Skip to content

Compliance

Compliance

Purpose

The Compliance module helps businesses verify and maintain compliance with mandatory security standards, legal requirements, or industry regulations. Each item is a set of standards with its own rules. (PCI-DSS, GDPR, HIPAA, NIST, TSC).

Key Features

  • Select sensor/office and time frame to cross-reference with the compliance checklist.
  • Generate audit reports on a weekly/monthly/custom basis for internal assessments or external audits.
  • Export reports (PDF/CSV) for auditing or management review.

Supported Standards

  1. PCI DSS
    • Full name: Payment Card Industry Data Security Standard
    • Applicable to: Organizations that process, store, or transmit payment card information (Visa, Mastercard, etc.).
    • Interface: Allows selecting a sensor (e.g., "Netnam Sensor") and time frame to view reports or violations.
    • Functionality: Verifies compliance with requirements such as encryption, access control, log monitoring, change detection...
  2. GDPR
    • Full name: General Data Protection Regulation
    • Applicable to: Businesses processing EU user data.
    • Objective: Track logs, alert on unauthorized access to personal data.
  3. HIPAA
    • Full name: Health Insurance Portability and Accountability Act
    • Applicable to: US healthcare organizations.
    • Objective: Protect personal health information (PHI), monitor access to medical record management systems.
  4. NIST SP 800-53
    • Full name: National Institute of Standards and Technology – SP 800-53
    • Applicable to: US federal government organizations and businesses seeking to build robust information security systems.
    • Characteristics: Very detailed, comprehensive coverage of IT system security (access management, configuration, log auditing...).
  5. TSC (Trust Services Criteria)
    • Applicable to: Organizations pursuing SOC 2 / SOC 3 standards (typically related to system auditing).
    • Objective: Ensure confidentiality, availability, processing integrity, privacy, and data security.

Applications

  • Automatically cross-reference logs and configurations against compliance requirements.
  • Support generation of violation lists and remediation recommendations.