Resources
Articles
Practical guides and industry updates to help your organization stay secure and compliant in a digital-first world.

Understanding CCPA Compliance
Understanding CCPA Compliance
The California Consumer Privacy Act (CCPA) is a crucial regulation designed to protect the personal information of California residents. Understanding CCPA compliance is essential for businesses that collect, store, and process personal data. This comprehensive guide will break down the key aspects of CCPA compliance and provide actionable steps for businesses to adhere to this important legislation.
What is the CCPA?
The CCPA, enacted on January 1, 2020, is a privacy law that grants California residents greater control over their personal information. It requires businesses to be transparent about the data they collect and empowers consumers with rights to access, delete, and opt-out of the sale of their personal data.
Does the CCPA Apply to my Business?
The CCPA applies to any for-profit entity doing business in California that controls and collects the processing of a consumer’s personal information and also satisfies ANY one of the following thresholds:
- Derives more than 50% of annual revenue from selling consumers' personal information.
- Handles the personal information of 50,000 or more California consumers, households, or devices annually, or
- Exceeds $25 million gross revenue annually
CCPA also applies to any organization that controls or is controlled by and entity that meets one of the following criteria listed above.
READ MORE: CCPA vs GDPR: Navigating Privacy Regulations
Key Components of CCPA Compliance
To ensure CCPA compliance, businesses must focus on several key areas:
1. Consumer Rights
Right to Know: Consumers have the right to know what personal information is being collected about them, including the specific pieces of information, the categories of sources from which the information is collected, the business or commercial purpose for collecting or selling the information, and the categories of third parties with whom the information is shared.
Right to Access: Consumers can request access to the personal information a business has collected about them. Businesses are required to provide this information free of charge, up to twice a year.
Right to Delete: Consumers have the right to request the deletion of their personal information that a business has collected. There are certain exceptions, such as when the information is needed to complete a transaction, for security purposes, to comply with a legal obligation, or for certain other business or legal reasons.
Right to Non-Discrimination: Consumers have the right to not be discriminated against for exercising their CCPA rights. This means businesses cannot deny services, charge different prices, or provide a different level of service to consumers who exercise their rights under the CCPA.
Right to Opt-Out of Sale: Consumers have the right to opt out of the sale of their personal information to third parties. Businesses must provide a "Do Not Sell My Personal Information" link on their website to facilitate this process.
Right to Data Portability:When consumers request access to their personal information, they also have the right to receive this information in a portable and readily usable format, allowing them to transmit this data to another entity easily.

2. Data Inventory and Mapping
Understanding what personal information is collected, where it is stored, and how it is used is crucial. Conduct regular data inventories and mapping exercises to keep track of personal data throughout its lifecycle.
3. Privacy Policies
Update your privacy policies to include details about consumer rights under the CCPA, the categories of personal information collected, and how consumers can exercise their rights. Make sure these policies are easily accessible on your website.
4. Establish a Consumer Request Process
Set up a system to handle consumer requests for information, deletion, and opt-out. Ensure you have a process for verifying the identity of consumers and responding to requests within the required time frame.
5. Train Your Team
Provide regular training to your employees on CCPA compliance. Make sure they understand their responsibilities and know how to handle personal information and consumer requests properly.
The Importance of Ongoing Compliance
CCPA compliance is not a one-time effort but an ongoing process. Regularly review and update your data practices and privacy policies to ensure continuous compliance. Stay informed about any amendments to the CCPA and adapt your practices accordingly.
Achieve CCPA Compliance with Johanson Group
Understanding CCPA compliance is essential for businesses that handle personal information. By focusing on key areas such as consumer rights, data inventory, privacy policies, and employee training, you can ensure your business complies with this important regulation. Remember, ongoing compliance is crucial to maintaining consumer trust and avoiding potential fines and legal issues. Contact us today to get started with CCPA compliance!

7 Common Myths About SOC 2: Debunking Misconceptions
7 Common Myths About SOC 2: Debunking Misconceptions
If you're navigating the world of SOC 2, it's essential to distinguish fact from fiction. Let's debunk seven common myths about SOC 2 to help you better understand its importance and application.
Myth 1: SOC 2 Is a Certification
Reality: Contrary to popular belief, SOC 2 is not a certification but an attestation. An independent auditor reviews and attests that your organization meets the SOC 2 criteria. This attestation is documented in a report, which can be shared with stakeholders to demonstrate your compliance. Unlike certifications, which often involve passing an exam or meeting a predefined set of requirements, SOC 2 attestation is a thorough examination of your controls over a period of time.
READ MORE: What is a SOC 2 Attestation?
Myth 2: SOC 2 Compliance Is Only for Tech Companies
Reality: While it's true that tech companies were early adopters of SOC 2, the standards are applicable to any organization that handles customer data. This includes industries like healthcare, finance, and even retail. The principles of SOC 2 - security, availability, processing integrity, confidentiality, and privacy - are universal and can benefit any business striving to protect its data and build trust with customers.
Myth 3: SOC 2 Compliance Is a One-Time Event
Reality: SOC 2 compliance is an ongoing process, not a one-time event. Achieving SOC 2 compliance means your organization has established systems and controls to protect data, but maintaining compliance requires continuous monitoring and regular audits. Typically, SOC 2 reports are issued annually, and businesses need to stay vigilant to ensure they meet the standards year-round.
READ MORE: SOC 2 Frequency: What You Should Know
Myth 4: SOC 2 Audits Are Expensive and Time-Consuming
Reality: While SOC 2 audits can be resource-intensive, they are not necessarily prohibitively expensive or excessively time-consuming. The cost and duration of an audit depend on the size of your organization, the complexity of your systems, and how well-prepared you are. Investing in SOC 2 compliance can actually save your company money in the long run by preventing data breaches and enhancing your reputation.
Myth 5: SOC 2 Compliance Guarantees Total Security
Reality: SOC 2 compliance significantly enhances your organization's security posture but does not guarantee absolute security. It ensures that you have effective controls in place to protect data, but it cannot account for every potential threat or vulnerability. Security is a dynamic field, and new risks emerge continuously. Thus, SOC 2 should be part of a broader, comprehensive security strategy.
Myth 6: SOC 2 and ISO 27001 Are Interchangeable
Reality: SOC 2 and ISO 27001 are both important security frameworks, but they are not interchangeable. SOC 2 focuses on service organizations and their handling of customer data, emphasizing the five Trust Service Criteria. In contrast, ISO 27001 is a global standard for managing information security, applicable to all types of organizations. Both have their own benefits, and choosing one over the other depends on your business needs and goals.
READ MORE: SOC 2 vs. ISO 27001: Which to Choose
Myth 7: Only Large Companies Need SOC 2 Compliance
Reality: Small and medium-sized enterprises (SMEs) can benefit just as much from SOC 2 compliance as large corporations. In fact, SOC 2 can be a differentiator for SMEs, demonstrating their commitment to security and gaining customer trust. As cyber threats don't discriminate by size, having robust security controls is crucial for businesses of all sizes.
READ MORE: Understanding SOC 2 Audits for Startups
Understanding SOC 2 compliance and dispelling common myths is essential for any organization aiming to protect its data and enhance its reputation. By recognizing that SOC 2 is applicable to various industries, requires ongoing effort, and forms part of a broader security strategy, businesses can better prepare for and benefit from SOC 2 compliance.
Johanson Group stands out as a premier choice for conducting your SOC 2 compliance audits. With years of experience and a team of seasoned professionals, Johanson Group offers a comprehensive approach to ensure your organization meets the rigorous SOC 2 standards.

Understanding SOC 2 Trust Service Criteria
Understanding SOC 2 Trust Service Criteria
If you're diving into the world of SOC 2 audits, you're likely familiar with the term "Trust Service Criteria." But what exactly are these criteria, why are they important, and how can you effectively incorporate them into your SOC 2 audit? Let's break it down.
What are the SOC 2 Trust Service Criteria?
The SOC 2 Trust Service Criteria are a set of standards designed by the American Institute of CPAs (AICPA) to help organizations manage and protect their data. These criteria provide a framework for evaluating and reporting on the security, availability, processing integrity, confidentiality, and privacy of a system.
Here's a brief overview of each criterion:

- Security: Systems and data stored by a company are protected against unauthorized access and disclosure.
- Availability: Information and systems are available for operation and use.
- Confidentiality: Confidential information is protected.
- Processing Integrity: System processing is complete, valid, accurate, timely, and authorized. Customer data remains correct through data processing.
- Privacy: Personal information is collected used, rented, retained, disclosed and disposed in accordance with pre-stated policies.
READ MORE: Streamlining The SOC 2 Audit Process in 10 Steps
The Importance of Each Trust Service Criteria
Understanding the significance of each criterion is crucial for any organization aiming to achieve SOC 2 compliance:
- Security: Protecting against unauthorized access is the cornerstone of any robust information system. This criterion is crucial to safeguard sensitive data and maintain trust with clients and stakeholders.
- Availability: Downtime can be costly and damaging to an organization's reputation. Ensuring that systems are consistently available helps maintain business continuity and customer satisfaction.
- Processing Integrity: Accurate and reliable processing of data is vital for operational efficiency and trustworthiness. This criterion ensures that processes work as intended and deliver expected outcomes.
- Confidentiality: For organizations dealing with sensitive information, protecting confidentiality is non-negotiable. This criterion helps in maintaining competitive advantage and compliance with legal requirements.
- Privacy: With increasing regulations around data privacy (like GDPR and CCPA), ensuring that personal information is handled appropriately is essential to avoid hefty fines and maintain user trust.
READ MORE: SOC 2 Compliance: 5 Common Questions
Which Criteria Should I Include in My SOC 2 Audit?
Determining which criteria to include in your SOC 2 audit depends on the nature of your services and the expectations of your clients and stakeholders. While the Security criterion is mandatory for all SOC 2 audits, the inclusion of other criteria varies:
- Availability: If your service commitments or system requirements include high availability, this criterion should be included.
- Processing Integrity: Include this if your clients depend on your system to process data accurately and reliably.
- Confidentiality: If you handle sensitive information, such as intellectual property or customer data, this is a must.
- Privacy: Essential for organizations that collect and manage personal information.
Johanson Group LLP Can Help with SOC 2 Audits
Navigating the complexities of SOC 2 compliance can be daunting. This is where Johanson Group LLP steps in. Our team of experts specializes in guiding organizations through the SOC 2 audit process, ensuring that you meet all necessary criteria with confidence and ease.
- Expert Guidance: We provide in-depth consultations to help you understand the SOC 2 requirements and how they apply to your specific situation.
- Comprehensive Audits: Our thorough audit process evaluates your controls against the Trust Service Criteria, identifying any gaps and providing actionable recommendations.
- Tailored Solutions: We understand that every organization is unique. Our services are customized to meet your specific needs and ensure that you achieve compliance efficiently and effectively.
- Ongoing Support: SOC 2 compliance is an ongoing process. We offer continuous support to help you maintain your controls and address any new challenges that arise.
Ready to secure your systems and build trust with your clients? Contact Johanson Group LLP today and take the first step towards SOC 2 compliance with confidence.

ISO 27017 vs ISO 27018: Which Is Right for Your Business?
ISO 27017 vs ISO 27018: Which Is Right for Your Business?
Among the most renowned certifications are ISO 27017 and ISO 27018, which focus on cloud security and personally identifiable information (PII) respectively. But what sets them apart, and which one does your organization need? Let’s delve into the details.
What is ISO 27017 and ISO 27018?
ISO 27017 and ISO 27018 are subsets of the ISO/IEC 27000 series, which comprises international standards for information security management systems (ISMS).
ISO 27017 specifically targets cloud security, providing guidelines and recommendations to ensure the confidentiality, integrity, and availability of information stored in the cloud. It assists cloud service providers and customers in addressing cloud-specific risks and implementing effective controls.
ISO 27018, on the other hand, focuses on protecting PII in cloud environments. It offers a framework for cloud service providers to establish policies and controls for the processing of personal data, addressing concerns related to data protection, privacy, and compliance with regulatory requirements.
How is ISO 27017 different than ISO 27018?
While both standards revolve around cloud security, their scopes and objectives differ significantly:
- ISO 27017 emphasizes the protection of information in cloud environments, addressing risks such as data breaches, data loss, and service disruptions specific to cloud computing.
- ISO 27018 narrows its focus to the protection of PII in cloud environments, encompassing principles such as consent, transparency, data minimization, and accountability in handling personal data.
Who Needs ISO 27017/ISO 27018?
Organizations that utilize cloud services or process PII should consider pursuing ISO 27017 and ISO 27018 certifications respectively. This includes:
- Cloud service providers
- Enterprises leveraging cloud solutions for data storage, processing, or communication
- Organizations handling sensitive personal data, such as healthcare providers, financial institutions, and e-commerce platforms
Benefits of ISO 27017/ISO 27018
The adoption of ISO 27017 and ISO 27018 offers numerous advantages:
- Enhanced Security: Implementing controls and best practices outlined in these standards strengthens the security posture of cloud environments, reducing the risk of data breaches and unauthorized access.
- Regulatory Compliance: Compliance with ISO 27017 and ISO 27018 demonstrates commitment to safeguarding sensitive information, facilitating adherence to data protection regulations such as GDPR, HIPAA, and CCPA.
- Customer Trust: Certification instills confidence among customers and stakeholders by showcasing a proactive approach to cloud security and privacy, fostering trust and credibility.
- Operational Efficiency: Standardized processes and procedures streamline cloud operations, leading to improved efficiency, resilience, and incident response capabilities.
What is the process to get certified for ISO 27017/ISO 27018?
Achieving ISO 27017/ISO 27018 certification involves several key steps:
- Information Sharing
- Please complete our inquiry form, providing thorough responses to questions. This will enable us to meticulously assess your review needs, identify gaps, and determine the certification requirements.
- Document Review/Internal Audit
- Our team will conduct document review and execute the initial audit, which can be done either on-site or remotely.
- Additional Services (If Applicable)
- Should additional certification or assessment services such as ISO/IEC 27001, ISO/IEC 42001, SSPA, be required, we will collaborate with you to establish the subsequent procedures and integrate resources as necessary.
- Registration for Certification
- Registration for certification involves the formal submission of required documentation and information to initiate the certification process. This includes providing details about organizational operations, policies, and procedures relevant to the certification sought.
- Annual Surveillance Audit
- A scheduled assessment will be planned and conducted at regular intervals, ensuring ongoing compliance with established standards and regulations.
- Recertification
- Upon successful completion of the audit, the certification body issues ISO 27017/ISO 27018 certification, valid for a specified period.
Johanson Group for ISO 27017/27018 Certifications
When it comes to selecting a partner for ISO 27017/ISO 27018 certifications, Johanson Group stands out for its expertise, reliability, and customer-centric approach. Here’s why:
- Specialized Knowledge: Johanson Group boasts a team of seasoned professionals with in-depth knowledge of cloud security and data privacy, ensuring comprehensive guidance throughout the certification process.
- Tailored Solutions: Recognizing that every organization is unique, Johanson Group offers customized solutions tailored to specific business requirements, enabling seamless integration of ISO 27017/ISO 27018 principles into existing processes.
- Proven Track Record: With a track record of successful certifications across various industries, Johanson Group demonstrates a commitment to delivering results and exceeding client expectations.
- Ongoing Support: Beyond certification, Johanson Group provides ongoing support and resources to help organizations maintain compliance, adapt to evolving threats, and continuously improve their security posture.

CCPA vs GDPR: Navigating Privacy Regulations
CCPA vs GDPR: Navigating Privacy Regulations
Governments worldwide have responded by enacting legislation to protect individuals' personal data. Two significant pieces of legislation leading this charge are the General Data Protection Regulation (GDPR) in the European Union and the California Consumer Privacy Act (CCPA) in the United States. So let's look into CCPA vs. GDPR, the similarities and differences between the two.
A Brief Summary of GDPR:
- EU law since 2018, protecting EU residents' data.
- Applies globally to organizations handling EU residents' data.
- Defines data subject rights, lawful processing, and accountability.
- Imposes fines up to 4% of global turnover for breaches.
More about GDPR:
- What is GDPR? - The Ultimate Guide to GDPR
- GDPR.EU - Official European Union site
A Brief Summary of CCPA:
- California law since 2020, enhancing residents' privacy.
- Applies to businesses meeting specific revenue or data criteria.
- Grants consumers rights to know, opt-out, and non-discrimination.
- Fines up to $7,500 per violation for non-compliance.
More about CCPA:
- CCPA Civil Code - Official code on California state legislation information site
- CCPA Overview - Official overview
Definition of Personal Data
CCPA Definition of Personal Information:
According to the CCPA, personal information refers to information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. This includes, but is not limited to, identifiers such as a real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, social security number, driver's license number, passport number, or other similar identifiers.
CCPA also considers personal information to include categories of information such as biometric information, geolocation data, professional or employment-related information, education information, and inferences drawn from other personal information that may create a profile about a consumer.
GDPR Definition of Personal Data:
Under the GDPR, personal data is defined as any information relating to an identified or identifiable natural person ('data subject'). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
GDPR's definition of personal data is broad and encompasses any information that can be linked to an individual, including basic identity information, web data, biometric data, health and genetic data, cultural or social identity information, and more.

What Rights Do the CCPA and GDPR Give People?
Both the California Consumer Privacy Act (CCPA) and the General Data Protection Regulation (GDPR) grant individuals certain rights regarding their personal data. Here's a comparison of the rights provided by each:
Rights under CCPA (California Consumer Privacy Act):
- Right to Know: Individuals have the right to know what personal information is being collected about them, the sources of the information, the purpose of collection, and whether it is being sold or disclosed.
- Right to Opt-Out: Individuals have the right to opt-out of the sale of their personal information to third parties. Businesses must provide a clear and conspicuous link on their websites titled "Do Not Sell My Personal Information" to enable this right.
- Right to Access: Individuals have the right to request access to the specific pieces of personal information that businesses have collected about them.
- Right to Deletion: Individuals have the right to request that businesses delete their personal information, subject to certain exceptions.
- Right to Non-Discrimination: Individuals have the right not to be discriminated against for exercising their privacy rights under the CCPA, including through denial of goods or services, charging different prices, or providing a different quality of service.
Rights under GDPR (General Data Protection Regulation):
- Right to Access: Data subjects have the right to obtain confirmation from the data controller as to whether personal data concerning them is being processed, and if so, access to that data.
- Right to Rectification: Data subjects have the right to request the correction of inaccurate or incomplete personal data.
- Right to Erasure ("Right to be Forgotten"): Data subjects have the right to request the deletion of their personal data under certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected or if the data was unlawfully processed.
- Right to Restriction of Processing: Data subjects have the right to request the restriction of processing of their personal data under certain circumstances, such as when the accuracy of the data is contested or the processing is unlawful.
- Right to Data Portability: Data subjects have the right to receive their personal data in a structured, commonly used, and machine-readable format and have the right to transmit that data to another controller.
- Right to Object: Data subjects have the right to object to the processing of their personal data, including for direct marketing purposes, on grounds relating to their particular situation.
- Rights related to Automated Decision Making and Profiling: Data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
Navigating the complexities of privacy regulations like CCPA and GDPR is essential for businesses aiming to build trust with consumers and avoid costly penalties. While both regulations share common principles, understanding their unique requirements is crucial for compliance. By prioritizing data protection and adopting robust privacy practices, businesses can navigate the intricacies of CCPA and GDPR while safeguarding individuals' rights to privacy.

What is NIST 800-53?
What is NIST 800-53?
One of the cornerstones of cybersecurity standards is NIST 800-53, a framework developed by the National Institute of Standards and Technology (NIST). In this blog, we'll dive into what NIST 800-53 is, its purpose, the benefits it offers, and best practices for compliance.
What is NIST 800-53?
NIST 800-53, officially titled "Security and Privacy Controls for Federal Information Systems and Organizations," is a publication that provides a comprehensive set of security controls for federal information systems and organizations. It outlines security and privacy controls that federal agencies and contractors must implement to protect their information systems from various threats.
The Purpose of NIST 800-53
The primary purpose of NIST 800-53 is to provide a standardized set of guidelines for securing information systems within the federal government. By establishing a common baseline of security controls, NIST aims to enhance the security posture of federal agencies and ensure the protection of sensitive information from unauthorized access, disclosure, or modification.
The Benefits of NIST 800-53
Implementing NIST 800-53 offers numerous benefits for organizations, including:
- Risk Management: NIST 800-53 helps organizations identify and mitigate security risks by providing a structured approach to cybersecurity.
- Compliance: Adhering to NIST 800-53 ensures compliance with federal regulations and mandates, such as the Federal Information Security Modernization Act (FISMA).
- Enhanced Security: By implementing the recommended security controls, organizations can strengthen their cybersecurity posture and better protect their systems and data from threats.
- Interoperability: NIST 800-53 provides a common language and framework for cybersecurity, promoting interoperability and collaboration among federal agencies and their partners.
Who Needs to Comply with NIST 800-53?
NIST 800-53 compliance is primarily mandated for federal agencies. However, its principles are applicable and beneficial for any organization handling sensitive information, spanning across industries such as healthcare, finance, and technology. Therefore, while originally intended for government entities, NIST 800-53's influence extends to a broader spectrum of organizations aiming to fortify their cybersecurity posture.
Three Classes of Information Systems in NIST 800-53
NIST 800-53 categorizes information systems into three classes:
- Low-Impact Systems: Systems where the loss of confidentiality, integrity, or availability could have a limited adverse effect.
- Moderate-Impact Systems: Systems where the loss of confidentiality, integrity, or availability could have a serious adverse effect.
- High-Impact Systems: Systems where the loss of confidentiality, integrity, or availability could have a severe or catastrophic adverse effect.
NIST 800-53 Controls
NIST 800-53 encompasses 20 security control families, each addressing specific aspects of cybersecurity. These families include:
- Access Control
- Awareness and Training
- Audit and Accountability
- Configuration Management
- Contingency Planning
- Identification and Authentication
- Incident Response
- Maintenance
- Media Protection
- Personnel Security
- Physical and Environmental Protection
- Planning
- Program Management
- Risk Assessment
- Security Assessment and Authorization
- System and Communications Protection
- System and Information Integrity
- System and Services Acquisition
- Supply Chain Risk Management
- Privacy Controls
NIST 800-53 Compliance and Best Practices
Achieving compliance with NIST 800-53 requires a strategic approach and adherence to best practices. Here are three key steps to ensure compliance:
1. Analyze
The first step in achieving NIST 800-53 compliance is to conduct a thorough analysis of your organization's current security posture. This involves assessing existing security controls, identifying vulnerabilities, and determining gaps in compliance. By understanding your organization's specific security needs and challenges, you can develop a tailored approach to implementing NIST 800-53 controls.
2. Educate
Effective implementation of NIST 800-53 requires comprehensive training and education for all stakeholders involved in the security process. This includes IT staff, security personnel, and end-users. Training should cover topics such as the importance of cybersecurity, NIST 800-53 requirements, and best practices for compliance. By ensuring that all stakeholders are knowledgeable about their roles and responsibilities, organizations can minimize security risks and foster a culture of security awareness.
3. Assess
Regular assessment and monitoring are essential for maintaining NIST 800-53 compliance over time. Organizations should conduct periodic security assessments to evaluate the effectiveness of implemented controls, identify emerging threats, and address any deficiencies. Additionally, continuous monitoring of systems and networks can help detect and respond to security incidents in a timely manner. By staying vigilant and proactive, organizations can ensure ongoing compliance with NIST 800-53 and mitigate the risk of security breaches.
NIST 800-53 serves as a critical framework for enhancing cybersecurity within federal agencies and organizations. By understanding its purpose, benefits, and best practices for compliance, organizations can strengthen their security posture, mitigate risks, and protect sensitive information from evolving threats.




