SEC536: Adversarial AI - Penetration Testing AI Systems

Cybersecurity leaders and compliance professionals are under increasing pressure to meet a growing array of global regulations—all while maintaining effective threat detection and response capabilities. Traditional monitoring is no longer enough. Full Packet Capture (FPC) is rapidly emerging as a foundational requirement—not only for real-time visibility and forensic analysis, but as a direct response to regulatory mandates in the U.S., EU, and beyond.

FPC is a network security capability that provides complete, forensic-grade records of all network communications, rather than relying on metadata or sampled traffic analysis, creating an authoritative source of truth for security investigations.
No single regulation universally mandates FPC by name, but frameworks including ISO/IEC 27001:2022, NIST Cybersecurity Framework 2.0, NIST SP 800-207 Zero Trust Architecture, PCI-DSS v4.0, and the EU's NIS2 Directive all include logging, monitoring, or evidence-preservation requirements that FPC is well-suited to satisfy.
NIST SP 800-207 requires continuous monitoring and validation of network communications, and its "never trust, always verify" principle requires the detailed network analysis capabilities that comprehensive packet capture can provide.
Organizations can use data minimization techniques such as selective capture, automated redaction, and access controls to maintain comprehensive monitoring while limiting access to personal information not relevant to security analysis.
The paper points to FIPS 140-3, Common Criteria/NIAP, and SOC 2 compliance status as key regulatory certifications to evaluate, particularly for organizations in government or other highly regulated environments.