Listen to this episode

Compliance Regs You Should be Following that Nobody Tells You About (And Craig Catches a Gator!)

0:001:08:02

Recorded May 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

In this episode of Encrypted Ambition, Craig of Petronella Technology Group joins Erin, Blake, and BJ to discuss compliance regulations that businesses may not realize apply to them. After Craig recounts almost catching an alligator while camping near North Carolina's Neuse River, the conversation turns to HIPAA, which Craig explains covers business associates like IT providers and accountants, who should have business associate agreements in place.

He describes a regulation affecting CPA firms and bookkeepers that, at the time of recording, had been in effect since January of 2022, and he argues that merchants using third-party payment platforms cannot outsource their PCI responsibilities. Blake outlines the four PCI levels based on transaction volume, and the group covers CCPA, GDPR, NIST, DFARS, CMMC 2.0, SOC 2 Type 2, and ISO 27001. Craig favors standardizing on CMMC 2.0, and the hosts compare compliance to diet and exercise, saying owners must still do the work. The team also brainstorms a cyber score and clearer product security labeling, and BJ cites a Gartner report predicting at least 40 percent XDR adoption while stressing these tools still need human expertise.

Worth remembering

Key takeaways

  1. Craig explains that any IT provider, accountant, or vendor exposed to patient health information is a HIPAA business associate and should sign a business associate agreement.
    “anybody that could potentially be exposed. To the patient health information or Phi can be considered a business associate.”
  2. Craig describes a new regulation, in effect at the time of recording, requiring CPA firms and bookkeepers to safeguard taxpayer data with policies, procedures, and evidence.
    “new one that came out is affecting CPA firms and bookkeepers that came out in January of 22, is this year.”
  3. Craig stresses that merchants using third-party payment platforms like Square still hold responsibility for securing card data and cannot outsource PCI obligations.
    “when you use those solutions, you can't outsource your responsibility for the proper handling of the credit cards.”
  4. At the time of recording, Blake outlines four PCI compliance levels by transaction volume, and Craig says high-volume merchants face a PCI certified assessor audit.
    “merchants that are handling less than 20,000 transactions per year are what's called number four.”
  5. Craig suggests companies buried under repeated vendor security questionnaires consider SOC 2 Type 2 or ISO 27001 audits, which he says most large organizations recognize.
    “if you're getting buried with all these different skews or vendor security questionnaires, you may want to consider a SOC two type two or an ISO 27,001.”
  6. Craig argues defense industrial base companies with existing contracts are already subject to DFARS and NIST 800-171 mandates at the time of recording.
    “if you already have a contract, you're subject to the 70 12, 70, 19, 70 20, and NIST 801 71 mandates, and you've already signed off on it.”
  7. BJ cites a Gartner prediction of at least 40 percent XDR adoption within a few years, while arguing these tools still require skilled human handling.
    “the Gartner says that they think within the next couple of years, XDR adoption will be at least 40%.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Today we welcome Craig back! Not only do we get to hear about Compliance regulations you're probably subject to but unaware of, but we also get to hear Craig's harrowing tail of 'Gator wrestling in the murky waters of North Carolina!

Link: Craig Reels in a Gator in Arapahoe, NC!

Co-Hosts: BJ, Blake, and Erin

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.