Can you translate your product or industry to the most current regulatory requirements?  Can you map your capabilities to the compliance problems you solve?  GRC is broken.  We can fix it. We tie out your security investment to your security and risk response.  With over 150 analyzed products, 5000 systems policies, and current models for seven major sectors, you can resolve your most perplexing regulatory challenges in just months. 

If you have hundreds of security products and you can't map them to your regulatory requirements, our methodology will make this relatively easy to accomplish.  If you have a product and you can't explain its capabilities to the security and compliance market, give us a call.  An investment of less than 15K USD will reap guaranteed results.

How we do it - First, we keep an eye on technology

eyeontechnology

Start with industry standards and experts.  Really study and contribute.

NIST CSF Annex A

Work as a team to add value to security operations and product architecture

CSFsystempolicy2framwork


Never wait for clients to tell you the new standard is needed.  Be first to let your clients understand what's important.  Get the materials out to the world within weeks or days of the new release.

See National Cyber Security Center NCSC UK Announces Major Updates to Cyber Essentials

DesCritCyberRisk

Pay full respect to Her Majesty the Queen and UK Cyber Frameworks. Keep in mind that they are no longer a part of the EU.

NCSC EnterpriseGRCUniverseMapping

Have a look at ISO/IEC 27001 Compliance Readiness and keep an eye on ISO/IEC FDIS 27002 - ISO's big, huge upgrade.

The ISO/IEC 27001 Certifications are continuously evolving. Never mistake passing an audit with getting to the heart of every risk.

Map everything back to NIST 800-53 r5 ISO/IEC 27002:2013 - add NIST 800-171r2 and 171A and 172, NIST.HB.162, CMMC and SPRS, for non-Federal or Public Sector Compliance - Include Mapping to 800-53R5 and ISO/IEC FDIS 27002.

SOC2Auditoncecomplymany


NIST 800-171 for Protecting CUI - NIST 171, DFARS and CMMC

NIST171Coverage

Read more about NIST 171 Assessment NIST 171, DFARS and CMMC

NIST 171 Connecting Tailoring attributes

NIST 171 Requirements and Protection Strategy

NIST 171 Requirements Protection Strategy


PCI DSS 3.2.1

PCI32AuditOnceComplyMany

We tie all the technical aspects of system configurations and policies to the most substantial security risk assessment. We make no pretense of extending to all areas of business.  We only play a part.

HIPAA HITRUST mapping


We assure you that the interpretation of risk is relative to industry recommendations and our role is to supply you with the resource to make the right decisions faster.

FedRampReady


Make it relevant to Security Program Architecture - never assign a human to the task that technology investment is supposed to do, never assign a technology to the monitoring that a human should do.

ProductsNecessary2GDPR


Tie products to their enterprise risks, threats based on architecture, strategy, and controls.

howwedoit


Compliance G-Force

 

RegulatoryDNAHelix


Here are some of our Industry-specific regulatory collections. We are always adding more. We stay current to within 30 days of any new release.

Telecom - FCC Construction HEALTH, US or International, Private of Federally Funded
  • NERC CIP (FERC)
  • CIS CSC top 18
  • CSF Framework for Improving Critical Infrastructure Cybersecurity
  • Cybersecurity Risk MGT Program - Description Criteria © AICPA 2017
  • General Data Protection Regulation (EU)
  • ISO/IEC 27002:2013 € Plus new ISO/IEC FDIS 27002
  • NCSC NATIONAL CYBER SECURITY STRATEGY
  • NIST 800-53 r5
  • FedRamp V5 Releasing April 2022
  • SOC2 Trust Services-AICPA
Education
  • CIS CSC top 18
  • CSF Framework for Improving Critical Infrastructure Cybersecurity
  • Cybersecurity Risk MGT Program - Description Criteria © AICPA 2017
  • HIPAA - HITECH Title 45 C.F.R. § 164
  • HITRUST CSF
  • General Data Protection Regulation (EU)
  • ISO/IEC 27002:2013 €
  • NCSC NATIONAL CYBER SECURITY STRATEGY
  • NIST SP 800-53 r5 and SP 800-53B or C
  • PCI DSS V3.2.1
  • SOC2 Trust Services-AICPA
  • NERC CIP
  • CIS CSC top 18
  • CSF Framework for Improving Critical Infrastructure Cybersecurity
  • Cybersecurity Risk MGT Program - Description Criteria © AICPA 2017
  • ISO/IEC 27002:2013 €
  • NCSC NATIONAL CYBER SECURITY STRATEGY
  • NIST SP 800-53 r5 and SP 800-53B or C
  • NIST 800-171
  • Sarbanes Oxley SOX
  • PCI DSS V3.2.1
  • SOC2 Trust Services-AICPA

  • CIS CSC top 18
  • CSF Framework for Improving Critical Infrastructure Cybersecurity
  • Cybersecurity Risk MGT Program - Description Criteria © AICPA 2017
  • CFR Part 820
  • HIPAA-HITECH CFR 45
  • Eudralex V4 Annex 11
  • GAMP® 5*
  • HITRUST 9.3*
  • General Data Protection Regulation (EU)
  • HIPAA - HITECH Title 45 C.F.R. § 164
  • HITRUST CSF
  • ISO/IEC 27002:2013 €
  • ISO 13485:2016
  • ISO/IEC 30111:2019
  • ISO/IEC 27001:2013 €
  • ISO/IEC 27017:2015 € 27002 for cloud services
  • ISO/IEC 27799:2016 €
  • ISO/IEC 27002:2013 €
  • NCSC NATIONAL CYBER SECURITY STRATEGY
  • NIST SP 800-171 r2+171A+172+NIST.HB.162 and CMMC 2.0
  • NIST SP 800-53 r5 and SP 800-53B or C
  • PCI DSS V3.2.1
  • SOC2 Trust Services-AICPA
Oil & Energy Sector Government Sector, DOJ, Federally Funded FINTECH – REGTECH, E-Commerce and Financial, US or International
  • NERC CIP (FERC)
  • CIS CSC top 18
  • CSF Framework for Improving Critical Infrastructure Cybersecurity
  • Cybersecurity Risk MGT Program - Description Criteria © AICPA 2017
  • General Data Protection Regulation (EU)
  • ISO/IEC 27002:2013 €
  • ISO/IEC 27002:2013 €ISO/IEC FDIS 27002
  • NCSC NATIONAL CYBER SECURITY STRATEGY
  • NIST SP 800-53 r5 and SP 800-53B or C
  • PCI DSS V3.2.1
  • SOC2 Trust Services-AICPA
  • CIS CSC top 18
  • Criminal Justice Information Services (CJIS)
  • CSF Framework for Improving Critical Infrastructure Cybersecurity
  • Cybersecurity Risk MGT Program - Description Criteria © AICPA 2017
  • FFIEC
  • FedRamp V5
  • General Data Protection Regulation (EU)
  • ISO/IEC 27002:2013 €ISO/IEC FDIS 27002
  • NCSC NATIONAL CYBER SECURITY STRATEGY
  • NIST SP 800-53 r5 and SP 800-53B or C
  • PCI DSS V3.2.1
  • SOC2 Trust Services-AICPA
  • General Data Protection Regulation (EU) 2017/679
  • CIS CSC Top 18
  • PCI DSS 3.2.1
  • SOC 2 2017 plus Cyber Description Criteria
  • Cybersecurity Framework, CSF Critical Infrastructure
  • ISO/IEC 27002:2013 and New ISO/IEC FDIS 27002
  • UK Cyber Essentials
  • NCSC NATIONAL CYBER SECURITY STRATEGY 2017-2021
  • FFIEC
  • GLBA
  • Sarbanes Oxley SOX
  • GLBA
Main Menu