HIPAA
Admin/physical/technical safeguards for PHI with documented policies and BAAs.
- Access controls, audit logging
- Risk analysis & remediation
- Workforce training & attestations
IRS 4557 / FTC Safeguards
Protect taxpayer data across people, process, tech—fit for CPA firms.
- Written ISP, vendor oversight
- Endpoint encryption & EDR
- MFA + email security (DMARC)
SOC 2
Trust Services Criteria alignment for confidentiality, availability, integrity.
- Change control & backups
- Identity & least privilege
- Monitoring & incident response
PCI DSS
Reduce scope, segment networks, and protect payment flows.
- Tokenization & segmentation
- Vulnerability management
- Logging & retention
SOX (ITGC)
Controls over financial systems and change management.
- Access reviews & SOD
- Change/Config management
- Backup & DR evidence
NIST CSF / CIS
Risk-based baseline for small/medium organizations.
- Identify assets & risks
- Protect/Detect/Respond plan
- Continuous improvement