Related Technologies & Tools

Core Skills Security, Compliance & Access Control
Experience Summary

Documentation work covering security frameworks, access management, and compliance controls, translating policy and regulatory requirements into procedures and reference material that technical and audit audiences can act on.

Technology
About
 
Microsoft Active Directory

Microsoft Active Directory is Microsoft's enterprise directory service for domain-based identity management, authentication, authorization, users, groups, computers, Group Policy, and Windows access control.

Additional Resources:

View Details
Microsoft Entra ID

Microsoft Entra ID formerly Azure Active Directory, is Microsoft's cloud identity and access management service for authentication, authorization, single sign-on, multifactor authentication, conditional access, roles, and enterprise access management.

Additional Resources:

View Details
Okta

Okta is an enterprise identity and access management platform for workforce identity, single sign-on, adaptive multifactor authentication, lifecycle management, identity governance, federation, and access controls across cloud and on-premises applications.

Additional Resources:

View Details
Genetec Security Center

Genetec Security Center is Genetec's unified physical security platform for security operations, access control, video surveillance, automatic license plate recognition, communications, monitoring, and integrated operational workflows. It helps organizations manage multiple physical-security functions from a single enterprise security environment.

Genetec Security Center belongs under Enterprise Applications & ERP Systems as an enterprise operational application for physical-security management. It also fits Security, Compliance & Access-Control Documentation because it directly supports access-control administration, monitoring, and security operations.

Additional Resources:

View Details
Genetec Synergis

Genetec Synergis is Genetec's IP-based enterprise access control system for managing doors, credentials, controllers, access events, and physical-security workflows. It supports centralized access-control administration and integration with the broader Genetec Security Center platform.

Genetec Synergis belongs under Enterprise Applications & ERP Systems as an enterprise operational system for physical access control. It also fits Security, Compliance & Access-Control Documentation because it supports credential/access management, door monitoring, and access-control governance workflows.

Additional Resources:

View Details
NIST Cybersecurity Framework (CSF)

The NIST Cybersecurity Framework (CSF) is a voluntary framework for managing and communicating cybersecurity risk.

It influences documentation for profiles, governance outcomes, risk management, policies, procedures, metrics, and executive cybersecurity communication.

Additional Resources:

View Details
NIST SP 800-53

NIST SP 800-53 provides a catalog of security and privacy controls for information systems and organizations.

It drives system security documentation, control implementation statements, assessment evidence, policies, procedures, plans, and authorization artifacts.

Additional Resources:

View Details
NIST SP 800-171

NIST SP 800-171 defines requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations.

It affects contractor documentation through security plans, policies, procedures, evidence of implementation, assessments, and CUI handling instructions.

Additional Resources:

View Details
Zero Trust Architecture - NIST SP 800-207

NIST SP 800-207 describes Zero Trust Architecture principles and deployment concepts.

It affects security documentation through identity, access, device, data-flow, policy-decision, monitoring, and architecture descriptions.

Additional Resources:

View Details
ISO/IEC 27001

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS).

It affects documentation through security policies, risk treatment plans, procedures, control evidence, statement of applicability, internal audits, and continual improvement.

Additional Resources:

View Details
FedRAMP

FedRAMP is the U.S. governmentwide program for standardized security assessment and authorization of cloud products and services.

It affects cloud security documentation, system security plans, control implementation evidence, policies, procedures, continuous monitoring, and authorization packages.

Additional Resources:

View Details
FISMA

FISMA establishes federal information-security program requirements and oversight expectations.

It influences federal system documentation, risk assessments, security plans, annual reporting, controls, incident response, and audit evidence.

Additional Resources:

View Details
CMMC

CMMC is the DoD cybersecurity assessment program for defense contractors and subcontractors.

It affects documentation for CUI protection, control implementation, policies, procedures, evidence collection, assessment preparation, and supplier compliance.

Additional Resources:

View Details
DFARS Cybersecurity Requirements

DFARS cybersecurity clauses establish defense acquisition requirements tied to safeguarding covered defense information and cyber incident reporting.

They affect contractor documentation for CUI handling, supplier flow-downs, security implementation, incident reporting, and audit-ready compliance evidence.

Additional Resources:

View Details
DoD Risk Management Framework (RMF)

DoDI 8510.01 establishes the cybersecurity Risk Management Framework for DoD systems.

It affects authorization documentation, assessment packages, system security plans, control evidence, risk decisions, continuous monitoring, and reciprocity records.

Additional Resources:

View Details
MIL-STD-882

MIL-STD-882 is the DoD standard practice for system safety.

It affects documentation through hazard analysis, risk acceptance, safety requirements, mitigation tracking, and evidence that hazards are identified and controlled.

Additional Resources:

View Details
HIPAA

HIPAA governs privacy and security protections for Protected Health Information (PHI) in healthcare contexts.

It affects documentation through Privacy Rule and Security Rule policies, Minimum Necessary procedures, Business Associate agreements, administrative safeguards, technical safeguards, and evidence of compliance.

Additional Resources:

View Details
HITECH Act

The HITECH Act promoted health IT adoption and strengthened HIPAA privacy and security enforcement.

It affects documentation for breach notification, electronic health information exchange, security controls, enforcement evidence, and healthcare compliance procedures.

Additional Resources:

View Details
42 CFR Part 2

42 CFR Part 2 governs confidentiality of substance use disorder patient records.

It affects healthcare documentation through consent, disclosure limits, redisclosure notices, privacy procedures, system records, and careful handling of sensitive clinical information.

Additional Resources:

View Details
21 CFR Part 11

21 CFR Part 11 defines FDA criteria for trustworthy electronic records and electronic signatures.

It affects regulated documentation through audit trails, validation, electronic signatures, access controls, record retention, and procedural evidence.

Additional Resources:

View Details
GDPR

GDPR is the European Union's data protection and privacy regulation.

It affects documentation through privacy notices, lawful-basis records, consent language, data subject rights procedures, retention rules, records of processing, and breach communication.

Additional Resources:

View Details
CCPA/CPRA

CCPA and CPRA establish California consumer privacy rights and implementing regulations.

They affect documentation through privacy notices, data-request procedures, opt-out language, retention disclosures, vendor terms, and evidence of privacy governance.

Additional Resources:

View Details
SOC 2

SOC 2 is an assurance reporting framework based on AICPA Trust Services Criteria.

It affects technical documentation through control descriptions, policies, procedures, evidence, service commitments, system boundaries, and audit-ready process records.

Additional Resources:

View Details
PCI DSS

PCI DSS is the Payment Card Industry Data Security Standard.

It affects documentation for cardholder-data environments, security controls, procedures, network diagrams, access controls, logging, testing, and compliance evidence.

Additional Resources:

View Details
Governance, Risk & Compliance (GRC)

Governance, Risk & Compliance (GRC) is the coordinated enterprise discipline for managing governance obligations, risk, controls, policies, and compliance evidence.

It affects technical writers through policy documentation, control narratives, procedures, accountability records, audit evidence, and compliance reporting.

Additional Resources:

View Details
Configuration Management (CM)

Configuration Management governs baselines, configuration items, controlled changes, release states, and traceability.

For documentation, configuration management keeps specifications, requirements, manuals, procedures, and system evidence synchronized with controlled product or system versions.

Additional Resources:

View Details
NIST AI Risk Management Framework (AI RMF)

The NIST AI Risk Management Framework helps organizations manage risks from AI systems.

It affects AI documentation through risk mapping, governance records, model and system documentation, transparency, evaluation evidence, monitoring, and responsible AI practices.

Additional Resources:

View Details
ISO/IEC 42001 - AI Management System

ISO/IEC 42001 is a management-system standard for artificial intelligence.

It affects AI governance documentation through policies, objectives, risk controls, accountability, lifecycle records, supplier controls, assessments, and continuous improvement.

Additional Resources:

View Details