Personam maps to anomalous activity detection and continuous access control monitoring requirements across every major regulatory framework, generating audit evidence as a byproduct of detection.
Each page below shows the specific requirements Personam addresses, where Personam monitors the control directly, and where it provides supporting evidence.
Personam maps to HIPAA Security Rule technical safeguards, directly on audit controls and workstation use, and indirectly across access, authentication, and transmission requirements. Critical for any organization handling protected health information.
Personam supports FISMA continuous monitoring requirements through behavioral detection across users, devices and systems that cannot host an agent, and maps to the continuous monitoring approach in NIST SP 800-137.
Personam addresses PCI-DSS requirements for perimeter monitoring, monitoring of access to the cardholder data environment, and alerting on anomalous activity, including movement between segments that perimeter tooling does not see.
Personam maps to the GLBA Safeguards Rule by providing behavioral monitoring of customer data access, insider threat detection, and continuous monitoring, even when credentials are valid.
Personam supports SOX Section 302 and 404 IT general controls by monitoring access to financial systems, detecting insider fraud patterns, and generating continuous audit evidence.
Personam supports GDPR Article 32 security requirements through behavioral monitoring that detects unauthorized access to personal data from network metadata, without decrypting traffic.
Personam maps to NISPOM insider threat program requirements, user activity monitoring, and continuous monitoring mandates for cleared contractor facilities.
Personam maps to CMMC Level 2 requirements for monitoring, detection, and identification of unauthorized use. This mapping is drawn against the published assessment objectives behind each requirement rather than the requirement title, which is a stricter bar than a title-level reading.
Just because we haven't mapped it here doesn't mean Personam can't address your requirements. Personam's behavioral detection maps to continuous monitoring, anomalous activity detection, and access control requirements across a wide range of regulatory frameworks. If you don't see yours here, talk to us.
Book a 30-minute demo showing behavioral detection mapped to your specific regulatory requirements.
Schedule a Demo