0Pricing
Cyber Security Academy · Lesson

Compliance Frameworks

ISO 27001, SOC 2, PCI DSS.

Compliance Frameworks is a free Cyber Security Academy lesson on CoddyKit — lesson 1 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Cyber Security Academy learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.

What Is Compliance

Compliance means meeting the security requirements set by laws, regulations, or industry standards. Frameworks give organizations a structured, recognized set of controls to implement and prove.

Compliance is not the same as security, but a good framework drives real improvements.

ISO 27001

ISO/IEC 27001 is an international standard for an ISMS (Information Security Management System). It is risk-based: you identify risks, select controls (from Annex A), and continuously improve.

  • Certification is issued by accredited auditors.
  • Emphasis on management process, not just technology.

SOC 2

SOC 2 (System and Organization Controls) is an attestation report, common for SaaS providers, based on the AICPA Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.

  • Type I: controls designed at a point in time.
  • Type II: controls operating effectively over a period.

PCI DSS

PCI DSS (Payment Card Industry Data Security Standard) applies to any organization that stores, processes, or transmits cardholder data. It is prescriptive, with concrete requirements.

  • Encrypt cardholder data and use network segmentation.
  • Restrict access on a need-to-know basis.
  • Regularly test and monitor.

Other Common Regimes

You will also encounter:

  • GDPR: EU data protection and privacy.
  • HIPAA: US healthcare data.
  • NIST CSF / 800-53: US framework and control catalog.

Many overlap, so controls can be mapped across frameworks.

Risk-Based vs Prescriptive

Frameworks fall on a spectrum:

  • Risk-based (ISO 27001): you choose controls proportional to your risks.
  • Prescriptive (PCI DSS): specific mandatory requirements regardless of context.

Knowing the type tells you how much room you have to tailor controls.

Scope and Boundaries

Defining scope is the first practical step. Scope sets which systems, data, and processes the framework applies to.

For PCI DSS, segmentation can shrink scope (and cost) by isolating cardholder systems from the rest of the network.

Controls and Control Families

Frameworks organize requirements into controls, often grouped into families such as access control, cryptography, logging, and incident response.

Each control needs an owner, an implementation, and evidence that it works.

Certification vs Attestation

Outputs differ by framework:

  • Certification (ISO 27001): a pass/fail certificate from an accredited body.
  • Attestation (SOC 2): an auditor opinion report shared under NDA.
  • Validation (PCI DSS): an AOC and/or ROC from a QSA.

Continuous Compliance

Compliance is not a one-time event. Standards expect ongoing operation, periodic reassessment, and improvement.

  • ISO 27001 requires surveillance audits.
  • SOC 2 Type II covers a window of months.
  • PCI DSS requires quarterly scans and annual assessment.

Mapping Frameworks

Most organizations face several frameworks at once. Build a control mapping so one well-implemented control (e.g. MFA) satisfies the matching requirement across ISO 27001, SOC 2, and PCI DSS at the same time, avoiding duplicate work.

Quick Check

Match the framework to its nature.

Recap

Compliance frameworks structure and prove security:

  • ISO 27001 = risk-based ISMS certification.
  • SOC 2 = Trust Services attestation for service providers.
  • PCI DSS = prescriptive standard for cardholder data.
  • Define scope, assign control owners, and map overlapping controls for efficiency.

Frequently asked questions

Is the “Compliance Frameworks” lesson free?

Yes — the full text of “Compliance Frameworks” is free to read here on the web, and the Cyber Security Academy course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Cyber Security Academy course, upgrade to CoddyKit PRO.

What will I learn in “Compliance Frameworks”?

ISO 27001, SOC 2, PCI DSS. You practise Cyber Security Academy with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.

Do I need any experience to start Cyber Security Academy?

No prior experience is required. Cyber Security Academy on CoddyKit is structured for beginners through advanced learners; this is — lesson 1 of 4, so you can start here or from the beginning and move at your own pace.

How long does the “Compliance Frameworks” lesson take?

Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.

Can I write and run code in this Cyber Security Academy lesson?

Yes. Every Cyber Security Academy lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.

All lessons in this course

  1. Compliance Frameworks
  2. Security Audits
  3. Policies and Procedures
  4. Evidence and Reporting
← Back to Cyber Security Academy