Managed detection and response (MDR) is a security service that provides continuous monitoring, threat detection, investigation, and response across an organization’s environment. For organizations with compliance obligations, MDR can address a specific gap: the monitoring, logging, incident detection, and response controls that appear in nearly every major security framework but require operational capability—not just documentation.
Key takeaways
- MDR can address the monitoring, logging, and incident response controls that appear in virtually every major security framework.
- Compliance auditors typically test for operational evidence of functioning controls—not just documentation that policies exist.
- Expel holds SOC 2 Type 2 and ISO 27001 certifications that may satisfy service provider due diligence requirements across major frameworks.
- Bridge Letters cover interim periods between SOC 2 report cycles, ensuring continuous compliance documentation.
Every major security compliance framework requires some version of the same three capabilities: continuous monitoring of systems and activity, the ability to detect and investigate security incidents, and a documented process for responding to them. These aren’t just policy requirements—they’re operational capabilities that auditors and assessors typically test for evidence of actual functioning, not just documentation. MDR can address these requirements.
What compliance controls does MDR address?
Across the major frameworks, the controls that MDR may support fall into two categories.
- Monitoring and logging controls: Requirements to collect, and review audit logs and activity records from systems in scope.
- Incident detection and classification controls: Requirements to detect security events, classify them against defined criteria, and initiate response.
The common pattern is that frameworks define what outcomes the controls should achieve; auditors test whether the organization has operational evidence that those outcomes are actually being delivered—not just that a policy says they should be.
MDR and PCI DSS—Requirements 10 and 12
PCI DSS Requirements 10 and 12 are the two requirements where security operations capabilities may determine whether an organization can demonstrate compliance.
Requirement 10 (log and monitor all access to system components and cardholder data) requires capturing and retaining logs from all in-scope system components, protecting logs from modification, retaining them for at least 12 months with 3 months immediately available, and reviewing logs for suspicious activity. Expel’s 24×7 monitoring across the cardholder data environment provides the active monitoring that Requirement 10 auditors might look for.
MDR and NIST SP 800-171
The NIST SP 800-171 domains where continuous monitoring and detection capabilities may be directly tested are Audit and Accountability (AU), Incident Response (IR), and System and Information Integrity (SI).
- AU.L2 (audit and accountability): NIST SP 800-171 requires creating and retaining system audit logs, protecting audit information, and reviewing and analyzing audit logs for potential security threats. Expel’s 24×7 monitoring ingests and actively analyzes this data—the active analysis component is what assessors may check for in AU control testing.
- IR.L2 (incident response): NIST SP 800-171 requires establishing an operational incident handling capability, tracking and documenting incidents, and testing incident response capability. Expel’s documented response performance may help provide evidence of an operational, tested IR capability.
- SI.L2 (system and information integrity): NIST SP 800-171 requires providing protection from malicious code, monitoring system security alerts, and monitoring organizational systems to detect attacks and unauthorized use. Expel’s continuous monitoring may address the monitoring and malicious code detection components.
You can read all about our compliance program here: https://expel.com/security-compliance/ and find all our compliance documentation within our Trust Center here: https://security.expel.com.
Frequently asked questions
Does MDR help with compliance?
Yes—MDR may directly address the monitoring, and incident detection, controls that appear in virtually every major security compliance framework that requires operational detection and response capabilities that MDR can provide. The key distinction: compliance auditors may test for operational evidence of functioning controls—not just documentation that the controls exist.
Does Expel have a SOC 2 report?
Yes. Expel holds an annual SOC 2 Type 2 report (audit period: May 1–April 30), available under NDA. Expel also holds ISO 27001:2013 certification, which is publicly verifiable. Bridge Letters cover interim periods between SOC 2 report cycles. All compliance documentation is available within our Trust Center here: https://security.expel.com.
