Debbie Zaller

Debbie is Principal and co-owner at Schellman & Company, LLC. She began her career in 2000 while working at Arthur Andersen in their Technology Risk Assurance practice. Debbie now leads the Midwest Region along with the Privacy, SOC 2 and SOC 3 service lines and is also on the AICPA’s SOC Specialist Task Force. She is responsible for internal training, methodology creation, and quality reporting. Debbie was a past member of the Florida Institute of Certified Public Accountants’ Board of Governors and served on the Finance and Office Advisory Committee. She also served on the AICPA’s Advanced SOC for Service Organizations Certificate Task Force.

  • Cross-Border Privacy System Gains Second U.S. Compliance Agent

    Cross-Border Privacy System Gains Second U.S. Compliance Agent

    (Article originally published on BloombergLaw.com)

    Read Article
  • APEC announces new US accountability agent for CBPR certifications

    APEC announces new US accountability agent for CBPR certifications

    The Asia-Pacific Economic Cooperation is set to boost the status of its Cross-Border Privacy Rules program in the U.S.

    Read Article
  • 8 Steps to Effective Multi-Cloud Cost Management

    8 Steps to Effective Multi-Cloud Cost Management

    Strategic thinking and careful planning can help you squeeze the maximum value out of your multi-cloud environment. Here are eight tips to help you get started.

    Read Article
  • SOC, Meet Cybersecurity

    SOC, Meet Cybersecurity

    As global cyberattacks become more common, organizations are fine tuning, or even implementing, a cybersecurity risk management program

    Read Article
  • What You Need to Know About Changes to the STAR Program

    What You Need to Know About Changes to the STAR Program

    The CSA recently announced that the STAR Program will now allow a one-time, first-year only, Type 1 STAR Attestation report. What is a Type 1 versus Type 2 examination and what are the...

    Read Article
  • Tell The World: "I've Completed My Audits!!"

    Tell The World: "I've Completed My Audits!!"

    Read Article
  • 5 Simple Steps for Creating an Effective Change Management Program

    5 Simple Steps for Creating an Effective Change Management Program

    Identifying changes that must be made is the easy part. Managing those changes successfully—not so simple! Organizations today need to be extraordinary at adapting to or influencing changes in...

    Read Article
  • How CISOs Can Work With Other Execs to Manage Information Security Risks

    How CISOs Can Work With Other Execs to Manage Information Security Risks

    Unfortunately, 2015 saw some seriously impressive information security hacks, the likes of which included those at major companies and entities like VTech, T-Mobile, the FBI, and even Trump...

    Read Article
  • Privacy Principle Undergoes an Overhaul.

    Privacy Principle Undergoes an Overhaul.

    The AICPA just released an updated version of TSP Section 100. The update amends TSP Section 100 and supersedes Appendix C of TSP Section 100A, which relates to the Generally Accepted Privacy...

    Read Article
  • Tips for Creating a Security Whistleblower Strategy

    Tips for Creating a Security Whistleblower Strategy

    When you hear the word “whistleblower,” do you think business traitor or Good Samaritan? In most company cultures, it tends to be the former, which is unfortunate because more often than not,...

    Read Article
  • 4 Tips for Minimizing Internal Fraud

    4 Tips for Minimizing Internal Fraud

    Your company has internal security measures in place, and it has met many compliance requirements. But do these things mean your business is now immune to fraud? Probably not. Research shows that...

    Read Article
  • 3 Things CEOs Need to Know About Compliance

    3 Things CEOs Need to Know About Compliance

    As CEO of your company, you’ve worked hard to grow the business and ensure success. But there can be a roadblock to future growth of your organization—lack of compliance. This can have several...

    Read Article
  • Does PCI provide an Attestation of Compliance report?

    Does PCI provide an Attestation of Compliance report?

    The result of a compliant PCI DSS assessment is the generation of an Attestation of Compliance (AOC) as well as a Report on Compliance (RoC). The AOC is attesting to the organization’s compliance...

    Read Article
  • How Compliance Leaders Can Prepare Companies for Audits

    How Compliance Leaders Can Prepare Companies for Audits

    Nobody likes a compliance audit, but they serve a necessary purpose in the business world. If an organization is lacking in its adherence to global compliance regulations, there could be serious...

    Read Article
  • Can An Organization Keep Using The Old TSPs?

    Can An Organization Keep Using The Old TSPs?

    My company completes SOC 2 audits annually, and have for the last several years based on the old trust criteria. Our processes and our customer prefer the old criteria. Can we continue to have the...

    Read Article
  • Segregation of Duties and Compensating Controls

    Segregation of Duties and Compensating Controls

    Segregation of Duties, Agile and DevOps development models may create scenarios where traditional SOD is impractical. Can compensating controls be considered for those requirements? Do you have...

    Read Article
  • Exposure Draft for Updates to the TSP Section 100

    Exposure Draft for Updates to the TSP Section 100

    The Assurance Services Executive Committee (ASEC) of the American Institute of Certified Public Accountants (AICPA) issued an exposure draft on June 15, 2015, to amend the Trust Services...

    Read Article
  • Do Most Organizations Attest to TSP's?

    Do Most Organizations Attest to TSP's?

    Do most organizations attest to all of the TSP's? If not, how do you decide which TSP best suits what's required for your organization?

    Read Article
  • SOC 2 Type 1 and Type 2: A Quick Overview

    SOC 2 Type 1 and Type 2: A Quick Overview

    Can you provide a quick overview on what a SOC 2 examination snd the difference between a Type 1 and Type 2 report? In early 2011, the AICPA issues its Service Organization Control (SOC) reporting...

    Read Article
  • SOC Examination: Is there a SOC certification similar to an ISO 27001 certification?

    SOC Examination: Is there a SOC certification similar to an ISO 27001 certification?

    Is there a SOC certification similar to an ISO 27001 certification?

    Read Article
  • loading
    Loading More...