<?xml version='1.0' encoding='UTF-8'?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:video="http://www.google.com/schemas/sitemap-video/1.1" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1"><url><loc>https://knowledge.sensiba.com/employee-onboarding-checklist</loc><lastmod>2026-05-28</lastmod></url><url><loc>https://knowledge.sensiba.com/vendor-management-framework</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/best-practices/soc-2-system-security/acceptable-use-policy</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/type-1-vs-type-2-audits</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/vulnerability-scanning</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/the-board-of-directors-just-enough-governance-for-early-stage-companies</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/vulnerability-management-policy</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/governance-requirements/information-security-capability</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/the-drata-playbook</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/network-security/physical-security</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/governance-requirements/boundaries-of-cdr-data-environment</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/best-practices/soc-2-system-security/perimeter-security</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/terms-of-service-msa-sow-and-eula-your-key-customer-agreements</loc><lastmod>2026-06-01</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/anti-malware/anti-malware-practices</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/acceptable-use-policy-1</loc><lastmod>2026-05-28</lastmod></url><url><loc>https://knowledge.sensiba.com/gdpr-and-audit-requirements</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/information-asset-lifecycle/information-classification-and-handling-policy</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/incident-tracking-and-root-cause-analysis-a-streamlined-approach</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/vendor-attestation-reports</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/conducting-access-reviews</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/statement-of-applicability-what-you-need-to-know</loc><lastmod>2026-05-27</lastmod></url><url><loc>https://knowledge.sensiba.com/get-policy-ready-with-sensibas-automation-tool</loc><lastmod>2026-06-08</lastmod></url><url><loc>https://knowledge.sensiba.com/type-2-quickstart-guide</loc><lastmod>2026-06-09</lastmod></url><url><loc>https://knowledge.sensiba.com/risk-management-in-vanta</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/security-awareness/acceptable-use-policy</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/security-awareness/background-checks</loc><lastmod>2026-06-01</lastmod></url><url><loc>https://knowledge.sensiba.com/a-change-is-coming-to-how-you-log-into-pillar</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/incident-response-test</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/vulnerability-management/vulnerability-management-program</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/risk-assessments</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/best-practices/soc-2-system-operations/business-continuity-disaster-recovery</loc><lastmod>2026-05-28</lastmod></url><url><loc>https://knowledge.sensiba.com/what-is-an-assessment</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/best-practices/soc-2-change-management/software-development</loc><lastmod>2026-06-01</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/vulnerability-management/change-control-policy-environment</loc><lastmod>2026-05-28</lastmod></url><url><loc>https://knowledge.sensiba.com/preparing-for-your-iso-27001-stage-2-audit</loc><lastmod>2026-05-27</lastmod></url><url><loc>https://knowledge.sensiba.com/information-security-policies</loc><lastmod>2026-06-01</lastmod></url><url><loc>https://knowledge.sensiba.com/penetration-testing</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/vanta-quick-start-guide-soc2-type-1</loc><lastmod>2026-06-09</lastmod></url><url><loc>https://knowledge.sensiba.com/best-practices/soc-2-risk-management-and-internal-controls/vendor-risk-management</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-rep-attestations</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/continuous-audit-pillar</loc><lastmod>2026-05-28</lastmod></url><url><loc>https://knowledge.sensiba.com/iso-27001-internal-audits-key-things-to-know</loc><lastmod>2026-05-27</lastmod></url><url><loc>https://knowledge.sensiba.com/vendor-management-in-vanta</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/access-control/access-control-policy</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/penetration-testing-the-expected-requirements-of-enterprise</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/best-practices/soc-2-control-environment/policies</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/best-practices/soc-2-control-environment/governance</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/security-awareness/security-awareness-training</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/vanta-quick-start-guide-soc2-type2</loc><lastmod>2026-06-05</lastmod></url><url><loc>https://knowledge.sensiba.com/conducting-an-effective-incident-response-tabletop-exercise</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/access-control/user-access-reviews</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/ai-review</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/the-importance-of-cybersecurity-insurance-protecting-your-business-and-meeting-enterprise-expectations</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/network-security/the-cdr-policy</loc><lastmod>2026-06-01</lastmod></url><url><loc>https://knowledge.sensiba.com/terms-of-service</loc><lastmod>2026-06-01</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/access-control/joiners-leavers-checklists</loc><lastmod>2026-05-28</lastmod></url><url><loc>https://knowledge.sensiba.com/best-practices/soc-2-risk-management-and-internal-controls/risk-management</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/governance-requirements/cdr-security-governance</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/understanding-privacy-trust-services-criteria</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/faq-vanta-velocity</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/risk-management-policy-framework</loc><lastmod>2026-06-08</lastmod></url><url><loc>https://knowledge.sensiba.com/best-practices/soc-2-information-and-communication/boundaries-of-the-system</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/awareness-updates-on-security-and-incident-management</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/anti-malware/anti-virus-software</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/vulnerability-scanning-essential-practices-for-continuous-security</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/streamlining-access-termination-protecting-your-data-when-employees-and-contractors-exit</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/audit-findings-in-soc-1-soc-2-audits-what-do-they-mean</loc><lastmod>2026-06-01</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/network-security/encryption</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/continuous-audit-for-tailored-audits</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com</loc><image:image><image:loc>https://explore.sensiba.com/hubfs/Sensiba%20Rebrand%20Assets/Images/Sensiba_Logo_Hubspot-01.png</image:loc><image:caption>SensibaLogoHubspot01</image:caption><image:title>SensibaLogoHubspot01</image:title></image:image><lastmod>2026-05-04</lastmod></url><url><loc>https://knowledge.sensiba.com/best-practices/soc-2-system-security/user-access-controls</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/what-is-iso-27001</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/best-practices/soc-2-change-management/change-communications</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/disaster-recovery-plan</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/information-logging</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/best-practices/soc-2-control-environment/code-of-conduct</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-infrastructure-security-validations</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/policy-tree</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/kb-404</loc><image:image><image:loc>https://explore.sensiba.com/hubfs/Sensiba%20Rebrand%20Assets/Images/Sensiba_Logo_Hubspot-01.png</image:loc><image:caption>SensibaLogoHubspot01</image:caption><image:title>SensibaLogoHubspot01</image:title></image:image><lastmod>2026-05-04</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/governance-requirements/controls-assessment-program</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/drata-starter-faqs</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/encryption</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/data-classification-and-handling-policies</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/release-management-checklist</loc><lastmod>2026-05-28</lastmod></url><url><loc>https://knowledge.sensiba.com/privacy-policy</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/system-description</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/best-practices/soc-2-change-management/the-product-backlog</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/best-practices/soc-2-information-and-communication/customer-communications</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/how-do-i-document-management-meetings</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/security-awareness-training-1</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/end-user-device-controls</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/network-security/segregation-of-duties</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/best-practices/soc-2-data-protection/confidentiality</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/independent-code-review-systematically-enforced-segregation-of-duties</loc><lastmod>2026-06-01</lastmod></url><url><loc>https://knowledge.sensiba.com/quickstart-guide</loc><lastmod>2026-06-09</lastmod></url><url><loc>https://knowledge.sensiba.com/background-checks-finding-the-right-balance-for-compliance</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/user-access-reviews</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/cdr-guides/governance-requirements/manage-and-report-security-incidents</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/kb-search-results</loc><image:image><image:loc>https://explore.sensiba.com/hubfs/Sensiba%20Rebrand%20Assets/Images/Sensiba_Logo_Hubspot-01.png</image:loc><image:caption>SensibaLogoHubspot01</image:caption><image:title>SensibaLogoHubspot01</image:title></image:image><lastmod>2026-05-04</lastmod></url><url><loc>https://knowledge.sensiba.com/change-management-policy-change-control-process</loc><lastmod>2026-05-28</lastmod></url><url><loc>https://knowledge.sensiba.com/business-continuity-and-disaster-recovery-bcp/dr-testing</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/incident-management-policy</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/access-provisioning-balancing-control-with-practicality</loc><lastmod>2026-05-06</lastmod></url><url><loc>https://knowledge.sensiba.com/soc-2-trust-service-criteria-what-are-they</loc><lastmod>2026-05-06</lastmod></url></urlset>