---
title: Truvantis Blog | John MacInnis
description: Insights on Cybersecurity, Privacy and Compliance best practices from our industry experts. Topics include Penetration Testing, PCI DSS v4.0.1 Compliance and Risk Management.
---

[![truvantis-logo-reverse@2x](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-reverse@2x.png?width=1117&height=250&name=truvantis-logo-reverse@2x.png "truvantis-logo-reverse@2x")](https://www.truvantis.com)

[![truvantis-logo-main@2x-1](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-main@2x-1.png?width=1117&height=250&name=truvantis-logo-main@2x-1.png "truvantis-logo-main@2x-1")](https://www.truvantis.com/)

**

# Blog

### Subscribe For Updates

### Recent Posts

#### Related Articles By Topic

[Security Program](https://www.truvantis.com/blog/tag/security-program) [vCISO](https://www.truvantis.com/blog/tag/vciso) [CISO](https://www.truvantis.com/blog/tag/ciso) [PCI DSS](https://www.truvantis.com/blog/tag/pci-dss) [SOC2](https://www.truvantis.com/blog/tag/soc2) [Penetration Testing](https://www.truvantis.com/blog/tag/penetration-testing) [Privacy](https://www.truvantis.com/blog/tag/privacy) [Risk Assessment](https://www.truvantis.com/blog/tag/risk-assessment) [CIS Controls](https://www.truvantis.com/blog/tag/cis-controls) [Red Teaming](https://www.truvantis.com/blog/tag/red-teaming) [HIPAA](https://www.truvantis.com/blog/tag/hipaa) [Threat Intelligence](https://www.truvantis.com/blog/tag/threat-intelligence) [ISO27001](https://www.truvantis.com/blog/tag/iso27001) [CCPA](https://www.truvantis.com/blog/tag/ccpa) [CPRA](https://www.truvantis.com/blog/tag/cpra) [GDPR](https://www.truvantis.com/blog/tag/gdpr) [Ransomware](https://www.truvantis.com/blog/tag/ransomware) [Red Team](https://www.truvantis.com/blog/tag/red-team) [HITRUST](https://www.truvantis.com/blog/tag/hitrust)

### Related Articles By Topic

- [Security Program (76)](https://www.truvantis.com/blog/tag/security-program)
- [vCISO (38)](https://www.truvantis.com/blog/tag/vciso)
- [CISO (35)](https://www.truvantis.com/blog/tag/ciso)
- [PCI DSS (28)](https://www.truvantis.com/blog/tag/pci-dss)
- [SOC2 (28)](https://www.truvantis.com/blog/tag/soc2)
- [Penetration Testing (27)](https://www.truvantis.com/blog/tag/penetration-testing)
- [Privacy (26)](https://www.truvantis.com/blog/tag/privacy)
- [Risk Assessment (19)](https://www.truvantis.com/blog/tag/risk-assessment)
- [CIS Controls (12)](https://www.truvantis.com/blog/tag/cis-controls)
- [Red Teaming (8)](https://www.truvantis.com/blog/tag/red-teaming)
- [HIPAA (7)](https://www.truvantis.com/blog/tag/hipaa)
- [Threat Intelligence (7)](https://www.truvantis.com/blog/tag/threat-intelligence)
- [ISO27001 (6)](https://www.truvantis.com/blog/tag/iso27001)
- [CCPA (5)](https://www.truvantis.com/blog/tag/ccpa)
- [CPRA (2)](https://www.truvantis.com/blog/tag/cpra)
- [GDPR (2)](https://www.truvantis.com/blog/tag/gdpr)
- [Ransomware (2)](https://www.truvantis.com/blog/tag/ransomware)
- [Red Team (2)](https://www.truvantis.com/blog/tag/red-team)
- [HITRUST (1)](https://www.truvantis.com/blog/tag/hitrust)

[See all](https://www.truvantis.com/blog/author/john-macinnis#)

[CIS Controls](https://www.truvantis.com/blog/tag/cis-controls), [Security Program](https://www.truvantis.com/blog/tag/security-program)

## [Surviving Password Manager Data Breach](https://www.truvantis.com/blog/surviving-password-manager-data-breach)

 How your defense-in-depth strategy protected you from the LastPass data breach Most of us like using password managers for the security and user convenience. Password managers gave us a way to adhere to ever more complex password rules without having to keep track of them for 

[Read More **](https://www.truvantis.com/blog/surviving-password-manager-data-breach)

<https://www.truvantis.com/blog/tips-for-managing-the-risks-of-merges-acquisition> <https://www.truvantis.com/blog/tips-for-managing-the-risks-of-merges-acquisition>

[Threat Intelligence](https://www.truvantis.com/blog/tag/threat-intelligence)

### [Tips for Managing the Risks of Merges & Acquisition](https://www.truvantis.com/blog/tips-for-managing-the-risks-of-merges-acquisition)

 Along with the benefits of capabilities and growth, mergers and acquisitions add new risks to your attack surface. Managing M&A risk should be part of your organization's overall risk management program. Mergers and acquisitions (M&As) are a 

[Read More **](https://www.truvantis.com/blog/tips-for-managing-the-risks-of-merges-acquisition)

<https://www.truvantis.com/blog/why-did-the-dod-introduce-an-updated-zero-trust-cybersecurity-framework> <https://www.truvantis.com/blog/why-did-the-dod-introduce-an-updated-zero-trust-cybersecurity-framework>

[Threat Intelligence](https://www.truvantis.com/blog/tag/threat-intelligence)

### [Why did the DoD Introduce an updated Zero Trust Cybersecurity Framework](https://www.truvantis.com/blog/why-did-the-dod-introduce-an-updated-zero-trust-cybersecurity-framework)

 The concept of 'Zero Trust, ' which essentially presumes conventional perimeter protections don't exist, has been in cybersecurity for many years. Driven by the evolving threat landscape as well as maturing defensive frameworks, on November 22, 

[Read More **](https://www.truvantis.com/blog/why-did-the-dod-introduce-an-updated-zero-trust-cybersecurity-framework)

<https://www.truvantis.com/blog/soc-2-perils-and-pitfalls> <https://www.truvantis.com/blog/soc-2-perils-and-pitfalls>

[SOC2](https://www.truvantis.com/blog/tag/soc2), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [SOC 2 Perils and Pitfalls](https://www.truvantis.com/blog/soc-2-perils-and-pitfalls)

 Congratulations, product development was successful, and you have the utmost confidence in the capabilities of your new product or service. Engineering has assured you that the necessary controls are in place for secure operation. Sales demos are 

[Read More **](https://www.truvantis.com/blog/soc-2-perils-and-pitfalls)

<https://www.truvantis.com/blog/ddos-for-the-holidays> <https://www.truvantis.com/blog/ddos-for-the-holidays>

[Threat Intelligence](https://www.truvantis.com/blog/tag/threat-intelligence)

### [DDoS for the Holidays](https://www.truvantis.com/blog/ddos-for-the-holidays)

 Many find the holidays season exciting because they can relax, spend time with family and friends, and celebrate traditions. Additionally, most businesses have plenty to celebrate throughout the holidays since they usually have higher sales and 

[Read More **](https://www.truvantis.com/blog/ddos-for-the-holidays)

<https://www.truvantis.com/blog/the-five-step-adaptable-risk-based-privacy-program> <https://www.truvantis.com/blog/the-five-step-adaptable-risk-based-privacy-program>

[Security Program](https://www.truvantis.com/blog/tag/security-program), [Privacy](https://www.truvantis.com/blog/tag/privacy)

### [The Five-Step Adaptable Risk-based Privacy Program](https://www.truvantis.com/blog/the-five-step-adaptable-risk-based-privacy-program)

 In today's data-driven economy, an organization's data is its most valuable asset. The landscape of privacy regulations is vast and continuously evolving, forcing organizations to select and track applicable requirements for collecting and managing 

[Read More **](https://www.truvantis.com/blog/the-five-step-adaptable-risk-based-privacy-program)

<https://www.truvantis.com/blog/scoping-your-isms-for-iso-27001-compliance> <https://www.truvantis.com/blog/scoping-your-isms-for-iso-27001-compliance>

[Security Program](https://www.truvantis.com/blog/tag/security-program), [ISO27001](https://www.truvantis.com/blog/tag/iso27001)

### [Scoping Your ISMS for ISO 27001 Compliance](https://www.truvantis.com/blog/scoping-your-isms-for-iso-27001-compliance)

 The ISO 27001 standard provides requirements for establishing, implementing, maintaining and continually improving your Information Security Management System (ISMS) within the context of your organization. Your ISMS includes the people, processes 

[Read More **](https://www.truvantis.com/blog/scoping-your-isms-for-iso-27001-compliance)

<https://www.truvantis.com/blog/pentesting-for-pci-dss> <https://www.truvantis.com/blog/pentesting-for-pci-dss>

[PCI DSS](https://www.truvantis.com/blog/tag/pci-dss), [Penetration Testing](https://www.truvantis.com/blog/tag/penetration-testing)

### [Pentesting for PCI DSS](https://www.truvantis.com/blog/pentesting-for-pci-dss)

 Most industry-recognized security frameworks, including HITRUST, CIS Controls and PCI DSS, stipulate penetration testing requirements as part of an organization's risk management cycle. In addition, the Payment Card Industry Security Standards 

[Read More **](https://www.truvantis.com/blog/pentesting-for-pci-dss)

<https://www.truvantis.com/blog/the-board-vs.-security-privacy-programs> <https://www.truvantis.com/blog/the-board-vs.-security-privacy-programs>

[CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [The Board vs. Security & Privacy Programs](https://www.truvantis.com/blog/the-board-vs.-security-privacy-programs)

 In a corporation, the board is ultimately accountable to the shareholders for managing risks, including cybersecurity and privacy risk. Therefore, the need to address cybersecurity and privacy risk is generally accepted. However, there is often a 

[Read More **](https://www.truvantis.com/blog/the-board-vs.-security-privacy-programs)

<https://www.truvantis.com/blog/combined-risk-management-for-security-privacy-and-compliance> <https://www.truvantis.com/blog/combined-risk-management-for-security-privacy-and-compliance>

[Privacy](https://www.truvantis.com/blog/tag/privacy)

### [Combined Risk Management for Security, Privacy and Compliance](https://www.truvantis.com/blog/combined-risk-management-for-security-privacy-and-compliance)

 Privacy regulations boil down to protecting information. In other words, privacy is about the security of data. The various privacy rights can be traced back to core security principles defined by NIST as Confidentiality, Integrity, and Availability 

[Read More **](https://www.truvantis.com/blog/combined-risk-management-for-security-privacy-and-compliance)

[Next](https://www.truvantis.com/blog/author/john-macinnis/page/2)

## John MacInnis

### Recent Posts

<https://www.truvantis.com/blog/ddos-for-the-holidays> <https://www.truvantis.com/blog/ddos-for-the-holidays>

[Threat Intelligence](https://www.truvantis.com/blog/tag/threat-intelligence)

### [5 DDoS for the Holidays](https://www.truvantis.com/blog/ddos-for-the-holidays)

 Many find the holidays season exciting because they can relax, spend time with family and friends, and celebrate traditions. Additionally, most ... 

[Read More **](https://www.truvantis.com/blog/ddos-for-the-holidays)

<https://www.truvantis.com/blog/the-five-step-adaptable-risk-based-privacy-program> <https://www.truvantis.com/blog/the-five-step-adaptable-risk-based-privacy-program>

[Security Program](https://www.truvantis.com/blog/tag/security-program), [Privacy](https://www.truvantis.com/blog/tag/privacy)

### [6 The Five-Step Adaptable Risk-based Privacy Program](https://www.truvantis.com/blog/the-five-step-adaptable-risk-based-privacy-program)

 In today's data-driven economy, an organization's data is its most valuable asset. The landscape of privacy regulations is vast and continuously ... 

[Read More **](https://www.truvantis.com/blog/the-five-step-adaptable-risk-based-privacy-program)

<https://www.truvantis.com/blog/scoping-your-isms-for-iso-27001-compliance> <https://www.truvantis.com/blog/scoping-your-isms-for-iso-27001-compliance>

[Security Program](https://www.truvantis.com/blog/tag/security-program), [ISO27001](https://www.truvantis.com/blog/tag/iso27001)

### [7 Scoping Your ISMS for ISO 27001 Compliance](https://www.truvantis.com/blog/scoping-your-isms-for-iso-27001-compliance)

 The ISO 27001 standard provides requirements for establishing, implementing, maintaining and continually improving your Information Security ... 

[Read More **](https://www.truvantis.com/blog/scoping-your-isms-for-iso-27001-compliance)

<https://www.truvantis.com/blog/pentesting-for-pci-dss> <https://www.truvantis.com/blog/pentesting-for-pci-dss>

[PCI DSS](https://www.truvantis.com/blog/tag/pci-dss), [Penetration Testing](https://www.truvantis.com/blog/tag/penetration-testing)

### [8 Pentesting for PCI DSS](https://www.truvantis.com/blog/pentesting-for-pci-dss)

 Most industry-recognized security frameworks, including HITRUST, CIS Controls and PCI DSS, stipulate penetration testing requirements as part of ... 

[Read More **](https://www.truvantis.com/blog/pentesting-for-pci-dss)

<https://www.truvantis.com/blog/the-board-vs.-security-privacy-programs> <https://www.truvantis.com/blog/the-board-vs.-security-privacy-programs>

[CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [9 The Board vs. Security & Privacy Programs](https://www.truvantis.com/blog/the-board-vs.-security-privacy-programs)

 In a corporation, the board is ultimately accountable to the shareholders for managing risks, including cybersecurity and privacy risk. ... 

[Read More **](https://www.truvantis.com/blog/the-board-vs.-security-privacy-programs)

<https://www.truvantis.com/blog/combined-risk-management-for-security-privacy-and-compliance> <https://www.truvantis.com/blog/combined-risk-management-for-security-privacy-and-compliance>

[Privacy](https://www.truvantis.com/blog/tag/privacy)

### [10 Combined Risk Management for Security, Privacy and Compliance](https://www.truvantis.com/blog/combined-risk-management-for-security-privacy-and-compliance)

 Privacy regulations boil down to protecting information. In other words, privacy is about the security of data. The various privacy rights can ... 

[Read More **](https://www.truvantis.com/blog/combined-risk-management-for-security-privacy-and-compliance)

[All posts](https://www.truvantis.com/blog/all) [Next](https://www.truvantis.com/blog/author/john-macinnis/page/2)

[![truvantis-logo-white@2x-1](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-white@2x-1.png?width=1117&height=250&name=truvantis-logo-white@2x-1.png "truvantis-logo-white@2x-1")](https://www.truvantis.com/)

[info@truvantis.com](mailto:info@truvantis.com)

+1 (415) 422-9844

<https://www.facebook.com/truvantis> <https://www.linkedin.com/company/truvantis> <https://twitter.com/truvantis?lang=en>

© 2024 Truvantis, Inc All Rights Reserved.

[Privacy Policy](https://www.truvantis.com/privacy-policy)    [Terms of Service ](https://www.truvantis.com/terms-of-service)

![](https://px.ads.linkedin.com/collect/?pid=2614233&fmt=gif) ![](https://ws.zoominfo.com/pixel/dnjpprEKcMtv41HRInFR)