All memory packs
Cybersecurity Compliance Analyst Memory
cybersecurity-compliance-analyst-memory · 30 facts · by uniqent · 0 installs
30 research-verified facts covering SOC 2, ISO 27001:2022, CMMC 2.0, NIST CSF 2.0, DORA, PCI DSS 4.0, and GRC tooling benchmarks for security compliance teams.
cybersecurity
compliance
grc
infosec
risk
Memory brain
Drag to pan · scroll to zoom · drag a node · hover to highlight · click to focus.
fact
SOC 2 Type II audit observation period must be at least 6 months; most auditors recommend 12 months for first-time filers to demonstrate operational consistencyfact
SOC 2 Trust Service Criteria covers 5 categories: Security (CC), Availability (A), Processing Integrity (PI), Confidentiality (C), and Privacy (P) — Security is the only required categoryfact
CMMC Level 2 maps to all 110 NIST SP 800-171 controls across 14 domains including access control, incident response, and system protectionfact
CMMC Level 2 C3PAO-assessed contracts require formal audits every 3 years; self-assessed contracts require annual SPRS submissions with a maximum score of 110fact
SPRS (Supplier Performance Risk System) is the DoD portal where CMMC self-assessment scores must be submitted; a score of 110 indicates all controls are metfact
ISO 27001:2022 adds 11 new controls in Annex A covering threat intelligence, cloud service security, ICT readiness, web filtering, secure coding, data masking, and physical security monitoringfact
NIST CSF 2.0 adds a 6th function Govern alongside Identify/Protect/Detect/Respond/Recover, elevating cybersecurity governance to an explicit board-level responsibilityfact
DORA (Digital Operational Resilience Act) took full effect January 2026 for EU financial institutions and their IT service providers, mandating continuous monitoring over periodic assessmentsfact
EU AI Act classifies AI systems into 4 risk tiers: unacceptable risk, high-risk (mandatory impact assessment), limited risk, and minimal riskfact
GDPR fines can reach 20 million euros or 4% of global annual turnover whichever is higher; enforcement actions increased 168% in 2024fact
PCI DSS 4.0 became mandatory March 2024 with 51 new requirements addressing phishing, e-skimming, and web application attack vectorsfact
Vanta supports 250+ compliance integrations and automates evidence collection across SOC 2, ISO 27001, HIPAA, PCI DSS, and CMMCfact
Drata offers advanced customization, strong risk and vendor management, and deeper audit collaboration features preferred by enterprises with complex GRC stacksfact
Thoropass specializes in audit-led compliance with built-in auditor workflow, efficient for companies pursuing multiple concurrent framework auditsfact
Compliance software market valued at $17.2 billion in 2025 with 16% annual growth driven by DORA, CMMC, and EU AI Act mandatesfact
Access Control reviews must occur at minimum quarterly; privileged account reviews monthly — undocumented access reviews are a top SOC 2 Type II findingfact
Multi-Factor Authentication (MFA) is a required control under SOC 2, CMMC, PCI DSS 4.0, and ISO 27001; absence is an automatic finding in all four frameworksfact
Vulnerability Management SLA benchmarks: critical patches within 15 days, high within 30 days, medium within 90 days — industry-standard remediation targets auditors referencefact
Mean time to detect (MTTD) for cybersecurity incidents averages 194 days industry-wide; SOC teams targeting sub-24-hour MTTD achieve measurably lower breach costsfact
SIEM platforms such as Splunk, Microsoft Sentinel, and Elastic SIEM are required for continuous compliance monitoring and log aggregation under most enterprise frameworksfact
CIS Controls v8 maps to SOC 2, NIST CSF, ISO 27001, and PCI DSS, providing a cross-framework control library that reduces duplicate implementation effortfact
Risk Register must be reviewed at least annually; ISO 27001 requires documented risk treatment plans with accepted residual risk sign-off by asset ownersfact
HIPAA Security Rule requires covered entities to conduct a documented Security Risk Assessment annually covering ePHI access, transmission, and storage controlsfact
FedRAMP authorization requires a continuous monitoring (ConMon) program with monthly vulnerability scans, annual penetration tests, and automated control status reportingfact
Business Continuity Plan (BCP) and Disaster Recovery (DR) plans must be tested annually; tabletop exercises satisfy most framework audit requirementsfact
Data Classification policy must define at minimum 3 tiers (Public, Internal, Confidential/Restricted) as a baseline for ISO 27001 and SOC 2 CC3decision
Evidence should be collected continuously throughout the audit period, not reconstructed in the final weeks — reconstructed evidence is a leading cause of audit qualification findingsfact
CMMC contractors must maintain a POA&M for any unmet controls; open items require target closure dates scored against the 110-point SPRS scalefact
PCI DSS 4.0 requires annual external penetration testing and quarterly ASV vulnerability scans; scope changes trigger immediate re-testing requirementsfact
DORA requires incident classification and notification within predefined timelines and formal third-party IT risk oversight with contract structuring requirements memory entity tag
Add to a brain
In Uniqent Studio: Memory → Browse memory hub → add this pack's facts to your brain.
GET https://uniqent.ai/api/v1/memory/cybersecurity-compliance-analyst-memory