Compliance
A key advantage of the FinLego enterprise policy and standards documentation approach is that documents can be brought into alignment both internally and with external regulations or expectations. While the overarching policy framework is intentionally aligned with NIST, various controls and procedures account for the treatment of particularly sensitive or regulated data and its storage or processing. For example, GDPR and/or DPA 2018 (UK GDPR) protections are embodied where appropriate, and provide proof of fully integrated compliance with these important regulatory regimes. Furthermore, contractual obligations, including PCI DSS and Standard Contractual Clauses (SCCs), can be addressed through proper documentation.