TechKnowSurge
NIST 800-53 CA-7 NIST CSF GV.OV-03 ISC2 CISSP 6.3 CompTIA Security+ 5.4 CompTIA Security+ 5.3 ISC2 CISSP 6.5 NIST 800-53 CA-2 NIST CSF GV.SC-07
VideoSecurityFree

Compliance Monitoring and Reporting

Regulatory compliance is an ongoing process that requires continuous monitoring and structured reporting, not a one-time implementation. This content covers how organizations track adherence to standards internally and externally, and how attestation and automation support those efforts.

Complete this video to capture a CTF flag worth 1 point.

About this video

Regulatory and contractual compliance is not a one-time event but a sustained operational commitment. Organizations must continuously monitor their processes to confirm that required controls remain active and effective, then translate that monitoring data into reports that demonstrate measurable adherence to the applicable standards. These activities operate on two tracks: internal monitoring and reporting directed at leadership, boards, and relevant departments, and external monitoring and reporting directed at regulators, customers, and partners who need documented assurance that agreements are being honored. The relationship between two business partners illustrates how these obligations scale in practice. A company handling sensitive customer data on behalf of another party may begin by simply acknowledging that it follows the agreed standards. As accountability requirements increase, it may need to produce detailed compliance reports as evidence, a process known as attestation in its first sense. At higher levels of scrutiny, a qualified third party may be brought in to independently verify compliance, which represents the formal definition of attestation as witnessing or certifying conformance to a standard. Frameworks such as PCI DSS for credit card processing and CMMC for U.S. Department of Defense contractors follow exactly this tiered model, where lower-risk levels require self-assessment and higher-risk levels require independent third-party verification. Managing multiple simultaneous compliance obligations across different customers, partners, and regulatory bodies can become complex, but purpose-built automation tools help organizations streamline the process. Compliance software can track applicable standards, log operational activities as evidence, generate required reports, and ensure that nothing falls through the cracks as requirements evolve. Organizations that adopt these tools are better positioned to meet the demands of customers, vendors, and regulators without duplicating effort across separate compliance programs.

What you'll learn

What's covered

Monitoring and Compliance

Aligned to

NIST 800-53
CA-7 Continuous Monitoring
CA-2 Control Assessments
NIST CSF
GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed.
GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship.
ISC2 CISSP
6.3 Collect security process data
6.5 Conduct or facilitate security audits
CompTIA Security+
5.4 Summarize elements of effective security compliance.
5.3 Explain the processes associated with third-party risk assessment and management.

Key terms

Attestation
The process of providing evidence or formal certification that a set of standards is being followed, either through self-reported documentation or third-party verification.
Compliance Reporting
The process of generating reports that measure and communicate how well an organization is adhering to applicable standards, laws, or regulations.
Continuous Compliance Monitoring
The ongoing process of observing and evaluating an organization's activities to ensure sustained adherence to applicable standards and regulations.
Payment Card Industry Data Security Standard
PCI DSS
A set of security requirements mandated by major credit card brands that organizations must follow to process, store, or transmit cardholder data. PCI DSS covers controls such as encryption, access restriction, and regular security testing.
Cybersecurity Maturity Model Certification
CMMC
A U.S. Department of Defense program that establishes cybersecurity standards and a certification process for defense contractors to ensure they adequately protect sensitive unclassified information. It uses a tiered model requiring third-party assessments to verify compliance before award of DoD contracts.
Due Diligence
The preparatory research and planning work performed to identify what obligations must be met before carrying out due care actions.

Topics

Compliance Monitoring Regulatory Reporting Attestation Pci Dss Cmmc Cybersecurity Compliance Audit Automation

Transcript

When we are complying with these laws and regulations, it's not just that you do it once and then you're done. Usually there's some sort of ongoing task that we need to complete, so we need to monitor to make sure things are happening on a regular basis, and then perhaps we need to turn those into some sort of reports.

Most of the laws and regulations and agreements are really specifying actions that we're going to be taking all the time. That is, we can't just implement these one time and then be done with it — it's actions that we're continually taking. And so what happens is we have these standards, and are we still taking those actions? We need to monitor to make sure that that is still happening, that we're still carrying out the intention of what these compliance standards are.

Compliance reporting then is turning all of that into reports. So we've got our standards here, we're taking action on those, and then what we do is we take both of those and we turn it into a report — reports of how we're performing, how we're measuring up against those standards.

Internal and external

Now the thing is, with both monitoring and reporting, there could be internal and external. Internal means happening within the company, and then external meaning that we're reporting this to something external from the company. So we could be internally monitoring what's happening within our company — and most likely we want to do that — and then perhaps there is somebody externally that's also monitoring our company. Same thing with reporting: maybe we're taking these reports and we're reporting it internally into the company, other stakeholders within the company, or perhaps we're turning those reports off to some sort of external entity.

Let's give some examples of internal reporting. There were some things that I reported to the whole company, things like key performance indicators, or if we did a SOC attestation I would advertise that to the whole company. But usually you're doing it within maybe certain departments within the company, or maybe it's certain people within the company. A lot of times it would be maybe a committee or somebody higher up in the company, perhaps it's even the board of directors or the shareholders or company owners. So you're reporting usually up — you're taking these reports and reporting it up through the company.

Let's talk about external monitoring and external reporting. Who would we be reporting this to, and why? Well, there could be laws and regulations that we have to report this to based off of those laws and regulations. Or maybe the customer is demanding it, or maybe there's some vendors and partners that are demanding this. And so what they want to know is, are you still following what we agreed upon? And so they're going to check up and make sure we're following those agreements.

One example is I had a customer that I would ship these reports off to on a yearly basis. They would check up on a yearly basis with us and just make sure that we were agreeing to all of their stipulations, and I had to turn in all of these different reports of our compliance.

A scenario

Let's come up with a scenario so we can better understand some of the concepts that we're going to talk about. Let's say we have two companies, we have Company A and Company B here. Company A has information on their customers, some sort of identification information and some sort of information that needs to be processed. They're going to use a service that business B here offers, and so they offer some sort of product where we turn over the data to them, they process it and then hand that processed information back.

And so what's going to happen is business A wants to make sure that business B is complying with all of the agreements that they stated. They have sensitive data here that they're turning over to Company B in order for this processing to happen, and so they want to make sure that that data is going to be safe and not fall into the wrong hands, which if it did could be devastating to business A.

So one thing that business A is relying on business B for is that they're going to do due diligence and due care. Remember, due diligence is that they're doing all that prep work and research to make sure that they're putting the time and effort needed, a reasonable time and effort, into making sure that the data is safe, and then they're taking action on that to make sure that data is then safe. So that's due diligence and due care.

Levels of assurance

So from a very basic level, maybe Company A just needs an acknowledgement that the standards are being followed. So this is a very basic checks and balances here: there is a set of standards that we're agreed upon, Company B has implemented those standards or is following those standards, and then Company A just requires Company B to acknowledge and say, yes, we are doing those things. So that's just a basic level here.

The next level of this might be where Company A requires a little more backing to this acknowledgement, and that is maybe they're requiring some sort of reporting. Maybe Company B can do internal monitoring and they can monitor themselves, but generate reports that are going to be handed over to Company A that show that they are following the agreed upon standards. This offers a little bit of proof that yes, in fact, we are doing what we're saying we're going to do. So maybe they turn over certain proof proving that they're doing that.

What they're doing is they're attesting to something, or an attestation. This is our first definition of attestation: attestation is just giving evidence or proof of something. So they're proving that they're following the standards by turning over some sort of documentation.

Maybe Company A needs a little more proof though, so they're going to require not only external reporting but external monitoring as well. This could mean that business A is actually taking a look at the processes and doing this evaluation. Maybe they have some internal people that are going into business B and evaluating to make sure that they're following the standards. So this would be an example of external monitoring.

I would say that more often than not, though, it's not Company A themselves going into Company B and analyzing Company B. Usually what's happening is we're finding a third party, a third party who specializes in this type of analyzing, and going into Company B to specifically look at specific standards to make sure that Company B is following those standards.

So let's look at the second definition of attestation. An attestation happens when this third party goes in and verifies these standards. So it's being a witness to or formally certifying something. So this third party is going into and witnessing or certifying that in fact business B is complying to a set of standards.

PCI DSS and CMMC

So let me give you two examples so that way we can get some perspective on this. One example would be PCI DSS, which is credit card processing. So if I'm processing credit cards, I'm going to have to comply with PCI DSS. CMMC is if I have a government contract with the US Department of Defense, then I'm going to have to comply with CMMC. If I don't comply with CMMC, I could lose that contract and lose that business. If I don't comply with PCI DSS, then I probably get fined for that.

And so what this looks like — and the reason why I chose these two is because there's different levels. I'm not going to get into what all the different levels are, but there are some different levels with both of these.

Let's say I have the basic level of processing credit card information, and maybe I'm not storing the data but I'm just taking the data and processing it, and then the data is not being stored anywhere. That's the very basic level. Then what I can do is I just go through an acknowledgement process. So I'm doing internal monitoring, and then I go through a questionnaire and say, yeah, I'm doing these things, and I checked off a bunch of things. Same thing with CMMC: this basic level is just, yeah, I'm doing these things, I'm acknowledging that I'm carrying out these functions. So that's a real basic level.

But if I go into the other levels, then what I'm going to maybe have to do is hire a third party to come in and do those attestations to make sure that yes, in fact, I'm doing everything that's required of me in order to maintain this level of compliance.

Streamlining the process

Now this all could get really complex, because I could have a lot of different compliances that I'm working with, depending on what customers I have, what government agencies I'm working with, what laws and regulations that I have to comply with.

Thankfully there's some ways that we can streamline managing all of this process. There is automation that can happen where we have different software, and there's a lot of different software that can actually help with this as well. So we can automate these tasks and use different software that helps us track what standards we need to be complying with, help us do our operations where we actually check things off and we upload proof, and then it generates reports off of that. So there's automation and there's software that can help us streamline all this process and meet our customers' needs, meet our vendors' and our different partners' demands, and meet the laws and regulation demand.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →