⛏️ Get Splunky!
Lv.1Intern
0 XP
0
Home Map Stats Drill Board Log In
Back to Floor
GRC Vault • Room 1

Regulatory Frameworks & Mapping

Architects must align Splunk deployments to regulatory requirements. Key frameworks include: NIST Cybersecurity Framework (CSF) — Identify, Protect, Detect, Respond, Recover; PCI DSS — payment card data protection with specific logging requirements (10.3 mandates retaining logs for 1 year); HIPAA — PHI protection with 6-year log retention; SOC 2 — service organization controls.

The architect maps detection capabilities to framework controls. A Control Matrix shows which Splunk searches satisfy which compliance requirements. For example, "Detect privilege escalation" satisfies NIST DE.CM-3, PCI DSS 10.2.5, and SOC 2 CC6.3 simultaneously.

Knowledge Check

Prove your understanding to clear the room (Rewards XP)
❤️❤️❤️
Question 1 of 1
PCI DSS requires audit log retention for at least how long, with 3 months immediately available?
A6 months
B1 year
C3 years
D7 years