Compliance Overview
Aquilon DLP includes built-in compliance policy frameworks that automatically classify findings and generate violations according to regulatory requirements.
Available Frameworks
| Framework | Description | Key Controls | Edition |
|---|---|---|---|
| GDPR | EU General Data Protection Regulation | Articles 5, 32, 33 | All |
| CCPA | California Consumer Privacy Act | §1798.100-199 | All |
| HIPAA | Health Insurance Portability and Accountability Act | §164.306, §164.312 | Enterprise |
| PCI DSS | Payment Card Industry Data Security Standard | Requirements 3, 4, 12 | Enterprise |
| SOX | Sarbanes-Oxley Act | Sections 302, 404, 409 | Enterprise |
| ISO 27001 | Information Security Management | Controls A.8.12, A.5.12, A.8.11 | Enterprise |
| CUI | Controlled Unclassified Information | NIST SP 800-171 | Enterprise |
| CMMC | Cybersecurity Maturity Model Certification | DFARS 252.204-7012 | Enterprise |
| FedRAMP | Federal Risk and Authorization Management | NIST SP 800-53 | Enterprise |
| FISMA | Federal Information Security Modernization Act | FIPS 199, NIST SP 800-53 | Enterprise |
How Policy Frameworks Work
Each policy framework:
- Evaluates scan findings from all 50+ scanner plugins
- Applies regulatory logic to determine violations
- Classifies severity based on data type and details
- Generates metadata for compliance reporting
Example Flow
File scanned → SSN detected → HIPAA evaluates → PHI violation (Critical)
→ PCI DSS evaluates → No violation (SSN not PAN)
→ GDPR evaluates → Personal data violation (High)
Enabling Policies
Configure policies in aquilon_dlp_config.toml:
[policies]
enabled_policies = ["gdpr", "hipaa", "pci_dss", "sox", "iso27001", "cui", "cmmc", "fedramp", "fisma"]
# Optional: customize specific policies
# [policies.policy_configs.hipaa]
# settings = { covered_entity = "true" }
# [policies.policy_configs.pci_dss]
# settings = { merchant_level = "2" }
# [policies.policy_configs.cmmc]
# settings = { level = "2" }
Policy Configuration Options
Each policy supports configuration options:
| Option | Description | Default |
|---|---|---|
enabled | Enable/disable the policy | true |
confidence_threshold | Minimum scanner confidence to generate violation | 0.7 |
sensitivity_level | Adjust severity calculation | 2 (1-3) |
Framework-Specific Settings
HIPAA:
covered_entity: Whether organization is a HIPAA covered entity
PCI DSS:
merchant_level: PCI merchant level (1-4)version: PCI DSS version (3.2.1 or 4.0)
ISO 27001:
enforce_data_masking: Require data masking for violationsclassification_level: Default classification (restricted/confidential/internal/public)
Violation Severity Levels
All frameworks use consistent severity levels:
| Level | Description | Typical Response |
|---|---|---|
| Critical | Immediate breach risk | Immediate investigation |
| High | Significant exposure | Investigate within 24 hours |
| Medium | Moderate risk | Investigate within 7 days |
| Low | Minor concern | Review during regular audit |
Compliance Reporting
OSQuery Queries
Query violations by policy:
-- All HIPAA critical findings
SELECT * FROM aquilon_dlp_alerts
WHERE policy = 'HIPAA' AND severity = 'critical';
-- Policy violation summary
SELECT policy, severity, COUNT(*) as count
FROM aquilon_dlp_alerts
GROUP BY policy, severity;
-- Recent violations by framework
SELECT policy, path, scanner, severity, timestamp
FROM aquilon_dlp_alerts
WHERE timestamp > (strftime('%s', 'now') - 86400)
ORDER BY timestamp DESC;
Audit Trail
Each violation includes metadata for audit purposes:
- Policy: Framework that generated the violation
- Severity: Risk classification
- Scanner: Detection method
- Context: Surrounding text for validation
- Timestamp: Detection time
- File path: Location of finding
Custom Policies
Beyond built-in frameworks, create custom policies for:
- Company-specific identifiers
- Internal compliance requirements
- Industry-specific patterns
See Policy Frameworks for custom policy creation.
Next Steps
- HIPAA - Healthcare data protection
- PCI DSS - Payment card security
- SOX - Financial controls
- ISO 27001 - Information security management
- GDPR - EU data protection
- CCPA - California consumer privacy
- CUI - Controlled Unclassified Information (NIST SP 800-171)
- CMMC - DoD contractor certification
- FedRAMP - Federal cloud authorization
- FISMA - Federal agency security