Compliance Detection Pack
47 detection rules mapped to compliance control requirements — covering SOC 2, ISO 27001, PCI DSS v4.0, HIPAA, and GDPR. Continuous compliance monitoring, not just point-in-time audit evidence.
Pack summary
- Detection rules
- 47
- Frameworks covered
- 5
- Critical controls
- 12
- Evidence export
- Included
What's included
47 rules mapped across 5 compliance frameworks and 5 control domains.
MFA enforcement, privileged access review, shared account use, access without approval (SOC 2 CC6, PCI 8).
Log tampering, retention policy violations, CDE log review failures (SOC 2 CC7, ISO A.12.4, PCI 10).
Unencrypted storage, plaintext transmission, key expiry, CDE data classification (PCI DSS 3, ISO A.10).
Incident SLA violations, unapproved production changes, breach notification timing (SOC 2 CC7/CC8).
Vendor access outside approved windows, PHI minimum necessary, GDPR request SLA, BAA coverage.
Detection rules (20 of 47 shown)
Showing 20 representative rules. All 47 rules activate with one click.
| Rule name | Severity |
|---|---|
| Privileged Access — Admin Account Without MFA (SOC 2 CC6.1 / PCI DSS 8.4) | Critical |
| Audit Log Tampering or Gap Detected (SOC 2 CC7.2 / ISO 27001 A.12.4.2) | Critical |
| Data Encryption at Rest — Unencrypted S3 Bucket Detected (PCI DSS 3.5) | High |
| PCI DSS — Cardholder Data Environment Access by Unauthorised User | Critical |
| HIPAA — PHI Access by Unaffiliated User (Minimum Necessary Rule) | Critical |
| Access Review — Privileged Account Not Reviewed in 90 Days (SOC 2 CC6.3) | High |
| Third-Party Vendor — Access Outside Approved Window (SOC 2 CC9.2) | High |
| Password Policy Violation — Password Not Meeting Complexity Requirements | Medium |
| Encryption Key — Certificate Expiring Within 14 Days (ISO 27001 A.10.1) | Medium |
| PCI DSS — Default Credentials Detected on Network Device | Critical |
| HIPAA — Audit Log Covering PHI Access Not Retained 6 Years | High |
| SOC 2 CC7.4 — Security Incident Not Logged in ITSM Within SLA | High |
| PCI DSS Requirement 10 — Audit Log Not Reviewed Daily | Medium |
| GDPR — Data Subject Right to Erasure — Request Not Actioned in 30 Days | High |
| ISO 27001 A.9.4.1 — Shared Admin Account Used | High |
| SOC 2 CC6.7 — Data Transmitted Without Encryption | High |
| PCI DSS — Anti-Virus Not Running on Cardholder Data System | Critical |
| Change Management — Production Change Deployed Without Approval (SOC 2 CC8.1) | High |
| HIPAA — Workforce Training — User Access Granted Without Required Training | Medium |
| Vendor Risk — Third-Party with Expired Security Assessment (SOC 2 CC9.2) | High |
Prerequisites
- Identity provider (Okta or Entra ID) connected for access control and MFA enforcement monitoring
- Cloud audit logs enabled (AWS CloudTrail, Azure Activity Log, GCP Audit) for infrastructure compliance rules
- ITSM integration (Jira or ServiceNow) for incident SLA and change management monitoring
- GRC platform integration (optional — Vanta, Drata) for cross-referencing control evidence with ManySignal detections
Compliance Detection Pack: frequently asked questions
Which compliance frameworks does this detection pack cover?
The compliance detection pack covers SOC 2 Type II (Trust Services Criteria), ISO 27001:2022, PCI DSS v4.0, HIPAA Security Rule, and GDPR. Each detection rule includes a compliance control reference in its documentation. The pack is designed to provide continuous compliance monitoring rather than point-in-time audit evidence.
Can ManySignal generate compliance evidence for auditors?
Yes. ManySignal's reporting module generates structured evidence exports — alert history, detection coverage mapping, and control-to-rule mapping reports — formatted for SOC 2 auditors. Each rule maps to specific Trust Services Criteria. Evidence exports are timestamped and tamper-evident for audit purposes.
How does this pack differ from a GRC platform like Vanta or Drata?
GRC platforms (Vanta, Drata, Secureframe) provide evidence collection and control documentation for periodic audits. ManySignal's compliance pack provides real-time continuous monitoring of control effectiveness — detecting when a control is violated at the moment of violation, not at the next audit. The two are complementary: ManySignal detects and responds; GRC platforms document and report.
Does the HIPAA coverage include breach notification timing?
Yes. The pack includes detection for PHI access anomalies and data exfiltration events that would trigger HIPAA breach notification requirements (45 CFR 164.410). ManySignal does not automate breach notification, but it generates the timestamped evidence of the incident and affected records needed to assess notification obligations within HIPAA's 60-day window.
How does ManySignal handle compliance monitoring for multi-region cloud environments?
Compliance requirements vary by region (GDPR in EU, state privacy laws in US, PIPEDA in Canada). ManySignal tags cloud resources with their geographic region and applies region-specific rule variants where required. For example, GDPR data subject request SLA monitoring applies only to EU-region data processing activities, not to US-only workloads.
Continuous compliance monitoring for SOC 2, PCI DSS, HIPAA, and ISO 27001
47 detection rules mapped to compliance control requirements — generate real-time evidence of control effectiveness between audits.