CyberTRIZPEDIA

Technology

127 regulations apply to this sector.

Written for this sector

AI ActAI Act regulates providers and deployers of AI systems across the EUAI EOUS Executive Order on AI directs federal AI safety and standards developmentBerlin Group NextGen PSD2Third-party providers and fintechs implementing PSD2 APIs.BIS Export LicenseDual-use technologies heavily regulated under BIS export controls.CCPA/CPRATech companies are primary targets of California consumer privacy lawCIS ControlsTechnology organisations widely implement CIS Controls for securityCMMI DEVCMMI DEV is a process maturity model primarily for software development organisationsCOPPAUS law governing online collection of children's data from tech platformsCRAEU Cyber Resilience Act targets manufacturers and developers of digital productsCyber Resilience ActTechnology manufacturers of connected products must comply with security requirements.DGAEU Data Governance Act regulates data intermediaries and data sharing services.DMATargets large online platforms and gatekeepers in digital marketsDMBOK ExtensionTechnology organisations apply extensions for advanced data managementDMBOK v2Core reference for technology organisations managing data assetsDSAOnline platforms and intermediary services are the primary targetEAADigital products and software must meet accessibility requirementsEARTechnology transfers and software exports subject to EAR controlsEU Data ActTech companies building connected products and data services are primary addressees.EU IPRIPR frameworks primarily protect technology innovations and patents.EU Platform Work DirectiveDigital platforms operating gig economy services are primary scope.FTC AI GuidanceFTC AI guidance targets technology companies developing and deploying AI systems.GDPRTechnology companies are core data controllers and processors under GDPR.India Information Technology Act, 2000Regulates IT companies, digital intermediaries and electronic commerce in IndiaIoT Cybersecurity Improvement ActIoT device manufacturers selling to US federal government must comply.ISO 12207Defines software lifecycle processes directly for software development organizationsISO 15288ISO 15288 defines systems and software lifecycle processes for technology productsISO 20000Technology companies obtain ISO 20000 certification for IT service deliveryISO 22989AI concepts and terminology standard is foundational for AI technology developers.ISO 23053ML system framework standard is foundational for AI/ML technology developers.ISO 23894AI risk management guidance is written for AI developers and technology organisations.ISO 24748Systems and software lifecycle management is core for technology developers.ISO 25010Software quality characteristics standard is written for software developers and engineers.ISO 27001Technology companies certify to ISO 27001 to demonstrate security to customers.ISO 27002Technology organisations use ISO 27002 controls as implementation guidance.ISO 27004Technology organisations use measurement frameworks to assess security programme effectiveness.ISO 27017/27018Cloud service providers are primary implementers of these standardsISO 27034Software developers and technology firms are primary target audienceISO 27036Technology vendors and their customers apply it in procurementISO 27701Technology companies managing personal data implement it as privacy frameworkISO 29100Technology system designers apply privacy principles during developmentISO 29134Technology developers conduct PIAs using this standard for new systemsISO 31700Privacy by design standard targets product and system developers handling personal dataISO 33001ISO 33001 covers process assessment concepts for software and systemsISO 38500IT governance standard guides board-level oversight of information technologyISO 38507Addresses governance implications of AI use by organisationsISO 42001AI management system standard targets organisations developing or deploying AIISO 56002Innovation management system standard targets technology-driven organisationsISO 9001 SWISO 9001 for software applies specifically to software development quality management.KanbanKanban is most widely applied in software and technology development workflows.KanbanKanban is most widely applied in software and technology development workflows.KanbanKanban Method is most widely applied in software and technology development workflows.NIST AI RMFFramework written for technology organizations developing and deploying AI systems.NIST IoT CSFIoT manufacturers and technology developers are the primary audience.NIST IoT Cyber BaselineTargets IoT device manufacturers and technology solution providers.NIST Privacy FrameworkTechnology companies managing personal data are core audience for this framework.NY SHIELD ActBroad application to any business handling NY residents' private dataOAuth 2.1Authorization framework standard for software and API developersOIDCOpenID Connect is an identity layer standard for software applicationsOpen Banking StandardFintechs and TPPs must implement open banking API standardsOpen Banking UKThird-party providers and fintechs operate under this frameworkOWASP SAMMFramework directly for software development teams and organizationsPRINCE2 AgileAgile delivery methods are native to software and technology teams.PSD2Fintechs and TPPs (PISPs/AISPs) are core regulated entities.PSD3Fintechs and open banking providers are core regulated entities under PSD3.PSR SafeguardingE-money institutions and fintechs must segregate and safeguard funds.SAFe 6.0SAFe is primarily adopted by technology and software development organisationsScrum 2020Scrum is the dominant agile framework for software product development teamsSOC2Cloud and SaaS providers commonly undergo SOC 2 audits for customer assurance.SSAE 18Technology service organizations use SSAE 18 to produce SOC 1 and SOC 2 reports.SSDFApplies to software developers and technology product vendorsTOGAF 10Technology teams use TOGAF ADM to govern architecture decisions and transformationsUS State Privacy LawsTech companies handling personal data are primary targets of state privacy legislation.W3C VCW3C Verifiable Credentials standard governs digital credential infrastructure and implementation.

Also applies

3DSPayment technology providers integrate and maintain 3DS infrastructureBook VII Payment ServicesFintech and payment technology firms providing payment services.CHIPSTech companies relying on chip supply chains affected by CHIPS ActCOBIT 2019Technology firms use COBIT to govern internal and client-facing ITCOBIT 2019Technology firms use COBIT to govern internal and client-facing ITCOBIT 2019Technology firms use COBIT to govern internal and client-facing ITCOSO 2013Technology companies apply COSO for financial reporting internal controlsCSA CCMTechnology firms adopting cloud services use CCM for compliance.Cyber Trust MarkTechnology firms producing IoT products must comply with the mark's standards.DCAMTechnology organisations apply DCAM for data capability assessments.EBA Major Incident Reporting PSD2Fintech and payment technology firms operating under PSD2 in scopeEIDAS2Tech providers must implement trust services and wallet standards.EMDFintech and payment technology providers subject to EMD licensing rules.EMD2Payment and fintech technology firms must comply with EMD2 licensing.EMVPayment technology providers must build EMV compliance into solutions.ePrivacy DirectiveTechnology platforms and online services must comply with cookie and tracking rules.EU Foreign Direct Investment Screening RegulationStrategic technology sectors including AI and semiconductors are screening targets.EU Import/Export ControlsDual-use technology exports require licensing under EU controls.FAPITechnology providers building financial APIs must implement FAPI standardsFAPI 2Technology vendors implementing open finance APIs must adopt FAPI 2.0FDX APIFintech and API providers implementing financial data exchange standardsFedRAMPCloud service providers must obtain FedRAMP authorization to serve federal clientsFIDAFintech and data service providers building financial data access solutionsHealth Insurance Portability and Accountability ActHealth tech platforms processing PHI are subject to HIPAA requirements.IEC 62304Software developers building medical device software must comply with IEC 62304.IEC 62366Tech firms developing medical software apply IEC 62366 usability requirements.IFRSListed technology companies apply IFRS financial reporting standards.IOSCO OutsourcingTech vendors providing outsourced services to regulated firms are in scope.ISAE 3402Technology service providers obtain ISAE 3402 reports for client assuranceISO 27032Tech companies apply it to manage cybersecurity in online environmentsISO 27040Cloud and storage technology vendors apply it for product securityISO 8583Payment technology providers implement ISO 8583 in processing systems.ISO 9001Tech companies adopt ISO 9001 for software and service quality assurance.ITARTechnology firms handling controlled technical data must comply with ITAR.ITIL 4Technology companies adopt ITIL 4 to structure and improve IT service operations.Markets in Crypto-Assets Regulation 2023/1114Tech firms issuing or servicing crypto assets fall under MiCA scope.MiCA StablecoinTech firms issuing stablecoins must meet MiCA stablecoin requirements.NACHAFintech and payment technology firms processing ACH transactions subject to NACHA.NACHA RulesPayment technology providers processing ACH transactions must comply with NACHA Rules.New Zealand Strategic Goods ListAdvanced technologies with military applications are subject to export control.NIST RMFTech firms serving government adopt RMF for complianceP3M3 v3Commonly applied in technology organisations for delivery capability improvement.PCI Contactless Payments on COTSSoftware vendors building COTS payment acceptance solutions must comply.PCI DSSTechnology providers processing or storing card data must comply.PMBOKWidely used in technology project delivery and software development programmes.PRINCE2Technology organisations use PRINCE2 for structured project delivery.PSRFintech payment service providers are regulated participants.Reg EFintech apps and digital wallets facilitating EFTs must comply.Regulation (EU) 2021/697 European Defence FundDefence technology development is a key EDF funding category.Regulation CCFintech platforms processing check deposits must comply with availability rules.SEC Cyber DiscTech public companies subject to SEC cybersecurity disclosure obligations.SEC Cyber DisclosureTech public companies subject to SEC cybersecurity disclosure obligations.Singapore Strategic Goods Control Act 2002Strategic technologies with military applications subject to export controls.SOX ITGCPublicly listed technology companies must maintain SOX ITGC compliance.

TRIZ for Technology

Worked contradictions and resolutions for this sector.