The Compass:
More posts

Blog Post
7 min read
How do I know what categories to choose for my SOC 2® report?
In general, all SOC 2 reports must cover the trust services criteria relevant to security, so that is a good place to start.
READ MORE

Blog Post
6 min read
Is the auditor’s role in a SOC 2® audit just to find gaps in our system?
During the audit process, we might identify gaps or control exceptions, but our role encompasses much more than that.
READ MORE

Article
Penetration Testing: Why It’s Important + Common Types
Penetration testing simulates an outside attack on your applications and network. Drata shares the types of pen tests and how to conduct one to prevent risk.
READ MORE






