Articles on Compliance
What we publish on Compliance for CISOs, IT and compliance teams in LATAM.
Articles on how an awareness program turns into compliance evidence: PCI DSS 12.6, ISO/IEC 27001 (control A.6.3), LGPD and local AML/CFT rules. We cover what each standard asks for on phishing and training, what record format an external auditor expects, and why "we ran a course" isn't a sufficient answer. If your compliance team needs to show annual review, coverage by role and exportable evidence, this category collects the concrete cases: what each standard controls, what auditors ask, and how the report gets built without a manual spreadsheet.

PCI DSS 12.6: what the auditor wants to see (and what an annual course doesn't prove)
The requirement asks for a formal awareness program that includes phishing and social engineering. The evidence isn't a screenshot.
Read moreWant to see this in your organization?
Book a demo. We will look at how to measure human risk in your team and what to change first.
Book a demo