Compliance and Controls
Compliance Control Areas American CIO Can Assist With
American CIO can help organizations interpret, organize and operationalize security and technology controls. Advisory services support readiness, documentation and implementation planning. Final legal interpretation should be reviewed by qualified counsel.
GLBA Safeguards
Risk assessment, WISP support, access controls, vendor oversight, encryption, MFA, incident response, employee training and ongoing monitoring.
FTC Safeguards Rule
Designated security accountability, risk-based safeguards, service provider controls, testing cadence, board reporting and written program maturity.
PCI DSS Alignment
Cardholder data scope reduction, network segmentation, access control, vulnerability management, logging, vendor payment flows and policy readiness.
HIPAA Adjacent Controls
Administrative, technical and physical safeguard mapping for healthcare-adjacent organizations and vendors that handle sensitive health-related information.
SOC 2 Readiness
Security, availability, confidentiality and privacy control preparation, evidence discipline, policy mapping, vendor oversight and audit readiness planning.
NIST CSF
Identify, Protect, Detect, Respond and Recover maturity mapping to create an executive cybersecurity operating model.
NIST 800-53
Control family mapping across access control, audit logging, configuration, contingency planning, incident response and system protection.
CIS Controls
Practical implementation roadmap for asset inventory, vulnerability management, secure configuration, access control, logging, malware defense and recovery.
CMMC Readiness
Foundational scoping and advisory support for organizations pursuing defense contractor cybersecurity maturity expectations.
CJIS-Oriented Controls
Advisory support for access discipline, audit logging, MFA, personnel controls, encryption, incident handling and policy structure for justice-adjacent environments.
State Privacy Laws
Technology control support for data inventory, retention, access, deletion workflows, privacy governance and vendor data handling.
Cyber Insurance Readiness
MFA, EDR, backup testing, email security, vulnerability management, privileged access, incident response and underwriting evidence preparation.