Public Sector
74 regulations apply to this sector.
Written for this sector
AI EOFederal agencies must implement AI governance and procurement standardsBE Civil ProtectionBelgian civil protection regulation primarily governs public emergency servicesBE WhistleblowingBelgian whistleblowing law applies broadly, especially to public sector entities.Canada Security of Information ActGoverns government officials handling classified informationCBE-KBOCBE/KBO is the Belgian official company register maintained by public authorities.DGADGA governs re-use of public sector data held by government bodies.Federal Information Security Modernization ActWritten specifically for US federal agencies and their information security programs.FedRAMPFedRAMP governs cloud security authorization for US federal government agenciesIIA StandardsPublic sector internal audit functions widely adopt IIA Standards.IoT Cybersecurity Improvement ActFederal agencies must procure only compliant IoT devices under this Act.ISO 22301Government bodies require continuity plans for essential public services.ISO 22320Emergency management is a core government and civil protection function.ISO 22322Government bodies are responsible for public warning and crisis communications.ISO 22361Crisis leadership guidance directly supports government crisis management functions.ISO 37001Government entities adopt ISO 37001 to prevent bribery in procurement and operationsNIS2Public administration is a named essential entity category under NIS2.NIST 800-53Primarily mandated for US federal agencies and government information systems.NIST RMFMandatory for US federal agencies under FISMAOSCE Code of Conduct on Politico-Military AspectsAddresses state responsibilities and politico-military governance obligations.PRINCE2PRINCE2 originated in UK government and is mandated across public projects.UN Convention against CorruptionTreaty primarily targets corruption in public administration and officials.Also applies
BE Codex WellbeingPublic sector employers must comply with wellbeing at work obligationsCharter of the United NationsGoverns state conduct and international obligations of governmentsCIS ControlsGovernment agencies reference CIS Controls for cybersecurity postureCOBIT 2019Commonly implemented in government IT governance programmesCOBIT 2019Commonly implemented in government IT governance programmesCOBIT 2019Commonly implemented in government IT governance programmesCOBIT Design GuidePublic sector applies design guide to customise governance frameworksConvention for the Protection of Cultural PropertyStates must implement protective measures for cultural heritageCOSO 2013Government entities adopt COSO for internal control over financial reportingDMBOK v2Government data management programs adopt DMBOK standardsEIAPublic authorities responsible for authorising and reviewing EIAs.EIDAS2Public services must integrate EU digital identity wallet acceptance.EU Data ActB2G data sharing provisions allow public bodies to request privately held data.EU-NATO Joint Declaration 2023Government policy coordination between EU institutions and NATO is a key focus.EUICS2Government entities coordinate and report under critical sector cyber rulesFERPAPublic educational institutions and government-funded programs must complyICAO Annex 17National aviation authorities and governments implement Annex 17 obligations.ISO 22313Public bodies reference this guidance when building continuity capabilities.ISO 22317Government agencies use BIA to prioritise continuity of essential services.ISO 27001Government agencies adopt ISO 27001 for information security governance.ISO 27002Government bodies reference ISO 27002 controls for information security policy.ISO 27004Government agencies use security metrics to report on ISMS effectiveness.ISO 27005Government entities use it for structured information risk managementISO 27014Government bodies use it to govern information security at executive levelISO 27017/27018Government cloud adoption requires these controls for data protectionISO 27031Government agencies use it for continuity of essential ICT servicesISO 27035Government agencies use it for structured incident management processesISO 27036Government procurement of ICT services uses this standardISO 27037Law enforcement and government agencies apply it for digital forensicsISO 27050Government agencies apply it for public records and legal proceedingsISO 27701Government bodies use it to manage citizen personal data privacyISO 29100Government ICT systems use it as foundational privacy design frameworkISO 29134Government agencies apply it for mandatory privacy impact assessmentsISO 30414Public organisations adopt human capital reporting for transparencyISO 31000Government bodies use ISO 31000 for organisational risk frameworksISO 37000Public bodies adopt ISO 37000 for effective organisational governanceISO 37301Government agencies adopt compliance management frameworks from ISO 37301ISO 38500Government bodies use ISO 38500 to govern public IT investmentsISO 38507Government bodies reference ISO 38507 when governing AI system deploymentISPS CodePort authorities and coast guards enforce ISPS Code compliance obligations.ITIL 4Government IT departments widely use ITIL 4 for service management.MSPGovernment bodies widely adopt MSP for managing transformational change programmes.NIST CSFGovernment agencies broadly adopt NIST CSF for cybersecurity governance.NIST Privacy FrameworkGovernment agencies managing citizen data apply this privacy risk framework.P3M3 v3Widely adopted in government for assessing project management capability.PMBOKGovernment agencies frequently use PMBOK for managing large-scale projects.PRINCE2 AgileGovernment digital transformation projects adopt PRINCE2 Agile.Singapore Cybersecurity Act 2018Government systems fall within critical infrastructure protection scope.Statute of the International Court of JusticeStates as subjects of international law are primary parties before the ICJ.TOGAF 10Government agencies use TOGAF to structure digital transformation architectureUK Bribery ActPublic officials are covered as recipients of bribes under the Act.UNDP SDG ImpactGovernments align national policies and reporting with SDG Impact principles.Vienna Document 2011 on Confidence- and Security-BGovernment and state actors are the parties obligated to implement the document.TRIZ for Public Sector
Worked contradictions and resolutions for this sector.
Safety, Security & Police TRIZ
e Government TRIZ
Smart City TRIZ