Compliance¶
Compliance¶
Purpose¶
The Compliance module helps businesses verify and maintain compliance with mandatory security standards, legal requirements, or industry regulations. Each item is a set of standards with its own rules. (PCI-DSS, GDPR, HIPAA, NIST, TSC).
Key Features¶
- Select sensor/office and time frame to cross-reference with the compliance checklist.
- Generate audit reports on a weekly/monthly/custom basis for internal assessments or external audits.
- Export reports (PDF/CSV) for auditing or management review.
Supported Standards¶
- PCI DSS
- Full name: Payment Card Industry Data Security Standard
- Applicable to: Organizations that process, store, or transmit payment card information (Visa, Mastercard, etc.).
- Interface: Allows selecting a sensor (e.g., "Netnam Sensor") and time frame to view reports or violations.
- Functionality: Verifies compliance with requirements such as encryption, access control, log monitoring, change detection...
- GDPR
- Full name: General Data Protection Regulation
- Applicable to: Businesses processing EU user data.
- Objective: Track logs, alert on unauthorized access to personal data.
- HIPAA
- Full name: Health Insurance Portability and Accountability Act
- Applicable to: US healthcare organizations.
- Objective: Protect personal health information (PHI), monitor access to medical record management systems.
- NIST SP 800-53
- Full name: National Institute of Standards and Technology – SP 800-53
- Applicable to: US federal government organizations and businesses seeking to build robust information security systems.
- Characteristics: Very detailed, comprehensive coverage of IT system security (access management, configuration, log auditing...).
- TSC (Trust Services Criteria)
- Applicable to: Organizations pursuing SOC 2 / SOC 3 standards (typically related to system auditing).
- Objective: Ensure confidentiality, availability, processing integrity, privacy, and data security.
Applications¶
- Automatically cross-reference logs and configurations against compliance requirements.
- Support generation of violation lists and remediation recommendations.
