Audit and compliance

Regulatory Compliance

NSA's IT compliance programs are based on industry standards and years of development. For most organizations, the first challenge is understanding the requirements imposed by the regulation of the contracts they currently have in place (as in the case of PCIDSS).

In general, compliance means conforming to a rule, such as a specification, policy, standard or law. Regulatory compliance describes the goal that corporations or public agencies aspire to in their efforts to ensure that personnel are aware of and take steps to comply with relevant laws and regulations.

Due to the increasing number of regulations and need for operational transparency, organizations are increasingly adopting the use of consolidated and harmonized sets of compliance controls. This approach is used to ensure that all necessary governance requirements can be met without the unnecessary duplication of effort and activity from resources.

Our IT compliance methodology whether for HIPAA, PCI/DSS, or ISO consists of the following steps:

  • Education - interpreting the standard in the context of your unique business environment & risks
  • Assistance in closing compliance gaps
  • Formal compliance assessment
  • Communication - a Compliance Statement for organizations to use with third parties to demonstrate their compliance with the standard or regulation
  • Annual compliance update

We help our clients interpret the particular regulation or standard within the context of their unique business model and help them understand what it means to comply. We then work with organizations to identify pertinent compliance gaps and provide practical recommendations to close those gaps.

Once those gaps are closed, NSA will return to perform a rigorous compliance assessment and document the company's success in a format to be shared with relevant third parties.