Regulatory compliance is an ongoing process that requires continuous monitoring and structured reporting, not a one-time implementation. This content covers how organizations track adherence to standards internally and externally, and how attestation and automation support those efforts.
Monitoring and Compliance
When we are complying with these laws and regulations, it's not just that you do it once and then you're done. Usually there's some sort of ongoing task that we need to complete, so we need to monitor to make sure things are happening on a regular basis, and then perhaps we need to turn those into some sort of reports.
Most of the laws and regulations and agreements are really specifying actions that we're going to be taking all the time. That is, we can't just implement these one time and then be done with it — it's actions that we're continually taking. And so what happens is we have these standards, and are we still taking those actions? We need to monitor to make sure that that is still happening, that we're still carrying out the intention of what these compliance standards are.
Compliance reporting then is turning all of that into reports. So we've got our standards here, we're taking action on those, and then what we do is we take both of those and we turn it into a report — reports of how we're performing, how we're measuring up against those standards.
Now the thing is, with both monitoring and reporting, there could be internal and external. Internal means happening within the company, and then external meaning that we're reporting this to something external from the company. So we could be internally monitoring what's happening within our company — and most likely we want to do that — and then perhaps there is somebody externally that's also monitoring our company. Same thing with reporting: maybe we're taking these reports and we're reporting it internally into the company, other stakeholders within the company, or perhaps we're turning those reports off to some sort of external entity.
Let's give some examples of internal reporting. There were some things that I reported to the whole company, things like key performance indicators, or if we did a SOC attestation I would advertise that to the whole company. But usually you're doing it within maybe certain departments within the company, or maybe it's certain people within the company. A lot of times it would be maybe a committee or somebody higher up in the company, perhaps it's even the board of directors or the shareholders or company owners. So you're reporting usually up — you're taking these reports and reporting it up through the company.
Let's talk about external monitoring and external reporting. Who would we be reporting this to, and why? Well, there could be laws and regulations that we have to report this to based off of those laws and regulations. Or maybe the customer is demanding it, or maybe there's some vendors and partners that are demanding this. And so what they want to know is, are you still following what we agreed upon? And so they're going to check up and make sure we're following those agreements.
One example is I had a customer that I would ship these reports off to on a yearly basis. They would check up on a yearly basis with us and just make sure that we were agreeing to all of their stipulations, and I had to turn in all of these different reports of our compliance.
Let's come up with a scenario so we can better understand some of the concepts that we're going to talk about. Let's say we have two companies, we have Company A and Company B here. Company A has information on their customers, some sort of identification information and some sort of information that needs to be processed. They're going to use a service that business B here offers, and so they offer some sort of product where we turn over the data to them, they process it and then hand that processed information back.
And so what's going to happen is business A wants to make sure that business B is complying with all of the agreements that they stated. They have sensitive data here that they're turning over to Company B in order for this processing to happen, and so they want to make sure that that data is going to be safe and not fall into the wrong hands, which if it did could be devastating to business A.
So one thing that business A is relying on business B for is that they're going to do due diligence and due care. Remember, due diligence is that they're doing all that prep work and research to make sure that they're putting the time and effort needed, a reasonable time and effort, into making sure that the data is safe, and then they're taking action on that to make sure that data is then safe. So that's due diligence and due care.
So from a very basic level, maybe Company A just needs an acknowledgement that the standards are being followed. So this is a very basic checks and balances here: there is a set of standards that we're agreed upon, Company B has implemented those standards or is following those standards, and then Company A just requires Company B to acknowledge and say, yes, we are doing those things. So that's just a basic level here.
The next level of this might be where Company A requires a little more backing to this acknowledgement, and that is maybe they're requiring some sort of reporting. Maybe Company B can do internal monitoring and they can monitor themselves, but generate reports that are going to be handed over to Company A that show that they are following the agreed upon standards. This offers a little bit of proof that yes, in fact, we are doing what we're saying we're going to do. So maybe they turn over certain proof proving that they're doing that.
What they're doing is they're attesting to something, or an attestation. This is our first definition of attestation: attestation is just giving evidence or proof of something. So they're proving that they're following the standards by turning over some sort of documentation.
Maybe Company A needs a little more proof though, so they're going to require not only external reporting but external monitoring as well. This could mean that business A is actually taking a look at the processes and doing this evaluation. Maybe they have some internal people that are going into business B and evaluating to make sure that they're following the standards. So this would be an example of external monitoring.
I would say that more often than not, though, it's not Company A themselves going into Company B and analyzing Company B. Usually what's happening is we're finding a third party, a third party who specializes in this type of analyzing, and going into Company B to specifically look at specific standards to make sure that Company B is following those standards.
So let's look at the second definition of attestation. An attestation happens when this third party goes in and verifies these standards. So it's being a witness to or formally certifying something. So this third party is going into and witnessing or certifying that in fact business B is complying to a set of standards.
So let me give you two examples so that way we can get some perspective on this. One example would be PCI DSS, which is credit card processing. So if I'm processing credit cards, I'm going to have to comply with PCI DSS. CMMC is if I have a government contract with the US Department of Defense, then I'm going to have to comply with CMMC. If I don't comply with CMMC, I could lose that contract and lose that business. If I don't comply with PCI DSS, then I probably get fined for that.
And so what this looks like — and the reason why I chose these two is because there's different levels. I'm not going to get into what all the different levels are, but there are some different levels with both of these.
Let's say I have the basic level of processing credit card information, and maybe I'm not storing the data but I'm just taking the data and processing it, and then the data is not being stored anywhere. That's the very basic level. Then what I can do is I just go through an acknowledgement process. So I'm doing internal monitoring, and then I go through a questionnaire and say, yeah, I'm doing these things, and I checked off a bunch of things. Same thing with CMMC: this basic level is just, yeah, I'm doing these things, I'm acknowledging that I'm carrying out these functions. So that's a real basic level.
But if I go into the other levels, then what I'm going to maybe have to do is hire a third party to come in and do those attestations to make sure that yes, in fact, I'm doing everything that's required of me in order to maintain this level of compliance.
Now this all could get really complex, because I could have a lot of different compliances that I'm working with, depending on what customers I have, what government agencies I'm working with, what laws and regulations that I have to comply with.
Thankfully there's some ways that we can streamline managing all of this process. There is automation that can happen where we have different software, and there's a lot of different software that can actually help with this as well. So we can automate these tasks and use different software that helps us track what standards we need to be complying with, help us do our operations where we actually check things off and we upload proof, and then it generates reports off of that. So there's automation and there's software that can help us streamline all this process and meet our customers' needs, meet our vendors' and our different partners' demands, and meet the laws and regulation demand.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →