CyberTRIZPEDIA

IT & Cybersecurity

133 regulations apply to this sector.

Written for this sector

AI ActAI cybersecurity tools and biometric systems are explicitly regulatedAI EOEO mandates AI cybersecurity standards and red-teaming requirementsBudapest Convention on CybercrimePrimary international treaty targeting cybercrime and digital offencesCFTC System SafeguardsRegulation sets cybersecurity and IT system standards for registrantsCIRCIACIRCIA mandates cyber incident reporting for critical infrastructureCIS ControlsCIS Controls are a foundational cybersecurity best-practice frameworkCISA Cross-Sector Cybersecurity Performance GoalsDirectly establishes cybersecurity baseline goals for critical infrastructureCMMCCMMC sets cybersecurity maturity standards for defence supply chainCOBIT 2019IT governance framework directly governing enterprise technology and information systemsCOBIT 2019IT governance framework directly governing enterprise technology and information systemsCOBIT 2019IT governance framework directly governing enterprise technology and information systemsCOBIT Design GuideGuide for designing tailored IT governance systems using COBIT frameworkCRADirectly mandates cybersecurity requirements for products with digital elementsCSA CCMCloud Security Alliance Cloud Controls Matrix targets cloud security practices.Cyber Resilience ActRegulation written for cybersecurity of products with digital elements.Cyber Trust MarkUS IoT Cyber Trust Mark certifies cybersecurity standards for connected devices.D3FENDMITRE D3FEND is a cybersecurity countermeasure framework for defensive techniques.DMBOK ExtensionExtends DMBOK data management practices into specific technical domainsDMBOK v2Data management framework widely applied in IT and data governance rolesDORAICT third-party providers to financial entities are directly regulatedEBA ICT RiskICT risk management and cybersecurity are the core subject matterEBA Major Incident Reporting PSD2ICT incident reporting and security breach notification is centralEIDAS2eIDAS2 governs electronic identity, authentication and trust services.EUICS2EU Cyber Incidents for Critical Sectors targets cybersecurity incident reportingFAIRFAIR is a cyber risk quantification framework used by cybersecurity professionalsFAPIFAPI defines security standards for API authentication and authorisationFAPI 2FAPI 2.0 defines advanced OAuth/OIDC security for high-risk API environmentsFederal Information Security Modernization ActCore cybersecurity compliance framework for federal IT systems and contractors.FedRAMPCloud security assessment and authorization framework central to IT/cybersecurity complianceFTC AI GuidanceAI-driven cybersecurity products and practices fall under FTC scrutiny.GDPRIT and cybersecurity firms process personal data and must embed GDPR compliance.IEC 62443IEC 62443 is the primary cybersecurity standard for industrial OT/ICS systems.India Information Technology Act, 2000India's foundational IT law covering cybersecurity, digital transactions and offencesIoT Cybersecurity Improvement ActAct mandates NIST IoT security guidelines central to cybersecurity practice.ISO 12207Cybersecurity and IT teams apply ISO 12207 for secure software developmentISO 22989IT and security professionals use AI terminology standards for consistent practice.ISO 23053IT professionals use the ML framework for structured system development guidance.ISO 23894IT security teams apply AI risk management to assess AI system threats.ISO 25010IT teams use quality models to evaluate security and reliability of software.ISO 27001ISO 27001 is the primary ISMS standard written for IT and security organisations.ISO 27002ISO 27002 provides the security controls guidance underpinning ISMS implementation.ISO 27004Security measurement and monitoring guidance supports ISMS performance evaluation.ISO 27005Information security risk management standard core to cybersecurity practiceISO 27014Governance of information security standard aimed at security leadershipISO 27017/27018Cloud-specific security and PII protection controls for cloud environmentsISO 27031ICT readiness for business continuity is core cybersecurity and resilience standardISO 27032Cybersecurity guideline specifically addressing the cyberspace security domainISO 27033Network security standard covering design, implementation and management of secure networksISO 27034Application security standard guiding secure software development lifecycleISO 27035Information security incident management standard for detection and responseISO 27036Supplier relationship information security standard for ICT supply chainsISO 27037Digital evidence identification, collection and preservation for investigationsISO 27040Storage security standard addressing protection of stored information assetsISO 27050Electronic discovery standard for identification and collection of ESIISO 27701Privacy information management system extending ISO 27001 for PII protectionISO 29100Privacy framework standard providing principles for PII protection in ICT systemsISO 29134Privacy impact assessment guidelines for ICT systems processing personal dataISO 31700IT and security teams embed privacy controls into systems by designISO 42001AI security and risk management integral to cybersecurity functionsMAS TRMTechnology risk management framework requiring robust cybersecurity controls.MAS TRM NoticeNotice mandates specific cybersecurity and technology risk controls.MITRE ATT&CKMITRE ATT&CK is a cyber threat intelligence framework for cybersecurity practitioners.NIS2NIS2 is the EU's primary cybersecurity directive targeting essential and important entities.NIST 800-53NIST 800-53 is a foundational cybersecurity controls catalogue for federal and IT systems.NIST AI RMFAI risk management framework directly targets AI system developers and security practitioners.NIST CSFNIST CSF is a core voluntary cybersecurity risk management framework for all sectors.NIST IoT CSFProvides cybersecurity framework specifically tailored to IoT device ecosystems.NIST IoT Cyber BaselineEstablishes baseline cybersecurity capabilities required for IoT devices.NIST Privacy FrameworkPrivacy risk management framework primarily targets IT and cybersecurity practitioners.NIST RMFCore framework for IT security risk management processesNY DFS Part 500Regulation directly mandates cybersecurity programs and controlsNY SHIELD ActRequires reasonable cybersecurity safeguards for NY residents' dataNYDFS TPSPFocuses on cybersecurity risk management of third-party vendorsOAuth 2.1Core protocol for secure access delegation and identity securityOIDCCore protocol for federated identity and authentication securityOWASP SAMMSoftware assurance maturity model for secure development practicesPCI DSSPCI DSS mandates security controls and cybersecurity practices for cardholder data.PCI DSS ExtensionSecurity extensions address cybersecurity controls for cardholder data environments.RED CyberMandatory cybersecurity requirements for connected products drive compliance.SEC Cyber DiscCybersecurity incident disclosure requirements directly involve IT and security functions.SEC Cyber DisclosureCybersecurity incident disclosure requirements directly involve IT and security functions.SEC Regulation SCIRegulation mandates technology resilience, system integrity, and cybersecurity for market systems.Singapore Cybersecurity Act 2018Directly regulates cybersecurity practices and critical information infrastructure protection.SOC2SOC 2 assesses security, availability, and confidentiality controls at technology service organizations.SOX ITGCIT General Controls are a core SOX compliance domain covering access, change management, and operations.SSAE 18SSAE 18 governs SOC reports assessing controls at technology and IT service organizations.SSDFSSDF (Secure Software Development Framework) targets software security practicesTOGAF 10TOGAF is an enterprise architecture framework widely adopted in IT organisationsUS State Privacy LawsData privacy compliance is a core IT and cybersecurity obligation under state laws.W3C VCVC standard underpins digital identity verification and authentication security.

Also applies

21 CFR Part 11IT systems managing electronic records must meet Part 11 controls3DSFraud prevention and secure authentication are core cybersecurity functionsBerlin Group NextGen PSD2Secure API and authentication standards require cybersecurity implementation.CBM BelgiumNBB issues cybersecurity and operational resilience guidance to supervised entities.CSCFIT/security teams implement CSCF controls within financial messaging environments.DCAMIT and data governance teams use DCAM to assess data management capabilities.DFARS 7012IT security controls and incident reporting are core DFARS 7012 obligations.EBA OutsourcingICT outsourcing arrangements are the primary risk focus of guidelinesEBA SCA RTSAuthentication security requirements affect payment technology and security providers.ePrivacy DirectiveCookie and data confidentiality rules affect IT and cybersecurity service providers.EU TFR CryptoTechnical systems must capture and transmit required originator/beneficiary data.EU-NATO Joint Declaration 2023Hybrid threats and cybersecurity cooperation are addressed in the joint declaration.FFIEC CATCybersecurity maturity assessment framework applied within financial institutionsFFIEC IT HandbookCovers IT risk, security and operations management within banking contextGLBAGLBA Safeguards Rule imposes cybersecurity requirements on financial data processors.Health Insurance Portability and Accountability ActIT and cybersecurity providers handling PHI must comply as business associates.HKMA OR2IT and cyber risk management is a core component of HKMA OR requirements.HKMA TM G1Covers IT risk management and cybersecurity controls within banking institutions.HKMA TMG1Covers IT risk management and cybersecurity controls within banking institutions.IEC 61508Software safety integrity levels in IEC 61508 apply to safety-critical software.IEC 62304Cybersecurity and software quality requirements intersect with IEC 62304 processes.IOSCO OP RESOperational resilience requires robust IT and cybersecurity frameworks.IOSCO OutsourcingIT outsourcing to cloud and tech providers subject to IOSCO principles.ISO 22301IT service providers implement BCM to meet client and regulatory expectations.ISO 22313IT organisations apply guidance to align BCM with service management frameworks.ISO 24748IT organisations apply lifecycle management to software and system development.ISO 31010Cybersecurity risk assessments reference ISO 31010 methodologiesISO 9001 SWIT and cybersecurity firms apply software QMS standards to their development processes.NBB Payment OversightPayment system resilience and security requirements apply to IT providers.NERC CIPMandates cybersecurity controls for critical infrastructure systems.NY DFS 504Compliance programs include cybersecurity governance requirementsOpen Banking StandardSecurity requirements for API access and data sharingOpen Banking UKMandates security standards for API access and customer dataPCI Contactless Payments on COTSSecurity and operational requirements for software-based contactless acceptance.PCI MPOCSecurity requirements for software-based payment acceptance on mobile devices.PCI P2PEEncryption and security requirements are core to P2PE compliance.PCI PINPIN security mandates cryptographic and security controls for PIN protection.PSD2Strong customer authentication and security requirements drive IT compliance.PSD3Security and fraud prevention obligations require IT compliance work.Red Flags RuleIdentity theft detection programs require cybersecurity monitoring tools.SWIFT CSPDefines technical cybersecurity controls and assessment requirementsSYSC 15ARequires robust IT and cyber resilience as part of important business servicesTIBER-EUDefines advanced penetration testing methodology for critical financial infrastructure

TRIZ for IT & Cybersecurity

Worked contradictions and resolutions for this sector.