Maintain Compliance
From our experience working with high-growth technology companies subject to a myriad of compliance obligations, maintaining security and privacy compliance initiatives throughout the year is a prominent challenge that requires good management and a thorough understanding of reoccurring activities. If no one is tracking which requirements happen at what frequency, and who is in charge of ensuring they are completed, it’s easy to get lost. Documenting such details is the first step in understanding compliance program requirements that span business units, product teams, and geographical locations. Here is a helpful checklist to help think through ways to manage ongoing compliance, generally:- Inventory the Universe: Start by taking an inventory of the business’ regulatory and compliance universe (e.g., PCI DSS, SOC 2, HITRUST, GDPR, etc.) and the scope of those requirements. For example, the entire business may need to comply with GDPR, but perhaps only one or more products require a SOC 2 report.
- Understand the Overlap: Map the overlap of compliance requirements across compliance programs (e.g., user access reviews may be done once and provided to meet PCI DSS, SOC 2, HITRUST, etc. requirements). When feasible, utilization of a GRC platform, such as Phalanx GRC, can help to automate and synchronize these efforts as well as the collection of evidence.
- Assign Responsibility & Accountability: Assign control owners to each control/requirement across all programs (consider the scope of each compliance program).
- Collect Evidence Once: Ensure control owners understand their responsibility for operating controls, providing audit evidence per a defined cadence, and how to provide that evidence to a centralized repository (that may be used for various compliance programs).
- Implement Notifications & Technology: Where possible, implement technology to automate evidence collection and configure periodic reminder notifications to be sent to control owners to ensure compliance requirements are not missed (e.g., Phalanx GRC’s Compliance Calendar allows program owners to synchronize all compliance efforts across the business and send notifications to control owners).
Maintaining PCI DSS Compliance
The Payment Card Industry Data Security Standard (PCI DSS) has over thirty recurring compliance requirements spanning multiple business functions that must be maintained throughout the year. As part of Step 1 above, to maintain PCI DSS compliance, it is important to document the recurring PCI DSS requirements and to assign control owners to these requirements. As an example and for helpful reference, below is a table of recurring compliance activities for PCI DSS (v3.2.1). This table breaks down the PCI DSS requirements that have an associated and specific reoccurrence requirement throughout the year. By understanding the landscape of these requirements and assigning compliance activity to control owners, an organization can help ensure the compliance program's ongoing management and health. As a further best practice, it is recommended that program owners build in checkpoints throughout the year to validate that control owners are operating controls as assigned and intended.
Christian White
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)