Integrations Inventory and Attributes - Compliance and Regulatory attributes for the Integrations Inventory
Integrations Inventory and Attributes
Chapter 28. Compliance and Regulatory attributes for the Integrations Inventory
Executive Summary: Chapter Overview
IF4ITThe Bottom Line
Core Concepts
| Concept | Definition & Strategic Role |
|---|---|
| Regulatory Scope | Compliance attributes can identify which integrations are subject to obligations because of the data they carry, jurisdictions they cross, or systems they connect. |
| Control Evidence | The category supports mapping integrations to compliance controls, audit evidence, data-handling obligations, and regulatory impact analysis. |
Quick Q&A
Question: Why do integrations need compliance attributes?
Read More Below
Compliance and Regulatory attributes capture the regulatory obligations that apply to data transmitted through this Integration and the current compliance status.
| Attribute Name | Maturity | Description and Notes |
|---|---|---|
Regulatory Obligations [Multi-Value] | Walk | Description — The specific regulatory requirements, laws, or compliance frameworks that apply to the data transmitted through this integration. Benefit(s) — Enables per-integration regulatory scoping. When a regulator asks for all integrations in scope for GDPR Article 28 or HIPAA Security Rule, this attribute produces the answer directly. Source — Manual. Examples — GDPR Article 28; HIPAA Security Rule; PCI-DSS Requirement 4; SOX Section 404; CCPA; DORA Article 6 Notes — Separate multiple obligations with semicolons. Derive from the Data Sensitivities attribute — PII typically triggers GDPR/CCPA; PHI triggers HIPAA; PCI triggers PCI-DSS. |
| Compliance Status | Walk | Description — The current compliance status of this integration with respect to its applicable regulatory obligations and enterprise standards. Benefit(s) — Enables a compliance dashboard at the integration level — surfacing which integrations have open compliance gaps requiring remediation. Source — Manual. Examples — Compliant, Partially Compliant, Non-Compliant, Under Assessment Notes — Valid values: Compliant, Partially Compliant, Non-Compliant, Under Assessment. |
How to cite this page
When referencing this page in academic work, internal standards, or external publications, include the page title, IF4IT as author and publisher (The International Foundation for Information Technology (IF4IT), LLC), the URL, and your access date.
Example (informal web citation):
The International Foundation for Information Technology (IF4IT), LLC. Compliance and Regulatory attributes for the Integrations Inventory | Integrations Inventory and Attributes. https://if4it.org/best-practices/integrations-inventory-and-attributes/compliance-and-regulatory-attributes-for-the-integrations-inventory/ (accessed 2026-07-20).
See About Us for content governance and site-wide citation guidance.
Copyright for The International Foundation for Information Technology (IF4IT), LLC: 2008 - Present
Legal Disclaimers