Regulated Environments

The acronyms differ. The assurance questions repeat.

What is required? Where is it implemented? Who owns it? How is it evidenced? What breaks at the boundary? Nerthus applies that discipline across regulated technology environments.

Healthcare & public benefits

Safeguards across complex program boundaries

Security and privacy decisions involving eligibility, enrollment, claims, provider, constituent, and program data; cloud and SaaS boundaries; third-party oversight; and evidence that must support both operations and review.

HIPAA-related safeguards, NIST-based controls, state requirements, and program-specific obligations are context—not a promise of legal interpretation or certification.
Government-facing systems

Authorization, corrective action & annual evidence

Security program plans, authorization artifacts, CAPs, POA&Ms, annual submissions, common-control dependencies, interconnection boundaries, and remediation evidence.

FISMA, NIST RMF, IRS Publication 1075, and SSA-related expectations may inform the work. Formal authorization and agency acceptance remain with designated officials.
Payment security

Defensible boundaries in the PCI environment

Cardholder-data boundaries, responsibility allocation, architecture decisions, compensating-control reasoning, remediation, and readiness for assessor review in the current PCI DSS v4.0.1 context.

Nerthus does not act as a QSA or issue a ROC, AOC, or PCI certification unless separately qualified and expressly engaged.
Privacy engineering

Turn stated commitments into system decisions

Data flows, purpose and access, retention, vendor boundaries, privacy-by-design decisions, and the technical implementation of stated privacy commitments.

GDPR and other privacy regimes may shape design requirements. Nerthus does not provide legal advice or determine legal applicability.
FERPA-oriented education data

Student-data safeguards that match operations

Student-data flows, identity and access, vendor responsibilities, retention, incident readiness, and alignment between policy and system operation.

FERPA does not prescribe specific security controls. Nerthus provides security and privacy engineering support informed by the institution’s requirements; legal interpretations remain with qualified counsel and responsible institutions.
AI governance

Make the decision trail exist before launch

Pre-launch risk decisions, data provenance, access, human oversight, monitoring, vendor boundaries, and evidence that governance operates beyond the policy statement.

Nerthus provides architecture and governance advisory—not model certification, legal classification, or a guarantee of regulatory conformity.

A consistent operating lens

Six questions create the control story.

The framework supplies context. The operating lens reveals what must be decided, implemented, owned, and evidenced.

01

Requirement

What obligation or business promise is actually in scope?

02

Design

Where and how does the control operate?

03

Ownership

Which person, team, or third party is accountable?

04

Evidence

What proves operation over the required period?

05

Boundary

What depends on a vendor, common control, contract, or external official?

06

Sustainability

Can the organization repeat the control and retain the proof?

A practical place to begin

Bring the event, finding, or design decision.

Nerthus will determine whether the work fits a second opinion, a sprint, or a defined advisory relationship.

Book a Confidential Fit Call