Skip to main content

The Corner View

August 29, 2024

What’s Inside

Dive into our latest (and late) issue of “The Corner View,” where we explore “ISO 27001 or SOC Type II?”, uncover insights from “ILTACON – An Educational Conference,” and discuss the benefits of “Why Do a Tech Assessment.”

We hope you enjoy this edition and have a happy & safe Labor Day!

Are there any topics you would like to learn more about? Please email marriane.caraig@cornerstone.it.

— Marriane

ISO 27001 or SOC Type II?

In 2021, we built NIST 800 171 compliance into our managed services to ensure NIST standards are adhered to in real-time by both Cornerstone and its clients. Since then, many conversations occurred within Cornerstone and with our trusted certified information cybersecurity professional (CISSP) regarding which path we should take to reassure our clients that we continue to be serious about their IT security posture. As a national company, obtaining ISO 27001 certification seemed excessive. Did SOC Type II compliance make more sense? It boiled down to one key element that, in our opinion, made the effort of going for ISO 27001 certification worth the extra mile(s).

Before I reveal why we chose ISO 27001 certification, I need to point out that both ISO 27001 and SOC II certifications are valuable for Managed Service Providers (MSPs), serving slightly different purposes and offering distinct benefits to their clients. Here’s a high-level comparison:

(Skip the chart and jump to the reveal)

International Organization for Standardization (ISO) 27001 CertificationInternational Organization for Standardization (ISO) 27001 Certification
ScopeComprehensive information security management system (ISMS) covering policies, procedures, and controls.Focuses on five trust service criteria: security, availability, processing integrity, confidentiality, and privacy.
Continuous ImprovementEmphasizes ongoing improvement and regular audits to keep up with emerging threats.Focuses on maintaining controls but does not emphasize continuous improvement.
Global RecognitionRecognized worldwide as an international standard.Primarily recognized in the United States.
Risk ManagementProactively identifies and manages risks systematically.Focuses on maintaining controls but may not offer the same level of proactive risk management.
Certification BodyGranted by accredited certification bodies following a successful audit.Is not a certification, it is the auditor’s opinion of control efficacies on protecting data, also known as a ‘SOC II Attestation’. Achieved by obtaining a valid SOC II report from an independent third-party CPA firm.
Client AssuranceDemonstrates a commitment to high-security standards globally.Provides assurance to clients that the MSP has controls in place to protect their data.
Enhanced Data ProtectionProvides robust protection against data breaches and cyber threats with its comprehensive approach.Ensures data protection but may not be as comprehensive in overall information security management.

Simply put, this was not a quick or easy decision to make. While both certifications are valuable, Cornerstone.IT took the position to go beyond securing our internal systems and include how we manage and handle our clients’ systems. We believe that this additional component serves the best interests of our clients.

MSP Matters

Why Do a Tech Assessment?

Recently, I spoke on a panel at #ILTACON2024 about Strategy and Operations in legal IT and as October is Cybersecurity awareness month and the end of the year is approaching, it’s a good time to take stock in your IT operations. Are you ready for what’s next? Do you have the budget to achieve the strategic goals of the firm and the departmental goals you need to achieve in alignment? All this brings me back to technical assessments. Whether you do them yourself or get some help, taking stock of your technology, your team’s skills and your processes is never a bad thing. Many firms do them every few years as a self-check. They help you identify gaps that need to be addressed and points the way to solutions that may not be evident until you see everything summarized in one place.

Typically, assessments give you a rundown of your technology stack as a baseline but also where your team might need some upskilling. Assessments also find places to improve your processes and documentation to handle disasters and build a resilient, secure IT function. They answer questions like, what is your disaster recover plan? Have you tested it, fully? Do you test your backups? If you lose a key team member, are all your processes documented or locked in that individuals head? What if you experience a breach? Today, we know it’s a question of when, not if. Are your people and systems ready to minimize the impact and quickly recover? We don’t like to think about it happening to us, but being prepared is half the battle.

For 20 years, Cornerstone.IT has been a trusted legal partner, providing excellent service to the legal industry. We understand the unique challenges that law firms face today, and we have a deep understanding of the evolving landscape. As we start 2024, we are ready to face the challenges of the legal landscape with a deep team and a broad set of skills and tools to help you succeed.

Technical Assessments can be very quick and done over a few days for smaller environments or be much more involved if you are trying to answer bigger questions related to security and cloud readiness. Regardless of whether you perform the exercise yourself or contact someone like Cornerstone.IT to assist, knowing where you stand is never a bad thing. As the phrase goes, “There is no security in obscurity”. Knowing where you are today can only help you get to a better tomorrow.


by Adriana Vitale, Chief Business Development Officer

With over 4,000 attendees, ILTACON 2024 set a new attendance record. This milestone made me reflect on the conference’s broader impact. During my master’s in secondary education in the early 2000s, we were taught to emphasize critical thinking, interdisciplinary connections, and human interaction through perspective, reflection, and collaboration. These elements are what I associate with education, and as a former teacher, I constantly evaluate them.

So, how did ILTA fare in these aspects? Let’s reflect!

Jim Moreo, with fellow panel of industry-experts in the “Technology Assessment, Know Where You Stand” session at ILTACON 2024.

AI was a hot topic, almost a session staple. In discussions led by seasoned IT thought leaders, I witnessed the natural evolution of critical thinking and connections. The collection of experts, often inaccessible outside ILTACON, sparked conversations that transcended product innovations and bottom lines, leaving attendees deep in thought. While some sessions were dry, the exchange of experiences, ideas, and insights created a vibrant think tank. The conference’s spirited energy was palpable. I believe AI won’t diminish our intellect but will push us out of our comfort zones, fostering more creative “human” thinking and collaboration. Looks like I learned something – how about you?

Product EOLs

Microsoft

Microsoft Host Integration Server 2013
Visual Studio 2022 , Version 17.2 (LTSC channel)
Windows Server 2008, Extended Security Update
Windows Server 2008 R2, Extended Security

iManage

Classic Clients DeskSite / FileSite
Indexer powered by IDOL
FileShare

Citrix

NetScaler VPX-4 / VPX-6 / VPX-8 / VPX-10 / VPX-12 / VPX-16 / VPX-20