Schellman is a leading provider of attestation and compliance services. We are the only company in the world that is a CPA firm, a globally licensed PCI Qualified Security Assessor, an ISO Certification Body, HITRUST CSF Assessor, a FedRAMP 3PAO, and most recently, an APEC Accountability Agent. Renowned for expertise tempered by practical experience, Schellman's professionals provide superior client service balanced by steadfast independence. Our approach builds successful, long-term relationships and allows our clients to achieve multiple compliance objectives through a single third-party assessor.
By:
Schellman
October 31st, 2023
If you’re in healthcare, you likely already know that maintaining HIPAA compliance requires a very thorough risk assessment. What you may not know is that HIPAA risk assessments are also an aspect of the law that is too often overlooked.
By:
Schellman
October 24th, 2023
The Cybersecurity Maturity Model Certification (CMMC) is a new framework that aims to better secure federal contract information (FCI) and controlled unclassified information (CUI) that is stored, processed, or transmitted by defense contractors and the entire defense industrial base (DIB).
By:
Schellman
October 16th, 2023
Unlike Scope 1 and Scope 2 emissions—which are the direct and purchased energy emissions of a corporation, respectively—Scope 3 emissions are indirect emissions generated from activities of assets not owned or controlled by the reporting organization.
By:
Schellman
October 2nd, 2023
Inaugural Compliance and Risk Management Conference to Provide Insight from Leading Compliance, Cybersecurity Experts
By:
Schellman
September 26th, 2023
A new landmark in corporate climate change legislation, California Senate Bill (SB) 253, the Climate Corporate Accountability Act, has just been passed in the California Senate, and—now that it's been signed into law by the governor—it will mandate that the applicable companies report their direct greenhouse gas emissions as well as those generated by their utilities.
Payment Card Assessments | Penetration Testing
By:
Schellman
September 12th, 2023
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to protect cardholder data. One of the key (and almost always applicable) requirements of PCI DSS is that organizations must perform internal and external penetration testing for the entire scoped environment—this not only applies to systems that store, process, or transmit cardholder data, but also those that can impact the security of cardholder data.
By:
Schellman
August 31st, 2023
If you’ve ever owned a home in a neighborhood that has a homeowners association, you likely know that you have to pay those fees to avoid a lien being placed on your property, which could complicate your life in annoying ways. But on the flip side, paying those fees should mean you also reap the benefits like landscaping, community pool management, security, or maintenance.
SOC Examinations | Artificial Intelligence
By:
Schellman
August 22nd, 2023
Now that artificial intelligence (AI) has more fully engrained itself into the digital world and economy, it makes sense that the American Institute of Certified Public Accountants (AICPA)—as the organization that sets the most recognized auditing standards in the U.S.—would have an opinion on AI use, particularly in terms of the possibility of related SOC-compliance issues.