IronRoot Risk Consultants

Regulatory Compliance Checklist

Key Requirements for Small Businesses

FFIEC / GLBA  ·  PCI DSS  ·  NIST CSF  ·  ISO/IEC 27001  ·  SOC 2


How to Use This Checklist: Use this checklist to perform a quick self-assessment against each framework that applies to your business. Check each box when a requirement is substantially met. Unchecked gaps are prime candidates for your risk register and remediation roadmap. Priority ratings: REQUIRED = mandatory per the framework; RECOMMENDED = strongly advised; BEST PRACTICE = advanced or aspirational.
Organization:
Assessor:
Assessment Date:
Next Review:
FFIEC IT Examination Handbook / GLBA Safeguards Rule
Gramm-Leach-Bliley Act (Reg. P) + FFIEC Guidance
Applies to: Financial institutions, banks, credit unions, mortgage companies, insurance, fintech, tax preparers, accountants, financial advisors
Requirement / ControlCategoryPriority
[ ]Board/senior management has formally designated information security program oversight responsibility.GovernanceREQUIRED
[ ]A written Information Security Program (ISP) is in place, reviewed at least annually.GovernanceREQUIRED
[ ]A formal risk assessment identifies reasonably foreseeable threats to customer information.Risk AssessmentREQUIRED
[ ]Risk assessment results are used to implement appropriate safeguards.Risk AssessmentREQUIRED
[ ]Access to customer financial data is limited to authorized personnel with a legitimate need.Access ControlsREQUIRED
[ ]Multi-factor authentication (MFA) is required for any system accessing customer financial data.Access ControlsREQUIRED
[ ]Customer financial information is encrypted in transit (TLS 1.2+) and at rest (AES-256).EncryptionREQUIRED
[ ]Encryption key management procedures are documented.EncryptionREQUIRED
[ ]Service providers with access to customer data are contractually required to implement appropriate safeguards.Vendor MgmtREQUIRED
[ ]Service provider security arrangements are reviewed periodically.Vendor MgmtREQUIRED
[ ]A written Incident Response Plan addresses customer notification within 30 days (GLBA Safeguards Rule).Incident ResponseREQUIRED
[ ]The IRP is tested at least annually.Incident ResponseRECOMMENDED
[ ]All employees with access to customer financial data receive security awareness training at onboarding and annually.TrainingREQUIRED
[ ]Systems are monitored for unauthorized access to or use of customer financial data.MonitoringREQUIRED
[ ]Changes to systems handling customer data follow a documented change control process.Change MgmtRECOMMENDED
[ ]Penetration tests or vulnerability assessments are conducted at least annually.TestingRECOMMENDED
PCI DSS v4.0
Payment Card Industry Data Security Standard
Applies to: Any business that accepts, processes, stores, or transmits credit/debit card data
Requirement / ControlCategoryPriority
[ ]A firewall is installed and maintained between the internet and cardholder data environment.Network SecurityREQUIRED
[ ]Cardholder data environment is network-segmented from other business systems.Network SecurityREQUIRED
[ ]Primary Account Numbers (PANs) are not stored after authorization unless absolutely necessary.Data ProtectionREQUIRED
[ ]Stored PANs are protected by strong cryptography (AES-256) if storage is required.Data ProtectionREQUIRED
[ ]Full card data (track data, CVV, PIN) is never stored post-authorization.Data ProtectionREQUIRED
[ ]Cardholder data transmitted over open networks is encrypted (TLS 1.2+).TransmissionREQUIRED
[ ]Anti-malware software is deployed on all systems regularly exposed to malware.Anti-MalwareREQUIRED
[ ]All systems and software are patched within one month for critical vulnerabilities.Patch MgmtREQUIRED
[ ]Access to cardholder data is restricted by business need-to-know.Access ControlsREQUIRED
[ ]Each user has a unique ID; shared or generic accounts are prohibited.Access ControlsREQUIRED
[ ]MFA is required for all non-console administrative access to the cardholder data environment.Access ControlsREQUIRED
[ ]Physical access to cardholder data and systems is restricted and logged.Physical SecurityREQUIRED
[ ]All access to cardholder data and systems is logged and retained for 12 months (3 months online).LoggingREQUIRED
[ ]Internal and external vulnerability scans are conducted quarterly.Vulnerability MgmtREQUIRED
[ ]Annual penetration tests are conducted by a qualified assessor covering network and application layers.Pen TestingREQUIRED
[ ]An information security policy is maintained, reviewed annually, and communicated to all personnel.PolicyREQUIRED
[ ]Card data scope is minimized — use a PCI-compliant payment gateway to avoid direct card data handling.Scope ReductionBEST PRACTICE
NIST Cybersecurity Framework (CSF) 2.0
National Institute of Standards and Technology — Voluntary Framework
Applies to: All organizations seeking a risk-based cybersecurity baseline; often required for government contractors
Requirement / ControlFunctionPriority
[ ]Cybersecurity roles and responsibilities are formally assigned and documented.GOVERNREQUIRED
[ ]Cybersecurity risk is incorporated into enterprise risk management processes.GOVERNREQUIRED
[ ]A current inventory of hardware, software, and data assets is maintained.IDENTIFYREQUIRED
[ ]Cybersecurity risks to assets and systems are identified and documented.IDENTIFYREQUIRED
[ ]Supply chain and third-party risks are assessed and managed.IDENTIFYRECOMMENDED
[ ]Access to assets is managed and limited to authorized users and devices.PROTECTREQUIRED
[ ]Multi-factor authentication is used for critical systems and remote access.PROTECTREQUIRED
[ ]Data at rest and in transit is protected with current encryption standards.PROTECTREQUIRED
[ ]Security awareness training is provided to all personnel.PROTECTREQUIRED
[ ]Configuration baselines are established and maintained for systems.PROTECTRECOMMENDED
[ ]Backups of critical data are maintained, encrypted, and tested.PROTECTREQUIRED
[ ]Monitoring is in place to detect anomalies, incidents, and indicators of compromise.DETECTREQUIRED
[ ]Security events are logged and reviewed on a defined schedule.DETECTRECOMMENDED
[ ]An incident response plan is documented and tested.RESPONDREQUIRED
[ ]Incidents are reported to appropriate internal and external stakeholders per defined timelines.RESPONDREQUIRED
[ ]Recovery plans for critical systems exist and are tested at least annually.RECOVERREQUIRED
[ ]Lessons learned from incidents are incorporated into governance and process improvements.RECOVERBEST PRACTICE
ISO/IEC 27001:2022
International Standard for Information Security Management Systems (ISMS)
Applies to: Organizations seeking formal ISMS certification; often required by enterprise customers and regulated industries globally
Requirement / ControlClause / AnnexPriority
[ ]The organization's context (internal/external issues, interested parties, scope) is documented.Clause 4REQUIRED
[ ]Top management demonstrates leadership and commitment to the ISMS.Clause 5REQUIRED
[ ]An Information Security Policy is established, documented, communicated, and reviewed.Clause 5REQUIRED
[ ]Information security objectives are established with plans to achieve them.Clause 6REQUIRED
[ ]A risk assessment process is defined and results are documented in a risk register.Clause 6REQUIRED
[ ]A Statement of Applicability (SoA) identifies applicable Annex A controls.Clause 6REQUIRED
[ ]Employees are aware of the ISMS, their contribution, and consequences of non-conformity.Clause 7REQUIRED
[ ]ISMS documentation is controlled — creation, update, and retention of records.Clause 7REQUIRED
[ ]Access control policies and procedures are implemented and enforced.Annex AREQUIRED
[ ]Cryptographic controls for data protection are in place with a key management policy.Annex AREQUIRED
[ ]Physical and environmental security controls protect facilities and equipment.Annex AREQUIRED
[ ]Operations security includes logging, monitoring, and malware protection.Annex AREQUIRED
[ ]Supplier relationships are managed with documented security requirements.Annex AREQUIRED
[ ]Information security incident management procedures are established and tested.Annex AREQUIRED
[ ]Business continuity management includes information security requirements.Annex AREQUIRED
[ ]Internal audits of the ISMS are conducted at planned intervals.Clause 9REQUIRED
[ ]Management reviews of the ISMS are conducted at planned intervals.Clause 9REQUIRED
[ ]An external certification body audit has been engaged (Stage 1 and Stage 2).CertificationBEST PRACTICE
SOC 2 (AICPA Trust Services Criteria)
System and Organization Controls 2 — Type I and Type II
Applies to: SaaS companies, cloud providers, MSPs, and any B2B company storing or processing customer data
Requirement / ControlTSC CategoryPriority
[ ]Management has demonstrated a commitment to integrity and ethical values.CC1 — Control Env.REQUIRED
[ ]The board (or equivalent) exercises independent oversight of internal controls.CC1 — Control Env.REQUIRED
[ ]Internal and external communications about security commitments are established.CC2 — CommunicationREQUIRED
[ ]The organization assesses risks to achieving its objectives, including fraud risk.CC3 — Risk AssessmentREQUIRED
[ ]Logical access controls restrict access to systems and data to authorized users.CC6 — Logical AccessREQUIRED
[ ]MFA is implemented for remote and privileged access.CC6 — Logical AccessREQUIRED
[ ]Access provisioning, modification, and deprovisioning processes are documented.CC6 — Logical AccessREQUIRED
[ ]User access is reviewed at least annually.CC6 — Logical AccessREQUIRED
[ ]The system environment is monitored for anomalies and security events.CC7 — Sys. OperationsREQUIRED
[ ]Security incidents are identified, reported, and responded to.CC7 — Sys. OperationsREQUIRED
[ ]Changes to infrastructure and software follow a documented, authorized process.CC8 — Change MgmtREQUIRED
[ ]Vendor and business partner risks are assessed and managed.CC9 — Risk MitigationREQUIRED
[ ]System availability commitments are met and performance is monitored.A1 — AvailabilityREQUIRED
[ ]Confidential information is identified and protected per confidentiality commitments.C1 — ConfidentialityREQUIRED
[ ]Personal data is collected, used, retained, and disposed of per privacy commitments.P — PrivacyREQUIRED
[ ]Controls are designed effectively (Type I) and operating effectively over 6–12 months (Type II).Audit ScopeBEST PRACTICE
[ ]A readiness assessment has been conducted prior to engaging the external auditor.ReadinessBEST PRACTICE

Overall Compliance Summary

Framework Applicable? Items Checked Total Items Key Gaps / Next Steps
FFIEC / GLBA[ ] Yes   [ ] No___ /16
PCI DSS v4.0[ ] Yes   [ ] No___ /17
NIST CSF 2.0[ ] Yes   [ ] No___ /17
ISO/IEC 27001[ ] Yes   [ ] No___ /18
SOC 2[ ] Yes   [ ] No___ /17

Not Sure Which Frameworks Apply to You?

IronRoot Risk Consultants helps small businesses identify their compliance obligations, prioritize the highest-risk gaps, and build practical remediation roadmaps — without enterprise overhead.

Free 30-minute consultation:   chris@ironrootrisk.com  |   ironrootrisk.com