---
title: "What type of Cybersecurity regulations are there and how can Cynergy help?"
canonical: "https://kb.cynergy.app/space/WC/902889527/What%20type%20of%20Cybersecurity%20regulations%20are%20there%20and%20how%20can%20Cynergy%20help%3F"
format: markdown
---
Cyber security regulations are laws that govern the types of measures an organization must take to protect itself, its data, and its customers from cyber threats and data breaches.

Compliance regulations provide organizations with acceptable standards for developing strong cybersecurity programs. Compliance is an important tenet underlying the development and maintenance of information security programs. Different regulations have emerged over the years to address increasing security challenges.

### <u>**What kind of regulations are there?**</u>

<u>**NIST**</u>**- **NIST compliance is complying with the requirements of one or more NIST standards. NIST (National Institute of Standards and Technology) is a non-regulatory agency under the US Department of Commerce. Its primary role is to develop standards (particularly for security controls) that apply to various industries. 

NIST standards are based on best practices. That's why the government has been recommending them for use by companies or organizations. Among NIST's standards and guidelines, the most widely adopted is the **[NIST Cybersecurity Framework](https://www.ftc.gov/tips-advice/business-center/small-businesses/cybersecurity/nist-framework)** (CSF), used for assessing cybersecurity risks.

[https://www.nist.gov/](https://www.nist.gov/)

<u>**CIS controls**</u>**- **The Center for Internet Security (CIS) Controls are a set of recommended cyber defense measures designed to protect your organization against hackers and cybercriminals. The CIS Controls prioritize low-effort, high-impact actions and tactics that will improve your cybersecurity posture immediately. (These controls were formerly known as the CIS Critical Security Controls– or CIS CSC. The version 8 update shortened the CIS CSC from 20 to 18 controls and changed the name simply to– CIS Controls.) 

The CIS Controls are effective because they've been created based on some of the most common cyber-attack patterns and trends. The standards were designed by a pool of experts from the National Security Administration (NSA) and some of the nation's top cybersecurity forensic experts.

This makes the CIS Controls a dynamic, always-relevant framework as it's constantly updated based on new and emerging threats.

[https://www.cisecurity.org/](https://www.cisecurity.org/)

<u>**ISO**</u>** - **The International Organization for Standardization (ISO) is an international nongovernmental organization made up of national standards bodies; it develops and publishes a wide range of proprietary, industrial, and commercial standards and is comprised of representatives from various national standards organizations.

[https://www.cisecurity.org/](https://www.cisecurity.org/)

<u>**HIPAA- **</u>The HIPAA Privacy Rule establishes national standards to protect individuals' medical records and other individually identifiable health information (collectively defined as "protected health information") and applies to health plans, health care clearinghouses, and those health care providers that conduct certain health care transactions electronically. 

[https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html](https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html)

<u>**PCI-DSS- **</u>**[The Payment Card Industry Data Security Standard (PCI DSS)](https://digitalguardian.com/solutions/compliance-pci-dss)** is a set of requirements intended to ensure that all companies that process, store, or transmit credit card information maintain a secure environment. It was launched on September 7, 2006, to manage PCI security standards and improve account security throughout the transaction process. An independent body created by Visa, MasterCard, American Express, Discover, and JCB, the **[PCI Security Standards Council (PCI SSC)](https://www.pcisecuritystandards.org/)** administers and manages the PCI DSS. Interestingly, the payment brands and acquirers are responsible for enforcing compliance rather than the PCI SSC.

[https://www.pcisecuritystandards.org/pci_security/maintaining_payment_security](https://www.pcisecuritystandards.org/pci_security/maintaining_payment_security)

<u>**GDPR- **</u>The **[General Data Protection Regulation (GDPR)](https://gdpr.eu/)** is the toughest privacy and security law in the world. Though it was drafted and passed by the European Union (EU), it imposes obligations onto organizations anywhere, so long as they target or collect data related to people in the EU. The regulation was put into effect on May 25, 2018. The GDPR will levy harsh fines against those who violate its privacy and security standards, with penalties reaching into the tens of millions of euros.

[https://gdpr.eu/tag/gdpr/](https://gdpr.eu/tag/gdpr/)

<u>**CCPA-**</u>** **The [California Consumer Privacy Act of 2018](http://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?division=3.&part=4.&lawCode=CIV&title=1.81.5) (CCPA) gives consumers more control over the personal information that businesses collect about them, and the [CCPA regulations](https://govt.westlaw.com/calregs/Browse/Home/California/CaliforniaCodeofRegulations?guid=IEB210D8CA2114665A08AF8443F0245AD&originationContext=documenttoc&transitionType=Default&contextData=(sc.Default)) provide guidance on how to implement the law. This landmark law secures new privacy rights for California consumers, including:

- The [right to know](https://oag.ca.gov/privacy/ccpa#sectionc) about the personal information a business collects about them and how it is used and shared;
- The [right to delete](https://oag.ca.gov/privacy/ccpa#sectione) personal information collected from them (with some exceptions);
- The [right to opt-out](https://oag.ca.gov/privacy/ccpa#sectionb) of the sale of their personal information; and
- The [right to non-discrimination](https://oag.ca.gov/privacy/ccpa#sectionf) for exercising their CCPA rights.

[https://oag.ca.gov/privacy/ccpa](https://oag.ca.gov/privacy/ccpa)

<u>**AICPA-**</u>** **The American Institute of CPAs is the world’s largest member association representing the accounting profession, with 431,000+ members in 130 countries. The AICPA provides educational guidance materials; develops and grades the Uniform CPA Examination, and monitors and enforces compliance within the profession. There are currently 669,000+ actively licensed CPAs around the globe.

[https://www.aicpa.org/resources/landing/about](https://www.aicpa.org/resources/landing/about)

<u>**SOX-**</u> The Sarbanes-Oxley Act of 2002, often simply called SOX or Sarbox, is U.S. law meant to protect investors from fraudulent accounting activities by corporations. Sarbanes-Oxley was enacted after several major accounting scandals in the early 2000’s perpetrated by companies such as Enron, Tyco, and WorldCom.  So what is SOX? The law mandates strict reforms to improve financial disclosures from corporations and prevent accounting fraud. It also covers issues such as auditor independence, corporate governance, internal control assessment, and enhanced financial disclosure.

[https://www.soxlaw.com/](https://www.soxlaw.com/)

<u>**COBIT**</u>**- **Control Objectives for Information and Related Technologies, more popularly known as COBIT, is a framework that aims to help organizations that are looking to develop, implement, monitor, and improve IT governance and information management.

COBIT was established by ISACA, which stands for Information Systems Audit and Control Association. Both ISACA and the IT Governance Institute (ITGI) publish it.

[https://digitalguardian.com/blog/what-cobit](https://digitalguardian.com/blog/what-cobit)

<u>**GLBA-**</u> In the regular course of business, many companies that possess consumers’ financial information share it with their affiliates and other business partners. Owing to the sensitive nature of such financial information, the U.S. Congress passed the [Gramm-Leach-Bliley Act (GLBA)](https://www.ftc.gov/tips-advice/business-center/privacy-and-security/gramm-leach-bliley-act), also known as the Financial Services Modernization Act of 1999, to protect consumer financial privacy. GLBA requires companies acting as “financial institutions” – i.e., companies that offer consumers financial products or services like loans, financial or investment advice, or insurance – to explain their information-sharing practices to their customers and to safeguard sensitive data.

[https://www.mcafee.com/enterprise/en-us/about/cloud-compliance/glba-compliance-requirements.html](https://www.mcafee.com/enterprise/en-us/about/cloud-compliance/glba-compliance-requirements.html)

<u>**FISMA-**</u> FISMA is one of the most important regulations for federal data security standards and guidelines. It was introduced to reduce the security risk to federal information and data while managing federal spending on information security. To achieve these aims, FISMA established a set of guidelines and security standards that federal agencies have to meet. The scope of FISMA has since increased to include state agencies administering federal programs like Medicare. FISMA requirements also apply to any private businesses that are involved in a contractual relationship with the government.

[https://digitalguardian.com/blog/what-fisma-compliance-fisma-definition-requirements-penalties-and-more](https://digitalguardian.com/blog/what-fisma-compliance-fisma-definition-requirements-penalties-and-more)

<u>**FedRAMP-**</u> The [Federal Risk and Authorization Management Program (FedRAMP)](https://www.fedramp.gov/about/) is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services. FedRAMP empowers agencies to use modern cloud technologies, with emphasis on security and protection of federal information and helps accelerate the adoption of secure cloud solutions.

[https://www.gsa.gov/technology/government-it-initiatives/fedramp](https://www.gsa.gov/technology/government-it-initiatives/fedramp)

 <u>**FERPA-**</u> The Family Educational Rights and Privacy Act (FERPA) (20 U.S.C. § 1232g; 34 CFR Part 99) is a Federal law that protects the privacy of student education records. The law applies to all schools that receive funds under an applicable program of the U.S. Department of Education.

FERPA gives parents certain rights with respect to their children's education records. These rights transfer to the student when he or she reaches the age of 18 or attends a school beyond the high school level

[https://www2.ed.gov/policy/gen/guid/fpco/ferpa/index.html](https://www2.ed.gov/policy/gen/guid/fpco/ferpa/index.html)

<u>**ITAR-**</u>** **International Traffic in Arms Regulations (ITAR) is a United States regulatory regime to restrict and control the export of defense and military-related technologies to safeguard U.S. national security and further U.S. foreign policy objectives.

[https://www.federalregister.gov/documents/2020/01/23/2020-00574/international-traffic-in-arms-regulations-us-munitions-list-categories-i-ii-and-iii](https://www.federalregister.gov/documents/2020/01/23/2020-00574/international-traffic-in-arms-regulations-us-munitions-list-categories-i-ii-and-iii) 

<u>**COPPA-**</u> COPPA imposes certain requirements on operators of websites or online services directed to **children under 13 years of age**, and on operators of other websites or online services that have actual knowledge that they are collecting personal information online from a child under 13 years of age.

[https://www.ftc.gov/enforcement/rules/rulemaking-regulatory-reform-proceedings/childrens-online-privacy-protection-rule](https://www.ftc.gov/enforcement/rules/rulemaking-regulatory-reform-proceedings/childrens-online-privacy-protection-rule)

**NERC CIP-** The North American Electric Reliability Corporation (NERC) is a not-for-profit international regulatory authority whose mission is to assure the effective and efficient reduction of risks to the reliability and security of the grid. NERC develops and enforces Reliability Standards; annually assesses seasonal and long‐term reliability; monitors the bulk power system through system awareness; and educates, trains, and certifies industry personnel. NERC’s area of responsibility spans the continental United States, Canada, and the northern portion of Baja California, Mexico. NERC is the Electric Reliability Organization (ERO) for North America, subject to oversight by the Federal Energy Regulatory Commission (FERC) and governmental authorities in Canada. NERC's jurisdiction includes users, owners, and operators of the bulk power system, which serves nearly 400 million people.

[https://www.nerc.com/AboutNERC/Pages/default.aspx](https://www.nerc.com/AboutNERC/Pages/default.aspx)