One training library that satisfies the security awareness control across eight major frameworks — SOC 2, PCI DSS, ISO 27001, HIPAA, NISTCSF, HITRUST, CMMC, and CIS Controls.

Compliance is Mandatory. Boredom is Optional.

Cross-Framework Coverage

01 / 08

Compliance Training  · awareness SoulEyez  · vulnerability
01

SOC 2

2017 Trust Services Criteria

Compliance Training — satisfies directly

CC1.4 / CC2.2

Security awareness & communication

SoulEyez — satisfies directly

CC7.1 / CC4.1

Vulnerability identification & periodic control evaluation

What the training reinforces

Day-to-day staff behavior is where these controls hold or fail. The curriculum reinforces access control (CC6), monitoring & incident response (CC7), change management (CC8), availability & backup (A1), and vendor risk (CC9).

02

PCI DSS

v4.0.1

Compliance Training — satisfies directly

Req 12.6

Formal security awareness program

SoulEyez — satisfies directly

Req 11

Regular scanning & testing of systems and networks

What the training reinforces

Cardholder data is only as safe as the people who handle it. The curriculum reinforces malware defenses (5), secure coding & OWASP (6), least privilege (7), MFA & passwords (8), physical security (9), logging (10), data protection (3), and vendor management (12.8).

03

ISO 27001

:2022

Compliance Training — satisfies directly

Cl. 7.2–7.3 + A.6.3

Competence & awareness

SoulEyez — satisfies directly

A.8.8

Management of technical vulnerabilities

What the training reinforces

Your ISMS leans on people doing the right thing by default. The training reinforces supplier security (A.5.19–5.22), access control (A.5.15–18), data protection, physical security (A.7), and logging (A.8.15).

04

HIPAA

Security Rule

Compliance Training — satisfies directly

§164.308(a)(5)

Security Awareness & Training

SoulEyez — supports

§164.308(a)(1)(ii)(A) & (a)(8)

Risk analysis & periodic technical evaluation

The Security Rule names no explicit scanning requirement — these are the nearest analogues, and scanning is evidence toward them rather than the control itself.

What the training reinforces

Protecting PHI starts with everyday staff judgment. The modules reinforce administrative, physical & technical safeguards, incident procedures, and device & media controls.

05

NIST CSF

2.0

Compliance Training — satisfies directly

PR.AT

Awareness & Training

SoulEyez — satisfies directly

ID.RA-01 / DE.CM

Vulnerability identification & continuous monitoring

What the training reinforces

Awareness touches every part of your security program, not just one corner. The training reaches all six functions: Govern, Identify, Protect, Detect, Respond, and Recover.

06

HITRUST CSF

e1 Assessment

Compliance Training — satisfies directly

Domain 13 / 02.e

Education, training & awareness

SoulEyez — satisfies directly

Domain 07

Vulnerability management

What the training reinforces

This is the bar the whole curriculum was built to. Past Domain 13, it reinforces endpoint & portable media protection (02–03), password management (10), access control (11), audit logging (12), third-party assurance (14), incident management (15), and data protection & privacy (19).

07

NIST 800-171 / CMMC

DoD / CUI contractors

Compliance Training — satisfies directly

3.2

Awareness & Training family

SoulEyez — satisfies directly

3.11.2 / 3.12.1

Vulnerability scanning & periodic control assessment

What the training reinforces

Handling CUI demands disciplined habits from everyone on the contract. The curriculum reinforces access control, audit & accountability, configuration management, incident response, and media protection — for DoD and CUI contractors.

08

CIS Controls

v8

Compliance Training — satisfies directly

Control 14

Security Awareness & Skills

SoulEyez — satisfies directly

Controls 7 & 18

Continuous vulnerability management & penetration testing

What the training reinforces

Skilled, aware staff are what make the technical safeguards actually work. The training maps to Controls 3, 4, 5/6, 7, 8, 11, and 15.

Every framework here asks the same two things of you: that your people know better, and that you are looking for holes on a cadence. The training library covers the first, SoulEyez covers the second, and both leave an evidence trail. Neither is certification on its own — each framework asks for more than these two controls.

SoulEyez - Testing Is the Control. The Report Is the Proof.

Advanced Pentesting. Audit-Ready Output.

Every framework on this page asks the same two questions: are you looking for vulnerabilities on a defined cadence, and can you prove it? Most teams answer the first with one annual third-party engagement and the second with a scramble through old Slack threads.

SoulEyez collapses both into a single workflow. Run the scan, track the finding through remediation, generate the report — with the full engagement history sitting behind it as your evidence trail.

Satisfies directly
SOC 2 — CC7.1 vulnerability identification and monitoring; CC4.1 periodic control evaluation
HITRUST CSF — Domain 07, Vulnerability Management

Also reinforces
ISO 27001 A.8.8 · NIST CSF 2.0 ID.RA-01 and DE.CM · NIST 800-171 §3.11.2 and §3.12.1 · CIS Controls v8 #7 and #18 · PCI DSS Req 11 scanning and testing activity

Lightweight, open-source friendly, and built to drop into the pipeline you already have.

Who We Are

Aliyeh Zeijnali

"Doubt is the eraser of dreams"

Finding a family that made me realize that I’m the unicorn, made me feel fearless when diving head-first into the unknown. I was told that working hard on a part of your dream will carry over to other aspects of your life, and I see it now!

Unintentionally, I realized that being organized in the work place is a job! I really enjoyed helping out on the GRC side of things; reporting, collecting evidence, policies, etc. After a few years working with our lovely team - we found our niche: Compliance Training! I’m beyond proud of our growth and what came of our courses. And if you don’t know - they’re based on us and our real life personalities! Maybe a little exaggerated…

Im not just an enginerd at CyberSoul SecurITy - ironically, I’ve found peace in training martial arts… my favorite right now is boxing! I think it’s safe to say that all our life goals are to profit from what we love doing, make new connections, and build a loving community. Unicorn out!

Co-Founder & Head of Programs

Jr Babauta

“We Work Hard With Each Other For Ourselves, & We Work Hard By Ourselves For Each Other!”

When I first started my career, I wasn't a "techie" at all. I had no fancy degrees and zero experience—literally none! But I had two powerful tools: a strong reason and an unwavering belief in myself. Armed with those, I set out on my journey and have spent over 20 years in Security and IT, taking on roles as both a technical leader and a strategist.

Why did you create CyberSoul SecurITy?

I created CyberSoul SecurITy because I’m passionate about sharing the knowledge I’ve gained over the years. My goal is to help others succeed without the burden of exorbitant education costs, providing an accessible path for young adults and others interested in cybersecurity and IT.

What would you be doing if you weren't in Security?

The easy answer is, you’d find me living on Maui, training in boxing with my wife and practicing jiu jitsu with friends. In the evenings, I’d be performing Spoken Word at a cozy restaurant, sharing my truth with an intimate crowd.

Co-Founder & Head of Security
Head of Operations

Maggielynn Babauta

True freedom is achieved when we become conscious of and connected to our own thoughts, allowing us to lead with our hearts and navigate daily life with ease.

I am a results-driven professional with 18 years of experience in operations within the health and wellness industry. My expertise lies in planning, enhancing operational efficiency, team building, and meticulous process optimization. I excel at identifying strengths and weaknesses, implementing policies and standards, and making operational changes that boost productivity and profitability. My demonstrated ability to motivate staff and manage costs effectively through optimal resource utilization has been a cornerstone of my career. After years of leading in the corporate world, I chose to adopt a more heart-centered approach to leadership. This shift aimed to restore clarity and peace in my life, leading to significant personal and professional transformations. I believe that work-life balance and recognizing one’s own worth are essential for success, regardless of one’s role within a company.

Head of Social Media

Arman Zeijnali

“True potential is a stone that must be carved.”

What made me want to get into cybersecurity is a great question. Money. And I also love breaking into things, and I saw that you can do that virtually by becoming a pen-tester in cybersecurity.

In the midst of this, I was asked by my sister to become a part of a starting cybersecurity company. Being an enginerd like her I said yes. I also didn’t want to be too much of a nerd, so I started boxing and lifting weights to even it out.

My dream is to become a professional nerd, make money, and become the best version of myself- both physically and mentally.