Surveillent Cyber

Compliance Management

Our compliance management services center around elements of Governance, Risk, and Compliance (GRC) services. These services also contain professional services necessary to achieve the objectives of your cybersecurity program. These services involve identifying organizational risks, assessing cybersecurity compliance, and responding to and recovering from incidents. Compliance as a service refers to outsourcing the management and implementation of compliance tasks and responsibilities to a third-party provider like Surveillent Cyber, ensuring that the organization meets industry standards, regulations, and best practices. These services can be delivered in the form of our monthly virtual CISO services, compliance-as-a-service, project-based work, or blocks of hours.

Virtual CISO

Develop enterprise-wide security program
Identify, Report, and Control Incidents
Manage and train IT/security staff
Monitor Threats and take preventative measures
Communicate and Manage Risks
Quarterly Executive Reporting

Compliance-as-a-Service

Compliance Readiness
Compliance Assessment
Over 50 compliance frameworks supported
Penetration Testing

Supported Frameworks

We support over 50+ Cybersecurity Frameworks

  • US
    • Federal
      • NIST CSF 2.0 – US Critical Infrastructure
      • NIST SP 800-16r1 – US Supply Chain framework
      • NIST SP 800-171 R3 – CUI protection framework
      • NIST Privacy Framework v1.0 – Voluntary privacy framework
      • SOC 1 Type I and II – Financial data control
      • SOC 2 Type I and II – Secure customer data with 5 trust criteria
      • ISO 27001 (2022) – Implement and maintain an ISMS
      • PCI DSS – Secure credit card data
      • CJIS – Protects criminal justice system information
      • FedRAMP – Government data in cloud storage
      • NIST AI Risk Management Framework – AI Risk Mitigation
      • CIS Controls – Cybersecurity best practices
    • Industry Specific
      • CMMC 2.0 – Securing US defense contractors
      • FFIEC Cybersecurity Assessment – Assessment for financial institutions (Sunsets August 2025)
      • Cyber Risk Institute (CRI) Profile for the Financial Sector – a cybersecurity framework specifically designed for financial institutions. 
      • CISA Cybersecurity Performance Goals 
      • FTC Safeguards Rules – Rules for financial institutions
      • HIPAA – Securing personal health information
      • MARS – For health, identification, and tax purposes
    • State Specific
      • CCPA – California Privacy Law
      • NYDFS Cybersecurity Regulation – New York’s cybersecurity regulation for financial institutions
      • TX-RAMP – Texas ‘ cloud computing requirements
  • International
    • GDPR – The European mega-mandate
    • COBIT 2019 – Support for enterprise IT
    • CSA-CCM v4.03 – Cloud computing industry standards
    • ISO/IEC 27017:2015 – Security standards for cloud computing 
    • ISO/IEC 27018:2019 – PII and cloud computing foundations
    • ISO-IEC 27701  – Data privacy framework
    • ISO/IEC 42001 – AI management framework
    • Microsoft DPR –  For SSPA program participants
    • Motion Picture Association – the film industry framework
    • PCI DSS – Secure credit card data
    • SCF v2022.2 andv2023.2 -Maximizing cybersecurity at all levels

Compliance in the News

Maryland Man Pleads Guilty to Conspiracy to Commit Wire Fraud

Maryland Man Pleads Guilty to Conspiracy to Commit Wire Fraud

Tuesday, April 15, 2025, Minh Phoung Ngoc Vong Participated in a Multi-Year Fraudulent Scheme to Obtain Remote Information Technology Work With U.S. Companies and Government Agencies for Persons Based in China Minh Phuong Ngoc Vong, 40, of Bowie, Maryland, pleaded guilty today to conspiracy to commit wire fraud in connection…

Sunset of FFIEC Cybersecurity Assessment Tool

Sunset of FFIEC Cybersecurity Assessment Tool

The Federal Financial Institutions Examination Council (FFIEC) issued a statement to communicate the August 31, 2025, sunset of the FFIEC Cybersecurity Assessment Tool (CAT). Highlights: The CAT was released in June 2015 as a voluntary assessment tool to help financial institutions identify their risks and determine their cybersecurity preparedness. While…

The Surge in vCISO Services: MSPs, MSSPs Can’t Lag Behind

The Surge in vCISO Services: MSPs, MSSPs Can’t Lag Behind

MSSP Alerts, February 12, 2024.  The cybersecurity market is experiencing growing demand for robust services and solutions, across all industries and organizations. This is due to the increasing volume and sophistication of cyberattacks, which is driving both enterprises and SMBs to ensure their systems and data are secure. One of…