External compliance assessment

Know where you stand before an auditor or a customer asks.

It starts from each control in your framework and works backwards to what can be verified from the internet. It covers the assets on your boundary, like mail, web, APIs, remote access, and DNS, and determines the software versions, encryption levels, and configurations that map to the framework.

Who does the work

I have been on both sides of the assessment.

On one side, I ran third-party risk assessments of 171 companies at a Fortune 200 global bank. On the other:

Mergers and Acquisition

Acquired by our customer

I led our HITRUST r2 assessment from the inside: the gap assessment, remediating the controls that had to pass in each domain, and assembling the evidence for the assessors. That certification won customer trust and gave Optum, already one of our customers, the confidence in our systems to acquire us.

I have also been through a HIPAA assessment that ended with a CPA firm's certificate.

How it works

What anyone on the internet can verify about you, mapped to your framework.

It is read-only, and nothing is exploited. Where the traffic comes from, how it identifies itself, and what it will not do are published on the Scanning page.

If I emailed you about something I observed, that finding is a sample of this assessment.

Timeline
One week
You get
  • An external posture inventory
  • A control scorecard
  • Findings with recommendations
  • A prioritized remediation roadmap
  • A live readout

It is not a PCI ASV scan and does not replace one.

Sample findings

Two findings in the format every report uses, with identifying details removed.

Severity: High

Internet-facing SSH jump box

Observation
The SSH service on a jump box answered a connection from an outside address. It is reachable from the entire internet, not just from the office or the VPN.
Criteria
NIST SP 800-53 AC-17 (Remote Access), HIPAA §164.312(a)(1) (Access Control), and HITRUST Domain 08 (Network Protection).
Impact
Malicious actors from the entire internet can attempt to brute force their way into the jump box as a way of gaining initial entry into the data environment. Even if password authentication is disabled, vulnerabilities in the SSH service like CVE-2024-6387 and CVE-2024-6409 can still allow remote code execution from any source.
Recommendation
Measure who and what is legitimately interacting with the jump box. Restrict access to known IP ranges. If unrestricted public access has to remain, conduct a risk analysis to identify mitigating controls and record an exception in the company's risk register.

Severity: Medium

TLS 1.0 and 1.1 accepted on a public hostname

Observation
A public-facing host completes TLS 1.0 and TLS 1.1 handshakes, both obsolete protocol versions.
Criteria
NIST SP 800-52 Rev. 2 (TLS guidelines), HITRUST Domain 09 (Transmission Protection), HIPAA §164.312(a)(2)(iv) (Encryption and Decryption), and PCI DSS 4.2.1 (strong cryptography for cardholder data in transit).
Impact
TLS 1.0 has known cryptographic weaknesses. A network-positioned attacker can downgrade or decrypt traffic to this host, exposing data in transit.
Recommendation
Measure whether anything is actually interacting with these services on TLS 1.0, then set the minimum protocol version to TLS 1.2 on whatever terminates these hostnames. Create guardrails to prevent new services from offering TLS 1.0.

Framework mapping

Each category of finding maps to the controls it is evidence toward. Only direct matches are shown: where a framework has no control that speaks to a finding directly, it is left out rather than stretched to fit.

  • Exposed remote access service

    SSH answering connections from any address on the internet

    • SOC 2 CC6.1, CC6.6
    • HIPAA §164.312(a)(1)
    • HITRUST Domain 08
    • ISO 27001 A.8.20, A.8.22
    • PCI DSS 1.3.1, 1.4.2, 8.4.3
    • NIST CSF PR.IR-01
    • NIST 800-53 AC-17, SC-7
  • Dangling DNS record

    A name under your domain that points at something you no longer run

    • SOC 2 CC6.1
    • ISO 27001 A.5.9, A.8.9
    • NIST CSF ID.AM-08
    • NIST 800-53 CM-8
  • End-of-life software version

    A server or platform past the end of the vendor's support lifecycle

    • SOC 2 CC7.1
    • HIPAA §164.308(a)(1)(ii)(B), §164.308(a)(5)(ii)(B)
    • HITRUST Domain 07
    • ISO 27001 A.8.8, A.8.19
    • PCI DSS 6.3.3, 12.3.4
    • NIST CSF PR.PS-02
    • NIST 800-53 SA-22, SI-2
  • Missing security headers

    Browser protections the web server never asks the browser to use

    • SOC 2 CC6.6
    • HITRUST Domain 06
    • ISO 27001 A.8.9
    • PCI DSS 2.2.1
    • NIST CSF PR.PS-01
    • NIST 800-53 CM-6
  • Weak TLS configuration

    Protocol versions or cipher suites that should have been retired

    • SOC 2 CC6.7, CC6.1
    • HIPAA §164.312(e)(1), §164.312(a)(2)(iv)
    • HITRUST Domain 09
    • ISO 27001 A.8.24, A.5.14
    • PCI DSS 4.2.1, 2.2.7
    • NIST CSF PR.DS-02
    • NIST 800-53 SC-8, SC-13
  • Broken mail authentication

    SPF, DKIM, or DMARC that lets someone else send as your domain

    • SOC 2 CC6.6
    • ISO 27001 A.5.14
    • PCI DSS 5.4.1

References are to the 2017 Trust Services Criteria for SOC 2, the HIPAA Security Rule at 45 CFR Part 164, the HITRUST CSF assessment domains, ISO/IEC 27001:2022 Annex A, PCI DSS v4.0.1, NIST CSF 2.0, and NIST SP 800-53 Rev. 5.

How they build on each other

Each step can lead to the next.

  1. 01

    A finding

    Something I observed from the outside and emailed you about.

  2. The whole outside view, mapped to your framework.

  3. The inside view: your policies, controls, and the evidence behind them.

  4. Scoped from what the assessments found.

The business case

Enterprise security reviewers and cyber insurers often check what you expose to the internet before they ask you anything. Seeing it first means you fix it before it comes up in a deal or a renewal.

The compliance case

Supporting evidence for:

  • SOC 2 CC3.2, CC4.1
  • HIPAA §164.308(a)(1)(ii)(A), §164.308(a)(8)
  • ISO 27001 A.5.35
  • NIST CSF ID.IM-01
  • NIST 800-53 CA-2

References are to the 2017 Trust Services Criteria for SOC 2, the HIPAA Security Rule at 45 CFR Part 164, ISO/IEC 27001:2022 Annex A, NIST CSF 2.0, and NIST SP 800-53 Rev. 5.

Pricing

A fixed fee, quoted after a 30-minute scoping call.

What moves the price:

  • The framework
  • Company size, and how many systems, cloud accounts, or domains are in scope

Start with a conversation.

The right engagement depends on what you’re building and where the gaps are. A 30-minute call gets us to whether and how I can help.