LNC Nexus Compliance Mapping Overview
Status: Internal mapping reference for customer and partner review
Purpose
This document summarizes how LNC Nexus security practices align with common assurance frameworks. It is intentionally high level. Detailed control identifiers, assessment artifacts, configuration values, system topology, and remediation notes are shared only through a verified, private review.
Framework Alignment
| Framework | Public posture | Review boundary |
|---|---|---|
| HIPAA Security Rule | Safeguard-oriented application and operational guidance | Customer risk analysis, workforce, physical safeguards, legal terms, and deployment configuration |
| NIST SP 800-53 | Selected control-family references | System boundary, assessment evidence, risk acceptance, and environment-specific controls |
| ISO/IEC 27001 | Internal alignment references | Certified ISMS scope, organizational processes, physical controls, and certification status |
| SOC 2 Trust Services Criteria | Control-language references; no attestation claimed | Independent examination, audit period, auditor opinion, and customer reliance |
Control Domains
Our public control descriptions address:
- Identity, authentication, authorization, and access lifecycle
- Data protection, privacy, retention, and secure disposal
- Auditability, integrity, provenance, and review context
- Secure development, change management, and dependency review
- Vulnerability response and responsible disclosure
- Backup, continuity, incident response, and recovery governance
- Shared responsibility for hosted, private, and self-managed deployments
Shared Responsibility
The application supplies security capabilities and guardrails. Customers and operators remain responsible for lawful data use, user provisioning and offboarding, endpoint and network security, storage and key management, backup and retention decisions, workforce practices, physical safeguards, and required contractual terms.
Assurance Boundary
Framework alignment is not a certification, attestation, penetration-test report, or determination that a customer is compliant. Deployment-specific evidence is available through a controlled review after requester verification. We do not publish system inventories, network details, security thresholds, open findings, or remediation plans on this public page.