Skip to Main Content

Compliance Risk Assessments

Evaluate and treat risks related to in-scope assets

Stay up-to-date on risk assessment requirements

Risk assessments are required as part of many regulatory and contractual processes, and ISO 27005, NIST 800-30, PCI DSS all include specific practices for performing these assessments. Our risk assessments use specific practices for evaluating and treating risks related to in-scope assets. The ISO 27005 methodology aligns closely with the requirements of ISO 27001, while NIST SP 800-30 methodology is often used to support other federal requirements including NIST SP 800-53, NIST SP 800-171, CMMC, and HIPAA.

Related Links

“Weaving risk, group theory, and adaptation with business strategy is one way we stand out.”
Rockie BrockwayDirector of Advisory Innovations

Read Our Blog

Explore current cybersecurity topics on the TrustedSec Security Blog

Blog May 04 2023

Why Risk Assessments are Essential for Information Security Maturity

Introduction Many compliance frameworks require Information Security Risk Assessments, and some organizations may receive third-party requests for Risk…

Read about this article
Blog July 24 2026

CCPA Update: Cybersecurity Requirements (Part 2)

Confirmed you're in scope for CCPA? Now comes the cybersecurity audit requirement. In Part 2 of this blog series, we cover what it entails, the phased…

Read about this article
Blog July 23 2026

CCPA Update: Who’s In Scope (Part 1)

California updated CCPA... again. Before you do anything else, does it apply to you? In Part 1 of this blog series, we clarify who falls under scope, what data…

Read about this article
Blog July 21 2026

The New Hotness in Phishing: Device Code Attacks in M365

Device code phishing is quietly becoming one of the more effective techniques targeting M365 environments. In this blog, we detail how it works and the…

Read about this article
Blog July 16 2026

CMMC is (Not) Cancelled

Just because CMMC Phase II audits are paused doesn't mean compliance is. In this blog, we clarify what the suspension means for defense contractors and why…

Read about this article
Blog July 14 2026

Pandora’s Container Part 1: Unpacking Azure Container Security

Azure container services are everywhere. Their attack surface? Often overlooked. In Part 1 of this blog series, we walk through offensive techniques targeting…

Read about this article
Blog July 09 2026

Vulnify: Giving Your Agents a CVE Brain

The CVE brain your AI agent has been missing. In this blog, we introduce Vulnify, an open-source tool that stitches eight authoritative vulnerability databases…

Read about this article
Blog July 07 2026

Welcoming ObfusGit

What if your public repo could stay out of AI training data without changing how you commit? In this blog, we introduce ObfusGit, a Python tool that obfuscates…

Read about this article
Blog July 02 2026

Inheriting the Receipts: Securing the AI Your Company Already Adopted

The work is not new. The speed is. In this blog, we're outlining how existing security pillars apply to the AI your organization has already adopted; no new…

Read about this article
Blog June 25 2026

Large Workflows with Local LLMs

As it turns out, local LLMs have a few opinions about large workflows. In this blog, we walk through the scaling challenges of local LLMs and the custom Python…

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.