Summary
Compliance and certification serve two purposes: giving you a framework and checklists to ensure you’re doing the right things and giving your customers/auditors confidence in the same.
Throughout this chapter, we’ve examined the main concerns of legislators and regulators, centering on security, data privacy, and transparency. We introduced security frameworks such as NIST and SSDF to guide your efforts and help you meet certification standards. We’ve also covered the crucial elements of disclosure, consent, and control in data handling, and highlighted the differences between proving compliance for customers/partners versus regulators.
One of the best ways to decide which to implement or use as a measuring stick for yourself is to ask your people in legal and sales which ones their contacts among regulators and customers are asking them about. Remember, compliance is not just about implementing security measures but also about properly documenting...