What Security Documentation a B2B SaaS Company Needs

Determine which regulatory security standards (PCI, GDPR, HIPAA, ISO 27001) your company must comply with and put a process in place to maintain compliance and documentation.

Maintained in the open at github.com/Golden-Section-Tx/playbook · CC BY-SA 4.0

PlayersCTO
Initial Effort13 SP
Ongoing5 SP
FrequencyAnnual
StageEarly Traction

Security compliance is a legal concern for organizations in many industries today. Regulatory standards like PCI DSS, HIPAA, and ISO 27001 prescribe recommendations for protecting data and improving information security management in the enterprise.

Aligning your technical, operational and security standards with these regulatory standards - and following appropriate documentation practices - is crucial to protecting your company.

The goal: Determine which regulatory standards your company needs to comply with and put in place a process to maintain compliance.

Background

PCI

Payment card industry (PCI) compliance refers to the technical and operational standards that businesses must follow to ensure that credit card data provided by cardholders is protected.

GDPR

The General Data Protection Regulation 2016/679 is a regulation in EU law on data protection and privacy for all individual citizens of the European Union and the European Economic Area. It also addresses the transfer of personal data outside the EU and EEA areas.

HIPAA

HIPAA (Health Insurance Portability and Accountability Act of 1996) is United States legislation that provides data privacy and security provisions for safeguarding medical information. The law has emerged into greater prominence in recent years with the proliferation of health data breaches caused by cyberattacks and ransomware attacks on health insurers and providers.

Steps

  1. Is your software currently compliant to any security compliance standard?
  2. If so, which ones?
  3. Do you need security compliance you don't yet have? If so, create an actionable plan to comply and earn certification.

Questions this play answers

Which security compliance standards apply to my SaaS company?

Security compliance is a legal concern for organizations in many industries today. Regulatory standards like PCI DSS, HIPAA, and ISO 27001 prescribe recommendations for protecting data and improving information security management in the enterprise.

When does PCI compliance apply to my business?

Determine which regulatory security standards (PCI, GDPR, HIPAA, ISO 27001) your company must comply with and put a process in place to maintain compliance and documentation.

Does GDPR apply to my SaaS company?

Determine which regulatory security standards (PCI, GDPR, HIPAA, ISO 27001) your company must comply with and put a process in place to maintain compliance and documentation.

What does HIPAA require me to protect?

Determine which regulatory security standards (PCI, GDPR, HIPAA, ISO 27001) your company must comply with and put a process in place to maintain compliance and documentation.