<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Compliance on CuraSec</title><link>https://curasec.metacog.co.kr/tags/compliance/</link><description>Recent content in Compliance on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 05 Aug 2026 13:01:27 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/compliance/index.xml" rel="self" type="application/rss+xml"/><item><title>Chiaro SOC 2 Readiness Methodology Published on GitHub</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-chiaro-hq-methodology-58/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-chiaro-hq-methodology-58/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A publicly available SOC 2 readiness framework with controls, criteria, and evidence standards; useful as a benchmarking reference when preparing for or reviewing audit posture.&lt;/li>
&lt;/ul></description></item><item><title>FedRAMP 20x Replaces Rev5 With Continuous Evidence Requirements</title><link>https://curasec.metacog.co.kr/insights/2026-07-24-fedramp-rev5-is-ending-what-the-20x-transition-really-requir/</link><pubDate>Fri, 24 Jul 2026 12:43:46 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-24-fedramp-rev5-is-ending-what-the-20x-transition-really-requir/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If your team supports a FedRAMP-authorized product, start mapping how you&amp;rsquo;ll generate continuous, machine-readable control evidence — point-in-time assessment artifacts will no longer suffice once the transition deadline arrives.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If your organization holds or pursues FedRAMP authorization, place the Rev5-to-20x transition on the roadmap this quarter: budget for tooling that produces continuous evidence and assess your current ATO timeline against the sunset date. Note this piece appears to be vendor-authored content from Anecdotes, so verify transition specifics against GSA primary sources.&lt;/li>
&lt;/ul></description></item><item><title>2026 HIPAA Security Rule Update Overview</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-2026-hipaa-security-rule-update/</link><pubDate>Mon, 13 Jul 2026 13:18:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-2026-hipaa-security-rule-update/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If you operate in a HIPAA-covered environment, review the updated Security Rule requirements this quarter and identify any new technical safeguards or control gaps to address before enforcement deadlines.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Healthcare or health-data leaders should read the updated rule now, map changes to your current compliance posture, and brief legal/compliance on any new obligations or deadline-driven gaps before they surface in your next audit.&lt;/li>
&lt;/ul></description></item></channel></rss>