LakeRidge Blog

Compliance guides, checklists & news

Practical, control-by-control guidance for CMMC, NIST SP 800-171, HIPAA, ISO 27001 and NCA ECC — written by the team that gets companies certified.

Which Logs Prove Session Authenticity Maturity? (SC.L2-3.13.15)

Cybersecurity ·Jul 2026

Which Logs Prove Session Authenticity Maturity? (SC.L2-3.13.15)

Use session authenticity maturity evidence logs to score SC.L2-3.13.15 from ad hoc TLS proof to monitored, optimized mutual authentication.

What Vendor Policies Should a Dental Office Review in Microsoft 365?

HIPAA ·Jul 2026

What Vendor Policies Should a Dental Office Review in Microsoft 365?

Use this Microsoft 365 vendor policy review checklist for dental offices to tier vendors, collect evidence, and document HIPAA due diligence.

What Security Terms Go in an Offer Letter? ISO 27001 vs SOC 2 vs NIST

Cybersecurity ·Jul 2026

What Security Terms Go in an Offer Letter? ISO 27001 vs SOC 2 vs NIST

offer letter security terms ISO 27001 SOC 2 NIST map employment security clauses to evidence that supports enterprise reviews and audits.

What Questions Should You Ask a Media Disposal Vendor?

Cybersecurity ·Jul 2026

What Questions Should You Ask a Media Disposal Vendor?

Use these questions to ask a media disposal vendor about destruction methods, chain of custody, evidence, contracts, and ISO 27001 alignment.

What Google Cloud KPIs Show Health Plan Data Is Protected?

HIPAA ·Jul 2026

What Google Cloud KPIs Show Health Plan Data Is Protected?

Use google cloud kpis for health plan data protection to prove encryption, access, backups, monitoring, and incident reporting are working.

What Does a Signed Acceptable Use Policy Need to Cover? (1-9-4)

Cybersecurity ·Jul 2026

What Does a Signed Acceptable Use Policy Need to Cover? (1-9-4)

Learn what employee acceptable use policy cybersecurity requirements must cover under ECC 2:2024 control 1-9-4, including signed acknowledgments and awareness.

What Do SIEM Logs Need to Include for Network Security? (2-5-3)

Cybersecurity ·Jul 2026

What Do SIEM Logs Need to Include for Network Security? (2-5-3)

Network security management SIEM log requirements: the events, evidence, and approvals needed to support ECC 2:2024 practice 2-5-3.

What Do Auditors Look for in Microsoft 365 Event Triage?

Cybersecurity ·Jul 2026

What Do Auditors Look for in Microsoft 365 Event Triage?

What do auditors look for in microsoft 365 event triage? Clear assessment decisions, retained evidence, accountable owners, and incident escalation records.

What Clauses Require Subcontractors to Secure ePHI Workstations?

HIPAA ·Jul 2026

What Clauses Require Subcontractors to Secure ePHI Workstations?

Use subcontractor contract clauses for ePHI workstations to require HIPAA-aligned use rules, physical safeguards, evidence, audit access, and termination.

What Caused the Shared Chromebook ePHI Incident? Postmortem

HIPAA ·Jul 2026

What Caused the Shared Chromebook ePHI Incident? Postmortem

This shared Chromebook ePHI incident postmortem explains how an unsecured signed-in session exposed patient data and how to prevent recurrence.

What Caused a Google Apps Script Breach? Postmortem (SC.L2-3.13.13)

Cybersecurity ·Jul 2026

What Caused a Google Apps Script Breach? Postmortem (SC.L2-3.13.13)

A google apps script breach postmortem showing how an unapproved OAuth-enabled script exfiltrated files and how to evidence SC.L2-3.13.13.

What Audit Log KPIs Should a Compliance Officer Report Monthly?

HIPAA ·Jul 2026

What Audit Log KPIs Should a Compliance Officer Report Monthly?

Use an audit log kpis monthly compliance report to show HIPAA log coverage, review completion, alert response, retention, and control gaps.

What Are Physical Access Requirements for Google Workspace Devices?

HIPAA ·Jul 2026

What Are Physical Access Requirements for Google Workspace Devices?

Learn hipaa physical access requirements google workspace devices: protect offices, endpoints, visitors, and emergency access under HIPAA.

What Are HIPAA Device and Media Control Requirements in Microsoft 365?

HIPAA ·Jul 2026

What Are HIPAA Device and Media Control Requirements in Microsoft 365?

HIPAA device and media control requirements Microsoft 365: govern ePHI devices, removal, disposal, reuse, movement records, and backups.

What Are Audit Log Requirements for Patient Records? (164.312(b))

HIPAA ·Jul 2026

What Are Audit Log Requirements for Patient Records? (164.312(b))

Understand audit log requirements for patient records under HIPAA 164.312(b), including what to log, who is covered, and practical evidence of compliance.

Vulnerability Scans vs Pen Tests: Start With Scans (2-10-3)

Cybersecurity ·Jul 2026

Vulnerability Scans vs Pen Tests: Start With Scans (2-10-3)

Vulnerability scans vs penetration tests for small business: start with scheduled scans, then use pen tests to validate high-risk exposure.

Using PowerShell to Remove Former Vendor Access

Cybersecurity ·Jul 2026

Using PowerShell to Remove Former Vendor Access

Use powershell remove former vendor access workflows to disable accounts, revoke sessions, remove group access, and retain audit evidence.

Using Amazon Macie to Find and Tag CUI Files in S3 (MP.L2-3.8.4)

Cybersecurity ·Jul 2026

Using Amazon Macie to Find and Tag CUI Files in S3 (MP.L2-3.8.4)

Learn how using Amazon Macie to find and tag CUI files in S3 supports MP.L2-3.8.4 with discovery, tags, verification, and evidence.

Ultimate Guide to Off-Site Asset Security for MSSP Analysts

Cybersecurity ·Jul 2026

Ultimate Guide to Off-Site Asset Security for MSSP Analysts

An off-site asset security guide for MSSP analysts: protect client devices and media away from premises with evidence-ready ISO 27001 controls.

The Ultimate Guide to USB Evidence in Defender (MP.L2-3.8.8)

Cybersecurity ·Jul 2026

The Ultimate Guide to USB Evidence in Defender (MP.L2-3.8.8)

Use this defender usb ownership evidence checklist to block unowned removable media and prove MP.L2-3.8.8 compliance with Azure evidence.

The Ultimate Guide to Remote Worker File Scans (SI.L2-3.14.5)

Cybersecurity ·Jul 2026

The Ultimate Guide to Remote Worker File Scans (SI.L2-3.14.5)

cmmc remote worker antivirus scanning requires defined periodic scans and real-time scanning of externally sourced files when downloaded, opened, or executed.

The Ultimate Guide to Email TLS for Patient Data

HIPAA ·Jul 2026

The Ultimate Guide to Email TLS for Patient Data

This email TLS for patient data ultimate guide explains HIPAA transmission security, implementation evidence, a testing checklist, and audit FAQs.

The Ultimate Guide to CMMC Password Vaults (IA.L2-3.5.10)

Cybersecurity ·Jul 2026

The Ultimate Guide to CMMC Password Vaults (IA.L2-3.5.10)

This cmmc password vault guide explains how to protect stored and transmitted passwords for CMMC IA.L2-3.5.10 with evidence-ready steps.

The Ultimate Guide to a Vulnerability Board Deck (2-10-3)

Cybersecurity ·Jul 2026

The Ultimate Guide to a Vulnerability Board Deck (2-10-3)

Build a vulnerability management board deck that translates ECC 2-10-3 evidence into business risk, remediation progress, and decisions.

Single Breach vs Pattern: Which Triggers a Vendor Cure Plan?

HIPAA ·Jul 2026

Single Breach vs Pattern: Which Triggers a Vendor Cure Plan?

Single breach vs pattern vendor cure plan: HIPAA requires action when a known pattern creates material vendor contract violations.

Phishing Risk Policy Template for Employees (AT.L2-3.2.1)

Cybersecurity ·Jul 2026

Phishing Risk Policy Template for Employees (AT.L2-3.2.1)

Use this phishing risk policy template for employees to define reporting, training, testing, and evidence for CMMC Level 2 compliance.

Okta vs Entra ID: User Lifecycle Pricing for 50-User SaaS

Cybersecurity ·Jul 2026

Okta vs Entra ID: User Lifecycle Pricing for 50-User SaaS

Compare okta vs entra id user lifecycle pricing for 50-user saas, including tiers, M&A fit, ISO 27001 lifecycle controls, and alternatives.

Microsoft 365 CUI Access Policy Template: Screening Gates (PS.L2-3.9.1)

Cybersecurity ·Jul 2026

Microsoft 365 CUI Access Policy Template: Screening Gates (PS.L2-3.9.1)

Use this Microsoft 365 CUI access policy template to document screening gates before authorizing access to CUI systems under PS.L2-3.9.1.

In-House vs MSP Maintenance: Which Pays Back Faster? (MA.L2-3.7.1)

Cybersecurity ·Jul 2026

In-House vs MSP Maintenance: Which Pays Back Faster? (MA.L2-3.7.1)

Compare in-house vs msp maintenance cost, 12-month budgets, risk savings, and breakeven points for MA.L2-3.7.1 maintenance.

How to Set Up Continuous Microsoft 365 Security Alerts

HIPAA ·Jul 2026

How to Set Up Continuous Microsoft 365 Security Alerts

Learn how to set up continuous microsoft 365 security alerts with prioritized telemetry, Sentinel queries, tuning, and incident response workflows.

How to Set Google Session Length in Admin Console (SC.L2-3.13.9)

Cybersecurity ·Jul 2026

How to Set Google Session Length in Admin Console (SC.L2-3.13.9)

Learn to set Google Workspace session length admin console policies, test expiration, and produce SC.L2-3.13.9 evidence for assessors.

How to Run a Test Data Leak Tabletop Exercise

Cybersecurity ·Jul 2026

How to Run a Test Data Leak Tabletop Exercise

Run a test data leak tabletop exercise to validate containment, notification, evidence, and ISO 27001 test-information controls.

How to Require HTTPS for PHI in Azure App Service in 30 Minutes

HIPAA ·Jul 2026

How to Require HTTPS for PHI in Azure App Service in 30 Minutes

Learn to require https for phi azure app service with HTTPS Only, TLS 1.2, validation, and HIPAA evidence in 30 minutes.

How to Move Shared Clinic PCs to Badge Login in 30 Days

HIPAA ·Jul 2026

How to Move Shared Clinic PCs to Badge Login in 30 Days

Run a hipaa shared clinic pc badge login migration in 30 days with a phased plan, rollback controls, and evidence for HIPAA workstation security.

How to Move From Untracked USBs to a Check-Out Log

HIPAA ·Jul 2026

How to Move From Untracked USBs to a Check-Out Log

Learn how to move from untracked USBs to a check-out log with a phased HIPAA-ready process for inventory, custody, encryption, and validation.

How to Generate Employment Security Clauses with PowerShell

Cybersecurity ·Jul 2026

How to Generate Employment Security Clauses with PowerShell

Learn to generate employment security clauses with PowerShell using approved templates, HR data, audit logs, and review gates.

How to Destroy Keys Before Disk Disposal: Cloud KMS > Key Versions

Cybersecurity ·Jul 2026

How to Destroy Keys Before Disk Disposal: Cloud KMS > Key Versions

How to cloud kms destroy key versions before disk disposal with Google Cloud steps, verification, and ISO 27001 evidence.

How to Build an Azure Asset Inventory in 2 Hours

Cybersecurity ·Jul 2026

How to Build an Azure Asset Inventory in 2 Hours

Learn how to build an azure asset inventory in 2 hours using Azure Resource Graph, owners, and evidence for ISO 27001 5.9.

How to Approve Secure-Area Visitors in Microsoft Bookings

Cybersecurity ·Jul 2026

How to Approve Secure-Area Visitors in Microsoft Bookings

Configure Microsoft Bookings secure area visitor approval settings to require staff approval, document sponsor details, and retain visitor records.

How to Add ePHI Safeguards to Plan Documents in 60 Minutes

HIPAA ·Jul 2026

How to Add ePHI Safeguards to Plan Documents in 60 Minutes

Use a focused amendment package to add ephi safeguards to group health plan documents and create assessment-ready evidence in 60 minutes.

Fire Suppression vs Fire Detection: Server Rooms Need Both

Cybersecurity ·Jul 2026

Fire Suppression vs Fire Detection: Server Rooms Need Both

Fire suppression vs fire detection server room controls serve different purposes: detect and alert early, then contain or extinguish fire.

Does an Information Security Policy Need CEO Approval?

Cybersecurity ·Jul 2026

Does an Information Security Policy Need CEO Approval?

Does an information security policy need CEO approval? ISO 27001 requires management approval, not necessarily CEO sign-off.

DocuSign vs Ironclad: IP Agreement Pricing for Small Teams

Cybersecurity ·Jul 2026

DocuSign vs Ironclad: IP Agreement Pricing for Small Teams

docusign vs ironclad IP agreement pricing for small teams: DocuSign is cheaper for standard IP signatures; Ironclad suits complex contract workflows.

Cyber Incident vs Data Breach: Which Goes to the Prime? (IR.L2-3.6.2)

Cybersecurity ·Jul 2026

Cyber Incident vs Data Breach: Which Goes to the Prime? (IR.L2-3.6.2)

Cyber incident vs data breach prime contractor reporting: report contractually required incidents, not only confirmed breaches, and document every decision.

Can Vendor Escort Rules Reach a 2-Hour Baseline? (MA.L2-3.7.6)

Cybersecurity ·Jul 2026

Can Vendor Escort Rules Reach a 2-Hour Baseline? (MA.L2-3.7.6)

Meet cmmc vendor escort requirements with a two-hour baseline: named escorts, restricted temporary access, and maintenance logs an assessor can verify.

Can Google Drive Store CUI With FIPS Encryption? (SC.L2-3.13.11)

Cybersecurity ·Jul 2026

Can Google Drive Store CUI With FIPS Encryption? (SC.L2-3.13.11)

Learn whether can google drive store cui with fips encryption, what evidence is needed, and how SC.L2-3.13.11 applies.

Are API Endpoints Included in Pen Test Scope? (2-11-3)

Cybersecurity ·Jul 2026

Are API Endpoints Included in Pen Test Scope? (2-11-3)

API penetration testing scope requirements 2-11-3 explicitly include APIs supporting Internet-facing services under ECC 2:2024.

7 Unauthorized-Use Checks: 3-Hour Assessment Quick Start (SI.L2-3.14.7)

Cybersecurity ·Jul 2026

7 Unauthorized-Use Checks: 3-Hour Assessment Quick Start (SI.L2-3.14.7)

Use this CMMC unauthorized use assessment checklist to define authorized activity, review evidence, and baseline SI.L2-3.14.7 in three hours.

Showing the 48 most recent

Browse the full archive by framework

2764 control-by-control guides, checklists, and news — organized by the framework you need.