Architects must align Splunk deployments to regulatory requirements. Key frameworks include: NIST Cybersecurity Framework (CSF) — Identify, Protect, Detect, Respond, Recover; PCI DSS — payment card data protection with specific logging requirements (10.3 mandates retaining logs for 1 year); HIPAA — PHI protection with 6-year log retention; SOC 2 — service organization controls.
The architect maps detection capabilities to framework controls. A Control Matrix shows which Splunk searches satisfy which compliance requirements. For example, "Detect privilege escalation" satisfies NIST DE.CM-3, PCI DSS 10.2.5, and SOC 2 CC6.3 simultaneously.