<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Audit-Checklist Guides</title>
    <link>https://audit-checklist.com/blog/</link>
    <description>Operational field notes on ISO, cybersecurity, and privacy — each paired with an interactive checklist.</description>
    <language>en-us</language>
    <item>
      <title>ISO 27001:2022 audit readiness: what Stage 1 and Stage 2 actually test</title>
      <link>https://audit-checklist.com/blog/iso-27001-audit-readiness-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/iso-27001-audit-readiness-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to prepare an ISMS for ISO 27001:2022 certification in 2026 — scope, SoA, internal audit, and what registrars sample in Stage 2.</description>
      <category>ISO Standards</category>
    </item>
    <item>
      <title>SOC 2 Type II in 2026: observation windows, evidence, and exceptions</title>
      <link>https://audit-checklist.com/blog/soc-2-type-ii-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/soc-2-type-ii-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>A practical guide to SOC 2 Type II — Trust Services Criteria, Type I vs Type II, and how to collect evidence over the observation period.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>GDPR for web applications: lawful basis, cookies, and processor chains</title>
      <link>https://audit-checklist.com/blog/gdpr-web-app-compliance-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/gdpr-web-app-compliance-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How web and SaaS teams operationalize GDPR — ROPA, consent UX, subprocessors, and transfers — without treating the privacy policy as the program.</description>
      <category>Data Privacy &amp; Law</category>
    </item>
    <item>
      <title>HIPAA Security Rule for HealthTech: ePHI, BAAs, and OCR-ready evidence</title>
      <link>https://audit-checklist.com/blog/hipaa-security-rule-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/hipaa-security-rule-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How HealthTech teams run a Security Rule program — risk analysis, safeguards, BAAs, and what OCR and customers actually ask for.</description>
      <category>Data Privacy &amp; Law</category>
    </item>
    <item>
      <title>ISO 9001:2015 for product organizations: process, risk, and audit sampling</title>
      <link>https://audit-checklist.com/blog/iso-9001-qms-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/iso-9001-qms-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to stand up a quality management system that matches how work actually happens — not a shelf manual — before an ISO 9001 Stage 2 audit.</description>
      <category>ISO Standards</category>
    </item>
    <item>
      <title>PCI DSS v4.0.1 in 2026: ROC scope, SAQ choice, and customized approach</title>
      <link>https://audit-checklist.com/blog/pci-dss-v4-compliance-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/pci-dss-v4-compliance-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How payment teams prepare for PCI DSS v4.0.1 — cardholder data environment, SAQ vs ROC, and what QSAs sample after the 2025 future-dated requirements.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>NIST CSF 2.0: Govern, profiles, and how to use the framework without a certificate</title>
      <link>https://audit-checklist.com/blog/nist-csf-2-0-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/nist-csf-2-0-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>A 2026 guide to NIST Cybersecurity Framework 2.0 — the new Govern function, current vs target profiles, and how CSF sits next to ISO 27001 and SOC 2.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>CMMC Level 2 and NIST 800-171 Rev 3: CUI, SPRS, and what assessors sample</title>
      <link>https://audit-checklist.com/blog/cmmc-level-2-800-171-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/cmmc-level-2-800-171-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How defense contractors prepare for CMMC Level 2 — CUI scoping, SPRS scores, and the gap between a self-attestation spreadsheet and a C3PAO assessment.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>NIST SP 800-53 Moderate: control families, overlays, and FedRAMP adjacency</title>
      <link>https://audit-checklist.com/blog/nist-800-53-moderate-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/nist-800-53-moderate-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to implement NIST 800-53 Rev 5 at the Moderate baseline — selecting families, documenting overlays, and producing assessable evidence.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>CIS Controls v8: IG1 to IG3 and how to stop boiling the ocean</title>
      <link>https://audit-checklist.com/blog/cis-controls-v8-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/cis-controls-v8-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>A practical 2026 guide to CIS Controls Version 8 — Implementation Groups, Safeguards that actually reduce ransomware risk, and how CIS maps to SOC 2.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>FedRAMP Moderate in 2026: 3PAO, SSP, and the authorization path that is not a SOC 2</title>
      <link>https://audit-checklist.com/blog/fedramp-moderate-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/fedramp-moderate-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>What Cloud Service Providers actually do for FedRAMP Moderate — boundary, inheritance, continuous monitoring, and why a Type II report is not an ATO.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>ISO 27701 PIMS: how to extend ISO 27001 without a second fake ISMS</title>
      <link>https://audit-checklist.com/blog/iso-27701-pims-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/iso-27701-pims-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How privacy teams add ISO/IEC 27701 to an existing ISO 27001 ISMS — PII roles, processors vs controllers, and what certification audits sample.</description>
      <category>ISO Standards</category>
    </item>
    <item>
      <title>ISO 22301: BIA, MTPD, and why a DR runbook is not a BCMS</title>
      <link>https://audit-checklist.com/blog/iso-22301-business-continuity-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/iso-22301-business-continuity-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to build an ISO 22301:2019 business continuity management system — business impact analysis, strategies, tests, and certification sampling.</description>
      <category>ISO Standards</category>
    </item>
    <item>
      <title>ISO 14001: aspects, compliance obligations, and an EMS that is not a green poster</title>
      <link>https://audit-checklist.com/blog/iso-14001-ems-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/iso-14001-ems-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How operations and EHS teams stand up ISO 14001:2015 — environmental aspects, legal registers, and what Stage 2 auditors sample on site.</description>
      <category>ISO Standards</category>
    </item>
    <item>
      <title>ISO 45001: hazard identification, worker participation, and OH&amp;S that survives a site tour</title>
      <link>https://audit-checklist.com/blog/iso-45001-ohs-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/iso-45001-ohs-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to implement ISO 45001:2018 — participation, risk, contractors, and the difference between a safety binder and an occupational health and safety MS.</description>
      <category>ISO Standards</category>
    </item>
    <item>
      <title>ISO/IEC 42001: an AI management system that is not a model card in a slide deck</title>
      <link>https://audit-checklist.com/blog/iso-42001-ai-management-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/iso-42001-ai-management-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to implement ISO 42001:2023 — AI system inventory, risk, data, and what certification audits look for next to the EU AI Act.</description>
      <category>ISO Standards</category>
    </item>
    <item>
      <title>ISO/IEC 27017: cloud control guidance that actually names who does what</title>
      <link>https://audit-checklist.com/blog/iso-27017-cloud-security-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/iso-27017-cloud-security-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How CSPs and cloud customers use ISO 27017 — shared responsibility, virtualization, and how it extends ISO 27001 for cloud services.</description>
      <category>ISO Standards</category>
    </item>
    <item>
      <title>ISO/IEC 27018: PII processor controls for public cloud — not a GDPR certificate</title>
      <link>https://audit-checklist.com/blog/iso-27018-cloud-privacy-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/iso-27018-cloud-privacy-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>What ISO 27018 covers for public-cloud PII processors — customer control of data, return/deletion, and how it differs from ISO 27701.</description>
      <category>ISO Standards</category>
    </item>
    <item>
      <title>ISO/IEC 20000-1: ITSM certification without copying ITIL theatre</title>
      <link>https://audit-checklist.com/blog/iso-20000-itsm-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/iso-20000-itsm-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to prepare an ISO 20000-1:2018 service management system — service catalog, SLAs, and what auditors sample beyond ticket queues.</description>
      <category>ISO Standards</category>
    </item>
    <item>
      <title>ISO 13485: medical device QMS, design controls, and why 9001 is not enough</title>
      <link>https://audit-checklist.com/blog/iso-13485-medical-device-qms-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/iso-13485-medical-device-qms-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How MedTech teams implement ISO 13485:2016 — design and development, suppliers, and the records auditors and regulators expect.</description>
      <category>ISO Standards</category>
    </item>
    <item>
      <title>ISO 37001: anti-bribery management that goes beyond a code of conduct PDF</title>
      <link>https://audit-checklist.com/blog/iso-37001-anti-bribery-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/iso-37001-anti-bribery-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to implement ISO 37001:2016 — due diligence, gifts, third parties, and what certification audits test in high-risk markets.</description>
      <category>ISO Standards</category>
    </item>
    <item>
      <title>ISO 31000: enterprise risk that is not a heat map for the annual report</title>
      <link>https://audit-checklist.com/blog/iso-31000-risk-management-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/iso-31000-risk-management-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to apply ISO 31000:2018 — principles, framework, and process — so risk registers drive decisions instead of decorating a board pack.</description>
      <category>ISO Standards</category>
    </item>
    <item>
      <title>ISO 50001: EnMS, energy baselines, and why a green tariff is not an energy MS</title>
      <link>https://audit-checklist.com/blog/iso-50001-energy-management-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/iso-50001-energy-management-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How facilities and operations implement ISO 50001:2018 — energy review, SEUs, baselines, and certification sampling in offices and industry.</description>
      <category>ISO Standards</category>
    </item>
    <item>
      <title>IATF 16949: automotive QMS beyond ISO 9001 — APQP, PPAP, and customer specifics</title>
      <link>https://audit-checklist.com/blog/iatf-16949-automotive-qms-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/iatf-16949-automotive-qms-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How automotive suppliers prepare for IATF 16949:2016 — core tools, customer-specific requirements, and what CB auditors sample on the line.</description>
      <category>ISO Standards</category>
    </item>
    <item>
      <title>CCPA and CPRA in 2026: thresholds, CPRA rights, and the “sale/share” problem for ads</title>
      <link>https://audit-checklist.com/blog/ccpa-cpra-privacy-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/ccpa-cpra-privacy-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How US-facing businesses operationalize California consumer privacy — notices, requests, service providers, and what CPRA added beyond CCPA.</description>
      <category>Data Privacy &amp; Law</category>
    </item>
    <item>
      <title>NIS2 in 2026: essential vs important, supply chain, and 24-hour incident reporting</title>
      <link>https://audit-checklist.com/blog/nis2-directive-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/nis2-directive-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How in-scope entities prepare for the EU NIS2 Directive — management accountability, cybersecurity measures, and incident notification clocks.</description>
      <category>Data Privacy &amp; Law</category>
    </item>
    <item>
      <title>DORA: ICT risk, TLPT, and critical third parties in EU financial services</title>
      <link>https://audit-checklist.com/blog/dora-ict-risk-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/dora-ict-risk-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How financial entities operationalize the Digital Operational Resilience Act — ICT risk management, incident reporting, testing, and third-party registers.</description>
      <category>Data Privacy &amp; Law</category>
    </item>
    <item>
      <title>EU AI Act in 2026: prohibited, GPAI, high-risk — and who is provider vs deployer</title>
      <link>https://audit-checklist.com/blog/eu-ai-act-readiness-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/eu-ai-act-readiness-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>A practical guide to EU AI Act readiness — role classification, high-risk obligations, GPAI documentation, and how it sits next to ISO 42001.</description>
      <category>Data Privacy &amp; Law</category>
    </item>
    <item>
      <title>Cookie consent and ePrivacy in 2026: prior consent, dark patterns, and CMP reality</title>
      <link>https://audit-checklist.com/blog/cookie-consent-eprivacy-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/cookie-consent-eprivacy-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How websites implement cookie and tracking consent that survives EU ePrivacy practice — banners, GPC, and what still goes wrong with analytics.</description>
      <category>Data Privacy &amp; Law</category>
    </item>
    <item>
      <title>GDPR DPIAs: when Article 35 is mandatory, and how to write one that is not a template</title>
      <link>https://audit-checklist.com/blog/gdpr-dpia-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/gdpr-dpia-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to run a Data Protection Impact Assessment under GDPR — screening, consultation, residual risk, and when to talk to a supervisory authority.</description>
      <category>Data Privacy &amp; Law</category>
    </item>
    <item>
      <title>UK GDPR and DPA 2018: ICO, IDTA, and what actually diverged from the EU after Brexit</title>
      <link>https://audit-checklist.com/blog/uk-gdpr-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/uk-gdpr-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to run a UK data-protection program in 2026 — UK GDPR, PECR, transfers, and where EU GDPR copy-paste still fails.</description>
      <category>Data Privacy &amp; Law</category>
    </item>
    <item>
      <title>LGPD in 2026: ANPD, lawful bases, and why a GDPR clone is not Brazilian compliance</title>
      <link>https://audit-checklist.com/blog/lgpd-brazil-privacy-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/lgpd-brazil-privacy-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How companies with Brazilian users operationalize LGPD — agents, rights, incidents, and ANPD expectations versus GDPR muscle memory.</description>
      <category>Data Privacy &amp; Law</category>
    </item>
    <item>
      <title>HITRUST CSF: scored assessments, inheritance, and why HealthTech buyers ask for it</title>
      <link>https://audit-checklist.com/blog/hitrust-csf-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/hitrust-csf-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to prepare a HITRUST CSF assessment — scoping, control inheritance, and the difference between a self-assessment and a certified report.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>TISAX: VDA ISA, labels, and what automotive OEMs actually check in ENX</title>
      <link>https://audit-checklist.com/blog/tisax-assessment-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/tisax-assessment-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How automotive suppliers prepare for TISAX — assessment levels, prototype protection, and the ENX portal labels customers look up.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>SOC 1 Type II: ICFR, user control considerations, and when SOC 2 is the wrong report</title>
      <link>https://audit-checklist.com/blog/soc-1-type-ii-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/soc-1-type-ii-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How finance-adjacent processors prepare for SOC 1 Type II — control objectives, observation windows, and complementary user entity controls.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>Cyber Essentials Plus: IASME, the hands-on test, and why the badge is not a pen test</title>
      <link>https://audit-checklist.com/blog/cyber-essentials-plus-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/cyber-essentials-plus-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How UK organizations prepare for Cyber Essentials Plus — scope, technical verification, and the difference from the questionnaire-only scheme.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>Incident response in 2026: severity, legal clocks, and a CSIRT that can page at 2 a.m.</title>
      <link>https://audit-checklist.com/blog/incident-response-program-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/incident-response-program-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to build an operational IR program — roles, playbooks, evidence, and notification duties that span GDPR, NIS2, and customer contracts.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>Third-party risk in 2026: inherent risk, continuous monitoring, and the death of the annual PDF</title>
      <link>https://audit-checklist.com/blog/third-party-risk-management-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/third-party-risk-management-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to run TPRM that scales — tiering, questionnaires vs evidence, fourth parties, and what SOC 2 and ISO actually tell you about a vendor.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>Backup and disaster recovery: 3-2-1, ransomware, and the restore you never tested</title>
      <link>https://audit-checklist.com/blog/disaster-recovery-backup-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/disaster-recovery-backup-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to build DR that survives ransomware — immutability, RTO/RPO honesty, and why a snapshot in the same account is not a strategy.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>OWASP ASVS: verification levels, and how to stop treating AppSec as a pentest PDF</title>
      <link>https://audit-checklist.com/blog/owasp-asvs-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/owasp-asvs-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How engineering teams use OWASP ASVS — L1 to L3, mapping to sprint work, and what “verified” means versus a one-week pentest.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>Cloud shared responsibility: IaaS vs PaaS vs SaaS, and the controls you still own</title>
      <link>https://audit-checklist.com/blog/cloud-shared-responsibility-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/cloud-shared-responsibility-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to make AWS, Azure, and GCP shared-responsibility real — identity, data, config, and what customer questionnaires get wrong.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>Privileged access management: standing admin is the incident, not the exception</title>
      <link>https://audit-checklist.com/blog/privileged-access-management-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/privileged-access-management-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to implement PAM — vaulting, just-in-time, cloud admin, and the evidence SOC 2 and ISO auditors actually sample.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>Vulnerability management: SLA by severity, internet-facing truth, and scanner theatre</title>
      <link>https://audit-checklist.com/blog/vulnerability-management-program-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/vulnerability-management-program-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to run vuln management that reduces risk — coverage, exception process, and why a monthly Qualys PDF is not a program.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>Penetration test scoping: rules of engagement, retesting, and what a PDF does not prove</title>
      <link>https://audit-checklist.com/blog/penetration-test-scoping-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/penetration-test-scoping-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to buy and survive a pentest — scope, credentials, environments, and how to use findings without treating the report as a certificate.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>SOX ITGCs: access, change, and IT operations that external audit will sample</title>
      <link>https://audit-checklist.com/blog/sox-itgc-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/sox-itgc-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How public-company IT runs IT general controls for SOX — in-scope systems, IPE, and the three control families that still cause deficiencies.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>GLBA Safeguards Rule: FTC information security for non-bank financial companies</title>
      <link>https://audit-checklist.com/blog/glba-safeguards-rule-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/glba-safeguards-rule-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How financial institutions under the FTC Safeguards Rule build a written program — Qualified Individual, risk assessment, encryption, and 2023+ expectations.</description>
      <category>Data Privacy &amp; Law</category>
    </item>
    <item>
      <title>COPPA: verifiable parental consent, child-directed design, and the FTC’s 2025–26 posture</title>
      <link>https://audit-checklist.com/blog/coppa-childrens-privacy-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/coppa-childrens-privacy-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How online services handle children’s privacy under COPPA — actual knowledge, notice, consent, and what “directed to children” still means in product design.</description>
      <category>Data Privacy &amp; Law</category>
    </item>
    <item>
      <title>WCAG 2.2 in 2026: AA as the procurement bar, and why an overlay is not conformance</title>
      <link>https://audit-checklist.com/blog/wcag-2-2-accessibility-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/wcag-2-2-accessibility-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How product teams audit toward WCAG 2.2 Level AA — new success criteria, testing, and the legal/procurement reality in the US and EU.</description>
      <category>Data Privacy &amp; Law</category>
    </item>
    <item>
      <title>PIPEDA: fair information principles, meaningful consent, and breach reporting to the OPC</title>
      <link>https://audit-checklist.com/blog/pipeda-canada-privacy-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/pipeda-canada-privacy-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How organizations with Canadian personal information run a PIPEDA program — ten principles, consent, and what still differs from GDPR.</description>
      <category>Data Privacy &amp; Law</category>
    </item>
    <item>
      <title>Singapore PDPA: consent, deemed consent, and PDPC’s 2026 enforcement posture</title>
      <link>https://audit-checklist.com/blog/singapore-pdpa-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/singapore-pdpa-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How organizations operationalize Singapore’s PDPA — obligations, DNC, data breaches, and where GDPR templates mislead.</description>
      <category>Data Privacy &amp; Law</category>
    </item>
    <item>
      <title>Data retention and deletion: schedules that survive legal hold, backups, and logs</title>
      <link>https://audit-checklist.com/blog/data-retention-deletion-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/data-retention-deletion-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to build a retention schedule that is operational — legal hold, backup lag, and deletion that GDPR and customer DPAs can test.</description>
      <category>Data Privacy &amp; Law</category>
    </item>
    <item>
      <title>GDPR Article 30 ROPA: the record that is not a spreadsheet graveyard</title>
      <link>https://audit-checklist.com/blog/gdpr-article-30-ropa-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/gdpr-article-30-ropa-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to keep Records of Processing Activities that match the product — systems, recipients, transfers, and what supervisory authorities sample.</description>
      <category>Data Privacy &amp; Law</category>
    </item>
    <item>
      <title>International transfers after Schrems: SCCs, TIAs, and the UK IDTA in 2026</title>
      <link>https://audit-checklist.com/blog/international-data-transfer-tia-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/international-data-transfer-tia-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to run a transfer program — mapping flows, SCCs/IDTA, Transfer Impact Assessments, and supplementary measures that are not theatre.</description>
      <category>Data Privacy &amp; Law</category>
    </item>
    <item>
      <title>Zero trust in 2026: identity, device, and path — not a product SKU</title>
      <link>https://audit-checklist.com/blog/zero-trust-architecture-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/zero-trust-architecture-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How to implement zero trust architecture as a program — PEP/PDP thinking, least privilege, and what NIST SP 800-207 actually asks for.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
    <item>
      <title>Kubernetes security: supply chain, RBAC, and runtime — the cluster is the estate</title>
      <link>https://audit-checklist.com/blog/kubernetes-container-security-guide/</link>
      <guid isPermaLink="true">https://audit-checklist.com/blog/kubernetes-container-security-guide/</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>How platform teams harden Kubernetes and containers — CIS benchmarks, admission, secrets, and what auditors sample in cloud-native shops.</description>
      <category>Cybersecurity &amp; Cloud</category>
    </item>
  </channel>
</rss>
