Skip to main content
REF-STR-002

Compliance

Helps organizations comply with the laws, regulations, and industry standards that apply to information security and data protection, across both international and regional frameworks.

An archive room with rows of identical records boxes
Frameworks

The standards we work against.

International

  • Information Security & Data Protection (ISO 27001, PCI-DSS)
  • Cybersecurity Framework (NIST CSF)
  • Business Continuity Management (ISO 22301)
  • Data Protection & Privacy (GDPR, ISO 27701)
  • IT Governance (COBIT)

Regional

  • Financial sector standards (CBJ, SAMA CSF, SAMA BCM, SAMA CTI)
  • National Cybersecurity Regulations (NCA)
  • Data Governance (NDMO)
  • Saudi Aramco Cybersecurity Standards
Approach

Seven phases to compliance.

1

Assessment

A gap analysis or compliance assessment identifies non-compliance issues and vulnerabilities.

Gap Analysis Report
2

Action Planning

Tasks, timelines, and responsibilities are outlined for reaching compliance.

Corrective Action Plan
3

Policies & Procedures

Documentation is developed to meet the target framework's requirements.

Policies & Procedures
4

Governance Development

Governance materials are created and aligned with the relevant standard.

Governance Documentation
5

Training

Training and awareness programs build employee understanding of the new controls.

Awareness Materials
6

Ongoing Support

Compliance is maintained through continued monitoring and testing.

7

Certification

Certification services demonstrate the standard has been achieved, where applicable.

Certification Audit Report Certificate
Deliverables

What you receive.

Gap analysis and compliance assessment report
Corrective action plan
Policies and procedures
Governance-related documentation
Awareness material
Certification audit report, where the engagement runs to certification
The certificate itself, where the engagement runs to certification
FAQ

Common questions.

Which frameworks do you work against?

Internationally, ISO 27001, PCI-DSS, NIST CSF, ISO 22301, GDPR, ISO 27701, and COBIT. Regionally, CBJ, the SAMA standards, NCA, NDMO, and Saudi Aramco cybersecurity standards.

Where does the engagement start?

With a gap analysis or compliance assessment that identifies non-compliance issues and vulnerabilities, delivered as a gap analysis report before any remediation work is planned.

Do you write the documentation for us?

Yes. Policies and procedures are developed to meet the target framework's requirements, and governance materials are created and aligned with the relevant standard.

Does support continue once we are compliant?

Yes. Compliance is maintained through continued monitoring and testing, and certification services demonstrate the standard has been achieved where certification applies.

Ready to scope Compliance?

Request an Assessment
Request an Assessment Email Us