Title 1, Part 10, Chapter 202 of the Texas Administrative Code sets information security standards for Texas state agencies and certain vendors.
Title 201, Section 17 of the Code of Massachusetts Regulations is a state regulation setting minimum standards for the protection of Massachusetts residents' personal information.
Title 23, Chapter I, Part 500 of the New York Codes, Rules and Regulations is a state regulation setting information security requirements for most banks, insurance companies, and financial institutions that operate in New York.
The AWS Foundational Technical Review (FTR) helps you identify AWS Well-Architected best practices specific to your software or solution.
The Azure Security Benchmark (ASB) provides prescriptive best practices and recommendations to help improve the security of workloads, data, and services on Azure.
The Cloud Security Alliance Cloud Controls Matrix is a cloud focused control framework that provides guidance for security and privacy.
The CIS Critical Security Controls (CIS Controls) are a prioritized set of Safeguards to mitigate the most prevalent cyber-attacks against systems and networks.
The General Data Protection Regulation (GDPR) is a legal framework that sets guidelines for the collection and processing of personal information from individuals who live in the European Union. Since the Regulation applies regardless of where websites are based, it must be implemented by all sites that have European visitors, even if they don't specifically market goods or services to EU residents.
SYSC, Chapter 13.7 of the UK Financial Conduct Authority’s Handbook of Rules and Guidance is a regulation that sets information security requirements for financial services firms and markets that operate in the UK.
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) mandates industry-wide standards for health care information on electronic billing and other processes and requires the protection and confidential handling of protected health information. The HITECH Act, published in 2013, made several changes to HIPAA and introduced new requirements for HIPAA-covered entities with notable changes for business associates.
HITRUST CSF (“Common Security Framework”) is provides a prescriptive set of controls that meet the requirements of multiple regulations and standards. It leverages internationally accepted standards and regulations such as GDPR, ISO, NIST, PCI, and HIPAA to create a comprehensive set of baseline security and privacy controls. HITRUST customizes security control requirements based on organization type, size, infrastructure, and requirements. In v9.* HITRUST is looking to gain wider adoption by supporting security and privacy standards outside of healthcare.
ISO 27001 is an international standard that helps organizations manage the security of their information assets. It provides a management framework for implementing an information security management system to ensure the confidentiality, integrity, and availability of all corporate data such as financial information, intellectual property, employee details or information managed by third parties.
The MITRE ATT&CK framework models the behaviors and techniques known as TTPs (Tactics, Techniques, and Procedures) of the real-life adversaries and how to detect and mitigate these attacks.
This framework provides a catalog of security and privacy controls primarily geared towards government and critical infrastructure. NIST SP 800-53 Revision 4 has since been superseded by Revision 5. The controls address a diverse set of security and privacy requirements, derived from legislation, executive orders, policies, directives, regulations, standards, and/or mission/business needs.
This framework provides a catalog of security and privacy controls primarily geared towards government and critical infrastructure.The controls address a diverse set of security and privacy requirements, derived from legislation, executive orders, policies, directives, regulations, standards, and/or mission/business needs.
The NIST Cybersecurity Framework is a voluntary set of guidelines to help organizations manage and reduce cybersecurity risk.
Chapter 603A of the Nevada Revised Statutes is a state law setting minimum standards for the protection of Nevada residents' personal information.
The Payment Card Industry Data Security Standard is an information security standard for organizations that handle branded credit cards from the major card providers. The standard was created to increase controls around cardholder data to reduce credit card fraud.
The South Carolina Insurance Data Security Act sets information security requirements for insurance industry-related businesses operating in South Carolina.
System and Organization Controls 2 provides guidance to organizations by ensuring their internal security practices meet industry standards for security, privacy, availability, processing integrity, and confidentiality.