uniqent.ai
All memory packs

Cybersecurity Compliance Analyst Memory

cybersecurity-compliance-analyst-memory · 30 facts · by uniqent · 0 installs

30 research-verified facts covering SOC 2, ISO 27001:2022, CMMC 2.0, NIST CSF 2.0, DORA, PCI DSS 4.0, and GRC tooling benchmarks for security compliance teams.

cybersecurity
compliance
grc
infosec
risk
Memory brain

Drag to pan · scroll to zoom · drag a node · hover to highlight · click to focus.

fact
SOC 2 Type II audit observation period must be at least 6 months; most auditors recommend 12 months for first-time filers to demonstrate operational consistency
fact
SOC 2 Trust Service Criteria covers 5 categories: Security (CC), Availability (A), Processing Integrity (PI), Confidentiality (C), and Privacy (P) — Security is the only required category
fact
CMMC Level 2 maps to all 110 NIST SP 800-171 controls across 14 domains including access control, incident response, and system protection
fact
CMMC Level 2 C3PAO-assessed contracts require formal audits every 3 years; self-assessed contracts require annual SPRS submissions with a maximum score of 110
fact
SPRS (Supplier Performance Risk System) is the DoD portal where CMMC self-assessment scores must be submitted; a score of 110 indicates all controls are met
fact
ISO 27001:2022 adds 11 new controls in Annex A covering threat intelligence, cloud service security, ICT readiness, web filtering, secure coding, data masking, and physical security monitoring
fact
NIST CSF 2.0 adds a 6th function Govern alongside Identify/Protect/Detect/Respond/Recover, elevating cybersecurity governance to an explicit board-level responsibility
fact
DORA (Digital Operational Resilience Act) took full effect January 2026 for EU financial institutions and their IT service providers, mandating continuous monitoring over periodic assessments
fact
EU AI Act classifies AI systems into 4 risk tiers: unacceptable risk, high-risk (mandatory impact assessment), limited risk, and minimal risk
fact
GDPR fines can reach 20 million euros or 4% of global annual turnover whichever is higher; enforcement actions increased 168% in 2024
fact
PCI DSS 4.0 became mandatory March 2024 with 51 new requirements addressing phishing, e-skimming, and web application attack vectors
fact
Vanta supports 250+ compliance integrations and automates evidence collection across SOC 2, ISO 27001, HIPAA, PCI DSS, and CMMC
fact
Drata offers advanced customization, strong risk and vendor management, and deeper audit collaboration features preferred by enterprises with complex GRC stacks
fact
Thoropass specializes in audit-led compliance with built-in auditor workflow, efficient for companies pursuing multiple concurrent framework audits
fact
Compliance software market valued at $17.2 billion in 2025 with 16% annual growth driven by DORA, CMMC, and EU AI Act mandates
fact
Access Control reviews must occur at minimum quarterly; privileged account reviews monthly — undocumented access reviews are a top SOC 2 Type II finding
fact
Multi-Factor Authentication (MFA) is a required control under SOC 2, CMMC, PCI DSS 4.0, and ISO 27001; absence is an automatic finding in all four frameworks
fact
Vulnerability Management SLA benchmarks: critical patches within 15 days, high within 30 days, medium within 90 days — industry-standard remediation targets auditors reference
fact
Mean time to detect (MTTD) for cybersecurity incidents averages 194 days industry-wide; SOC teams targeting sub-24-hour MTTD achieve measurably lower breach costs
fact
SIEM platforms such as Splunk, Microsoft Sentinel, and Elastic SIEM are required for continuous compliance monitoring and log aggregation under most enterprise frameworks
fact
CIS Controls v8 maps to SOC 2, NIST CSF, ISO 27001, and PCI DSS, providing a cross-framework control library that reduces duplicate implementation effort
fact
Risk Register must be reviewed at least annually; ISO 27001 requires documented risk treatment plans with accepted residual risk sign-off by asset owners
fact
HIPAA Security Rule requires covered entities to conduct a documented Security Risk Assessment annually covering ePHI access, transmission, and storage controls
fact
FedRAMP authorization requires a continuous monitoring (ConMon) program with monthly vulnerability scans, annual penetration tests, and automated control status reporting
fact
Business Continuity Plan (BCP) and Disaster Recovery (DR) plans must be tested annually; tabletop exercises satisfy most framework audit requirements
fact
Data Classification policy must define at minimum 3 tiers (Public, Internal, Confidential/Restricted) as a baseline for ISO 27001 and SOC 2 CC3
decision
Evidence should be collected continuously throughout the audit period, not reconstructed in the final weeks — reconstructed evidence is a leading cause of audit qualification findings
fact
CMMC contractors must maintain a POA&M for any unmet controls; open items require target closure dates scored against the 110-point SPRS scale
fact
PCI DSS 4.0 requires annual external penetration testing and quarterly ASV vulnerability scans; scope changes trigger immediate re-testing requirements
fact
DORA requires incident classification and notification within predefined timelines and formal third-party IT risk oversight with contract structuring requirements
memory entity tag
Add to a brain

In Uniqent Studio: Memory → Browse memory hub → add this pack's facts to your brain.

GET https://uniqent.ai/api/v1/memory/cybersecurity-compliance-analyst-memory