Digital Infrastructure
56 regulations apply to this sector.
Written for this sector
CIRCIACritical digital infrastructure operators must report incidents under CIRCIACISA Cross-Sector Cybersecurity Performance GoalsTargets operators of critical digital infrastructureCSA CCMDirectly applies to cloud infrastructure providers and data centres.DGAData sharing infrastructure providers directly regulated under DGA.DMACloud and digital infrastructure services included in scopeDORACritical ICT infrastructure providers subject to DORA oversightEU Data ActCloud and edge service providers face switching and interoperability obligations.EU Foreign Direct Investment Screening RegulationCritical digital infrastructure is an explicitly listed sector for FDI screening.EUICS2Critical digital infrastructure operators are core scope of cyber incident regulationISO 22301Data centres and cloud providers must ensure continuous service availability.ISO 27001Cloud and data centre operators widely adopt ISO 27001 certification.ISO 27002Cloud and data centre operators implement ISO 27002 controls for certification.ISO 27017/27018Cloud infrastructure providers must implement these controls directlyISO 27040Data centre and storage infrastructure providers implement it directlyNIS2Digital infrastructure providers are explicitly named as essential entities under NIS2.NIST CSFDeveloped for critical infrastructure protection including digital systems.NIST RMFApplied to digital infrastructure security risk managementSingapore Cybersecurity Act 2018Covers operators of critical information infrastructure including digital systems.SOC2Data centers and infrastructure providers use SOC 2 to demonstrate operational controls.Also applies
CIS ControlsDigital infrastructure operators apply CIS Controls for resilienceCRADigital infrastructure components subject to CRA requirementsCyber Resilience ActDigital infrastructure products subject to cybersecurity requirements.D3FENDInfrastructure defenders use D3FEND to structure protective countermeasures.DSAHosting and cloud services included as intermediary service providersEBA OutsourcingCloud and infrastructure outsourcing to financial firms regulatedECB T2 RulesT2 operates critical financial market infrastructure requiring technical compliance.EIDAS2Digital infrastructure must support interoperable electronic identity systems.ESMA CloudCloud service providers serving financial sector affected by ESMA guidance.EU-NATO Joint Declaration 2023Cyber resilience and critical infrastructure protection feature in the declaration.Federal Information Security Modernization ActFederal contractors operating digital infrastructure must comply.FedRAMPCloud and digital infrastructure providers serving government must complyIEC 62443Critical digital infrastructure operators apply IEC 62443 for OT/IT convergence security.IoT Cybersecurity Improvement ActIoT devices embedded in digital infrastructure subject to security standards.ISAE 3402Data centers and cloud providers frequently obtain ISAE 3402 certificationISO 20000Data centers and cloud providers apply ISO 20000 for managed service qualityISO 22313Digital infrastructure providers use the guidance for continuity programme design.ISO 27004Cloud providers apply metrics to demonstrate security control performance.ISO 27005Critical infrastructure operators apply it for risk assessmentsISO 27014Infrastructure operators use it to align security with organisational strategyISO 27031Critical infrastructure operators apply it to ensure ICT resilienceISO 27032Infrastructure providers use it to secure cyberspace interactionsISO 27033Data centres and infrastructure operators apply it for network securityISO 27035Infrastructure operators apply it for incident response planningISO 31700Infrastructure providers build privacy into platforms and servicesMITRE ATT&CKUsed to assess and defend critical digital infrastructure against adversary tactics.NERC CIPApplies to control systems and digital infrastructure supporting the grid.NIST 800-53Widely adopted for securing critical digital infrastructure systems.NIST IoT Cyber BaselineIoT baseline applies to connected infrastructure components.OAuth 2.1Underpins identity and access management in digital platformsOIDCUsed for identity management across digital platform infrastructureOWASP SAMMApplied to secure development of digital infrastructure softwareSEC Regulation SCICovers technology infrastructure supporting critical securities market operations.SSDFApplies to infrastructure software development and deploymentTARGET2-SecuritiesOperates as critical financial market infrastructure requiring technical complianceTIBER-EUApplies to critical financial market infrastructure operators and payment systemsW3C VCCredential infrastructure forms part of broader digital identity ecosystem.TRIZ for Digital Infrastructure
Worked contradictions and resolutions for this sector.
Telecommunications TRIZ
Cyber TRIZ