Vantage Point Group, LLC
Reference Guide

Compliance & security frameworks, explained.

You'll see these terms across our site — SOC 2, HIPAA, HITRUST, NIST, and more. Here's what each one actually means, in plain English, and where it fits.

Security & Compliance

SOC 2

SOC 2 (System and Organization Controls 2) is an attestation report — not a certification — defined by the AICPA and based on the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. A Type I report evaluates control design at a single point in time; a Type II report evaluates operating effectiveness over a period, typically 6–12 months. SOC 2 is commonly required of SaaS companies and requested by enterprise customers during vendor due diligence.

Where we help: gap assessment, control implementation, and policy documentation ahead of working with a licensed CPA firm for the actual attestation. Read the SOC 2 readiness guide.

HIPAA

HIPAA (the Health Insurance Portability and Accountability Act) applies to covered entities — healthcare providers, health plans, healthcare clearinghouses — and their business associates. It includes the Privacy Rule (use and disclosure of protected health information, or PHI), the Security Rule (administrative, physical, and technical safeguards for electronic PHI), and the Breach Notification Rule (notification requirements after a breach of unsecured PHI).

Where we help: HIPAA-aligned security programs, required risk assessments, and the policies the Security Rule calls for. Read the HIPAA guide.

HITRUST CSF

HITRUST CSF (Common Security Framework), maintained by the HITRUST Alliance, harmonizes and cross-references multiple standards and regulations — including HIPAA, NIST, ISO 27001, and PCI DSS — into a single certifiable framework. It's widely used in healthcare and by organizations that need to demonstrate compliance with several overlapping requirements at once.

Where we help: HITRUST readiness — gap assessment, control remediation, and preparation ahead of a formal assessment.

NIST CSF 2.0

The NIST Cybersecurity Framework (CSF) 2.0 organizes cybersecurity risk management around six core functions: Govern, Identify, Protect, Detect, Respond, and Recover (Govern was added in the 2.0 update). It's a voluntary, widely-adopted framework that gives organizations of any size a common structure and vocabulary for a security program.

Where we help: we build client security programs around NIST CSF 2.0 as a foundation.

ISO/IEC 27001

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS) — a certifiable standard, assessed by accredited third-party auditors. It requires a formal risk assessment, a Statement of Applicability mapping controls to the standard's Annex A, and ongoing management review.

Where we help: implementing an ISMS and preparing for ISO 27001 certification.

CIS Controls

The CIS Controls (from the Center for Internet Security) are a prioritized set of cybersecurity safeguards, organized into Implementation Groups (IG1, IG2, IG3) scaled to an organization's size and risk profile. IG1 in particular is designed as essential cyber hygiene for smaller organizations with limited security resources.

Where we help: implementing CIS Controls, especially IG1, for growing businesses.

GLBA, PCI DSS & state privacy laws

GLBA (Gramm-Leach-Bliley Act) governs how financial institutions handle consumer financial information. PCI DSS (Payment Card Industry Data Security Standard) applies to any business that processes, stores, or transmits credit card data. State privacy laws — CCPA/CPRA in California and a growing number of others — impose their own requirements on how businesses collect, use, and protect personal data, and which ones apply depends on where your customers are located, not just where your business is based.

Governance & Risk

COSO Framework & ISO 31000

COSO (Committee of Sponsoring Organizations of the Treadway Commission) publishes the leading Enterprise Risk Management (ERM) framework, widely used for how organizations identify, assess, and respond to risk at a governance level. ISO 31000 is the international standard for risk management principles and guidelines.

Where we help: designing governance structures, risk committees, and executive reporting around both.

AI Governance

NIST AI RMF

The NIST AI Risk Management Framework is a voluntary framework organized around four functions — Govern, Map, Measure, Manage — that helps organizations identify and manage risks specific to AI systems, distinct from traditional cybersecurity risk.

Where we help: AI use policies and risk reviews. Read the AI governance guide.

ISO/IEC 42001

Published in December 2023, ISO/IEC 42001 is the first international standard specifically for an AI Management System (AIMS). It gives organizations that develop, provide, or use AI systems a structured framework for doing so responsibly.

EU AI Act

The EU AI Act is the European Union's risk-based regulation for AI systems, using a tiered classification: unacceptable, high, limited, and minimal risk. It's relevant to U.S. businesses with EU customers, EU operations, or AI systems whose outputs reach EU users.

Not sure which of these apply to you?

That's exactly what the free assessment or a quick conversation is for.