M ManySignal
Detection Pack Compliance

Compliance Detection Pack

47 detection rules mapped to compliance control requirements — covering SOC 2, ISO 27001, PCI DSS v4.0, HIPAA, and GDPR. Continuous compliance monitoring, not just point-in-time audit evidence.

Pack summary

Detection rules
47
Frameworks covered
5
Critical controls
12
Evidence export
Included

What's included

47 rules mapped across 5 compliance frameworks and 5 control domains.

Access Control & Identity 16 rules

MFA enforcement, privileged access review, shared account use, access without approval (SOC 2 CC6, PCI 8).

Audit Log Integrity 10 rules

Log tampering, retention policy violations, CDE log review failures (SOC 2 CC7, ISO A.12.4, PCI 10).

Data Protection & Encryption 10 rules

Unencrypted storage, plaintext transmission, key expiry, CDE data classification (PCI DSS 3, ISO A.10).

Incident & Change Management 7 rules

Incident SLA violations, unapproved production changes, breach notification timing (SOC 2 CC7/CC8).

Third-Party & HIPAA/GDPR 4 rules

Vendor access outside approved windows, PHI minimum necessary, GDPR request SLA, BAA coverage.

Detection rules (20 of 47 shown)

Showing 20 representative rules. All 47 rules activate with one click.

Rule name Severity
Privileged Access — Admin Account Without MFA (SOC 2 CC6.1 / PCI DSS 8.4) Critical
Audit Log Tampering or Gap Detected (SOC 2 CC7.2 / ISO 27001 A.12.4.2) Critical
Data Encryption at Rest — Unencrypted S3 Bucket Detected (PCI DSS 3.5) High
PCI DSS — Cardholder Data Environment Access by Unauthorised User Critical
HIPAA — PHI Access by Unaffiliated User (Minimum Necessary Rule) Critical
Access Review — Privileged Account Not Reviewed in 90 Days (SOC 2 CC6.3) High
Third-Party Vendor — Access Outside Approved Window (SOC 2 CC9.2) High
Password Policy Violation — Password Not Meeting Complexity Requirements Medium
Encryption Key — Certificate Expiring Within 14 Days (ISO 27001 A.10.1) Medium
PCI DSS — Default Credentials Detected on Network Device Critical
HIPAA — Audit Log Covering PHI Access Not Retained 6 Years High
SOC 2 CC7.4 — Security Incident Not Logged in ITSM Within SLA High
PCI DSS Requirement 10 — Audit Log Not Reviewed Daily Medium
GDPR — Data Subject Right to Erasure — Request Not Actioned in 30 Days High
ISO 27001 A.9.4.1 — Shared Admin Account Used High
SOC 2 CC6.7 — Data Transmitted Without Encryption High
PCI DSS — Anti-Virus Not Running on Cardholder Data System Critical
Change Management — Production Change Deployed Without Approval (SOC 2 CC8.1) High
HIPAA — Workforce Training — User Access Granted Without Required Training Medium
Vendor Risk — Third-Party with Expired Security Assessment (SOC 2 CC9.2) High

Prerequisites

  • Identity provider (Okta or Entra ID) connected for access control and MFA enforcement monitoring
  • Cloud audit logs enabled (AWS CloudTrail, Azure Activity Log, GCP Audit) for infrastructure compliance rules
  • ITSM integration (Jira or ServiceNow) for incident SLA and change management monitoring
  • GRC platform integration (optional — Vanta, Drata) for cross-referencing control evidence with ManySignal detections

Compliance Detection Pack: frequently asked questions

Which compliance frameworks does this detection pack cover?

The compliance detection pack covers SOC 2 Type II (Trust Services Criteria), ISO 27001:2022, PCI DSS v4.0, HIPAA Security Rule, and GDPR. Each detection rule includes a compliance control reference in its documentation. The pack is designed to provide continuous compliance monitoring rather than point-in-time audit evidence.

Can ManySignal generate compliance evidence for auditors?

Yes. ManySignal's reporting module generates structured evidence exports — alert history, detection coverage mapping, and control-to-rule mapping reports — formatted for SOC 2 auditors. Each rule maps to specific Trust Services Criteria. Evidence exports are timestamped and tamper-evident for audit purposes.

How does this pack differ from a GRC platform like Vanta or Drata?

GRC platforms (Vanta, Drata, Secureframe) provide evidence collection and control documentation for periodic audits. ManySignal's compliance pack provides real-time continuous monitoring of control effectiveness — detecting when a control is violated at the moment of violation, not at the next audit. The two are complementary: ManySignal detects and responds; GRC platforms document and report.

Does the HIPAA coverage include breach notification timing?

Yes. The pack includes detection for PHI access anomalies and data exfiltration events that would trigger HIPAA breach notification requirements (45 CFR 164.410). ManySignal does not automate breach notification, but it generates the timestamped evidence of the incident and affected records needed to assess notification obligations within HIPAA's 60-day window.

How does ManySignal handle compliance monitoring for multi-region cloud environments?

Compliance requirements vary by region (GDPR in EU, state privacy laws in US, PIPEDA in Canada). ManySignal tags cloud resources with their geographic region and applies region-specific rule variants where required. For example, GDPR data subject request SLA monitoring applies only to EU-region data processing activities, not to US-only workloads.

Continuous compliance monitoring for SOC 2, PCI DSS, HIPAA, and ISO 27001

47 detection rules mapped to compliance control requirements — generate real-time evidence of control effectiveness between audits.