Event

Compliance & Certification

12
examples

Compliance & Certification

Mailerlite

at

Mailerlite

Got questions about email marketing and GDPR? We compiled 99 (yes, 99!) FAQs to debunk the myths, state the facts and give you and your subscribers peace of mind. #GDPR #emailmarketing #email

Open in Linkedin

Got questions about email marketing and GDPR? We compiled 99 (yes, 99!) FAQs to debunk the myths, state the facts and give you and your subscribers peace of mind.

#GDPR#emailmarketing#email

mailerlite-international_TpmO
Air

at

Air

We are proud to announce that Air is now SOC 2 compliant! πŸ”’ Click through to learn about how we achieved this important milestone (with the help of Drata) and what it means for our ongoing commitment to privacy and security.

Open in Linkedin

We are proud to announce that Air is now SOC 2 compliant! πŸ”’ Click through to learn about how we achieved this important milestone (with the help of Drata) and what it means for our ongoing commitment to privacy and security.

airhq_DdHV
Contractbook

Founder & CEO

at

Contractbook

Seriously, Viktor Heide is right for once!! Who would have guessed? Its now officially past the 25th of May (gdpr day) and your business has not drowned in fines yet.. But should you be data ethical? we work towards helping our clients with getting automated consent, sending DPAs and much more. We made the solution for ourselves, but sharing is caring! So use it, be happy and avoid fines in the future as well.

Open in Linkedin

Seriously,Viktor Heideis right for once!! Who would have guessed?

Its now officially past the 25th of May (gdprday) and your business has not drowned in fines yet.. But should you be data ethical? we work towards helping our clients with gettingautomated consent, sending DPAsand much more.

We made the solution for ourselves, but sharing is caring! So use it, be happy and avoid fines in the future as well.

niels-martin-brochner-18a7b1b_qC9F
Mailerlite

at

Mailerlite

Are your opt-in forms GDPR compliant? With all the different rules to follow, things can get confusing. Grab yourself a coffee and check out our guide on how to create opt-in forms that work and still comply with GDPR legislation. #GDPR #emailmarketing #newsletter

Open in Linkedin

Are your opt-in forms GDPR compliant? With all the different rules to follow, things can get confusing.

Grab yourself a coffee and check out our guide on how to create opt-in forms that work and still comply with GDPR legislation.

#GDPR#emailmarketing#newsletter

mailerlite-international_uDA1
Hubspot

Change Management Project Manager

at

Hubspot

You can now become a Certified Revenue Operations Professional! On April 1, HubSpot Academy launched an entire course on Revenue Operations. The certification is full of templates and strategies based on best practices from current operators and business leaders.We’d love for you to take it, and have you share your opinion on it with us, and with the world! What does the course entail? Introduction to RevOps Applying RevOps to the Flywheel Holding Your Teams Accountable With an SLA How to Map a Sales Process Systems Management for RevOps Communicating the Value of RevOps to Company Leaders Structuring Your RevOps Team Hiring RevOps Team Members Evaluating and Iterating Your RevOps Strategy https://lnkd.in/eyStYYp7 Courses & Lessons

Open in Linkedin

You can now become a Certified Revenue Operations Professional!

On April 1, HubSpot Academy launched an entire course on Revenue Operations. The certification is full of templates and strategies based on best practices from current operators and business leaders.We’d love for you to take it, and have you share your opinion on it with us, and with the world!

What does the course entail?

Introduction to RevOps
Applying RevOps to the Flywheel
Holding Your Teams Accountable With an SLA
How to Map a Sales Process
Systems Management for RevOps
Communicating the Value of RevOps to Company Leaders
Structuring Your RevOps Team
Hiring RevOps Team Members
Evaluating and Iterating Your RevOps Strategy

https://lnkd.in/eyStYYp7


Courses & Lessons

dzalaquett_QlOs
Drata

Cybersecurity Risk Management & Compliance

at

Drata

Misinformation about information security compliance is all over the place. Below are some of the myths I hear on a regular basis. #SOC2 🚫 SOC2 is a certification 🚫 The Points of Focus are required to be met 🚫 All five Trust Services Categories are required 🚫 SOC2 prescribes the controls that are required 🚫 An organization can provide their cloud service provider's SOC2 report (i.e. AWS) to their customers and they do not need to obtain their own SOC2 report #ISO27001 🚫 Only accredited certifications can be issued 🚫 Annex A controls are required to be implemented 🚫 ISO 27002 implementation guidance is required 🚫 The risk assessment must follow ISO 27005 guidance 🚫 Certification means non-conformities were not identified #HIPAA 🚫 An organization can be certified against HIPAA 🚫 An organization is only required to comply with HIPAA if they sign a Business Associate Agreement (BAA) with a Covered Entity (CE) 🚫 Business Associates are not required to adhere to the Privacy Rule 🚫 Information collected by personal fitness trackers is covered by HIPAA #PCI 🚫 Levels are determined by the PCI Security Standards Council (PCI SSC) 🚫 PCI SSC determines the validation requirements for each level 🚫 PCI compliance is only required if your organization stores cardholder data 🚫 Self-Assessment Questionnaires (SAQs) must be completed by a Qualified Security Assessor #CMMC 🚫 The Cyber AB determines the control requirements for each level 🚫 The assessment objectives from NIST 800-171A are not required 🚫 Primes will actually take the time to identify which subcontractors are provided CUI 🚫 The DoD has this all under control #compliance 🚫 Achieving compliance and certification means an organization is secure 🚫 Compliance does not provide any value from a security perspective to an organization 🚫 All auditors are not technical and do not understand security 🚫 Control mapping documents are an easy button when it comes to proving conformance to multiple standards What did I miss?

Open in Linkedin

Misinformation about information security compliance is all over the place. Below are some of the myths I hear on a regular basis.

#SOC2
🚫 SOC2 is a certification
🚫 The Points of Focus are required to be met
🚫 All five Trust Services Categories are required
🚫 SOC2 prescribes the controls that are required
🚫 An organization can provide their cloud service provider's SOC2 report (i.e. AWS) to their customers and they do not need to obtain their own SOC2 report

#ISO27001
🚫 Only accredited certifications can be issued
🚫 Annex A controls are required to be implemented
🚫 ISO 27002 implementation guidance is required
🚫 The risk assessment must follow ISO 27005 guidance
🚫 Certification means non-conformities were not identified

#HIPAA
🚫 An organization can be certified against HIPAA
🚫 An organization is only required to comply with HIPAA if they sign a Business Associate Agreement (BAA) with a Covered Entity (CE)
🚫 Business Associates are not required to adhere to the Privacy Rule
🚫 Information collected by personal fitness trackers is covered by HIPAA

#PCI
🚫 Levels are determined by the PCI Security Standards Council (PCI SSC)
🚫 PCI SSC determines the validation requirements for each level
🚫 PCI compliance is only required if your organization stores cardholder data
🚫 Self-Assessment Questionnaires (SAQs) must be completed by a Qualified Security Assessor

#CMMC
🚫 The Cyber AB determines the control requirements for each level
🚫 The assessment objectives from NIST 800-171A are not required
🚫 Primes will actually take the time to identify which subcontractors are provided CUI
🚫 The DoD has this all under control

#compliance
🚫 Achieving compliance and certification means an organization is secure
🚫 Compliance does not provide any value from a security perspective to an organization
🚫 All auditors are not technical and do not understand security
🚫 Control mapping documents are an easy button when it comes to proving conformance to multiple standards

What did I miss?

troyjfine_RcWV
Hubspot

Chief of Staff to the CEO

at

Hubspot

According to the IDC, global data creation expected to reach 180 zettabytes by 2025. Zettabytes. That's why more and more companies are (and should) be thinking about how they manage and use their customers', employees', and users' data. At HubSpot, we talk a lot about how to ethnically handle data and privacy, and we use our company values as a guide. Beliefs like transparency and fairness are key to ethnical data management. In this new article from Nicholas Knoop, who leads HubSpot's Head of Privacy & Data Protection, he shares our company's framework for prioritizing trust in our approach. Shout out to Nick and Kritika Langhauser for helping us learn more about sustainable governance each day!

Open in Linkedin

According to the IDC, global data creationexpected to reach 180 zettabytes by 2025. Zettabytes.

That's why more and more companies are (and should) be thinking about how they manage and use their customers', employees', and users' data. At HubSpot, we talk a lot about how to ethnically handle data and privacy, and we use our company values as a guide. Beliefs like transparency and fairness are key to ethnical data management.

In this new article from Nicholas Knoop, who leads HubSpot's Head of Privacy & Data Protection, he shares our company's framework for prioritizing trust in our approach. Shout out to Nick and Kritika Langhauser for helping us learn more about sustainable governance each day!

hannahfleishman_Tjdn
Mailerlite

at

Mailerlite

GDPR: The sequel. Get the scoop on what’s happened since the GDPR kicked in (featuring new laws, shorter email lists and some hefty fines)! #GDPR #emailmarketing

Open in Linkedin

GDPR: The sequel. Get the scoop on what’s happened since the GDPR kicked in (featuring new laws, shorter email lists and some hefty fines)!

#GDPR#emailmarketing

mailerlite-international_2C1L
Zendesk

at

Zendesk

Make sure your agents are ready for anything with the Zendesk Omnichannel Agent Specialist Exam. πŸ’ͺ πŸ’» πŸ†

Open in Linkedin

Make sure your agents are ready for anything with the Zendesk Omnichannel Agent Specialist Exam. πŸ’ͺ πŸ’» πŸ†

zendesk_pPOD
Top Performing
Mailerlite

at

Mailerlite

Save
Copy

GDPR: The sequel. Get the scoop on what’s happened since the GDPR kicked in (featuring new laws, shorter email lists and some hefty fines)! #GDPR #emailmarketing

GDPR: The sequel. Get the scoop on what’s happened since the GDPR kicked in (featuring new laws, shorter email lists and some hefty fines)!

#GDPR#emailmarketing

mailerlite-international_2C1L
Top Performing
PROΒ FEATURE
Get Postwell Pro to unlock all examples
Get Postwell Pro