Compliance

Track regulatory compliance and audit readiness

Requirements

8

Compliance Rate

50%

Pending Tasks

3

Overdue

1

Framework Overview
Compliance status by regulatory framework
GDPR

50%

1/2 compliant

SOC 2

67%

2/3 compliant

HIPAA

0%

0/0 compliant

ISO 27001

50%

1/2 compliant

PCI DSS

0%

0/0 compliant

Internal

0%

0/1 compliant

Data Subject Rights

GDPR
Compliant

Processes for handling data subject access requests

Owner: Sarah ChenData PrivacyLast audit: 2024-09-15

12

Evidence

Controls8/8

Access Control

SOC 2
Compliant

User access management and authentication controls

Owner: David KimSecurityLast audit: 2024-10-01

18

Evidence

Controls12/12

Data Encryption

SOC 2
Partial

Encryption of data at rest and in transit

Owner: David KimSecurityLast audit: 2024-08-20

8

Evidence

Controls4/6

Vendor Management

ISO 27001
Partial

Third-party vendor risk assessment and monitoring

Owner: Michael RobertsOperationsLast audit: 2024-07-10

6

Evidence

Controls7/10

Incident Response

SOC 2
Compliant

Security incident detection and response procedures

Owner: David KimSecurityLast audit: 2024-11-01

15

Evidence

Controls8/8

Employee Training

Internal
Non-Compliant

Security awareness training for all employees

Owner: Emily WatsonHRLast audit: 2024-06-01

3

Evidence

Controls2/5

Backup & Recovery

ISO 27001
Compliant

Data backup procedures and disaster recovery

Owner: David KimOperationsLast audit: 2024-09-01

10

Evidence

Controls6/6

Privacy Policy

GDPR
Not Assessed

Customer-facing privacy policy and notices

Owner: Sarah ChenData Privacy

0

Evidence

Controls0/4