-testing-tools-every-security-pro-must-have/): Discover the top 5 penetration testing tools used by security experts. Learn what makes them essential and how they can strengthen your security assessments. - [Preventing CISO burnout: Vital strategies for sustainable leadership](https://community.trustcloud.ai/article/ciso-burnout-what-is-this/): CISO burnout is a growing crisis. Discover what causes it, how to spot the warning signs, and strategies to protect security leaders’ well-being. Learn how TrustCloud offers tools to lighten the load, reduce stress, and strengthen cybersecurity leadership. - [What is PHI? A complete guide to protected health information](https://community.trustcloud.ai/article/understanding-phi-a-comprehensive-guide-to-protected-health-information/): Protected Health Information, or PHI, is a broad and encompassing term used in the healthcare industry to refer to individually identifiable information related to an individual's medical history, health status, healthcare treatment, and payment for healthcare services. - [Compliance audit success: Proven strategies for preparation & execution](https://community.trustcloud.ai/article/compliance-audits-best-practices-for-preparation-and-execution/): Discover the best practices to prepare and execute compliance audits effectively. Learn how to scope, manage evidence, engage stakeholders, and streamline audit workflows. - [Why passwordless authentication is the future of zero trust security](https://community.trustcloud.ai/article/why-passwordless-authentication-is-the-future-of-zero-trust-security/): Explore how passwordless authentication enhances security and user experience. Learn why it’s the future of zero trust in modern identity management. - [How to prepare for your first cybersecurity compliance audit: 7 steps to success](https://community.trustcloud.ai/article/how-to-prepare-for-your-first-cybersecurity-compliance-audit-7-steps-to-success/): Get audit-ready with 7 expert steps for a successful cybersecurity compliance audit. Build confidence, avoid surprises, and impress auditors with preparation. - [How AI-powered SOAR tools cut incident response time by 70%](https://community.trustcloud.ai/article/how-ai-powered-soar-tools-cut-incident-response-time-by-70/): Discover how AI-powered SOAR tools reduce incident response time by 70%. Boost efficiency, speed up recovery, and strengthen your security posture today. - [What is CRQ (Cyber Risk Quantification)? 7 ways the FAIR framework transforms cyber risk reporting to the board](https://community.trustcloud.ai/article/what-is-crq-cyber-risk-quantification-7-ways-the-fair-framework-transforms-cyber-risk-reporting-to-the-board/): Learn how cyber risk quantification can improve decision-making, prioritize threats, and boost resilience. Explore proven methods for smarter risk management. - [How to create an incident response plan that reduces breach impact by 60%](https://community.trustcloud.ai/article/how-to-create-an-incident-response-plan-that-reduces-breach-impact-by-60/): Discover how modern incident response and resilience solutions can speed recovery, reduce downtime, and strengthen your security posture. Stay ready and confident. - [What is an insider threat? How employee mistakes become major security breaches](https://community.trustcloud.ai/article/what-is-an-insider-threat-how-employee-mistakes-become-major-security-breaches/): Discover how to tackle insider threats and human risk with proven resilience strategies. Learn key approaches to detect, prevent, and manage insider risks effectively. - [Unlock the power of security automation with XDR and AI in 2025](https://community.trustcloud.ai/article/unlock-the-power-of-security-automation-with-xdr-and-ai-in-2025/): Discover how security automation, machine learning, and XDR can transform threat detection and response in 2025. Boost efficiency, cut costs, and stay ahead of cyber risks. - [How to implement a zero-trust framework: 7 steps for stronger identity management](https://community.trustcloud.ai/article/how-to-implement-a-zero-trust-framework-7-steps-for-stronger-identity-management/): Learn how to implement a zero-trust framework in 7 proven steps. Strengthen identity management, reduce risk, and boost cloud security across your business. - [Empower your security: ultimate ISO 27001 vs NIST vs SOC 2 guide](https://community.trustcloud.ai/article/the-ultimate-guide-to-iso-27001-nist-and-soc-2-which-cybersecurity-governance-framework-is-right-for-your-business-in-2025/): Discover the best cybersecurity governance framework for your business in 2025. Compare ISO 27001, NIST, and SOC 2 to make a confident, smart choice. - [Empower compliance: Essential HIPAA checklist for healthcare](https://community.trustcloud.ai/article/hipaa-compliance-checklist-essential-steps-for-healthcare-organizations/): Ensure HIPAA success with this comprehensive checklist—covering risk assessments, policies, training, and audit readiness for healthcare teams. - [Risk management frameworks: ISO 31000 vs. COSO ERM](https://community.trustcloud.ai/article/risk-management-frameworks-iso-31000-vs-coso-erm/): Explore how ISO 31000 and COSO ERM frameworks help organizations handle risk confidently with proven strategies for effective risk management.​ - [Security as a business enabler: guiding executive strategy through risk insight](https://community.trustcloud.ai/article/security-as-a-business-enabler-guiding-executive-strategy-through-risk-insight/): Learn how security drives business growth by guiding executive strategy with risk insights. Turn cybersecurity into a strategic advantage with smart decision-making. - [Beyond the firewall: Strengthening third-party risk management in a connected world](https://community.trustcloud.ai/article/beyond-the-firewall-strengthening-third-party-risk-management-in-a-connected-world/): Discover proven strategies to strengthen third-party risk management and supply chain security. Learn how to mitigate risks, enhance oversight, and protect your operations effectively. - [Building a high-impact security team: Strategies for modern leadership](https://community.trustcloud.ai/article/building-a-high-impact-security-team-strategies-for-modern-leadership/): Discover proven security leadership strategies to boost team performance, drive cultural change, and strengthen your organization’s defenses. Lead with confidence. - [Unlock the power of background checks: Simple and trusted guide](https://community.trustcloud.ai/article/what-is-a-background-check/): Learn what a background check includes, why it's important in hiring, and how it helps protect your organization from hidden risks and compliance issues. - [10 critical SaaS security risks and how to mitigate them in 2025](https://community.trustcloud.ai/article/10-critical-saas-security-risks-and-how-to-mitigate-them-in-2025-2/): Stay ahead of emerging SaaS security risks in 2025. Discover expert strategies to quickly fix vulnerabilities and keep your business data protected. - [Uncover hidden costs of fraud and prevent them now](https://community.trustcloud.ai/article/the-hidden-costs-of-fraud-and-how-to-prevent-them/): Discover the hidden costs of fraud draining 7-10% of revenues, $534B globally—and proven strategies to prevent scams, account takeovers, and losses. Safeguard your business today. - [Powerful cross-border compliance strategies for confident growth](https://community.trustcloud.ai/article/cross-border-compliance-navigating-globalization-challenges-in-2024/): Discover how to manage cross-border compliance in 2025. Learn key regulatory challenges, region-specific risks, and practical strategies for secure, global business operations. - [7 Advanced Persistent Threats (APTs) targeting critical infrastructure: Detection & defense strategies](https://community.trustcloud.ai/article/7-advanced-persistent-threats-apts-targeting-critical-infrastructure-detection-defense-strategies/): Discover top advanced persistent threats targeting critical infrastructure and explore expert strategies to detect, defend, and stay resilient in today’s threat landscape. - [Security meme: 100+ funny cyber security memes & compliance memes 2025](https://community.trustcloud.ai/article/security-meme-100-funny-cyber-security-memes-compliance-memes-2025/): To make this SOC 2 compliance process a bit more joyful, here are some of the best compliance and cybersecurity memes for you! - [The evolving landscape of IT risk quantification](https://community.trustcloud.ai/article/the-evolving-landscape-of-it-risk-quantification/): By making IT risk quantification a cornerstone of your risk management strategy, you can build a more resilient, agile, and competitive organization that is well-equipped to thrive in an increasingly complex and uncertain digital landscape. - [Programmatic risk assessment: Secrets of success](https://community.trustcloud.ai/article/programmatic-risk-assessment-secrets-of-success/): Programmatic risk assessment plays a pivotal role in offering an approach to identifying, assessing, and mitigating risks across programmatic activities. - [TrustCloud’s dynamic trust portal and AI-powered security questionnaire automation: Revolutionizing security reviews](https://community.trustcloud.ai/article/trustclouds-dynamic-trust-portal-and-ai-powered-security-questionnaire-automation-revolutionizing-security-reviews/): Enter TrustShare, a groundbreaking solution that combines a dynamic trust portal with artificial intelligence to quickly answer security questionnaires. - [Complexity in vendor ecosystems: The case for proactive risk management](https://community.trustcloud.ai/article/complexity-in-vendor-ecosystems-the-case-for-proactive-risk-management/): As vendor ecosystems grow more complex, managing third-party risk through traditional, fragmented methods becomes increasingly inefficient and risky. - [From SLAs to ESG: Embedding responsibility in service agreements](https://community.trustcloud.ai/article/from-slas-to-esg-embedding-responsibility-in-service-agreements/): By aligning their service level agreements (SLAs) with ESG goals, organizations can drive positive change, foster responsible business practices, and create shared value for all stakeholders. - [The power of a centralized data repository: Revolutionizing data management](https://community.trustcloud.ai/article/the-power-of-a-centralized-data-repository-revolutionizing-data-management/): The centralized data repository represents a powerful solution for organizations seeking to harness the full potential of their data assets. By consolidating disparate data sources into a single, unified platform, businesses can improve data quality, enhance decision-making processes, and drive innovation across the enterprise. - [Securing PHI: A comprehensive exploration of the 18 identifiers](https://community.trustcloud.ai/article/securing-phi-a-comprehensive-exploration-of-the-18-identifiers/): This article comprehensively examines the security of Protected Health Information (PHI), focusing on the 18 identifiers that constitute PHI under HIPAA regulations. - [Security questionnaire essentials: 9 best practices for assessing and enhancing cybersecurity posture](https://community.trustcloud.ai/article/security-questionnaire-essentials-9-best-practices-for-assessing-and-enhancing-cybersecurity-posture/): This article from TrustCloud provides a comprehensive guide to security questionnaires, emphasizing best practices for creating effective responses. - [How to seamlessly integrate GRC into your business workflows](https://community.trustcloud.ai/article/how-to-seamlessly-integrate-grc-into-your-business-workflows/): Learn how to align Governance, Risk, and Compliance (GRC) with your day-to-day business processes. Boost efficiency, reduce risk, and stay audit-ready. - [Confidently overcome powerful compliance management challenges](https://community.trustcloud.ai/article/common-compliance-management-challenges-and-how-to-overcome-them/): By understanding the common challenges, implementing proven strategies, and leveraging the right technology solutions, you can overcome compliance obstacles and ensure that your organization remains compliant, protected, and positioned for long-term success. - [Why SOC 2 is critical for cloud security and customer trust](https://community.trustcloud.ai/article/why-soc-2-is-critical-for-cloud-security-and-customer-trust/): By embracing SOC 2 compliance, you can demonstrate your commitment to protecting your clients' information, build stronger relationships with your customers, and position your organization as a trusted and reliable service provider. - [Confident control: powerful ISMS guide for stronger security](https://community.trustcloud.ai/article/mastering-isms-a-practical-guide-to-building-stronger-information-security/): An ISMS helps maintain the trust of stakeholders and customers by demonstrating a commitment to security. Moreover, it ensures compliance with international standards and legal requirements, ultimately protecting the organization from potential fines and legal penalties. - [Protecting PII: Comprehensive guide to personal identifiable information](https://community.trustcloud.ai/article/protecting-pii-comprehensive-guide-to-personal-identifiable-information/): Learn how to identify, manage, and protect Personal Identifiable Information (PII) to ensure compliance and prevent data breaches. - [From compliance theory to real-world success: How modern teams get it right](https://community.trustcloud.ai/article/from-compliance-theory-to-real-world-success-how-modern-teams-get-it-right/): By leveraging the latest compliance technologies, fostering a culture of compliance, and investing in the training and development of your compliance professionals, you can position your organization for long-term success and position compliance as a competitive advantage in your industry. - [The power of encryption: ensuring PCI compliance through best practices and tools in 2025](https://community.trustcloud.ai/article/the-power-of-encryption-ensuring-pci-compliance-through-best-practices-and-tools-in-2025/): Encryption is a critical component of a robust PCI compliance strategy. By implementing best practices, leveraging the right encryption tools, and continuously monitoring and updating your encryption processes, you can effectively safeguard your customers' sensitive data, maintain compliance with PCI DSS, and build trust in your organization. - [Essential actions to take following a suspected HIPAA violation in 2025](https://community.trustcloud.ai/article/essential-actions-to-take-following-a-suspected-hipaa-violation-in-2025/): By understanding your obligations under HIPAA, implementing robust privacy and security controls, and maintaining a culture of compliance, you can help to protect your organization and your patients from the serious consequences of a HIPAA violation. - [Demystifying PCI DSS: a comprehensive guide to payment card security](https://community.trustcloud.ai/article/demystifying-pci-dss-a-comprehensive-guide-to-payment-card-security-2/): PCI DSS emerges as a formidable framework designed to ensure the secure handling of sensitive cardholder data. - [Elevate your standards: ISO 27001 vs 27002 insights revealed for [yy]](https://community.trustcloud.ai/article/iso-27001-vs-27002-key-differences-explained-by-security-experts-in-2025/): Discover the powerful differences between ISO 27001 and ISO 27002 in 2025. Gain expert insights to strengthen your information security strategy today. - [Essential ISO 19902 guide: powerful standard for safer offshore structures](https://community.trustcloud.ai/article/iso-19902-everything-you-need-to-know/): Discover what ISO 19902 requires for designing, building, and maintaining fixed steel offshore structures, from load design to ESG, safety, and lifecycle integrity. - [Compliance as a culture, not a checklist](https://community.trustcloud.ai/article/compliance-as-a-culture-not-a-checklist/): When you embrace compliance as a culture, you create an environment where every employee understands the importance of following regulations and acting ethically. This shift in mindset transforms compliance from a burdensome task to a natural part of daily operations. - [Zero trust architecture: Engineering a security model for the modern enterprise](https://community.trustcloud.ai/article/zero-trust-architecture-engineering-a-security-model-for-the-modern-enterprise/): Zero Trust Architecture (ZTA) - a security framework designed for modern enterprises where trust is never assumed, and access is granted based on continuous authentication, least privilege policies, and strict segmentation. - [What is CSF certification?](https://community.trustcloud.ai/article/what-is-csf-certification/): CSF certification is a recognition awarded to organizations that have successfully implemented the NIST Cybersecurity Framework. - [HIPAA compliance: Exploring the basics of safeguarding healthcare data](https://community.trustcloud.ai/article/hipaa-compliance-exploring-the-basics-of-safeguarding-healthcare-data/): The HIPAA compliance serves as a cornerstone for safeguarding health data and ensuring the privacy and security of patients. ## Companies - [IMO Health](https://community.trustcloud.ai/company/imo-health/): IMO Health is a clinical data intelligence business at the heart of a digital revolution in healthcare. Combining rich, highly nuanced medical terminology, extensive domain knowledge, and artificial intelligence (AI), we expertly structure and operationalize clinical data to generate sharper insights and inform more intelligent decision-making.  Deeply embedded in the provider world, we developed a comprehensive intelligence layer that captures and encodes patient encounters with unmatched completeness and precision. Now, by weaving ethical and accountable AI into this robust content, we are improving how data is used across the healthcare landscape with powerful new applications in health tech, drug discovery, population health, and payer processes. - [Sapio Sciences](https://community.trustcloud.ai/company/sapio-sciences/): Sapio Sciences' mission is to improve lives by accelerating discovery, and because science is complex, Sapio makes technology simple. Sapio is a global business offering an all-in-one science-aware (TM) lab informatics platform combining cloud-based LIMS, ELN, and scientific data solutions. Sapio serves some of the largest global and specialist brands, including biopharma, CRO/CDMOs and clinical diagnostic labs across NGS genomic sequencing, bioanalysis, bioprocessing, stability, clinical, histopathology, drug research, and in vivo studies. - [Highnote](https://community.trustcloud.ai/company/highnote/): Highnote is the world’s most modern card platform, purpose-built to grow customer loyalty, engagement, and revenue through embedded card issuance experiences. With an all-in-one platform and a fully integrated issuer processor built from scratch to address the use cases of today and tomorrow, Highnote gives you unparalleled control, flexibility, and speed to realize your customer vision through innovative embedded finance experiences. - [Verato](https://community.trustcloud.ai/company/verato/): Verato® powers exceptional experiences everywhere by solving the problem that drives everything else — knowing who is who. Verato MDM Cloud™, the next generation of master data management, delivers unprecedented data intelligence and interoperability by combining the most accurate identity resolution and enrichment with advanced insights, identity verification, and data governance. Verato re-imagines master data management (MDM) to be purpose-built and nimble to drive a complete and trusted 360-degree view of people, organizations, and networks across complex ecosystems with unmatched speed-to-value, enterprise grade performance, and customer success. More than 75% of the US population flows through Verato, powering a single source of truth for identity across the critical industries of healthcare, life sciences, financial services, public sector, and beyond. For more information, visit verato.com. - [Reltio](https://community.trustcloud.ai/company/reltio/): At Reltio, we believe data should fuel business success. Our AI-powered data unification and management offerings — Reltio Entity Resolution, Multidomain Master Data Management (MDM), and 360 Data Products—transform siloed data from disparate sources into unified, trusted, and interoperable data. Powered by the Reltio Connected Data Platform, these offerings unify and deliver interoperable data where and when it's needed, empowering data and analytics leaders with unparalleled business responsiveness. Many leading enterprise brands—across multiple industries around the globe—rely on our award-winning data unification and cloud-native MDM capabilities to improve efficiency, manage risk, and drive growth. - [Icon](https://community.trustcloud.ai/company/icon/): Equipping organizations that support seniors with the tools needed to ensure older adults and providers have the best experience possible with technology. - [Foundation Medicine](https://community.trustcloud.ai/company/foundation-medicine/): Foundation Medicine is a molecular information company dedicated to a transformation in cancer care in which treatment is informed by a deep understanding of the genomic changes that contribute to each patient's unique cancer. - [Volpara Health](https://community.trustcloud.ai/company/volpara-health/): Volpara Health makes software to help save more families from cancer. Healthcare providers use Volpara to better understand cancer risk, empower patients in personal care decisions, and guide recommendations about additional imaging, genetic testing, and other interventions. - [Guardoc Health](https://community.trustcloud.ai/company/guardoc-health/): Guardoc is a digital health company built by nurses for nurses that leverages AI to automate labor-intensive compliance processes typically handled by nurses. By streamlining these tasks, Guardoc increases direct patient care hours, enhances patient care and optimizes revenue management. - [Zant](https://community.trustcloud.ai/company/zant/): Zant revolutionizes mental health support by empowering users on their journey with accessible, affordable, and high-quality services while providing an all-in-one solution for providers to manage their practice, process payments, and organize their work. - [OOt Social Health](https://community.trustcloud.ai/company/oot-social-health/): OOt Social Health enables organizations and individuals to form private (via invite codes) and public communities based on shared interests, skills, and organizational affiliations. Face-to-face interactions are emphasized, and are essential for building trust bonds, serving as the foundation of community building. - [Principia Health Sciences](https://community.trustcloud.ai/company/principia-health-sciences/): We create integrated health science networks leveraging next-generation technology and operating models to empower researchers with superlative data and analytics and transform healthcare with the right insights at the right time. - [Paige](https://community.trustcloud.ai/company/paige/): Paige is using the power of AI to drive a new era of cancer discovery and treatment. To improve the lives of patients with cancer, Paige has created a cloud-based platform that transforms pathologists’ workflow and increases diagnostic confidence as well as productivity, all on a global scale. Paige is the first company to receive FDA approval for a clinical AI application in digital pathology. - [Zus Health](https://community.trustcloud.ai/company/zus-health/): Zus is the only shared health data platform designed to accelerate healthcare data interoperability by providing easy-to-use patient data at the point of care via API, embedded components, and direct EHR integrations. - [Quantivly](https://community.trustcloud.ai/company/quantivly/): Providing better imaging care to more patients. - [Suggestic](https://community.trustcloud.ai/company/suggestic/): At Suggestic, we are at the forefront of transforming the health and wellness industry through our innovative white-label telehealth and AI-powered engagement tools. - [Actofit](https://community.trustcloud.ai/company/actofit/): Actofit is a pioneering health tech company dedicated to enhancing wellness. With a deep commitment to addressing chronic health issues, Actofit empowers individuals to make sustainable lifestyle changes, promoting longevity and better health. - [Omcare](https://community.trustcloud.ai/company/omcare/): Omcare is a digital health company that aims to change the way the world cares by extending the reach of caregivers, increasing medication adherence, and improving treatment outcomes through the power of remote care and two-way video technology. - [SageSurfer](https://community.trustcloud.ai/company/sagesurfer/): SageSurfer is an AI Powered Behavioral Healthcare digital care coordination & member engagement platform (web and mobile) that connects members with their full circle of the care team and helps them stay on track between visits and for providers enable them to deliver remote patient monitoring and unlock millions of dollars in reimbursements, cost savings, and better care outcomes. - [Health Scholars](https://community.trustcloud.ai/company/health-scholars/): Frontline clinicians need to know they’re properly equipped and supported as they face everyday challenges — their preparation is paramount to patient safety and outcomes. But many nurses don’t get to practice managing high-risk events. - [Innovation Health Services](https://community.trustcloud.ai/company/innovation-health-services/): Remote Cardiac CT and MRI interpretation nationwide. Pathway implementation, Level 2 CT training and certification. - [Music Health](https://community.trustcloud.ai/company/music-health/): Music Health introduces Precision Music®, an AI-driven music intervention technology created to improve brain health outcomes. - [Vyne Dental](https://community.trustcloud.ai/company/vyne-dental/): Easy-to-use software that simplifies practice claims processing, attachments, encrypted email, and electronic forms. - [Adyptation](https://community.trustcloud.ai/company/adyptation/): Adyptation provides a benefit solution that helps employers contain costs from specialty diseases like Rheumatoid Arthritis and Inflammatory Bowel Disease while helping plan members who have these diseases feel their best. - [NavvTrack](https://community.trustcloud.ai/company/navvtrack/): NavvTrack is an indoor location services technology that provides enhanced iOS fleet management for hospitals and health systems. - [SaRA Health](https://community.trustcloud.ai/company/sara-health/): Helping Movement Health Professionals (PTs, OTs, and Orthos) connect deeper with their patients while generating additional revenue via Remote Therapeutic Monitoring. - [Statera](https://community.trustcloud.ai/company/statera/): Our goal is to bring transparency and predictability to clinical compensation, and return clinicians' focus to providing quality patient care. - [AC Health](https://community.trustcloud.ai/company/ac-health/): AC Health is changing the way that medical and wellness professionals engage with their clients, patients and users. Our SaaS platform instantly creates mobile mini-app Channel hosted on our IOS/Android App. - [MCR Technologies](https://community.trustcloud.ai/company/mcr-technologies/): HealthTouch® a leading patient nutritional management software development company. Our food service software solution helps hospitals manage patient nutrients and food service operations. - [Sway Medical](https://community.trustcloud.ai/company/sway-medical/): Sway is an innovative software company using mobile technology to improve outcomes. Sway's application is a FDA class II medical device, focused around balance, cognitive, and functional testing that uses objective measures to revolutionize the way athletes and patients are monitored for signs of neurological and vestibular dysfunction. - [My HealthConnection](https://community.trustcloud.ai/company/my-healthconnection/): Fully integrated telemedicine platform for providers. We bring the world of healthcare to You. Flexible TeleMedicine Options MHC has the flexibility to be integrated as stand alone modules or as a completely customizable secure Telehealth platform integrated into a hospital system. - [Altitude Fitness Management](https://community.trustcloud.ai/company/altitude-fitness-management/): Skyrocket your gym's membership and revenue with Altitude Fitness Management Group (AFMG). We offer data-driven marketing, member acquisition, and retention strategies to help gyms, fitness studios, and personal trainers thrive. Increase leads, boost conversions, and watch your gym grow. - [RosterLab](https://community.trustcloud.ai/company/rosterlab/): At RosterLab, we use cutting-edge AI and operations research to optimise staff rostering with the click of a button. Our advanced technology can solve complex rosters within minutes, taking into account intricate rules, staffing requirements, and individual preferences. - [SupplyRx, Inc.](https://community.trustcloud.ai/company/supplyrx-inc/): SupplyRx, Inc. is a technology company focused on cloud-based solutions for clinical trial supplies and point-of-sale pharmacy programs in North America. We created the first and only cloud-based pharmacy card platform connecting sponsors, CROs, research sites and patients with pharmacies for just-in-time commercial medicines used in clinical trials. - [VurvHealth](https://community.trustcloud.ai/company/vurvhealth/): We offer affordable access to the health benefits you need in one easy app. - [Agota Health](https://community.trustcloud.ai/company/agota-health/): Managing multiple staffing agencies at your healthcare facility is hard, but it doesn’t have to be. Automate communications, record keeping, and cost management with Agota Health. Agota Health is a win-win. We help healthcare facilities save headaches and time, and help agencies fill more shifts! - [DoctorFare](https://community.trustcloud.ai/company/doctorfare/): The Digital Appointment Marketplace for Value-Based Care. VBC Referral Coordination and Navigation. Eliminates the hassles of phone calls and faxes. Passionate about Value-Based Healthcare. - [Sentur](https://community.trustcloud.ai/company/sentur/): Wildly engaging client-centered solutions integrating cutting-edge psychotherapeutic trauma-treatment techniques with technology to create world-class outcomes for humanity. - [Aztute Precision Health](https://community.trustcloud.ai/company/aztute-precision-health/): Aztute is forging safer and healthier communities with a modern health platform addressing community needs through data, collaboration, education, and social determinants of health. - [Miresource](https://community.trustcloud.ai/company/miresource/): Working to make the world a mentally healthier place. People are our passion and mental health is our mission. - [Promaxo](https://community.trustcloud.ai/company/promaxo/): We are transforming the lives of patients and doctors through our single-sided portable MRI. Fast, safe and convenient. - [MyCabinet](https://community.trustcloud.ai/company/mycabinet/): The only virtual medicine cabinet empowering individuals and caregivers to manage medications, refills, reminders, drug interactions and health data, for an unparalleled user experience. MyCabinet minimizes adverse health outcomes and increases overall health and wellness. - [Steer Health](https://community.trustcloud.ai/company/steer-health/): Steer’s Conversational AI platform for provider organizations combines the power of AI with the human touch of your team to deliver 5-star patient experiences while boosting profitability. - [Meenta](https://community.trustcloud.ai/company/meenta/): Meenta was born out of the idea that life science and diagnostics could greatly benefit from the technological revolution that has forever changed the way we shop, dine, vacation, and catch a ride. - [Zuar](https://community.trustcloud.ai/company/zuar/): Zuar is the analytics headquarters for organizations of all sizes. Automate the flow of data from hundreds of potential sources into a single destination for analytics, fully prepped and ready for use. - [Xenia](https://community.trustcloud.ai/company/xenia/): Xenia is a unified frontline operations platform, giving managers and deskless workers modern, powerful software in the palm of their hands. - [ThoughtSpot](https://community.trustcloud.ai/company/thoughtspot/): ThoughtSpot is the AI-Powered Analytics company - [TeamSense](https://community.trustcloud.ai/company/teamsense/): TeamSense is the app-free digital connection to your hourly workforce. - [SaaSWorks](https://community.trustcloud.ai/company/saasworks/): Democratizing the data-driven insights and expertise required to build and manage high-growth, high-value companies - [Robin](https://community.trustcloud.ai/company/robin/): Workplace experience platform - [Roam B.V.](https://community.trustcloud.ai/company/roam-b-v/): Location solutions for mobile apps - [Resolve Collaboration](https://community.trustcloud.ai/company/resolve-collaboration/): Event Experts In-Person - Virtual - Hybrid - [ProcureSpark, Inc.](https://community.trustcloud.ai/company/procurespark-inc/): Augment your sales effort with the latest generative AI capabilities to win more often. - [Pilot AI](https://community.trustcloud.ai/company/pilot-ai/): Use cutting-edge AI to automatically update and populate your CRM directly from your sales calls. - [P3iD Technologies Inc.](https://community.trustcloud.ai/company/p3id-technologies-inc/): Secure hybrid document automation processing services. - [Makeshapes](https://community.trustcloud.ai/company/makeshapes/): Group learning reimagined for scale - [Lumin Digital](https://community.trustcloud.ai/company/lumin-digital/): Lumin Digital is a fintech company specializing in cloud native digital banking solutions. - [Lanvera Ltd.](https://community.trustcloud.ai/company/lanvera-ltd/): Lanvera is a provider of end-to-end outsourcing solutions for transactional and business-critical communications. - [Hackolade](https://community.trustcloud.ai/company/hackolade/): Data modeling for NoSQL databases, storage formats, REST APIs, and JSON in RDBMS - [Gravy](https://community.trustcloud.ai/company/gravy/): Gravy is forever changing how people buy and own their first home by connecting two trillion dollar markets - home renting and home buying. - [FortaTech Security](https://community.trustcloud.ai/company/fortatech-security/): Cybersecurity managed and advisory services. - [Cribl](https://community.trustcloud.ai/company/cribl/): Cribl enables open observability and defies data gravity, giving customers radical levels of choice and control. - [AtScale](https://community.trustcloud.ai/company/atscale/): The Leading Semantic Layer Platform for Data and Analytics - [Appsurify Trust Cloud](https://community.trustcloud.ai/company/appsurify-trust-cloud/): AI Risk-based Testing Platform for CI Pipeline Optimization and Instant Automation Test Results! - [Zasio Enterprises, Inc.](https://community.trustcloud.ai/company/zasio-enterprises-inc/): News and updates from Zasio to help your business navigate records and information management with confidence. - [Wrench.ai, Inc](https://community.trustcloud.ai/company/wrench-ai-inc/): Big data, deep learning, and machine learning scare and intimidate people—particularly business leaders who don’t have a background in those fields. - [WorkEQ](https://community.trustcloud.ai/company/workeq/): Get hybrid work right by providing employees with the right work-life balance that makes them happy, healthy and productive - resulting in the best outcomes for your employees and your business. - [Wiserspread](https://community.trustcloud.ai/company/wiserspread/): End-to-End Salesforce Consulting Services to optimize and scale your business. - [Vygo](https://community.trustcloud.ai/company/vygo/): Support Ecosystem Platform, supporting industry-leading universities across the globe. - [Traxo](https://community.trustcloud.ai/company/traxo/): Traxo is the world’s only provider of real-time corporate travel data capture. - [TheTestMart](https://community.trustcloud.ai/company/thetestmart/): We use AI based automation testing to streamline your regular SaaS updates. - [Strive Business Solutions](https://community.trustcloud.ai/company/strive-business-solutions/): Business Solutions & Technology team of Actuarial Business Analysts, Solutions Analysts and Solution Architects to support business activities. - [Sevco Security](https://community.trustcloud.ai/company/sevco-security/): Sevco Security is a company of cyber experts building services and products for cyber experts. - [ProdPad](https://community.trustcloud.ai/company/prodpad/): ProdPad provides product management software that helps you and your team to collect ideas, identify priorities, and build flexible product roadmaps. - [Orbit](https://community.trustcloud.ai/company/orbit/): Grow and measure your community with Orbit, the leading community growth platform - [N2uitive Corporation](https://community.trustcloud.ai/company/n2uitive-corporation/): Cloud-based claims interview and recorded statement management solution for auto, home and workers compensation insurers - [MindfulText](https://community.trustcloud.ai/company/mindfultext/): Bringing more mindfulness and compassion into tech - [Mammoth Climate](https://community.trustcloud.ai/company/mammoth-climate/): The decarbonization platform for consumer brands - [MachineMetrics](https://community.trustcloud.ai/company/machinemetrics/): The leading machine data platform for manufacturing. - [KPI Fire](https://community.trustcloud.ai/company/kpi-fire/): Collaborate as a team and standardize your workflows so you can close more projects and get more done - [Gremlin](https://community.trustcloud.ai/company/gremlin/): The Reliability Management Platform for high-velocity engineering teams - [Gig Wage](https://community.trustcloud.ai/company/gig-wage/): Pay your gig workers, contractors & freelancers instantly. - [GCPay](https://community.trustcloud.ai/company/gcpay/): Simplify construction payments. - [Fetcher](https://community.trustcloud.ai/company/fetcher/): Fetcher finds the best talent for your team. - [Ethnio](https://community.trustcloud.ai/company/ethnio/): UX research recruiting, scheduling, incentives, participant database management, intercepts and more. - [DeleteMe](https://community.trustcloud.ai/company/deleteme/): DeleteMe is the category-defining market leader in the personal data removal space. - [Datajoin](https://community.trustcloud.ai/company/datajoin/): Integrate Your B2B Marketing Tech Stack, Without Code. - [Dashboard Legal](https://community.trustcloud.ai/company/dashboard-legal/): Collaboration and Matter Management For Attorneys - [DANAconnect](https://community.trustcloud.ai/company/danaconnect/): Automations for the financial and insurance ecosystem - [Concepta Technologies, LLC](https://community.trustcloud.ai/company/concepta-technologies-llc/): Award-winning technology agency that helps dev teams go-to-market faster with scalable apps that accelerate growth. - [Assignar](https://community.trustcloud.ai/company/assignar/): Improving contractor efficiency, profitability, and safety through labor and asset management and digitization. - [ArcSource Consulting, Inc](https://community.trustcloud.ai/company/arcsource-consulting-inc/): ArcSource makes success easier for businesses. We take care of IT strategy, security, infrastructure, and support. - [AceUp](https://community.trustcloud.ai/company/aceup/): AceUp delivers higher-performing leaders and enables purpose-aligned organizations through coaching at scale. - [TrustCloud](https://community.trustcloud.ai/company/trustcloud/): Make it effortless to earn trust in every business relationship ## Videos - [Audit dashboard](https://community.trustcloud.ai/vid/audit-dashboard/): Watch this video to understand audits in TrustOps to visualize your readiness for the specific compliance standard you are adhering to. - [Complete security questionnaires with ease using TrustShare’s chrome extension](https://community.trustcloud.ai/vid/complete-security-questionnaires-with-ease-using-trustshares-chrome-extension/): Watch this video to learn more about using Chrome extension with TrustShare. - [Create ServiceNow tickets from TrustCloud tasks](https://community.trustcloud.ai/vid/create-servicenow-tickets-from-trustcloud-tasks/): Learn how to create ServiceNow tickets from TrustCloud tasks. - [ServiceNow tickets as evidence](https://community.trustcloud.ai/vid/servicenow-tickets-as-evidence/): Watch this video to learn how you can provide ServiceNow tickets as evidence to your TrustCloud compliance program. - [Understanding Third-Party Vendor Risk and the Importance of Risk Assessments](https://community.trustcloud.ai/vid/understanding-third-party-vendor-risk/): Watch this video to understand third-party vendor risk and the importance of risk assessments. - [What is a Third-Party Risk Assessment (TPRA)?](https://community.trustcloud.ai/vid/what-is-a-third-party-risk-assessment-tpra/): Watch this video to understand third-party risk assessments (TPRA). - [Third-Party Risk Assessment (TPRA) made easy with TrustCloud](https://community.trustcloud.ai/vid/third-party-risk-assessment-tpra-made-easy/): Watch this video to understand how TrustLens helps you with easy third-party risk assessments (TPRA) using assessment templates, vendor tiers and how you can send assessments to vendors. - [Inventory](https://community.trustcloud.ai/vid/inventory/): Watch this video to understand what an inventory is and how it can be used as evidence. - [ISO 42001](https://community.trustcloud.ai/vid/iso-42001/): Watch this video to understand what ISO 42001 is, who needs this and how TrustCloud can help you track your ISO 42001 program. - [Custom Frameworks](https://community.trustcloud.ai/vid/custom-frameworks/): Watch this video to understand how TrustCloud offers the flexibility of creating your own custom frameworks and standards. - [TrustCloud – Onboarding](https://community.trustcloud.ai/vid/trustcloud-onboarding/): Watch this video to learn more about self-service TrustCloud onboarding to set up a comprehensive and personalized compliance program. - [Gap Analysis](https://community.trustcloud.ai/vid/gap-analysis/): Watch this video to learn more about how gap analysis with TrustCloud works to give you insight into your compliance standards and your gaps with them. - [Integrations – How to set it up](https://community.trustcloud.ai/vid/integrations-how-to-set-it-up/): Integrations are built-in connectors between TrustCloud and an external SaaS service that allows TrustCloud to run tests and pull inventories from the service. - [Vendors – Overview](https://community.trustcloud.ai/vid/vendors-overview/): The “Vendors” page provides you with information about the vendors. You can sort, search for and filter vendors by group, tier, risk rating, assessment status, status and owner. You can also add a new vendor from this page. - [Planned vs Adopted controls](https://community.trustcloud.ai/vid/planned-vs-adopted-controls/): Controls can be marked as “Adopted” or “Planned” in TrustOps. Planned controls are recommendations for implementation, while adopted controls have been reviewed and accepted as part of the program. - [Controls – Overview](https://community.trustcloud.ai/vid/controls-overview/): Controls are essential processes implemented by organizations to prevent potential risks and ensure compliance with legal requirements, industry standards, and internal policies. - [Systems and Data classifications](https://community.trustcloud.ai/vid/systems-and-data-classifications/): A system data classification is the mechanism used to denote what kind of data is stored or processed by a system. - [Trust Portal walkthrough](https://community.trustcloud.ai/vid/trust-portal-walkthrough/): Key features of Trust Portal include automatic trust portal generation, secure access management, safeguarding the confidentiality and many more. - [Post onboarding](https://community.trustcloud.ai/vid/post-onboarding/) - [All you need to know about tasks](https://community.trustcloud.ai/vid/all-you-need-to-know-about-tasks-video/): By breaking down work into small, actionable items, TrustOps makes compliance programs more manageable and prioritizes tasks for users. - [Uploading evidence](https://community.trustcloud.ai/vid/uploading-evidence/): TrustCloud’s intuitive platform empowers you to streamline the evidence management process, ensuring a seamless audit trail and facilitating transparent compliance reporting. - [How do you calculate residual risk?](https://community.trustcloud.ai/vid/how-do-you-calculate-residual-risk/): TrustRegister uses an algorithm to analyze multiple data points across your risk surface when calculating a “Residual Risk Rating.” - [What is Residual Risk?](https://community.trustcloud.ai/vid/what-is-residual-risk/): Residual risk refers to the level of risk that remains after risk mitigation strategies have been implemented. - [TrustShare overview](https://community.trustcloud.ai/vid/trustshare-overview/): TrustShare™ is TrustCloud’s digital platform that allows organizations to securely manage and share sensitive information with their customers, partners, and other stakeholders. - [How do you assign risk ownership?](https://community.trustcloud.ai/vid/how-do-you-assign-risk-ownership/): Watch this video to learn more about assigning risk ownership. - [TrustCloud Common Controls Framework](https://community.trustcloud.ai/vid/trustcloud-common-controls-framework/): Watch this video to learn more about TrustCloud common controls frameworks. - [Self-assessment tests](https://community.trustcloud.ai/vid/self-assessment-tests/): Watch this video to learn more about running self-assessments and uploading evidence on TrustOps. - [Automated tests](https://community.trustcloud.ai/vid/automated-tests/): Watch this video to learn more about running automated tests in Trustops. - [TrustOps overview](https://community.trustcloud.ai/vid/trustops-overview/): Watch this video to learn more about how TrustOps can help you with your compliance journey. - [Editing controls](https://community.trustcloud.ai/vid/editing-controls/) ## Changelogs - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-514/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-515/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-513/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-512/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-511/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-510/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-509/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-508/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-507/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-506/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-505/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-504/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-503/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-502/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-501/): An update that allows vendors to upload optional artifacts. - [TrustRegister](https://community.trustcloud.ai/changelog/trustregister-319/): An update to the Risk Details, AI-Generated Risk Assessment report modal to improve the user experience. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-500/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-499/): An update that allows vendors to upload optional artifacts. - [TrustRegister](https://community.trustcloud.ai/changelog/trustregister-318/): An update to the Risk Details, AI-Generated Risk Assessment report modal to improve the user experience. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-498/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-497/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-496/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-495/): An update that allows vendors to upload optional artifacts. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-494/): An update that allows vendors to upload optional artifacts. - [TrustRegister](https://community.trustcloud.ai/changelog/trustregister-317/): An update to the Risk Details, AI-Generated Risk Assessment report modal to improve the user experience. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-492/): An update that allows vendors to upload optional artifacts. - [TrustRegister](https://community.trustcloud.ai/changelog/trustregister-316/): An update to the Risk Details, AI-Generated Risk Assessment report modal to improve the user experience. - [TrustShare](https://community.trustcloud.ai/changelog/trustshare-480/): An update that allows vendors to upload optional artifacts. ## Docs - [Exceptions](https://community.trustcloud.ai/docs/trustops/exceptions/): The Exceptions page lets you manage all manual overrides applied to controls, tests, vendors, and attestations in a single workspace. - [Documents](https://community.trustcloud.ai/docs/trustops/documents/): Documents represent a consolidated section where users can upload, share, manage, and showcase key GRC documents like penetration testing reports, insurance policies, and procedures. - [Gap Analysis](https://community.trustcloud.ai/docs/trustops/gap-analysis/): Gap Analysis is designed to give you insight into other compliance standards and your gaps towards these. - [Excluding a Test or Assessment (Updated UI)](https://community.trustcloud.ai/docs/trustops/controls/excluding-a-control-test-or-resource/excluding-a-test-or-assessment-updated-ui/): Excluding a test or assessment allows you to remove certain tests or assessments from your program that may not apply to your business environment. - [Hybrid Data Fabric](https://community.trustcloud.ai/docs/trustops/hybrid-data-fabric/): Rather than chasing fragmented spreadsheets or outdated lists, hybrid data fabric gives you a single, unified view of everything that matters to compliance and security. - [Duo](https://community.trustcloud.ai/docs/trustcloud/integrations/device-management/duo/): This document outlines the steps you can take to grant TrustCloud access to only read metadata about the configuration settings for your Duo account and Duo Users and workstations, so that TrustOps can validate and generate evidence for your compliance program. - [Control Attributes](https://community.trustcloud.ai/docs/trustops/controls/control-attributes/): Every control has many attributes that help us understand it better for mapping and implementation purposes. - [Editing Controls](https://community.trustcloud.ai/docs/trustops/controls/editing-controls/): Control customization is a pillar of TrustCloud’s platform, effortless crafting of custom controls. With TrustOps, you can edit control and customize the control statement language, policy mappings, and frequency of the control to reflect your business practices. - [Adding Controls](https://community.trustcloud.ai/docs/trustops/controls/adding-controls/): TrustOps gives you the ability to add a custom control to your program, add any related tests to that control and map the custom control to any of TrustCloud's out-of-the-box standards. A step-by-step guide to creating a custom control and completing the mapping process, is provided in this article. - [Testing Controls](https://community.trustcloud.ai/docs/trustops/controls/testing-controls/): Once you have set up your integrations, you can leverage automated tests. Automated tests run automatically at the set evaluation frequency for each control. For self-assessment, you need to run the test and collect the required evidence manually. - [Self Attestations](https://community.trustcloud.ai/docs/trustops/self-assessments/): The Self Attestations page in TrustOps provides users with a streamlined, centralized workspace to manage all assigned assessments efficiently. It eliminates the need to navigate across multiple sections by offering a single, dedicated view of every assigned test. - [Rubrik](https://community.trustcloud.ai/docs/trustcloud/integrations/backup-and-recovery/rubrik/): The Rubrik integration enables TrustCloud to securely connect with your Rubrik Security Cloud (RSC) environment for automated evidence collection, compliance monitoring, and security posture validation. - [Backup and Recovery](https://community.trustcloud.ai/docs/trustcloud/integrations/backup-and-recovery/): Backup and recovery integrations help organizations protect critical data, applications, and systems from loss, corruption, cyberattacks, and unexpected disruptions. - [Google Cloud Platform](https://community.trustcloud.ai/docs/trustcloud/integrations/cloud-providers/google-cloud-platform/): This document outlines the steps you can take to grant TrustCloud access to only read metadata about the configuration settings for your GCP account so that TrustOps can validate and generate evidence for your compliance program. - [Bitbucket](https://community.trustcloud.ai/docs/trustcloud/integrations/source-control/bitbucket/): Instructions to grant TrustCloud read-only access to your Bitbucket organization - [Importing a New Assessment](https://community.trustcloud.ai/docs/trustshare/questionnaires/importing-a-new-questionnaire/): By leveraging TrustCloud AI, the system can auto-populate answers, reducing manual input and speeding up the review process. - [Essential asset inventory template for smart tracking](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/asset-inventory-template/): Download a ready-to-use asset inventory template to manage your IT assets efficiently. Stay compliant and boost visibility across your tech stack. - [Hybrid Data Fabric](https://community.trustcloud.ai/docs/trustcloud/integrations/): The Hybrid Data Fabric is a built-in connector between your TrustCloud and an external SaaS service. - [Getting started with SOC 2 trust service criteria: your essential guide for 2026 and beyond](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/getting-started-with-soc-2-trust-service-criteria-selection-guide/): Discover how to select the right SOC 2 trust service criteria for your business. Boost compliance success and customer trust for 2025 and beyond with this essential guide. - [GitLab V2](https://community.trustcloud.ai/docs/trustcloud/integrations/source-control/gitlab-v2/): TrustCloud's API-based integrations map seamlessly to your frameworks and controls to power automated evidence collection, continuous monitoring, and predictive risk analysis. Let's explore how you can set up GitLab for automated tests. - [Dashboard](https://community.trustcloud.ai/docs/trustshare/dashboard/): The TrustShare dashboard is a display of key information in an organized and easy-to-read manner. This includes a summary of users, questionnaires, companies, documents, and activity within your TrustShare account. - [Overview](https://community.trustcloud.ai/docs/trustshare/overview/): An app designed for startups, SMBs, and enterprises to securely share their compliance program with their customers. TrustShare Overview gives you how organizations can securely manage and share sensitive information with their customers, partners, and other stakeholders with the help of TrustShare. - [Apr-Jun 2026](https://community.trustcloud.ai/docs/changelogs/full-platform/apr-jun-2026/) - [Apr-Jun 2026](https://community.trustcloud.ai/docs/changelogs/trustcommunity/apr-jun-2026/) - [Apr-Jun 2026](https://community.trustcloud.ai/docs/changelogs/trustcloud/apr-jun-2026/) - [Apr-Jun 2026](https://community.trustcloud.ai/docs/changelogs/trustlens/apr-jun-2026/) - [Apr-Jun 2026](https://community.trustcloud.ai/docs/changelogs/trustregister/apr-jun-2026/) - [Apr-Jun 2026](https://community.trustcloud.ai/docs/changelogs/trustshare/apr-jun-2026/) - [Apr-Jun 2026](https://community.trustcloud.ai/docs/changelogs/trustops/apr-jun-2026/) - [Business intelligence](https://community.trustcloud.ai/docs/trustshare/business-intelligence/): Business Intelligenc in TrustShare – a powerful analytics and reporting dashboard that highlights TrustShare’s ROI and efficiency gains. Discover how it accelerates security reviews, saving your organization time and money. - [Groups](https://community.trustcloud.ai/docs/trustops/groups/): The groups are departments, business functions, units, or specialized teams in your organization. In TrustOps, controls, systems, evidence, and policies are categorized into groups. - [Crowdstrike](https://community.trustcloud.ai/docs/trustcloud/integrations/security-and-compliance/crowdstrike/): This document outlines the steps you can take to grant TrustCloud access to only read metadata about the configuration settings for your Crowdstrike instance so that TrustOps can validate and generate evidence for your compliance program. - [Okta](https://community.trustcloud.ai/docs/trustcloud/integrations/identity-management/okta/): Set up Okta for automated tests with TrustCloud! This document outlines the steps you can take to grant TrustCloud access to only read metadata about the configuration settings for your Okta account and Okta Users, Groups, Policies, and roles. - [ServiceNow](https://community.trustcloud.ai/docs/trustcloud/integrations/ticketing-and-collaboration/servicenow/): Set up ServiceNow for Ticket as Evidence with TrustCloud! This document outlines the steps you can take to grant TrustCloud access to retrieve ServiceNow ticket details and use them as evidence. - [Tenable.io](https://community.trustcloud.ai/docs/trustcloud/integrations/vulnerability-scanners/tenable-io/): This document outlines the steps you can take to grant TrustCloud access to only read metadata about the configuration settings for your Tenable.io account, so that TrustOps can validate and generate evidence for your compliance program. - [Manage my TrustShare](https://community.trustcloud.ai/docs/trustshare/manage-my-trustshare/): Manage My TrustShare makes it easy for you to personalize your TrustShare pages before publishing them, taking them live, and sharing them with your customers or prospects. - [Jira Cloud](https://community.trustcloud.ai/docs/trustcloud/integrations/ticketing-and-collaboration/jira-cloud/): Set up Jira Cloud for Jira Ticket as Evidence with TrustCloud! This document outlines the steps you can take to grant TrustCloud access to retrieve Jira ticket details and use them as evidence. - [AWS](https://community.trustcloud.ai/docs/trustcloud/integrations/cloud-providers/aws/): This document outlines the steps you can take to grant TrustCloud access to only read metadata about the configuration settings for your AWS account so that TrustCloud can validate and generate evidence for your compliance program. - [Getting started](https://community.trustcloud.ai/docs/trustlens/getting-started/): TrustLens provides a user-friendly platform for effective vendor risk management. - [Wiz](https://community.trustcloud.ai/docs/trustcloud/integrations/security-and-compliance/wiz/): This document outlines the steps you can take to grant TrustCloud access to only read metadata about the configuration settings for your Wiz account so that TrustOps can validate and generate evidence for your compliance program. - [Connected controls](https://community.trustcloud.ai/docs/trustregister/mitigation-and-treatment-plans/connected-controls/): Control effectiveness refers to how ‘effective’ your selected controls are at mitigating the risk. - [Assessment templates](https://community.trustcloud.ai/docs/trustlens/assessments/assessment-templates/): TrustLens supports the creation of programmatic vendor assessment templates that connect to your existing common control framework, making evaluation and submission easier. - [Vendors](https://community.trustcloud.ai/docs/trustlens/vendors/): Vendors play a crucial role in the supply chain, as they provide the necessary products or services that enable businesses to operate and meet the needs of their customers. - [Policies](https://community.trustcloud.ai/docs/trustops/policies/): A policy is a document that describes the intention, expectations, and overall approach that an organization uses to maintain certain processes and procedures within the organization. - [ISO 27001 statement of applicability – download free template for 2026](https://community.trustcloud.ai/docs/trustops/helpful-resources/iso-standards-documentation-templates/iso-27001-statement-of-applicability-download-free-template-for-2025/): A Statement of Applicability (SOA) Template provides an overview of the organization’s approach to managing specific risks and demonstrates how the organization meets the requirements of the standard. - [Strengthen security with smart data breach response practices](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/data-breach-response-strategies-a-proactive-approach-to-cybersecurity/): Learn proactive data breach response strategies to protect your business. Boost cybersecurity, reduce risk, and stay ahead with smart governance practices. - [Jamf Pro – API Client](https://community.trustcloud.ai/docs/trustcloud/integrations/device-management/jamf-pro-v2/): This document outlines the steps you can take to grant TrustCloud auditor access to only read metadata about the configuration settings for your Jamf Pro account and Jamf users and workstations. - [Powerful attestation of compliance: Key considerations for regulatory success](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/attestation-of-compliance-key-considerations-for-achieving-and-maintaining-regulatory-compliance/): By obtaining an attestation of compliance and adhering to key considerations such as understanding regulatory requirements, creating a compliance management system and continuously improving compliance efforts, organizations can reap numerous benefits. - [The evolution of compliance: top 7 trends to watch in 2026](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/the-evolution-of-compliance-top-7-trends-to-watch-in-2025/): As we navigate through 2025 and beyond, the evolution of compliance is evident in the convergence of global standards, the infusion of technology, and a heightened focus on ethical practices. - [Digital transformation in governance: strategies for success in 2026](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/digital-transformation-in-governance-strategies-for-success-in-2025/): Digital transformation in governance is driven by the increasing demand for improved government services and the need to keep pace with technological advancements. - [Risk summary and details](https://community.trustcloud.ai/docs/trustregister/risk-details/risk-summary-and-details/): "Risk Summary and Details" serve as a condensed yet comprehensive overview of potential threats. This section succinctly captures the essence of each risk, combining brevity with crucial details. - [Filter, Search and Sort Controls](https://community.trustcloud.ai/docs/trustops/controls/filter-search-and-sort-controls/): The controls page in TrustOps allows you to view controls using different filters, search options, and views. - [Access control policies for strong data security in 2026](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/ideal-access-control-policies-and-their-extensive-role-in-data-security-and-compliance/): Learn how ideal access control policies protect sensitive data, enforce user roles, and ensure compliance with modern security and privacy regulations. - [Support](https://community.trustcloud.ai/docs/security-assessments/support/): Please fill this form and a TrustCloud specialist will get in touch with you at the earliest. - [Settings](https://community.trustcloud.ai/docs/security-assessments/settings/): The Manage My TrustShare page allows you to configure and manage your TrustShare site settings. - [User Management](https://community.trustcloud.ai/docs/security-assessments/user-management/): The All Users page allows you to view and manage all users who have access to your TrustShare environment. - [Graph](https://community.trustcloud.ai/docs/security-assessments/graph/): The Graph section provides a connected view of your organization’s security and compliance framework. - [Powerful benefits of decentralized governance in 2026](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/decentralized-governance-exploring-the-role-of-blockchain-in-modern-organizations/): Explore how blockchain powers decentralized governance. Learn its impact on control, trust, and compliance in modern digital organizations. - [Virtual Audit](https://community.trustcloud.ai/docs/security-assessments/virtual-audit/): The Virtual Audit page allows you to create and manage Data Rooms, which are secure spaces for privately sharing customer-specific compliance information. - [Portal](https://community.trustcloud.ai/docs/security-assessments/portal/): The Portal page allows you to manage your external-facing trust pages, ensuring that your stakeholders have access to accurate and up-to-date information. - [Insights](https://community.trustcloud.ai/docs/security-assessments/insights/): The Insights page provides a centralized view of your organization’s key activities, including users, questionnaires, companies, and documents. - [Deleting questionnaire](https://community.trustcloud.ai/docs/security-assessments/answering-an-assessment/deleting-questionnaire/): You can delete your questionnaire if it is of no use. - [Archiving questionnaire](https://community.trustcloud.ai/docs/security-assessments/answering-an-assessment/archiving-questionnaire/): You can archive your questionnaire for future use. - [Assigning approver](https://community.trustcloud.ai/docs/security-assessments/answering-an-assessment/assigning-approver/): You can assign any of your team members as an approver for your questionnaire. - [Exporting an assessment](https://community.trustcloud.ai/docs/security-assessments/answering-an-assessment/exporting-an-assessment/): You can export the assessment for your record. - [Reopening the questionnaire](https://community.trustcloud.ai/docs/security-assessments/answering-an-assessment/reopening-the-questionnaire/): If you want to make any changes in answers after submitting the questionnaire or the question, you can always go back and make the changes by reopening the questionnaire or just a particular question. - [Review and submit assessment](https://community.trustcloud.ai/docs/security-assessments/answering-an-assessment/review-and-submit-assessment/): After carefully answering and reviewing the questionnaire, you can submit the assessment. - [Inviting other team members](https://community.trustcloud.ai/docs/security-assessments/inviting-other-team-members/): You can invite your team members to contribute to the questionnaire.  - [Answering an assessment](https://community.trustcloud.ai/docs/security-assessments/answering-an-assessment/): Read the question carefully and answer the question; you can also write comments supporting the answer. - [Invitation expired](https://community.trustcloud.ai/docs/security-assessments/invitation-and-sign-up/invitation-expired/): The invitation link is only active for 14 days, as mentioned in the invitation. - [How to log in](https://community.trustcloud.ai/docs/security-assessments/invitation-and-sign-up/how-to-log-in/): When you receive the new email, open it and click the invitation link as soon as possible (before the new expiry time) - [Signing-up](https://community.trustcloud.ai/docs/security-assessments/invitation-and-sign-up/signing-up/): You will complete your assessment using TrustCloud. The platform ensures that all information you provide is kept secure and confidential. - [Invitation and sign-up](https://community.trustcloud.ai/docs/security-assessments/invitation-and-sign-up/): When a partner organization conducts due diligence, they may invite your company to complete a vendor risk assessment using TrustCloud. - [Security Assessments](https://community.trustcloud.ai/docs/security-assessments/) - [The evolution of GRC technology: key trends shaping 2026 and beyond](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/the-evolution-of-grc-technology-key-trends-shaping-2024-and-beyond/): GRC technology serves as a powerful catalyst, enabling businesses to streamline processes, enhance decision-making, and foster a culture of accountability. - [Essential NIST password guidelines for stronger security](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/nist-password-guidelines-2025-what-you-need-to-know-to-stay-secure/): With a proactive and comprehensive approach, you can unlock the future of cybersecurity and safeguard your digital assets for years to come. - [Risk Approvals](https://community.trustcloud.ai/docs/trustregister/risk-approvals/): To use the risk approval workflow in TrustRegister as a risk owner, work through these stages: prepare the risk, send it for approval, track reviewer decisions, and review the final audit trail. - [How to implement a data classification policy in 2026](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/safeguarding-sensitive-information-implementing-a-data-classification-policy/): Learn how to implement a data classification policy to protect sensitive information, ensure compliance, and enhance your organization's data security. - [Adding, editing and disabling a vendor](https://community.trustcloud.ai/docs/trustlens/vendors/adding-editing-and-disabling-a-vendor/): This article will guide you on how to add, edit or disable a vendor with TrustLens. - [ISO 27001 toolkit: Essential tools and templates to simplify compliance in 2026](https://community.trustcloud.ai/docs/grc-launchpad/iso-27001/iso-27001-toolkit-list-of-tools-and-services-for-your-iso-27001/): Looking to achieve ISO 27001 compliance faster? Explore this curated ISO 27001 compliance toolkit with top tools, templates, and services that streamline audits, documentation, and control management. - [Powerful compliance automation for smarter healthcare](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/the-benefits-of-compliance-automation-in-the-healthcare-industry/): Discover how automation enhances healthcare compliance by reducing errors, saving time, and ensuring data security. Learn best practices for 2026. - [Stay ahead with powerful insights on cybersecurity risks in 2026](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/evolving-cybersecurity-risks-a-comprehensive-guide-to-digital-threats-in-2024/): Explore the top cybersecurity risks of 2025 and learn how to safeguard your digital assets. Get actionable insights to enhance resilience and reduce cyber threats. - [Jan-Mar 2026](https://community.trustcloud.ai/docs/changelogs/trustops/jan-mar-2026/) - [Jan-Mar 2026](https://community.trustcloud.ai/docs/changelogs/trustshare/jan-mar-2026/) - [Jan-Mar 2026](https://community.trustcloud.ai/docs/changelogs/trustregister/jan-mar-2026/) - [Jan-Mar 2026](https://community.trustcloud.ai/docs/changelogs/trustlens/jan-mar-2026/) - [Jan-Mar 2026](https://community.trustcloud.ai/docs/changelogs/trustcloud/jan-mar-2026/) - [Jan-Mar 2026](https://community.trustcloud.ai/docs/changelogs/trustcommunity/jan-mar-2026/) - [Jan-Mar 2026](https://community.trustcloud.ai/docs/changelogs/full-platform/jan-mar-2026/) - [Unlock powerful ethical decision-making in GRC for 2026 success](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/ethical-decision-making-in-grc-a-framework-for-success-in-2024/): The ethical decision-making framework outlined in this article provides a roadmap for success in the GRC in 2024 and beyond. It is through ethical decision-making that organizations can build a brighter future for themselves and the communities they serve. - [Unlock powerful global compliance success in 2026](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/global-compliance-challenges-in-2024-a-comprehensive-guide-for-businesses/): Explore 2026’s biggest global compliance challenges, from data privacy to ESG, and learn practical strategies, best practices, and tools to protect your business and grow confidently. - [Unlock essential GRC compliance trends for 2026](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/key-trends-in-grc-and-compliance-for-2025/): Discover 6 key GRC trends for 2026 including AI automation, ESG reporting, cybersecurity harmonization, and supply chain oversight. Stay ahead of regulatory complexity with proven strategies for resilient governance. - [Sumologic](https://community.trustcloud.ai/docs/trustcloud/integrations/logging-and-monitoring/sumologic/): Set up Sumologic for automated tests with TrustCloud! This document outlines the steps you can take to grant TrustCloud access to retrieve a list of employees to use as evidence. - [Questionnaires](https://community.trustcloud.ai/docs/trustshare/questionnaires/): Auto-generate and suggest answers to incoming security assessments directly from your TrustCloud. Its intelligence algorithm uses ML and NLP to automatically match questions to controls and policies in your program. - [Systems](https://community.trustcloud.ai/docs/trustops/systems/): A system is a piece of software, either built by the organization or purchased from a third party. For eg. cloud-based tools that employees use on a daily basis, typically qualify as systems. - [HITRUST – Overview and Guides](https://community.trustcloud.ai/docs/grc-launchpad/hitrust-overview-and-guides/): Enter HITRUST, a comprehensive risk-based framework made up of various industry standards, designed to streamline and strengthen your organization's security posture. - [List of tools and services for CMMC](https://community.trustcloud.ai/docs/grc-launchpad/cmmc-level-1/cmmc-toolkit-list-of-tools-and-services-for-your-cmmc/): A List of tools and services for your CMMC is curated to showcase the possible purchases required for your CMMC preparation. - [Mitigation and treatment plans](https://community.trustcloud.ai/docs/trustregister/mitigation-and-treatment-plans/): Mitigation and treatment plans stand as the linchpins of effective risk management, central to the dynamic landscape of a risk register. - [Risk Intelligence and Reporting](https://community.trustcloud.ai/docs/trustregister/intelligence/risk-intelligence-and-reporting/): The "Risk Intelligence" page is a visualization of the top metrics driving risk to quickly take action and minimize organizational risk. - [What is TrustRegister?](https://community.trustcloud.ai/docs/trustregister/overview/what-is-trustregister/): TrustRegister continuously scans your business to test and measure your level of risk based on the status of your controls and treatment plans across your entire business in real-time. - [Risk Register](https://community.trustcloud.ai/docs/trustregister/risk-register/): The Risk Register Page displays all your risks in a table view where you are able to customize, sort and filter specific risks. Included are fields that highlight key info of each risk to sort through. - [Overview](https://community.trustcloud.ai/docs/trustregister/overview/): TrustRegister is a TrustCloud application that is designed for startups, SMBs, and enterprises to achieve Business-wide, Continuous, and Actionable Risk Assessment so that you don’t struggle to identify, collaborate on, and remediate what’s important.  - [TrustRegister](https://community.trustcloud.ai/docs/trustregister/): TrustRegister is a TrustCloud application that is designed for startups, SMBs, and enterprises to achieve Business-wide, Continuous, and Actionable Risk Assessment so that you don’t struggle to identify, collaborate on, and remediate what’s important.  - [Intelligence](https://community.trustcloud.ai/docs/trustregister/intelligence/): TrustCloud makes it effortless to set up a comprehensive and personalized Risk Register. From either bringing in your own Risk Register or starting from scratch, you can set up your TrustRegister in a few simple steps. - [Powerful cybersecurity risk guide for GRC professionals in 2026](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/cybersecurity-risks-a-comprehensive-guide-for-grc-professionals/): Explore a comprehensive cybersecurity risk guide for GRC professionals. Learn effective risk management, threat identification, controls, and best practices for %currentyear%. - [Automating user management with SCIM](https://community.trustcloud.ai/docs/trustcloud/integrations/identity-management/automating-user-management-with-scim/): This allows customers to use the SCIM protocol with their IDP to automatically send TrustCloud invites to new users that have been assigned TrustCloud roles, plus automatically remove users from TrustCloud when they are deactivated. - [Assessments](https://community.trustcloud.ai/docs/trustlens/assessments/): Regular risk assessments should be performed on each vendor based on business criticality, vendor tier, compliance requirements, etc. - [Vendors dashboard](https://community.trustcloud.ai/docs/trustlens/vendors-dashboard/): The vendor dashboard of TrustLens is a robust analytics and reporting dashboard that provides valuable insights into the key metrics of your vendor risk management or third-party risk management. - [NIST CSF Overview and Guides](https://community.trustcloud.ai/docs/grc-launchpad/nist-csf/): The NIST CSF Overview and Guides talk about the Cybersecurity Framework (CSF), which is voluntary guidance released by the National Institute of Standards and Technology (NIST) in 2014 for private sector organizations in the US and has been embraced by organizations around the world. - [Documents](https://community.trustcloud.ai/docs/trustshare/documents/): The documents page automatically populates the policies and certifications already available within your TrustCloud for easy sharing with prospects/customers! - [ISO 27001 program audit checklist](https://community.trustcloud.ai/docs/grc-launchpad/iso-27001/iso-27001-program-audit-checklist/): The ISO 27001 program Audit Checklist is a simplified checklist to follow and move forward with confidence. You can download this checklist from here. - [Oct-Dec 2025](https://community.trustcloud.ai/docs/changelogs/full-platform/oct-dec-2025/): An update that adds risk subcategories as a filtering option - [Oct-Dec 2025](https://community.trustcloud.ai/docs/changelogs/trustcommunity/oct-dec-2025/) - [Oct-Dec 2025](https://community.trustcloud.ai/docs/changelogs/trustcloud/oct-dec-2025/): A bug that resolves subscription entries - [Oct-Dec 2025](https://community.trustcloud.ai/docs/changelogs/trustlens/oct-dec-2025/): An update to display the control name - [Oct-Dec 2025](https://community.trustcloud.ai/docs/changelogs/trustregister/oct-dec-2025/): An update that adds risk subcategories as a filtering option - [Oct-Dec 2025](https://community.trustcloud.ai/docs/changelogs/trustshare/oct-dec-2025/): An update to the Documents table - [Oct-Dec 2025](https://community.trustcloud.ai/docs/changelogs/trustops/oct-dec-2025/): A bug fix for the user app state - [Boost resilient security posture: Proven 10 steps for strong controls](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/8-essential-steps-to-implement-controls-for-a-resilient-security-posture/): Discover ten expert steps to easily implement controls and build a resilient security posture. Achieve robust protection and greater peace of mind with this practical guide. - [Search and filter](https://community.trustcloud.ai/docs/trustregister/risk-details/search-and-filter/): The Risk Register page in TrustRegister displays all your risks in a table view, where you can search for and filter them. - [Overview](https://community.trustcloud.ai/docs/trustlens/overview/): TrustLens, a third-party risk management solution offered by TrustCloud, provides customized risk assessment templates for each vendor tier, streamlining the assessment process. - [Third-Party Risk Assessments (TPRA)](https://community.trustcloud.ai/docs/trustlens/third-party-risk-assessments-tpra/): You can easily send, assess, and manage your third-party risk assessments using TrustLens. - [TrustLens](https://community.trustcloud.ai/docs/trustlens/): TrustLens, a third-party risk management solution offered by TrustCloud, provides customized risk assessment templates for each vendor tier, streamlining the assessment process. - [Users](https://community.trustcloud.ai/docs/trustshare/users/): TrustShare users are people or entities that have access to your trust portal. - [Data Rooms](https://community.trustcloud.ai/docs/trustshare/data-rooms/): Data rooms allow you to privately share specific documents with certain customers during the sales process. - [Archived Questionnaires](https://community.trustcloud.ai/docs/trustshare/questionnaires/archived-questionnaires/): The archived questionnaires feature in TrustShare allows users to manage outdated questionnaires by moving them to an archive. This process helps maintain an organized and current list of active questionnaires. - [Complete Questionnaires](https://community.trustcloud.ai/docs/trustshare/questionnaires/complete-questionnaires/): The complete questionnaires featured in TrustShare allow users to finalize and manage completed security assessments with ease. Once a questionnaire is marked as complete, it remains accessible for reference, review, and export. - [TrustGraph](https://community.trustcloud.ai/docs/trustshare/trustgraph/): Introducing TrustGraph in TrustShare – your program's compliance artifacts, including controls, policies, and Q&A knowledge base, come to life in a clear, interconnected view. See the data that fuels your security questionnaire responses, and understand where our AI sources its answers. - [Chrome Extension](https://community.trustcloud.ai/docs/trustshare/questionnaires/chrome-extension/): TrustShare's Chrome extension simplifies the completion of security questionnaires, saving time and improving accuracy. By installing and using Chrome extensions, users can optimize their browsing experience and access additional features with ease. - [Unlock business success: Choose the right control framework](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/choosing-the-right-control-framework-for-your-business/): The journey toward selecting the right control frameworks is not just a compliance exercise; it's a deliberate and strategic choice that empowers businesses to build a resilient foundation for sustainable growth and success. - [Questionnaire Workflow](https://community.trustcloud.ai/docs/trustshare/questionnaires/questionnaire-workflow/): The questionnaire workflow will guide you through the process of managing compliance questionnaires in TrustShare. - [Unlock powerful security awareness training for a safer workplace](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/security-awareness-training-what-it-is-and-why-your-company-needs-it-now/): Discover how effective security awareness training reduces risk, boosts employee vigilance, and strengthens your organization's compliance culture. - [Companies](https://community.trustcloud.ai/docs/trustshare/companies/): A public-facing trust portal that enables your prospects to access your compliance program securely and proactively. The Active Companies page sorts your users by organization name, so you can see a list of all of the active organizations in your TrustShare. - [TrustShare](https://community.trustcloud.ai/docs/trustshare/): Proactively share your program at the start of the sales process and avoid endless follow-ups on security assessments. Make security and compliance a key part of vendor selection, and show customers how you’re better than your competition. Save your marketing team from manually creating content that proves product security and compliance. - [Getting Started](https://community.trustcloud.ai/docs/trustshare/getting-started/): A guide to help you get started with TrustShare. - [Vital data privacy & AI ethics: Essential practices every organization must follow](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/data-privacy-and-ai-ethical-considerations-and-best-practices/): Learn how to strengthen data privacy while using AI. Discover ethical best practices to build trust, reduce risk, and ensure responsible AI adoption. - [Master change management in GRC: Build effective policies for 2025](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/change-management-in-grc-how-to-build-policies-that-actually-work-in-2025/): Learn how to create change management policies that reduce risk, support compliance, and drive business success. Practical tips for GRC and governance teams. - [Unlock effective agile compliance management strategies for evolving regulations](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/effective-agile-compliance-management-strategies-for-evolving-regulatory-frameworks/): Discover effective agile compliance management strategies to navigate evolving regulatory frameworks. Learn how to stay compliant and adaptable in a dynamic environment. - [Why are employee all hands meetings important?](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/why-are-employee-all-hands-meetings-important/): Discover how all-hands meetings boost communication, transparency, and engagement. Learn how to run impactful sessions that align and energize your team. - [Define your NIST 800-171 audit scope](https://community.trustcloud.ai/docs/grc-launchpad/nist-sp-800-171-overview-and-guides/define-your-nist-800-171-audit-scope/): Define your NIST 800-171 Audit Scope to set the boundaries of the audit and identify the object in focus. The object includes the people, data, system, or product in review. The scope definition allows the auditors to focus on an aspect of the organization. - [Compliance](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/): Explore the core of GRC (Governance, Risk & Compliance) compliance: frameworks, best practices, and tools that ensure your organization meets regulatory demands and builds stakeholder trust. Unlock actionable strategies to manage risk and sustain ethical standards. - [Master 9 infrastructure monitoring strategies for reliable IT performance](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/9-proven-strategies-for-effective-infrastructure-monitoring/): Discover 9 essential strategies to monitor your infrastructure effectively, ensuring optimal performance and minimizing downtime. - [Team](https://community.trustcloud.ai/docs/trustcloud/platform-administration/team/): Team functionality is divided into two pages, “Users” and “Roles Settings.” - [Platform Administration](https://community.trustcloud.ai/docs/trustcloud/platform-administration/): The “Platform Administration” menu stands as the central hub of TrustCloud, designed exclusively for administrators to optimize and secure the organization's digital environment. - [Empower employees with seamless access to policies & procedures to unlock compliance & efficiency](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/employee-access-to-the-organizations-policies-and-procedures/): Discover how centralized access to policies and procedures boosts employee compliance, productivity, and organizational transparency. Learn best practices for effective governance. - [Powerful workplace culture guide: Role of acceptable use policy in 2026](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/mastering-modern-workplace-culture-the-crucial-role-of-an-acceptable-use-policy/): Explore how an acceptable use policy shapes workplace culture, boosts security, and improves productivity. Learn key components and best practices for success. - [Acceptable use policy](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/acceptable-use-policy/): Using an Acceptable Use Policy (AUP) involves several key steps to ensure effective implementation and compliance within an organization. Download the template for free. - [ISO 9001 Overview and Guides](https://community.trustcloud.ai/docs/grc-launchpad/iso-9001/): ISO 9001 Overview and Guides talk about ISO 9001, a globally recognized framework, for governing an organization’s quality management program by providing a clear set of requirements for a Quality Management System (QMS). - [Master risk management in 2026: Breakthrough strategies for managing uncertainty](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/adapting-to-uncertainty-innovative-approaches-to-risk-management-in-2024/): Discover cutting-edge risk management strategies for 2024 that help organizations adapt to uncertainty. Learn how scenario planning, predictive analytics, resilience building, and agile governance can protect your business from emerging threats and accelerate decision-making with confidence. - [Preparing for an ISO 27001 audit](https://community.trustcloud.ai/docs/grc-launchpad/iso-27001/how-to-get-started-with-iso-27001/preparing-for-a-iso-27001-audit/): To pursue an ISO 27001 attestation, here are some things to keep in mind when drafting your audit preparation strategy. - [DATA-25 Data Lifecycle Management (DLM)](https://community.trustcloud.ai/docs/trustops/controls/data-management/data-25-data-lifecycle-management-dlm/): DATA-25 Data Lifecycle Management (DLM) control is about tracking all the stages of the data life cycle. Learn more about it with an example. - [Ultimate third-party risk management playbook: Shield your business in the digital era](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/the-ultimate-guide-to-third-party-risk-management-safeguarding-your-business-in-the-digital-age/): Discover third-party risk management strategies to secure vendor relationships, reduce threats, and enhance compliance. Build trusted digital partnerships today. - [Incident response plan template – download for free](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/incident-response-plan-example/): Download an incident response plan for free that outlines the procedures an organization should follow in the event of a cybersecurity incident or data breach. - [HIPAA program audit checklist](https://community.trustcloud.ai/docs/grc-launchpad/hipaa/hipaa-toolkit-hipaa-program-audit-checklist/): Get ready for HIPAA compliance with a robust audit checklist that tackles Privacy, Security, and Breach Notification rules. Learn how to prepare, audit, and strengthen your organization's HIPAA readiness with practical insights and structured guidance. - [Powerful guide: What is a security incident and how to report it effectively](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/what-is-an-incident-and-how-do-i-report-it/): Learn what an incident is, why it matters, and how to report it promptly with our clear, proactive steps. A powerful resource for risk management teams. - [PRIV-3 privacy management tool](https://community.trustcloud.ai/docs/trustops/controls/privacy/privacy-management-tool/): A privacy management tool control ensures that sensitive data is effectively managed according to applicable obligations. - [Backup Policy](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/backup-policy/): A backup policy is a set of guidelines and procedures that define how data backups are managed and maintained within an organization. - [Mastering security questionnaires: a comprehensive guide for vendors](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/mastering-security-questionnaires-a-comprehensive-guide-for-vendors/): Learn smart, proven strategies to complete vendor security questionnaires and impress clients. Ensure compliance and build lasting trust with actionable best practices. - [Effortlessly achieve ISO 27001 readiness: Timelines by company size](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/iso-27001-preparation-time-for-companies-of-different-sizes/): Discover realistic ISO 27001 preparation timelines: 6-12 months for small businesses, 12-18 for mid-sized, and 18-24 for large firms. Accelerate certification with proven steps and TrustCloud automation for faster compliance success. - [IT-16 Asset disposal](https://community.trustcloud.ai/docs/trustops/controls/asset-management/it-16-asset-disposal/): IT-16 – Asset Disposal Control is about implementing a formal process to dispose of an organization's equipment at the end of its useful life. - [NIST 800-171 program audit checklist: A comprehensive guide](https://community.trustcloud.ai/docs/grc-launchpad/nist-sp-800-171-overview-and-guides/nist-800-171-program-audit-checklist/): You’ve made it through the previous articles on NIST 800-171 and want a simplified checklist to follow along and forward with confidence. Click on the downloadable link at the end of the article for a copy of this checklist. - [Preparing for a HIPAA audit](https://community.trustcloud.ai/docs/grc-launchpad/hipaa/how-to-get-started-with-hipaa/preparing-for-a-hipaa-audit/): Get ahead of HIPAA audits with this expert guide. Learn essential steps, documents to prepare, and tips to ensure a stress-free audit process. - [Effective risk assessment methodologies: A complete comparative guide](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/risk-assessment-methodologies-a-comparative-review/): Explore and compare top risk assessment methodologies to enhance your organization's risk management strategy. Learn how to choose the right approach for improved decision-making and compliance. - [Define your ISO 27001 audit scope](https://community.trustcloud.ai/docs/grc-launchpad/iso-27001/define-your-iso-27001-audit-scope/): Learn how to define your ISO 27001 audit scope effectively. This guide helps you focus on the right assets, processes, and boundaries for compliance success. - [Building a security awareness training program: Essential steps for effective implementation](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/how-do-i-develop-a-security-awareness-training-program/): Learn how to build an effective security awareness training program, from assessing needs and designing content to rolling out training and measuring impact. - [Powerful strategies for successful acceptable use policy enforcement](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/enforcing-acceptable-use-policy-strategies-for-effective-implementation/): Enforcing an acceptable use policy (AUP) within an organization is crucial for maintaining a secure and productive environment. Disciplinary actions for violations should be clearly outlined in the policy and applied uniformly across all levels of the organization. - [Powerful ISO 42001 framework for trustworthy AI success](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/iso-42001-framework-ensuring-safety-consistency-and-accountability-with-ai/): Discover how the ISO 42001 framework helps you build safe, consistent, and accountable AI systems while boosting trust, compliance, and innovation. - [Unlock business stability: Implement robust risk management policies today](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/significance-of-implementing-robust-risk-management-policies-as-the-foundation-of-business-stability/): Discover how robust risk management policies can safeguard your business, enhance resilience, and ensure long-term stability. Learn the essential strategies now. - [Mastering compliance strategies for regulatory agility in 2026](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/mastering-compliance-strategies-for-staying-ahead-of-regulations/): Explore these compliance strategies to proactively manage regulatory changes, learn to assess risks, update controls, and embed agility across your organization. - [INFRA-2 Pen Testing](https://community.trustcloud.ai/docs/trustops/controls/vulnerability-management/infra-2-pen-testing/): Pen testing, or penetration testing, is an authorized simulated attack on an organization's systems to evaluate the security of the system. - [7 smart ways to find the right GRC software for your organization](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/top-7-tips-to-choose-the-best-grc-software-for-your-organization/): Discover 7 key factors to consider when selecting GRC software to ensure it aligns with your organization's needs and compliance requirements.​ - [ISO 27001 Overview and Guides](https://community.trustcloud.ai/docs/grc-launchpad/iso-27001/): An ISO 27001 certification demonstrates that your organization has an adequate information security system in place. - [Free job description templates you can customize for any role](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/free-job-description-templates-download-customizable-docs-for-any-role/): Access free, customizable job description templates designed for any role. Easily edit and download documents to streamline your recruitment and hiring process. - [AI-driven GRC automation: Enhancing governance with intelligent systems](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/grc-automation-in-governance-unleashing-the-potentia-of-leveraging-ai/): Discover how GRC automation powered by artificial intelligence can streamline governance, boost compliance efficiency, and drive smarter decision-making. - [Powerful scenario planning strategies for future success](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/risk-anticipation-scenario-planning-for-uncertain-futures/): Discover how risk anticipation and scenario planning help you prepare for uncertainty. Learn how to identify threats early and build a resilient, future-ready strategy. - [Business recovery](https://community.trustcloud.ai/docs/trustops/controls/business-recovery/): Business Recovery is the restoration activity that returns the business to an acceptable level of operation following a work disruption. - [Free disaster recovery plan template: Secure your business against disruptions](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/free-disaster-recovery-plan-template-safeguard-your-business-today/): Download a free, customizable disaster recovery plan template, designed to help you prepare, respond, and recover from business disruptions with ease. - [TrustCloud HITRUST audit partners](https://community.trustcloud.ai/docs/grc-launchpad/hitrust-overview-and-guides/trustcloud-hitrust-audit-partners/): TrustCloud’s HITRUST Audit Partners is a pool of CPA audit firms to help provide a joyfully crafted audit experience. - [DATA-6 Data In-Transit Encryption](https://community.trustcloud.ai/docs/trustops/controls/data-management/data-6-data-in-transit-encryption/): Data In-Transit Encryption translates data from plaintext into ciphertext in order to protect the data stored in computer resources from unauthorized access. - [Physical security policy](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/physical-security-policy/): A physical security policy is a formal document that outlines an organization's strategies and measures to protect its physical assets, personnel, and facilities from unauthorized access, theft, vandalism, and other physical threats. - [Jul-Sep 2025](https://community.trustcloud.ai/docs/changelogs/full-platform/jul-sep-2025/): The "Platform Administration" link in the avatar dropdown is now hidden - [Jul-Sep 2025](https://community.trustcloud.ai/docs/changelogs/trustcommunity/jul-sep-2025/) - [Jul-Sep 2025](https://community.trustcloud.ai/docs/changelogs/trustcloud/jul-sep-2025/) - [Jul-Sep 2025](https://community.trustcloud.ai/docs/changelogs/trustlens/jul-sep-2025/): An issue where sending an existing assessment to the vendor would not cause the assessment status to change - [Jul-Sep 2025](https://community.trustcloud.ai/docs/changelogs/trustregister/jul-sep-2025/): A bug fix that caused the risk categories page to display a 404 error - [Jul-Sep 2025](https://community.trustcloud.ai/docs/changelogs/trustshare/jul-sep-2025/): The "Platform Administration" link in the avatar dropdown is now hidden - [Jul-Sep 2025](https://community.trustcloud.ai/docs/changelogs/trustops/jul-sep-2025/): A bug that prevented applicable tests from being created or deleted - [Smart access control policy for effortless, secure teams](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/fine-tuning-your-access-control-policy-strategies-for-balancing-security-and-usability/): Learn how to fine‑tune your access control policy to boost security, cut risk, and keep users productive with balanced, user‑friendly controls. - [Data privacy rights: understanding and exercising consumer empowerment](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/data-privacy-rights-understanding-and-exercising-consumer-empowerment/): Learn how to exercise your data privacy rights and take control of your personal information. Discover practical ways to achieve true consumer empowerment. - [Creating a simplistic Information Security Policy framework: A step-by-step guide](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/creating-a-simplistic-information-security-policy-framework-a-step-by-step-guide/): Learn how to build a simple yet powerful information security policy framework with this step-by-step guide—ideal for startups and growing businesses. - [Powerful biometric data protection for safer privacy](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/biometric-data-protection-emerging-technologies-and-privacy-concerns-in-2024/): Discover how to safeguard biometric data in 2025 with emerging technologies, privacy-first strategies, and actionable security practices for your organization. - [Powerful acceptable use policies that confidently protect company data​](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/the-important-role-of-acceptable-use-policies-in-safeguarding-company-resources-and-data/): Explore how strong acceptable use policies reduce risk, prevent data leaks, and protect company resources while building a secure, accountable workplace culture. - [Essential guide to powerful acceptable use policies](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/why-every-organization-needs-an-acceptable-use-policy-aup-exploring-legal-and-security-implications/): Learn why an acceptable use policy is essential for legal protection, stronger security, and a safer digital workplace, plus key steps to create and enforce one effectively. - [Acceptable Use Policy: 5 common mistakes to avoid when implementing AUP](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/acceptable-use-policy-5-common-mistakes-to-avoid-when-implementing-aup/): Learn the top 5 mistakes to avoid when creating an acceptable use policy. Strengthen compliance, boost security, and protect your business from costly errors. - [Supercharge data protection in the age of innovation](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/data-protection-in-technological-advancements-balancing-between-innovation-and-privacy/): Explore how to strengthen data protection while embracing new technologies. Learn smart strategies to balance innovation, privacy, and regulatory compliance. - [Unlock powerful risk management: Discover how integrating ERM with GRC transforms success](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/integrating-erm-with-grc-a-comprehensive-guide-for-effective-risk-management/): Discover how integrating ERM with GRC boosts efficiency, compliance, and strategic decision-making. Learn proven steps and best practices for lasting success. - [Crafting an effective risk management policy for your business](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/crafting-an-effective-risk-management-policy-for-your-business/): Learn how to build a risk management policy that protects your business, minimizes threats, and boosts resilience with clear, strategic planning. - [Creating a data classification policy: best practices for organizational security](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/creating-a-data-classification-policy-best-practices-for-organizational-security/): Learn the best practices to create a smart data classification policy that enhances security, simplifies compliance, and protects sensitive business data. - [Designing an effective access control policy: best practices and key considerations](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/designing-an-effective-access-control-policy-best-practices-and-key-considerations/): Design a powerful access control policy with proven best practices. Strengthen data security, reduce risk, and stay compliant with modern frameworks. - [Information security policies: The crucial role in achieving regulatory compliance](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/information-security-policies-the-crucial-role-in-achieving-regulatory-compliance/): Information security policies play a crucial role in achieving regulatory compliance by providing a framework for protecting sensitive information, mitigating risks, and establishing a culture of security within organizations. - [Powerful acceptable use policy for safer businesses](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/crafting-an-effective-acceptable-use-policy-best-practices-for-businesses/): Learn how to create an effective acceptable use policy that promotes trust, accountability, and security across your organization’s digital environment. - [Blockchain and GRC: revolutionizing trust and transparency](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/blockchain-and-grc-revolutionizing-trust-and-transparency/): As blockchain continues to evolve, its integration with GRC frameworks will play a pivotal role in shaping the future of regulatory compliance and transparency across industries. - [The impact of blockchain technology on regulatory compliance: opportunities and challenges](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/the-impact-of-blockchain-technology-on-regulatory-compliance-opportunities-and-challenges/): Blockchain technology has the potential to revolutionize regulatory compliance by introducing transparency, efficiency, and automation. - [7 key benefits of data classification policies in data protection](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/7-key-benefits-of-data-classification-policies-in-data-protection/): Learn how data classification policies boost security, streamline compliance, and protect sensitive information with smart, structured data handling. - [How do I set up a governance program?](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/how-do-i-set-up-a-governance-program/): By following the steps outlined in this comprehensive guide, you can successfully establish a robust governance program that supports the long-term success and sustainability of your organization. - [Developing a strategic segregation of duties matrix](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/developing-a-strategic-segregation-of-duties-matrix/): Learn how to build a strategic segregation of duties matrix to reduce risk, improve accountability, and strengthen internal controls across your organization. - [Importance of Segregation of Duties (SoD)](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/importance-of-segregation-of-duties-sod/): Learn why segregation of duties is essential for risk reduction, fraud prevention, and strong internal controls. Boost accountability and meet compliance goals. - [Governance](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/): Governance is a process that focuses on creating a structured and systematic approach to managing and ensuring compliance with laws and regulations that affect an organization's operations. - [What are internal control metrics?](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/what-are-internal-control-metrics/): Learn what internal control metrics are, why they matter, and how to use them to improve compliance, reduce risk, and support confident decision-making. - [What’s a disciplinary action process?](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/whats-a-disciplinary-action-process/): Learn how to handle employee issues fairly with a clear, effective disciplinary action process. Build trust, reduce risk, and maintain workplace integrity. - [Policies vs procedures vs standards](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/policies-vs-procedures-vs-standards/): Understand the difference between policies, procedures, and standards. Learn how clear procedures help your team stay aligned, efficient, and audit-ready. - [Defining roles and responsibilities effectively](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/defining-roles-and-responsibilities-effectively/): Discover how to define roles and responsibilities that boost clarity, accountability, and team performance across your organization. - [Confidently communicate internal control metrics to your board](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/how-do-you-communicate-internal-control-metrics-to-your-board/): Learn how to communicate internal control metrics effectively to your board. Get tips on reporting, visuals, and insights that improve oversight and decision-making. - [Empower your information security policy with effective employee training](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/information-security-policy-implementation-the-extensive-role-of-employee-training/): Discover expert tips to create a strong information security policy. Protect your data, ensure compliance, and build a secure digital environment today. - [The evolution of Acceptable Use Policies: Adapting to modern workplace challenges](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/the-evolution-of-acceptable-use-policies-adapting-to-modern-workplace-challenges/): Discover how acceptable use policies are evolving to meet modern workplace needs. Learn how to create effective, compliant, and user-friendly policies today. - [Create powerful policies with these best practices](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/policy-best-practices/): Discover how to build strong, actionable policies that support governance, reduce risk, and keep your organization compliant with these proven best practices. - [Are the terms of service the same as the master service agreement?](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/are-the-terms-of-service-the-same-as-the-master-service-agreement/): The distinctions between Terms of Service and Master Service Agreements are significant, each serving distinct purposes and catering to different aspects of service and business relationships. - [Mastering data classification: Essential policies for compliance and risk management in 2026](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/data-classification-policies-and-their-role-in-regulatory-compliance-and-risk-management/): Discover how strong data classification policies help manage risk and meet compliance goals. Learn to protect sensitive data with clear, effective practices. - [External tests](https://community.trustcloud.ai/docs/trustops/controls/testing-controls/external-tests/): External tests are only available as custom tests & are associated with a control or the system. - [Powerful role of board of directors: Unlock strategic SOC 2 compliance advantage](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/the-role-of-board-of-directors-in-soc-2-compliance-necessity-or-strategic-advantage/): Discover how a powerful board of directors drives SOC 2 compliance, enhances risk management, and secures a strategic advantage for your organization. - [Excluding a Control, Test or Resource](https://community.trustcloud.ai/docs/trustops/controls/excluding-a-control-test-or-resource/): The exclusion allows you to remove certain resources, controls or tests from your program that may not apply to your business environment. Excluding a control, test or resource is made easy with TrustOps! - [Importance of contract agreement in supplier-vendor relationship](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/importance-of-contract-agreement-in-supplier-vendor-relationship/): Learn why a clear contract agreement is essential in supplier and vendor partnerships. Reduce risk, ensure accountability, and build lasting business relationships. - [Tasks](https://community.trustcloud.ai/docs/trustops/tasks/): Tasks is a project management feature in TrustOps to help you achieve organizational compliance goals easily. - [Controls](https://community.trustcloud.ai/docs/trustops/controls/): A control is a process for an organization to prevent a potential risk from affecting its business. In TrustCloud, controls are the foundational building blocks of the compliance program. - [Unlock robust vulnerability management for cybersecurity excellence](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/robust-vulnerability-management-practices-unlocking-cybersecurity-excellence/): Discover best practices for effective vulnerability management. Learn how to identify, assess, and remediate security gaps to boost resilience and compliance. - [The crucial role of supplier audit services in mitigating business risks](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/the-crucial-role-of-supplier-audit-services-in-mitigating-business-risks/): By conducting thorough supplier audits, you can gain valuable insights into your suppliers' operations, processes, and practices, enabling you to identify potential vulnerabilities, compliance issues, and areas for improvement. - [Enterprise Risk Management (ERM): A comprehensive guide to strategic risk oversight](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/enterprise-risk-management-erm-a-comprehensive-guide-to-strategic-risk-oversight/): Explore how enterprise risk management strengthens decision-making, improves resilience, and aligns risk with strategy. A must-read guide for proactive business leaders. - [Mastering enterprise risk management: A comprehensive guide](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/mastering-enterprise-risk-management-a-comprehensive-guide/): Learn how to build a modern enterprise risk management framework, identify and mitigate key risks, strengthen resilience, and align ERM with strategy for long-term growth. - [​​Mastering risk assessment: Prioritize and strengthen your risk management strategy](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/mastering-risk-assessment-prioritize-and-strengthen-your-risk-management-strategy/): Learn how to master risk assessment and make confident, data-driven decisions. Prioritize threats, strengthen resilience, and build a smarter risk strategy today. - [Risks and consequences of irresponsible AI in organizations: the hidden dangers](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/risks-and-consequences-of-irresponsible-ai-in-organizations-the-hidden-dangers/): Learn how to prevent the risks of irresponsible AI and adopt responsible AI practices. Build ethical, transparent, and trusted systems that protect your business. - [Data privacy compliance challenges: navigating the regulatory landscape](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/data-privacy-compliance-challenges-navigating-the-regulatory-landscape/): Overcome today’s data privacy compliance challenges with a clear strategy. Learn how to navigate regulations confidently and protect your organization’s data. - [Everything about security awareness training](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/everything-about-security-awareness-training/): Learn how effective security awareness training protects your organization from threats. Discover smart strategies to educate teams and strengthen cybersecurity culture. - [Master penetration testing with powerful tips for choosing the right type](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/what-type-of-pen-testing-is-required/): Learn how to choose the right type of penetration testing for your business. Explore expert tips to meet compliance, reduce risk, and strengthen cybersecurity. - [Choose the right security officer to protect your business](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/who-should-be-assigned-the-security-officer-role-in-your-organization/): Learn how to assign the right security officer in your organization to boost protection, ensure compliance, and lead your cybersecurity strategy effectively. - [Build a successful governance program that drives impact](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/what-does-a-successful-governance-program-look-like/): Discover what makes a governance program successful. Learn how to define roles, set policies, and create accountability that strengthens your organization’s growth. - [Risk Management](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/): Learn more about how effective risk management offers the potential to reduce both the possibility of a risk occurring and its potential impact. - [Apr-Jun 2025](https://community.trustcloud.ai/docs/changelogs/trustcommunity/apr-jun-2025/): 6 new TrustTalks (podcasts) in the month of April 2025 - [Apr-Jun 2025](https://community.trustcloud.ai/docs/changelogs/full-platform/apr-jun-2025/): A bug where a TypeError was thrown when opening a newly created vendor assessment without refreshing the page - [Apr-Jun 2025](https://community.trustcloud.ai/docs/changelogs/trustcloud/apr-jun-2025/): A bug that caused test runs to end up in an unfinished state - [Apr-Jun 2025](https://community.trustcloud.ai/docs/changelogs/trustlens/apr-jun-2025/): A bug where a TypeError was thrown when opening a newly created vendor assessment without refreshing the page - [Apr-Jun 2025](https://community.trustcloud.ai/docs/changelogs/trustregister/apr-jun-2025/): A bug when importing the risk register from the template - [Apr-Jun 2025](https://community.trustcloud.ai/docs/changelogs/trustshare/apr-jun-2025/): Import with large number of segments was not working - [Apr-Jun 2025](https://community.trustcloud.ai/docs/changelogs/trustops/apr-jun-2025/): A bug fix in the inventory evidence flow - [Top 4 must-know risk assessment methodologies you need to follow with examples](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/top-4-must-know-risk-assessment-methodologies-you-need-to-follow-with-examples/): Explore the top 4 risk assessment methodologies with real-world examples. Learn how to choose and apply the right method to improve clarity, control, and compliance. - [Unlock automation for streamlined vulnerability management](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/the-role-of-automation-in-streamlining-vulnerability-management-policies-for-modern-enterprises/): Revolutionize vulnerability management with automation for modern enterprises. Discover real-time scanning, risk prioritization, and compliance wins that cut threats and boost efficiency across your IT landscape. - [Unlock growth with powerful SLA compliance strategies](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/mastering-sla-compliance-unlocking-the-key-to-business-success/): Explore proven strategies to achieve SLA compliance. Strengthen client trust, boost service delivery, and drive sustainable business success. - [Supercharge success with smart risk management policies](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/mastering-risk-management-policies-building-a-resilient-business-for-success/): Unlock the power of effective risk management policies. Build a resilient business, reduce threats, and drive success with proven compliance strategies. - [Confidently choose your SOC 2 trust service criteria](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/which-soc-2-trust-service-criteria-are-applicable-to-my-organization/): After assessing an organization's controls against the selected Trust Service Criteria, independent auditors issue SOC 2 reports. These reports provide valuable insights to customers, stakeholders, and regulatory bodies about the effectiveness of an organization's controls in safeguarding data and ensuring operational integrity. - [Top HIPAA violations to avoid for patient trust](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/10-critical-hipaa-violations-to-avoid-protecting-patient-privacy/): Discover 10 common HIPAA violations and how to avoid them. Stay compliant, protect patient data, and build trust with your healthcare organization. - [Powerful ways blockchain boosts compliance in 2026](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/blockchain-and-compliance-ensuring-transparency-and-security-in-2024/): Explore how blockchain technology enhances compliance with unmatched transparency, trust, and security for your business in 2026 and beyond. - [Ultimate guide to global data privacy laws for businesses](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/global-data-privacy-laws-a-comprehensive-guide-for-businesses/): Stay compliant with global data privacy laws in 2025. Explore this clear, expert-written guide for businesses navigating GDPR, CCPA, and beyond. - [Powerful change management policy strategies for smooth growth](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/crafting-an-effective-change-management-policy-key-components-and-strategies/): Unlock seamless organizational change with a smart change management policy. Learn key components and winning strategies to lead transformation effectively. - [Strengthen internal controls with smart segregation of duties](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/why-is-segregation-of-duties-an-important-concept/): Learn how segregation of duties prevents fraud, strengthens accountability, and supports compliance. Discover best practices to build secure and trustworthy workflows. - [Unlock expert security with powerful vCISO services](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/vciso-101-learning-everything-about-virtual-chief-information-security-officers/): Discover how vCISO services deliver seasoned security leadership, flexible expertise, and compliance support—without the full-time cost. Learn more. - [Define your SOC 2 audit scope](https://community.trustcloud.ai/docs/grc-launchpad/soc-2/define-your-soc-2-audit-scope/): Learn how to define the right SOC 2 audit scope. Identify critical systems, services, and controls for a streamlined and successful audit experience. - [Organization](https://community.trustcloud.ai/docs/trustcloud/organization/): The Organization page in TrustCloud provides an interactive and structured way to define, visualize, and manage an organization’s GRC (Governance, Risk, and Compliance) structure. - [Risk assessment methodology](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/risk-assessment-methodology/): Discover a step-by-step risk assessment methodology to identify, evaluate, and manage risks effectively. Improve resilience and make smarter, data-driven decisions. - [Notifications](https://community.trustcloud.ai/docs/trustregister/settings/settings-and-notifications/): TrustRegister provides a structured and transparent way to track risk activities, assignments, and due dates. - [Everything about anonymous reporting lines](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/everything-about-anonymous-reporting-lines/): Learn how anonymous reporting lines promote trust, protect whistleblowers, and support a strong compliance culture. Explore best practices for secure reporting. - [Risk culture in organizations: fostering a proactive approach to challenges](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/risk-culture-in-organizations-fostering-a-proactive-approach-to-challenges/): Discover how to strengthen your organization’s risk culture. Learn strategies to empower teams, improve decision-making, and foster proactive responses to challenges. - [Powerful risk mitigation strategies with AI for success](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/risk-mitigation-strategies-the-role-of-artificial-intelligence-in-enhancements/): Discover how artificial intelligence transforms risk mitigation strategies. Learn how to reduce threats, improve accuracy, and build a proactive, data-driven GRC program. - [Effective compliance management: stay ahead of the game with a proactive approach](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/effective-compliance-management-stay-ahead-of-the-game-with-a-proactive-approach/): Taking a proactive approach to compliance management is crucial for organizations in today's complex regulatory environment. By being proactive, organizations can stay ahead of the game, protecting themselves from the risks of non-compliance and fostering a culture of ethical behaviour and trust. - [Risk management policy: mastering power of risk in continuous improvement](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/risk-management-policy-mastering-power-of-risk-in-continuous-improvement/): Explore how a strong risk management policy drives continuous improvement, boosts resilience, and aligns risk practices with business success. A must-read for modern leaders. - [Boost your security with a powerful pen test strategy](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/pen-testing-overview/): Learn what a pen test is, why it matters, and how it can uncover hidden vulnerabilities. Discover expert strategies to protect your systems and boost resilience. - [Top API security practices to protect your data now](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/how-do-you-maintain-api-security-and-why-is-it-important/): Discover essential API security best practices. Learn how to protect sensitive data, reduce breaches, and ensure compliance in your digital infrastructure. - [Unlock essential SOC 2 tools for a winning and stress-free audit](https://community.trustcloud.ai/docs/grc-launchpad/soc-2/essential-soc-2-tools-controls-what-you-actually-need-for-a-successful-audit/): Discover the powerful tools and controls that make your SOC 2 audit smooth and successful. Streamline compliance, enhance security, and maintain continuous monitoring with the right strategies. - [Effective risk prevention strategies: Proactive measures for business resilience](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/effective-risk-prevention-strategies-proactive-measures-for-business-resilience/): Discover effective risk prevention strategies that protect your business, reduce disruptions, and boost long-term resilience. Take proactive steps to secure success. - [A step-by-step guide to controls remediation planning](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/a-step-by-step-guide-to-controls-remediation-planning/): Learn how to create an effective controls remediation planning strategy. Follow step-by-step guidance to fix control gaps, strengthen compliance, and reduce risk. - [Navigating Controls Remediation: Best Practices and Case Studies](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/navigating-controls-remediation-best-practices-and-case-studies/): Learn how to approach controls remediation with confidence. Discover proven strategies and case studies to fix gaps, stay compliant, and strengthen risk controls. - [The basics of penetration testing: mastering the essentials](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/the-basics-of-penetration-testing-mastering-the-essentials/): Unlock the basics of penetration testing to strengthen your cybersecurity. Learn powerful techniques and tools to detect, prevent, and reduce threats. - [XFA](https://community.trustcloud.ai/docs/trustcloud/integrations/device-management/xfa/): By granting XFA limited access to metadata through an API integration, you can ensure that your systems remain compliant with your adopted controls. - [Assessment In Progress](https://community.trustcloud.ai/docs/trustshare/questionnaires/questionnaires-in-progress/): On the Assessments in Progress page, you can upload a new assessment and see a list of all of the previously uploaded or in-progress assessments. - [Who should be a risk owner?](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/who-should-be-a-risk-owner/): Discover who should be a risk owner and why it matters. Learn how assigning the right person improves accountability, supports compliance, and strengthens risk management. - [GDPR Overview and Guides](https://community.trustcloud.ai/docs/grc-launchpad/gdpr-overview-and-guides/): GDPR ensures that all personal data is collected in a secure and legal manner with proper consent from the users. - [ISO 27701 Overview and Guides](https://community.trustcloud.ai/docs/grc-launchpad/iso-27701-overview-and-guides/): Explore essential strategies for implementing ISO 27701, the global standard for Privacy Information Management Systems. Learn how to enhance data privacy and align with regulations like GDPR in 2025. - [Powerful data-driven compliance for smarter risk control](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/data-driven-compliance-leveraging-analytics-for-effective-risk-management/): Discover how data-driven compliance improves risk management. Learn to leverage analytics for smarter, faster, and more confident compliance decisions. - [NIST SP 800-171 Overview and Guides](https://community.trustcloud.ai/docs/grc-launchpad/nist-sp-800-171-overview-and-guides/): Unlock smooth NIST SP 800-171 compliance. Explore key controls, steps, and tips to build a stronger cybersecurity posture with confidence. - [Unleash powerful PHI protection: Secure sensitive health data easily](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/demystifying-the-phi-protected-health-information-a-comprehensive-guide-to-protecting-sensitive-data/): Discover how to protect PHI effectively with this comprehensive guide—understand what counts as sensitive health information, learn practical safeguards, and build stronger compliance strategies. - [Essential step-by-step guide to reporting HIPAA violations](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/reporting-hipaa-violations-a-step-by-step-guide/): Follow this clear, actionable guide to reporting HIPAA violations, protecting patient privacy, and ensuring compliance with legal safeguards. - [HIPAA security policy template for healthcare compliance](https://community.trustcloud.ai/docs/trustops/helpful-resources/hipaa-security-program-policy-template/): Download a ready-to-use HIPAA Security Program Policy Template. Ensure compliance, protect PHI, and simplify audits with this essential healthcare document. - [Badge access system template for physical security](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/badge-access-system-template/): Download a customizable badge access system template to enhance physical security, manage access control, and meet compliance requirements effectively. - [Protect your business with smart control over unmonitored downloads](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/what-are-the-dangers-of-unmonitored-downloads/): Unmonitored downloads can expose your organization to malware, data loss, and compliance risks. Learn how to manage and reduce these threats with smart controls. - [Why a vulnerability management policy is critical in 2026](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/vulnerability-management-policy-the-crucial-role-in-enhancing-cybersecurity-defence/): Learn why a strong vulnerability management policy is key to reducing cyber risk, improving defenses, and staying compliant with security standards in 2025. - [How to choose a trusted third-party assessment company for stronger compliance (expert guide)](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/how-do-i-choose-a-third-party-assessment-company/): Learn how to choose the right third‑party assessment company by evaluating expertise, methodology, credentials, and industry fit to boost compliance confidence. - [Third-party risk management: How to go from reactive to proactive](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/from-reactive-to-proactive-the-future-of-third-party-risk-management/): Stop reacting to vendor risks after they happen. Learn how proactive third-party risk management helps you predict, prevent, and control threats before they impact your business. - [Create a secure BYOD policy: template and best practices for 2025](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/bring-your-own-device-byod-policy/): Download a free BYOD security policy template and learn best practices to manage employee-owned devices. Ensure secure, compliant use of personal devices at work. - [SOC 2 Type 2 compliance checklist: Step-by-step guide for 2026](https://community.trustcloud.ai/docs/trustops/helpful-resources/soc-2-type-2-checklist/): Get your organization SOC 2 Type 2 audit-ready with this easy-to-follow checklist. Learn what evidence you need, which controls to focus on, and how to pass your next audit confidently. - [How to report on risks effectively: best practices for risk reporting](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/how-do-you-report-on-risks-effectively/): Effective risk reporting is an essential component of organizational governance and decision-making. Managers, stakeholders, and board members rely on well-structured reports to gain insights into potential threats and opportunities. - [SOC 2 audit checklist: steps, documents, and tips to pass your audit](https://community.trustcloud.ai/docs/grc-launchpad/soc-2/soc2-audit-checklist/): Prepare for a successful SOC 2 audit with this actionable checklist covering key steps, documentation, and common readiness gaps to avoid delays. - [Integrating ERM with GRC: Powerful strategies for smarter decisions](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/integrating-erm-with-grc-for-strategic-decision-making/): Unlock powerful ERM and GRC integration techniques for strategic decision-making. Strengthen your risk management process in %currentyear%. Learn how today! - [Treatment plans and tasks](https://community.trustcloud.ai/docs/trustregister/mitigation-and-treatment-plans/treatment-plans-and-tasks/): Treatment plans and tasks are components that outline strategies and specific actions to address and manage identified risks. - [Acceptable use policy guidelines: how to create and enforce one effectively](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/crafting-an-effective-acceptable-use-policy-guidelines-and-considerations/): Learn how to write an acceptable use policy that protects your business and employees. Get actionable guidelines, real-world examples, and a downloadable template. - [ISO 27001:2022 vs ISO 27001:2013 – which version should your business follow?](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/choosing-between-iso-270012013-and-iso-270012022/): Discover the main differences between ISO 27001:2022 and ISO 27001:2013. Understand new controls, transition, and which version better fits your compliance needs. - [Risk categories](https://community.trustcloud.ai/docs/trustregister/risk-details/risk-categories/): The flexibility to define both standard and custom risk categories, such as financial, operational, security, vendor, fraud, brand, strategic, and legal risks, ensures that all potential threats are systematically addressed. - [Risk subcategories](https://community.trustcloud.ai/docs/trustregister/risk-details/risk-subcategories/): Risks can be further divided into subcategories to make risk management easier and more precise. They are specific classifications or breakdowns of broader risk categories. - [Cloud GRC best practices: 8 strategies for secure & compliant operations](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/reshaping-grc-in-the-cloud-era-8-best-practices-for-secure-and-compliant-operations/): Discover 8 essential cloud GRC best practices to enhance security, ensure compliance, and streamline operations in 2025. Learn how to adapt your governance strategies for the cloud era. - [Setting up TrustRegister](https://community.trustcloud.ai/docs/trustregister/risk-register/setting-up-trustregister/): TrustRegister, a TrustCloud application, allows users to create and manage a risk register efficiently. Users can either start a new register or import an existing one. - [Creating a Risk](https://community.trustcloud.ai/docs/trustregister/risk-register/creating-a-risk/): While creating a risk in TrustRegister, it should be named clearly and briefly so anyone can understand what the risk is. - [Unlock powerful ISO 27001:2022 changes for compliance success](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/navigate-the-changes-between-iso-270012013-and-iso-270012022/): Understand the key differences between ISO 27001:2013 and ISO 27001:2022. This guide breaks down control changes, structure updates, and what your team must do to stay compliant. - [Privacy and confidentiality: what is the difference?](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/privacy-and-confidentiality-what-is-the-difference/): Discover the essential difference between privacy and confidentiality. Learn how both concepts impact data protection, compliance, and trust in your organization. - [Elevate your governance strategy: Mastering GRC for stronger business success](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/mastering-grc-integrating-governance-risk-and-compliance-for-business-success/): Learn how to integrate governance, risk, and compliance into a single GRC framework, improve decision-making, reduce risk, and drive sustainable business growth in 2026 and beyond. - [How to establish KPIs for risk management: a step-by-step guide](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/how-do-i-establish-kpis/): Discover how to establish KPIs that align with business goals. Learn best practices to track progress, improve outcomes, and build a performance-driven culture. - [Avoid costly mistakes: master your compliance scope now](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/what-is-a-scope/): Learn what a scope is in compliance, how to define it, and why it’s crucial for audits, certifications, and effective risk management. - [PCI DSS vs. PCI SAQ: Understanding the key differences and choosing the right compliance path](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/pci-dss-vs-pci-saq-understanding-the-key-differences-and-choosing-the-right-compliance-path/): Discover the differences between PCI DSS and PCI SAQ, and learn how to choose the right compliance path for your business's payment security needs. - [Integrating ESG into GRC: Strategies for sustainable compliance in 2026](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/integrating-esg-into-grc-strategies-for-sustainable-compliance/): Discover how integrating Environmental, Social, and Governance (ESG) factors into Governance, Risk, and Compliance (GRC) frameworks enhances sustainable compliance and meets evolving regulatory demands in 2025. - [When audit results in adverse findings](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/adverse-findings/): The response to adverse findings should be proactive, transparent, and comprehensive. It's essential to demonstrate a commitment to resolving the issues and preventing them from recurring in the future. - [Compliance gaps and their effective remediation techniques](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/compliance-gaps-and-effective-remediation-techniques/): Compliance gaps, the difference between what an organization is currently doing and what is required, can lead to significant financial, legal, and operational consequences. - [Risk completion status](https://community.trustcloud.ai/docs/trustregister/risk-details/risk-completion-status/): "Completion Status" in TrustRegister helps teams and stakeholders understand the current state of each identified risk and the progress in managing or mitigating those risks. - [Strategic compliance management: aligning business objectives with regulatory requirements](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/strategic-compliance-management-aligning-business-objectives-with-regulatory-requirements/): Strategic compliance management is a proactive and forward-thinking approach that positions compliance as a strategic asset rather than a mere obligation. - [Powerful fraud analytics strategies for confident detection](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/uncovering-fraud-with-data-analytics-a-modern-approach/): Learn how modern data analytics uncovers fraud in real time. Explore four powerful techniques, pattern recognition, anomaly detection, real-time monitoring, and predictive models. - [Modern internal audits: How to build a scalable, risk-aligned audit function](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/internal-audit-function-future-proof-strategies-for-long-term-success/): Learn how to build an internal audit function that adapts to regulatory change, mitigates risk, and drives long-term business value. Discover key frameworks, tools, and best practices. - [Which regulations have high penalties for non-compliance?](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/which-regulations-have-high-penalties-for-non-compliance/): In this article, we will explore which regulations have high penalties for non-compliance, empowering businesses to understand and prioritize their compliance efforts. - [How to implement a change management policy that supports compliance and reduces risk](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/implementing-a-change-management-policy-for-smooth-transitions/): Learn how to design and implement a change management policy that aligns with compliance goals and minimizes business risk. A practical guide for GRC teams. - [Empower your business: Master GDPR’s 7 data protection principles effortlessly](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/mastering-gdpr-a-comprehensive-guide-to-data-protection-principles/): Unlock GDPR mastery with our guide to the 7 data protection principles—lawfulness, minimization, accuracy & more. Avoid fines up to 4% of revenue, ensure compliance, and build trust using TrustCloud tools. - [Security Settings](https://community.trustcloud.ai/docs/trustcloud/platform-administration/security-settings/): “Security Settings” functionality bolster data protection measures by proactively managing user sessions. - [Branding](https://community.trustcloud.ai/docs/trustcloud/platform-administration/branding/): Branding page offers a pivotal opportunity to shape the TrustCloud program's identity in alignment with the organization's branding strategy. - [Employee settings](https://community.trustcloud.ai/docs/trustcloud/employees/employee-settings/): Employee settings in TrustCloud are the settings for your overall employee workflows. - [Authentication](https://community.trustcloud.ai/docs/trustcloud/platform-administration/authentication/): By configuring authentication settings, administrators can control who has permission to log in and access sensitive information. - [Opening a TrustCloud Customer Support Ticket](https://community.trustcloud.ai/docs/trustcloud/support/opening-a-support-ticket/): You can open a TrustCloud support ticket using one of the following methods: - [Employees](https://community.trustcloud.ai/docs/trustcloud/employees/): Employees are an essential part of security, privacy, and compliance. Without involvement from your employees and contractors, maintaining a secure organization is nearly impossible. - [Platform Capabilities](https://community.trustcloud.ai/docs/trustcloud/platform-capabilities/): We believe GRC should be a profit center, our goal is to empower our customers with joyfully crafted tools that make this vision a reality. - [Overview](https://community.trustcloud.ai/docs/trustcloud/overview/): TrustCloud® is a Trust Assurance Platform designed for startups, SMBs, and enterprises to achieve, share, and verify their trust obligations with customers. - [Support](https://community.trustcloud.ai/docs/trustcloud/support/): The articles outline the current TrustCloud customer support process. - [Support for Slack](https://community.trustcloud.ai/docs/trustcloud/support/opening-a-support-ticket/support-for-slack/): If you are using our Slack app and run into challenges, please send us an email at support@trustcloud.ai describing your problem. - [Free Tier Customers](https://community.trustcloud.ai/docs/trustcloud/support/free-tier-customers/): As a free tier customer, you have limited access to support. You can still ask questions in forums and read the documentation in TrustCloud’s TrustCommunity! - [Non-Self-Service Requests](https://community.trustcloud.ai/docs/trustcloud/support/opening-a-support-ticket/handling-non-self-service-requests/): TrustCloud helps in handling Non-Self-Service Requests related to your TrustCloud program. These are non-bug, non-feature request tasks that you need help with. This article will identify the most common requests and explain how to handle them by creating a TrustCloud customer support ticket. - [My Account](https://community.trustcloud.ai/docs/trustcloud/my-account/): The "My Account" page in TrustCloud is your personal portal for managing profile details, notification settings, and security preferences.  - [What to include in your support ticket](https://community.trustcloud.ai/docs/trustcloud/support/opening-a-support-ticket/what-to-include-in-your-support-ticket/): If you encounter a new problem after the initial problem has been solved, then please open a new ticket to represent that issue. - [ISO Standards and their Internal Audit (IA) requirements](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/iso-standards-and-their-internal-audit-ia-requirements/): ISO Standards and their Internal Audit (IA) requirement article talks about the organizations preparing for an ISO 27001 stage 1 and stage 2 audit. - [Privacy committee charter template](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/privacy-committee-charter-template/): Privacy Committee Charter serves as a foundational document, establishing the framework for the committee's operations, and guiding its members in carrying out their roles effectively. - [Vendor Management](https://community.trustcloud.ai/docs/trustops/controls/vendor-management/): Vendor Management is the process of ensuring that the use of service providers and Information Technology (IT) suppliers does not create an unacceptable potential risk for business or on business performance. - [Vulnerability Management](https://community.trustcloud.ai/docs/trustops/controls/vulnerability-management/): Vulnerability Management is the ongoing, continuous process of identifying, evaluating, and remediating vulnerabilities in internal systems and across all endpoints. - [Risk Management](https://community.trustcloud.ai/docs/trustops/controls/risk-management/): Risk Assessment is the process of identifying and analyzing potential events that may negatively impact an organization's assets and/or the environment. - [Data Management](https://community.trustcloud.ai/docs/trustops/controls/data-management/): Data management is the practice of collecting, organizing, protecting, and storing an organization’s data for analysis and business decision-making purposes. - [Incident Management](https://community.trustcloud.ai/docs/trustops/controls/incident-management/): Compliance frameworks highlight the importance of a strong incident management process to identify, triage, resolve, and report incidents. - [Communications Management](https://community.trustcloud.ai/docs/trustops/controls/communications-management/): Communication management is the process of planning, executing, monitoring, and improving communication processes within an organization. - [Governance](https://community.trustcloud.ai/docs/trustops/controls/governance/): The governance typically involves defining the company mission, values, and goals, and sharing those with all employees. - [Helpful Resources](https://community.trustcloud.ai/docs/trustops/helpful-resources/): A curated list of helpful toolkits to help organizations in their compliance journeys! - [Physical Security](https://community.trustcloud.ai/docs/trustops/controls/physical-security/): Physical security consists of security measures in place to protect personnel, hardware, software, networks, and data from physical actions and events that could cause serious loss to an organization. - [Custom Frameworks](https://community.trustcloud.ai/docs/trustops/custom-frameworks/): TrustCloud supports several standards and frameworks out of the box, including SOC 2, CMMC, and ISO 9001, to name a few. The best part is that TrustCloud is constantly adding new frameworks to expand the TrustCloud Common Control Framework (TCCCF). - [Scopes](https://community.trustcloud.ai/docs/trustops/scopes/): Scopes are the specific boundaries and focus areas of an audit. It outlines the extent and limits of the audit, including the controls, policies, systems, assets, and locations to be reviewed, the processes or areas within the organization to be examined, and the specific objectives to be achieved. - [Change management procedure template – download for free](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/change-management-procedure-template-download-for-free/): Change Management Procedure Template helps document and standardize the change management process across different systems within your business landscape. - [Encryption Management](https://community.trustcloud.ai/docs/trustops/controls/encryption-management/): Encryption is a process that uses algorithms to encode data and make it unreadable to unauthorized users. Encryption helps protect the data that is sent, received, and stored. - [Logical Access](https://community.trustcloud.ai/docs/trustops/controls/logical-access/): Logical Access processes and controls are in place to restrict access to data. It consists of identification, authentication, and authorization. - [Why are Master Service Agreements (MSA) required for security compliance?](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/why-are-master-service-agreements-msa-required-for-security-compliance/): Master Service Agreements help reduce legal risks, protect your organization's interests, and ensure that both parties in a business relationship understand and agree to the terms and conditions under which they will work together. - [Change Management](https://community.trustcloud.ai/docs/trustops/controls/change-management/): Change Management is a systematic approach to planning and implementing changes in an organization. - [Asset Management](https://community.trustcloud.ai/docs/trustops/controls/asset-management/): Asset management is the systematic process of developing, operating, maintaining, upgrading, and disposing of assets in the most cost-effective manner. - [Host hardening documentation: a comprehensive guide](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/host-hardening-documentation-a-comprehensive-guide/): Host hardening documentation is an essential tool in demonstrating an organization's commitment to security, ensuring compliance with regulations, and aiding in vulnerability assessments, making it a central request during audits. - [What are common controls and why do you need one?](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/what-are-common-controls-and-why-do-you-need-one/): Implementing common controls helps organizations build trust with stakeholders and maintain a secure and compliant operational environment. - [Discover the vital role of a compliance officer today](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/compliance-officer-role-explained-responsibilities-skills-career-path/): Learn how a compliance officer drives legal and ethical success by navigating regulations, training teams, and safeguarding your organization’s integrity. - [GRC explained: Key concepts and tools every business should know](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/what-are-the-basics-of-grc/): Get a clear understanding of Governance, Risk, and Compliance (GRC). Learn how GRC frameworks, tools, and real-world use cases apply to modern businesses. - [Who is a third-party vendor, a subprocessor and a third-party supplier?](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/risk-management/who-is-a-third-party-vendor-a-subprocessor-and-a-third-party-supplier/): Understand the key differences between a third-party vendor, subprocessor, and supplier. Learn how to manage vendor risks and strengthen compliance with clarity. - [Groups in Controls](https://community.trustcloud.ai/docs/trustops/controls/groups-in-controls/): TrustCloud provides you with a comprehensive set of controls to get certified against several out of the box standards. Adding a group to a control will help you identify which part of your business owns what controls, identify risks, and drive action through group owners. - [Mapping a Control](https://community.trustcloud.ai/docs/trustops/controls/mapping-a-control/): TrustCloud’s common controls framework maps a comprehensive set of certified standards controls and your custom controls to get certified against several out-of-the-box standards. - [Sharing Controls with customers](https://community.trustcloud.ai/docs/trustops/controls/sharing-controls-with-customers/): The TrustShare application in TrustCloud makes it easy for startups, SMBs, and enterprises to securely invite and share their trust and compliance program with their customers, including information about their controls. - [TrustCloud Common Controls Framework (TCCCF)](https://community.trustcloud.ai/docs/trustops/controls/tcccf/): The TCCCF is a set of comprehensive controls developed based on common requirements from various industry security and privacy frameworks, such as NIST, ISO, SOC, and HITRUST. - [Adopting Controls](https://community.trustcloud.ai/docs/trustops/controls/adopting-controls/): In TrustOps, you can filter controls on their status. Status can be "Adopted", "Planned" and "All". - [Audit Dashboard](https://community.trustcloud.ai/docs/trustops/audit-dashboard/): Audit dashboards in TrustOps help you visualize your readiness for the specific compliance standard. - [TrustOps](https://community.trustcloud.ai/docs/trustops/): With TrustOps, achieve audit-readiness for multiple infosec and data security, privacy, and governance standards simultaneously. - [Overview](https://community.trustcloud.ai/docs/trustops/overview/): TrustOps is designed for startups, SMBs, and enterprises to achieve and maintain adherence to multiple compliance standards. - [Risk threshold](https://community.trustcloud.ai/docs/trustregister/settings/risk-threshold/): The risk threshold refers to the predefined level of risk that an organization is willing to accept or tolerate. - [Settings and Notifications](https://community.trustcloud.ai/docs/trustregister/settings/): TrustCloud has enabled a Risk Settings page so that users can modify their Risk settings to match their organizations needs. Below you will find the different settings that will empower you to make your TrustRegister your own. - [Risk Reporting Groups](https://community.trustcloud.ai/docs/trustregister/settings/risk-reporting-groups/): Risk reporting groups typically refer to categorizations or classifications used to organize and present risks based on certain criteria. - [Risk subcategories](https://community.trustcloud.ai/docs/trustregister/settings/risk-subcategories/): Subcategories provide a more detailed classification of risks, allowing for a granular understanding of the specific types of risks that an organization may encounter. - [Risk categories](https://community.trustcloud.ai/docs/trustregister/settings/risk-categories/): Risk categories are essential for organizing and managing the diverse risks an organization may encounter. These classifications, which can be customized in TrustRegister, enhance understanding, targeted risk management, and effective communication. - [Impact](https://community.trustcloud.ai/docs/trustregister/impact/): The “Impact” page in TrustRegister gives you an overview of the overall risk impact for each of the reporting groups. - [General settings](https://community.trustcloud.ai/docs/trustregister/settings/general-settings/): The “General Settings” tab allows customers to switch between a ‘Very High to Very Low’ scoring mode and a ‘0-100%’ percentage-based scoring mode. - [Treatment types](https://community.trustcloud.ai/docs/trustregister/mitigation-and-treatment-plans/treatment-types/): Treatment types refer to the various approaches or strategies that organizations use to address and manage identified risks. - [Residual risk](https://community.trustcloud.ai/docs/trustregister/mitigation-and-treatment-plans/residual-risk/): Residual risk is a key measure of risk before or after treatment or mitigation efforts have been applied. It indicates how much progress has been made towards reducing the risk an organization faces.  - [Treating risks](https://community.trustcloud.ai/docs/trustregister/mitigation-and-treatment-plans/treating-risks/): Treating risks is made easy with TrustRegister. The "Treatment Plan" tab in TrustRegister is designed to outline strategies and actions to manage identified risks. - [Controls vs treatment plans](https://community.trustcloud.ai/docs/trustregister/mitigation-and-treatment-plans/controls-vs-treatment-plans/): The balance between controls and treatment plans can be set with TrustRegister. - [Residual risk scoring](https://community.trustcloud.ai/docs/trustregister/mitigation-and-treatment-plans/residual-risk-scoring/): Residual risk scoring is the final frontier in the risk management continuum, encapsulating the enduring uncertainties within a project. - [Advanced risk breakdown – CIA](https://community.trustcloud.ai/docs/trustregister/assessments/advanced-risk-breakdown-cia/): The advanced risk breakdown gives you the option to input your risk impact using the Confidentiality, Integrity, and Accessibility (CIA) triad. - [Assessments](https://community.trustcloud.ai/docs/trustregister/assessments/): The Assessments tab in TrustRegister provides crucial insights into each identified risk, detailing the assessment process, impact evaluation, and likelihood determination. - [Assigning and managing risk owners](https://community.trustcloud.ai/docs/trustregister/risk-details/assigning-and-managing-risk-owners/): "Risk Owners" are pivotal figures assigned to navigate potential threats. These individuals take ownership of specific risks, ensuring accountability and proactive management. - [Inherent risk](https://community.trustcloud.ai/docs/trustregister/assessments/inherent-risk/): Inherent risk is a key measure of risk before any treatment or mitigation efforts have been applied. It indicates how badly an organization would be impacted if a risk were to materialize and offers a baseline understanding of the problem.  - [Conducting risk assessments](https://community.trustcloud.ai/docs/trustregister/assessments/conducting-risk-assessments/): The significance of conducting risk assessments with the help of TrustRegister is about exploring how this proactive strategy empowers project teams to anticipate, analyze, and mitigate risks effectively. - [Next Assessment Date](https://community.trustcloud.ai/docs/trustregister/assessments/next-assessment-date/): Risk assessments are not static; they need to be periodically revisited to ensure that the information remains current and that any changes in the risk landscape are captured. - [Target Risk Level (Optional)](https://community.trustcloud.ai/docs/trustregister/assessments/target-risk-level-optional/): Target Risk Level is a key measure of the risk after treatment or mitigation efforts have been applied. This value allows you to set an acceptable target value for your risk, with the primary purpose being risk forecasting. - [Inherent Risk Scoring](https://community.trustcloud.ai/docs/trustregister/assessments/inherent-risk-scoring/): By assessing the inherent risks associated with a project, teams can lay a strong foundation for proactive risk mitigation strategies. - [Risk by groups (Departments)](https://community.trustcloud.ai/docs/trustregister/risk-details/risk-by-groups-departments/): Risk by groups are departments, business functions, units, or specialized teams in your organization. Risks can be tagged and viewed by organizational groups, such as departments. - [Assessment summary](https://community.trustcloud.ai/docs/trustregister/assessments/assessment-summary/): The assessment summary is an outline of how the risk was assessed, along with any relevant details that will help determine its impact and likelihood. - [Financial impact of risk](https://community.trustcloud.ai/docs/trustregister/assessments/financial-impact-of-risk/): Understanding the financial impact of risk is paramount to effective risk management within the context of a risk register. - [High Level Risk Definitions](https://community.trustcloud.ai/docs/trustregister/risk-register/high-level-risk-definitions/): High level risk definitions for TrustRegister provide a clear and accessible overview of key risk terminologies. They simplify complex risk concepts, ensuring a common understanding across teams. - [Tiers](https://community.trustcloud.ai/docs/trustlens/tiers/): With tiers, you can define the business information required, the specific type of assessment to send, and the necessary data to collect. - [How do I determine the scope of an audit?](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/how-do-i-determine-the-scope-of-an-audit/): Determining the scope of an audit is a critical step that sets the foundation for a successful and valuable audit engagement. By considering key factors, following best practices, and leveraging appropriate tools and techniques, auditors can define a scope that aligns with the organization's objectives, addresses potential risks, and meets stakeholder expectations. - [Jan-Mar 2025](https://community.trustcloud.ai/docs/changelogs/full-platform/jan-mar-2025/): A bug when editing a vendor tier - [Jan-Mar 2025](https://community.trustcloud.ai/docs/changelogs/trustcommunity/jan-mar-2025/) - [Jan-Mar 2025](https://community.trustcloud.ai/docs/changelogs/trustcloud/jan-mar-2025/): User with 'Employee' role was not able to view 'My Account' page - [Jan-Mar 2025](https://community.trustcloud.ai/docs/changelogs/trustlens/jan-mar-2025/): Vendor bulk import was updated - [Jan-Mar 2025](https://community.trustcloud.ai/docs/changelogs/trustregister/jan-mar-2025/): An improvement to TrustRegister loading time - [Jan-Mar 2025](https://community.trustcloud.ai/docs/changelogs/trustshare/jan-mar-2025/) - [Jan-Mar 2025](https://community.trustcloud.ai/docs/changelogs/trustops/jan-mar-2025/): An issue while adding product management evidence - [Standard vs Framework vs Laws vs Regulations](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/standard-vs-framework-vs-laws-vs-regulations/): Standard vs Framework vs Laws vs Regulations talks about the detailed difference between these four. - [What are PHI and ePHI in healthcare data security? – Understanding the distinction](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/what-are-phi-and-ephi-in-healthcare-data-security-understanding-the-distinction/): By following best practices for handling and storing PHI and ePHI, healthcare organizations can minimize the risk of data breaches and protect the privacy and security of patient information. - [Cross-functional collaboration in internal audits: A path to enhanced value](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/cross-functional-collaboration-in-internal-audits-a-path-to-enhanced-value/): Cross-functional collaboration in internal audits is not merely a best practice; it is a strategic imperative for organizations seeking to enhance the value derived from their audit processes. - [Security Incident Report Template](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/security-incident-report-template/): The Security Incident Report template helps you document the steps used to assess and respond to a security event. - [Compliance certification vs attestation: what is the difference?](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/compliance-certification-vs-attestation-what-is-the-difference/): Compliance Certification vs Attestation - Certification is a qualification that is recognized by an accredited body. An attestation is an opinion from the auditors on the state of your compliance program. - [Unlock innovative internal audit trends for smarter compliance](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/internal-audit-innovations-trends-and-transformations/): Discover the latest trends and transformations in internal audits to enhance compliance, foster innovation, and boost organizational efficiency. - [ISO 42001 – Overview and Guides](https://community.trustcloud.ai/docs/grc-launchpad/iso-42001-overview-and-guides/): At TrustCloud we fulfill all your compliance needs to implement ISO 42001 compliance and achieve certification to the standard. - [PCI DSS – Overview and Guides](https://community.trustcloud.ai/docs/grc-launchpad/pci-dss-overview-and-guides/): PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment. - [Compliance vs. ethics: what is the difference and why it matters](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/compliance-vs-ethics-what-is-the-difference-and-why-it-matters/): By fostering a culture that seamlessly integrates both compliance and ethics, businesses can build a strong foundation of trust, enhance their reputation, and position themselves for long-term success. - [The future of SLAs: Are we measuring what matters?](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/the-future-of-slas-are-we-measuring-what-matters/): Embracing the forward-thinking approach to SLAs is not just a choice; it's a necessity for businesses that strive to stay ahead in an increasingly competitive and customer-centric market. - [Heightened Regulatory Scrutiny: How to Meet Compliance Demands](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/heightened-regulatory-scrutiny-how-to-meet-compliance-demands/): Organizations of all sizes are facing heightened regulatory scrutiny. From data privacy regulations to industry-specific compliance requirements, the regulatory landscape has become increasingly complex and demanding. - [Implementing responsible AI in organizations: a step-by-step guide](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/how-is-responsible-ai-shaping-the-next-generation-of-tech-solutions/): By following the steps outlined in this guide, you can navigate the complexities of AI implementation while upholding ethical principles and fostering a culture of responsibility within your organization. - [Demystifying HITRUST vs. HIPAA: unraveling the distinctions](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/demystifying-hitrust-vs-hipaa-unraveling-the-distinctions/): As you navigate the complexities of HITRUST and HIPAA, it is essential to carefully evaluate your organization's unique needs, risk profile, and operational requirements. - [Data Retention And Disposal Policy](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/data-retention-and-disposal-policy/): A data retention and disposal policy adds value to an organization by ensuring compliance with legal and regulatory requirements, thereby avoiding fines and legal issues. - [List of tools and services for your NIST 800-171](https://community.trustcloud.ai/docs/grc-launchpad/nist-sp-800-171-overview-and-guides/list-of-tools-and-services-for-your-nist-800-171/): A list of tools and services for your NIST 800-171 is curated to showcase the possible purchases required for your NIST 800-171 preparation. - [ISMS template – Download for free](https://community.trustcloud.ai/docs/trustops/helpful-resources/iso-standards-documentation-templates/isms-template-download-for-free/): The Information Security Management System (ISMS) and Privacy Management System (PIMS) policy is a high-level document that outlines an organization’s commitment to information security and privacy. - [Privacy policy template – free download](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/privacy-policy-template/): Download the Privacy Policy Template here. - [LOG-13 File Integrity Monitoring (FIM)](https://community.trustcloud.ai/docs/trustops/controls/system-monitoring/log-13-file-integrity-monitoring-fim/): File Integrity Monitoring (FIM) is a type of change auditing that verifies and validates files by comparing the latest versions of them to a known, trusted "baseline". - [Inclusive governance: fostering diversity in decision-making](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/inclusive-governance-fostering-diversity-in-decision-making/): Inclusive governance is vital for fostering diversity in decision-making. By embracing inclusivity, organizations can capitalize on a wide range of perspectives and contribute to a more equitable future. - [LOG-3 centralized logging](https://community.trustcloud.ai/docs/trustops/controls/system-monitoring/log-3-centralized-logging/): Centralized Logging is a vital part of enterprise monitoring. Utilize a centralized monitoring tool to collect, analyze, predict, and report on system issues, such as performance issues. - [SOC 2 Section 3 Template](https://community.trustcloud.ai/docs/trustops/helpful-resources/soc-2-section-3-template/): An important part of the SOC 2 preparation is the draft of the section 3 by the service organization. Section 3 includes important information regarding the people, processes, and technology that support your product or service. - [PCI DSS FAQ](https://community.trustcloud.ai/docs/grc-launchpad/pci-dss-overview-and-guides/pci-dss-faq/): Here are the most frequently asked questions about PCI DSS compliance. - [TrustCloud PCI DSS audit partners](https://community.trustcloud.ai/docs/grc-launchpad/pci-dss-overview-and-guides/trustcloud-pci-dss-audit-partners/): PCI DSS audit partners are organizations authorized by the PCI Security Standards Council to conduct compliance audits on behalf of merchants and service providers. - [HITRUST FAQ](https://community.trustcloud.ai/docs/grc-launchpad/hitrust-overview-and-guides/hitrust-faq/): Here are the most frequently asked questions about HITRUST certification. - [ISO 42001 FAQ](https://community.trustcloud.ai/docs/grc-launchpad/iso-42001-overview-and-guides/iso-42001-faq/): Here are some of the frequently asked questions about ISO 42001. - [TrustCloud ISO 42001 audit partners](https://community.trustcloud.ai/docs/grc-launchpad/iso-42001-overview-and-guides/trustcloud-iso-42001-audit-partners/): TrustCloud’s ISO 42001 Audit Partners is a pool of CPA audit firms to help provide a joyfully crafted audit experience. - [Vendor offboarding checklist](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/vendor-offboarding-checklist/): The Vendor Offboarding Checklist template helps you document the steps used to successfully offboard a vendor. Download the Vendor Offboarding Checklist here. - [Essential compliance management trends for future success](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/the-future-of-compliance-management-trends-shaping-2024-and-beyond/): From the increasing use of artificial intelligence and data analytics to the rising focus on ethical and sustainable business practices, the future of compliance management promises to be a dynamic and transformative one. - [The impact of AI on corporate governance: opportunities and challenges](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/the-impact-of-ai-on-corporate-governance-opportunities-and-challenges/): As AI continues to reshape the business landscape, its integration into corporate governance represents a paradigm shift in governance practices. - [Oct-Dec 2024](https://community.trustcloud.ai/docs/changelogs/trustlens/oct-dec-2024/): Fixed a bug affecting the population of the Risk Surface section - [Oct-Dec 2024](https://community.trustcloud.ai/docs/changelogs/trustops/oct-dec-2024/): Ability to add evidence or run a self assessment directly from a task. - [Oct-Dec 2024](https://community.trustcloud.ai/docs/changelogs/trustshare/oct-dec-2024/): Fixed a question caching issue - [Oct-Dec 2024](https://community.trustcloud.ai/docs/changelogs/trustregister/oct-dec-2024/): Fixed a UI bug in bulk actions - [Oct-Dec 2024](https://community.trustcloud.ai/docs/changelogs/trustcloud/oct-dec-2024/): Fix for the 'Business Risk Changes' tests. - [Oct-Dec 2024](https://community.trustcloud.ai/docs/changelogs/full-platform/oct-dec-2024/): Ability to add evidence or run a self assessment directly from a task. - [Oct-Dec 2024](https://community.trustcloud.ai/docs/changelogs/trustcommunity/oct-dec-2024/) - [Jul-Sep 2024](https://community.trustcloud.ai/docs/changelogs/trustcommunity/jul-sep-2024/): The video on Policy attestations - [Apr-Jun 2024](https://community.trustcloud.ai/docs/changelogs/trustcommunity/apr-jun-2024/) - [Jan-Mar 2024](https://community.trustcloud.ai/docs/changelogs/trustcommunity/jan-mar-2024/) - [Supply chain management compliance: addressing ethical and legal standards](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/supply-chain-management-compliance-addressing-ethical-and-legal-standards/): Companies must implement comprehensive supply chain management compliance programs, conduct regular audits and assessments, promote collaboration and transparency, and leverage technology. - [Disciplinary action form template – Download for free](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/disciplinary-action-form-template/): Download the Disciplinary Action Form Template here. - [Board committee charter template – Download for free](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/board-committee-charter-template-download-for-free/): A board committee charter template helps you document the roles and responsibilities of all board members. Download the template from here. - [Align security and compliance to your business goals](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/align-security-and-compliance-to-your-business-goals/): In the ever-evolving landscape of modern enterprises, achieving synergy between compliance, security, and business goals is no longer an option but a necessity. - [PS-8 – Badge Access System](https://community.trustcloud.ai/docs/trustops/controls/physical-security/ps-8-badge-access-system/): The badge access control system is configured to log successful and unsuccessful activity traceable to individual cardholders. - [GRC 101](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/): Driven by three terms, GRC stands for Governance, Risk management, and Compliance! It is a compass that guides organizations through the complexities of modern business, ensuring they stay on course, mitigate risks, and operate ethically for fundamental and long-term success. - [Vulnerability Management Policy](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/vulnerability-management-policy/): A vulnerability management policy is a formal document outlining an organization's approach to identifying, assessing, and mitigating security vulnerabilities within its IT infrastructure. - [FAQ](https://community.trustcloud.ai/docs/trustshare/faq/): Read the most frequently asked questions about TrustShare. - [Setting up Single Sign-on for your TrustCloud](https://community.trustcloud.ai/docs/trustcloud/platform-administration/setting-up-single-sign-on-for-your-trustcloud/): Single Sign-on is invaluable in the modern digital landscape, providing a secure and user-friendly method for accessing multiple applications and websites with a single set of credentials. - [Google Workspace](https://community.trustcloud.ai/docs/trustcloud/integrations/identity-management/google-workspace/): This document outlines the steps you can take to grant TrustCloud access to only read metadata about the configuration settings for your Google Workspace account and Google Workspace users. - [CUST-11 Release notifications](https://community.trustcloud.ai/docs/trustops/controls/change-management/cust-11-release-notifications/): Release notifications control: Following the deployment of major features, it is vital to notify the internal and external stakeholders of the feature deployment. - [List of tools and services for your ISO 27701](https://community.trustcloud.ai/docs/grc-launchpad/iso-27701-overview-and-guides/list-of-tools-and-services-for-your-iso-27701/): A List of tools and services for your ISO 27701 preparation is curated to showcase the possible purchases required for the preparation. The implementation of some controls requires the purchase and implementation of tools or services. - [AUTH-1 Single Sign On (SSO)](https://community.trustcloud.ai/docs/trustops/controls/logical-access/auth-1-single-sign-on-sso/): Single Sign On (SSO) Control is a best practice recommendation for critical systems. - [List of tools and services for your NIST CSF](https://community.trustcloud.ai/docs/grc-launchpad/nist-csf/nist-csf-toolkit-list-of-tools-and-services-for-your-nist-csf/): The list of tools and services for your NIST CSF is curated to showcase the possible purchases required for your NIST CSF preparation. - [Host Hardening Template](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/host-hardening-template/): The host hardening template helps document the hardening configuration for all IT infrastructure used within your environment. - [Patch Management Process Template](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/patch-management-process-template/): The Patch Management Process template helps document the detailed process required to implement patches across all systems within your environment. - [Define your HIPAA Audit Scope](https://community.trustcloud.ai/docs/grc-launchpad/hipaa/define-your-hipaa-audit-scope/): Determining your HIPAA audit scope requires your organization to specify the product, the data, the systems, vendors, and type of scope. - [INFRA-5 Firewalls](https://community.trustcloud.ai/docs/trustops/controls/vulnerability-management/infra-5-firewalls/): Firewalls are a network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules. - [PDP-2 Restore Testing](https://community.trustcloud.ai/docs/trustops/controls/business-recovery/pdp-2-restore-testing/): PDP-2 – Restore Testing control ensures that the organization can retrieve backup data on a regular basis. - [HR-12 Organizational structure](https://community.trustcloud.ai/docs/trustops/controls/governance/hr-12-organizational-structure/): HR-12 organizational structure, or organizational chart control, demonstrates the hierarchy within the organization and helps employees understand their position in the organization. - [HR-13 Employee Handbook/Code of Conduct](https://community.trustcloud.ai/docs/trustops/controls/governance/hr-13-employee-handbook/): HR-13 Employee Handbook or Code of Conduct communicates the organization’s values and ethics. It lets employees know the acceptable code of conduct. It is a must to document an employee handbook with a code of conduct and update it every year. - [Audit Logging Policy](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/audit-logging-policy/): An audit logging policy is a set of guidelines and procedures that govern the recording and monitoring of events and activities within an organization's systems and networks. - [PRIV-13 Data Protection Impact Assessment](https://community.trustcloud.ai/docs/trustops/controls/privacy/priv-13-data-protection-impact-assessment/): Data Protection Impact Assessments (DPIA) are performed prior to any major new projects to assess privacy risks. - [HR-7 Disciplinary Process](https://community.trustcloud.ai/docs/trustops/controls/governance/hr-7-disciplinary-process/): HR-7 Disciplinary Process makes sure of the appeal and enforces corrective actions in response to employee misconduct, rule violations, or poor performance. - [Workday](https://community.trustcloud.ai/docs/trustcloud/integrations/hr-systems/workday/): Set up Workday for automated tests with TrustCloud! This document outlines the steps you can take to grant TrustCloud access to only read metadata about the configuration settings for your Workday account. - [VNDR-1 Inventory and Classification](https://community.trustcloud.ai/docs/trustops/controls/vendor-management/vndr-1-inventory-and-classification/): Inventory and Classification control talks about good compliance hygiene and a compliance requirement to track all your vendors and third parties with whom you conduct business. - [GRC Launchpad](https://community.trustcloud.ai/docs/grc-launchpad/): Explore our GRC launchpad to gain expertise on numerous compliance standards and topics. - [PRIV-15 Data Collection Tracking](https://community.trustcloud.ai/docs/trustops/controls/privacy/priv-15-data-collection-tracking/): The company limits the collection of personal data to only what is identified in the privacy notice, and implements processes to track and minimize its usage. - [Paylocity](https://community.trustcloud.ai/docs/trustcloud/integrations/hr-systems/paylocity/): This document outlines the steps you can take to grant TrustCloud access to only read metadata about the configuration settings for your Paylocity account so that TrustOps can validate and generate evidence for your compliance program. - [Getting Started – TrustCloud Customers](https://community.trustcloud.ai/docs/auditlens/getting-started-trustcloud-customers/): The “Audit Dashboard” page is where you can enable AuditLens and manage auditor access. To access the “Audit Dashboard” page, you simply need to select the Audits icon from your left navigation bar.  - [BIZOPS-30 Information Security Management System](https://community.trustcloud.ai/docs/trustops/controls/governance/bizops-30-information-security-management-system/): BIZOPS-30 Information Security Management System Control asks for high-level documentation that explains how the organization addresses the ISO requirements. - [INFRA-9 Vulnerability Scanning](https://community.trustcloud.ai/docs/trustops/controls/vulnerability-management/infra-9-vulnerability-scanning/): Vulnerability scanning is the process of identifying security weaknesses and flaws in systems and the software running on them. - [HR Systems](https://community.trustcloud.ai/docs/trustcloud/integrations/hr-systems/): HR Systems help organizations manage their core HR processes like payroll, employee benefits, etc. - [PRIV-23 Sensor Data Collection and Usage](https://community.trustcloud.ai/docs/trustops/controls/privacy/priv-23-sensor-data-collection-and-usage/): Embedded sensor systems such as cameras and radars are in place to collect data for notified individuals. The data is used minimally and for explicitly authorized purposes. - [Buildkite](https://community.trustcloud.ai/docs/trustcloud/integrations/ci-cd/buildkite/): Set up Buildkite for automated tests with TrustCloud! - [HR-6 Termination Process](https://community.trustcloud.ai/docs/trustops/controls/logical-access/hr-6-termination-process/): The termination process is a crucial part of any Logical Access process. It talks about how all privileged accounts should be managed and monitored. - [AUTH-11 Password Configurations](https://community.trustcloud.ai/docs/trustops/controls/logical-access/auth-11-password-configurations/): Password Configurations are an important part of the Logical Access process. A password policy is a configuration of a set of attributes that an administrator defines from the documented policy and implements on all organizational resources. - [PDP-1 Backup plan](https://community.trustcloud.ai/docs/trustops/controls/data-management/pdp-1-backup-plan/): A data backup plan is the process of evaluating what data will be backed up, identifying the tools and techniques for backing up the data and defining the frequency and recovery of the backups. - [Kandji](https://community.trustcloud.ai/docs/trustcloud/integrations/device-management/kandji/): This document outlines the steps you can take to grant TrustCloud access to only read metadata about the configuration settings for your Kandji account so that TrustOps can validate and generate evidence for your compliance program. - [Comprehensive Employee Handbook Template](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/employee-handbook-template-2/): A Comprehensive Employee Handbook template helps document the essential elements of an effective employee handbook. - [Define your NIST CSF Audit Scope](https://community.trustcloud.ai/docs/grc-launchpad/nist-csf/define-your-nist-csf-audit-scope/): Define your NIST CSF Audit Scope to set the boundaries of the audit and identify the object in focus. The object can include the people, data, system, or product in review. - [Demystifying attestation of compliance: a comprehensive guide for businesses](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/demystifying-attestation-of-compliance-a-comprehensive-guide-for-businesses/): In this comprehensive guide, we will demystify the concept of attestation of compliance and provide you with the knowledge you need to navigate the world of data security. - [How to implement an ISMS in your organization](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/governance/how-to-implement-an-isms-in-your-organization/): Implementing an Information Security Management System (ISMS) is crucial for organizations to protect their sensitive information, comply with regulations, enhance operational efficiency, and build trust with stakeholders. - [Authentication And Password Policy](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/authentication-and-password-policy/): An authentication and password policy is a set of rules and guidelines that define the requirements and best practices for user authentication and password management within an organization's IT environment. - [PDP-15 Agile process](https://community.trustcloud.ai/docs/trustops/controls/change-management/pdp-15-agile-process/): PDP-15 Agile Process addresses the need to respond to changes quickly, change management is agile. It is important to document how your organization is using the Agile process. - [IT-12 System Inventory](https://community.trustcloud.ai/docs/trustops/controls/asset-management/it-12-system-inventory/): For IT-12 System Inventory control, it is recommended that you frequently perform a system inventory to detect any unauthorized or non-monitored systems. - [IT-3 Workstations – Malware](https://community.trustcloud.ai/docs/trustops/controls/asset-management/it-3-workstations-malware/): Workstations malware control talks about how both your software and hardware must be protected from potential threats. - [IT-10 Remote Access](https://community.trustcloud.ai/docs/trustops/controls/logical-access/it-10-remote-access/): Remote Access control ensures that your organization has implemented secure measures for remote access to your organization’s sensitive information. - [Container Image Registry](https://community.trustcloud.ai/docs/trustcloud/integrations/container-image-registry/): The Container Image Registry is a Docker container registry that makes it easy to store, share, and deploy container images. - [Getting Started](https://community.trustcloud.ai/docs/trustcloud-api/guides/getting-started/): This guide walks you through getting started with the TrustCloud API. - [BIZOPS-21 Cyber Insurance](https://community.trustcloud.ai/docs/trustops/controls/business-recovery/bizops-21-cyber-insurance/): Cyber insurance protects your organization in the event of a data breach or other impact that negatively affects the company. - [Decoding RegTech: how regulatory technology is transforming compliance efforts](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/decoding-regtech-how-regulatory-technology-is-transforming-compliance-efforts/): RegTech is a game-changer in the realm of compliance, offering innovative solutions to navigate the complex landscape of regulatory requirements. - [The ultimate guide to designing effective technology controls in IT security frameworks: ensuring security and compliance](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/the-ultimate-guide-to-designing-effective-technology-controls-in-it-security-frameworks-ensuring-security-and-compliance/): Designing and implementing technology controls is a meticulous process that requires a deep understanding of the organization's IT environment and the prevailing threat landscape. This involves selecting appropriate controls that align with the identified risks and integrating them seamlessly into existing systems and processes. - [IRIS HR](https://community.trustcloud.ai/docs/trustcloud/integrations/hr-systems/iris-hr/): This document outlines the steps you can take to grant TrustCloud access to only read metadata about the configuration settings for your IRIS HR account so that TrustOps can validate and generate evidence for your compliance program. - [AUTH-5 User Access Reviews](https://community.trustcloud.ai/docs/trustops/controls/logical-access/auth-5-user-access-reviews/): User Access Reviews are a way to check and verify that users have the correct level of access to systems, applications, and data based on their job role. - [Background Check](https://community.trustcloud.ai/docs/trustcloud/integrations/background-check/): Background Check is a system that manages background screening for employees. - [LOG-8 – User Behaviors Analytics (UBA)](https://community.trustcloud.ai/docs/trustops/controls/system-monitoring/log-8-user-behaviors-analytics-uba/): User Behavior Analytics (UBA) control is about having a process in place to gather insights into the network events that users generate and analyze the events to detect the use of compromised credentials, lateral movement, and other malicious behaviour. - [PS-11 – Clear Desk Policy – PII](https://community.trustcloud.ai/docs/trustops/controls/physical-security/ps-11-clear-desk-policy-pii/): Implementing the PS-11 clear desk policy control is of utmost importance in maintaining information security and protecting sensitive data within an organization. - [PRIV-34 Automated Decision-Making](https://community.trustcloud.ai/docs/trustops/controls/privacy/priv-34-automated-decision-making/): Management has established procedures for identifying and documenting obligations to data subjects around PII processing based on automated decision-making. - [VNDR-10 Vendor Off-boarding](https://community.trustcloud.ai/docs/trustops/controls/vendor-management/vndr-10-vendor-off-boarding/): The Vendor Off-boarding process ensures that contractual obligations are fulfilled and any sensitive data is destroyed. - [APPS-3 Static Code Analysis](https://community.trustcloud.ai/docs/trustops/controls/vulnerability-management/apps-3-static-code-analysis/): Static code analysis is a method of examining source code before a program is run. This is a best practice usually performed as part of the code review process. - [PDP-11 SDLC – Security Reviews](https://community.trustcloud.ai/docs/trustops/controls/change-management/pdp-11-sdlc-security-reviews/): PDP-11 SDLC - Security Reviews talks about each change undergoing a security review. - [DATA-17 Data Disposal](https://community.trustcloud.ai/docs/trustops/controls/data-management/data-17-data-disposal/): Data disposal is the process of securely disposing of information from your system either physically (degaussing, shredding, etc.) or electronically (overwriting, sanitizing, etc.) at its end of life. - [Vendor Onboarding Due Diligence](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/vendor-onboarding-due-diligence/): The Vendor Onboarding Due Diligence Template helps you document the due diligence process you undertake when you bring on new vendors. Download the Vendor Onboarding Due Diligence here. - [Preparing for a self-attestation of NIST CSF](https://community.trustcloud.ai/docs/grc-launchpad/nist-csf/how-to-get-started-with-nist-csf/preparing-for-a-self-attestation-of-nist-csf/): Preparing for a self-attestation of NIST CSF involves no certification by a third-party assessor; however, the preparation process is the same as when preparing for meeting any other compliance requirements. - [DATA-5 Key Management](https://community.trustcloud.ai/docs/trustops/controls/encryption-management/data-5-key-management/): DATA-5 Key Management control is about how your organization handles the generation, exchange, storage, use, replacement, and protection of keys by only authorized personnel. - [Risk Management Policy](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/risk-management-policy/): A risk management policy is a formal document that outlines an organization's approach to identifying, assessing, mitigating, and monitoring risks across its operations. - [Change Management Policy](https://community.trustcloud.ai/docs/trustops/helpful-resources/documentation-templates/change-management-policy/): To use a change management policy template effectively, customize it to fit your organization's specific change management processes, procedures, and regulatory requirements.