Cybersecurity — 2,783 Nodes
- 16 CFR Part 314 - Standards for Safeguarding Customer Information
Organizations must develop, implement, and maintain a comprehensive written information security program to protect customer information, which includes designating a qualified individual, conducting risk assessments,… - A Profile for U.S. Federal Cryptographic Key Management Systems
This Profile for U.S. Federal Cryptographic Key Management Systems (FCKMSs) contains requirements for their design, implementation, procurement, installation, configuration, management, operation, and use by U.S.… - A01:2025 Broken Access Control
OWASP Top 10:2025 A01:2025 Broken Access Control. Access control enforces policy such that users cannot act outside of their intended permissions. Failures typically lead to unauthorized information disclosure,… - A02:2025 Security Misconfiguration
OWASP Top 10:2025 A02:2025 Security Misconfiguration. Security misconfiguration is when a system, application, or cloud service is set up incorrectly from a security perspective, creating vulnerabilities. This category… - A03:2025 Software Supply Chain Failures
OWASP Top 10:2025 A03:2025 Software Supply Chain Failures. Software supply chain failures are breakdowns or other compromises in the process of building, distributing, or updating software. This category sits within the… - A04:2025 Cryptographic Failures
OWASP Top 10:2025 A04:2025 Cryptographic Failures. Moving down two positions to #4, this weakness focuses on failures related to the lack of cryptography, insufficiently strong cryptography, leaking of cryptographic… - A05:2025 Injection
OWASP Top 10:2025 A05:2025 Injection. An injection vulnerability is an application flaw that allows untrusted user input to be sent to an interpreter (e.g. a browser, database, the command line) and causes the… - A06:2025 Insecure Design
OWASP Top 10:2025 A06:2025 Insecure Design. Insecure design is a broad category representing different weaknesses, expressed as "missing or ineffective control design." Insecure design is not the source for all other… - A07:2025 Authentication Failures
OWASP Top 10:2025 A07:2025 Authentication Failures. When an attacker is able to trick a system into recognizing an invalid or incorrect user as legitimate, this vulnerability is present. This category sits within the… - A08:2025 Software or Data Integrity Failures
OWASP Top 10:2025 A08:2025 Software or Data Integrity Failures. Software and data integrity failures involve code and infrastructure failing to protect against untrusted code or data being treated as valid. Examples… - A09:2025 Security Logging and Alerting Failures
OWASP Top 10:2025 A09:2025 Security Logging and Alerting Failures. Without logging and monitoring, attacks and breaches cannot be detected, and without alerting it is very difficult to respond quickly and effectively… - A10:2025 Mishandling of Exceptional Conditions
OWASP Top 10:2025 A10:2025 Mishandling of Exceptional Conditions. Mishandling exceptional conditions in software happens when programs fail to prevent, detect, and respond to unusual and unpredictable situations, which… - Acceptable Means of Compliance (AMC) and Guidance Material (GM) to Commission Regulation (EU) No 1321/2014 - Issue 1, Amendment 4 - Cybersecurity Requirements for Aircraft (ED-202A AMC/GM)
This regulation establishes cybersecurity requirements for aircraft design, production, and continuing airworthiness, mandating risk-based protection of aircraft systems against unauthorized access. It applies to design… - Account Management (NIST SP 800-53 AC-2)
The Account Management control establishes a comprehensive framework, consistent with NIST Special Publication 800-53 AC-2, for managing the full lifecycle of information system accounts. This governance is essential… - Act on the Promotion of Ensuring National Security through Integrated Economic Measures (Economic Security Promotion Act)
This act requires designated operators of Japan's specified critical infrastructure to submit plans for equipment installation or outsourcing of maintenance services for prior government review to mitigate external… - Advanced Encryption Standard (AES)
The Advanced Encryption Standard (AES) specifies a FIPS-approved cryptographic algorithm that can be used to protect electronic data. The AES algorithm is a symmetric block cipher that can encrypt (encipher) and decrypt… - Afghanistan ATRA Framework - Constitutional Privacy Obligations and ICT Regulatory Personal Data Provisions
Afghanistan's telecommunications and ICT sector is regulated by the Afghanistan Telecom Regulatory Authority (ATRA). The Afghan Constitution of 2004 (which was in force under the Islamic Republic of Afghanistan)… - AICPA SOC 2 Common Criteria CC1 - Control Environment (COSO Principles 1-5)
CC1 is the Control Environment series of the SOC 2 Common Criteria, drawn from COSO Principles 1-5. It requires the service organization to demonstrate a commitment to integrity and ethical values, board independence… - AICPA SOC 2 Common Criteria CC2 - Communication and Information (COSO Principles 13-15)
CC2 is the Communication and Information series of the SOC 2 Common Criteria (COSO Principles 13-15). It requires the entity to obtain or generate and use relevant, quality information to support internal control, to… - AICPA SOC 2 Common Criteria CC3 - Risk Assessment (COSO Principles 6-9)
CC3 is the Risk Assessment series of the SOC 2 Common Criteria (COSO Principles 6-9). It requires the entity to specify objectives with sufficient clarity, identify and analyze risks to those objectives, consider the… - AICPA SOC 2 Common Criteria CC4 - Monitoring Activities (COSO Principles 16-17)
CC4 is the Monitoring Activities series of the SOC 2 Common Criteria (COSO Principles 16-17). It requires the entity to select, develop, and perform ongoing and separate evaluations to ascertain whether the components… - AICPA SOC 2 Common Criteria CC5 - Control Activities (COSO Principles 10-12)
CC5 is the Control Activities series of the SOC 2 Common Criteria (COSO Principles 10-12). It requires the entity to select and develop control activities that contribute to the mitigation of risks to acceptable levels,… - AICPA SOC 2 Common Criteria CC6 - Logical and Physical Access Controls (CC6.1-CC6.8)
CC6 is the Logical and Physical Access Controls series of the SOC 2 Common Criteria. Its eight criteria (CC6.1-CC6.8) require the entity to implement logical access security software and architecture, to register and… - AICPA SOC 2 Common Criteria CC7 - System Operations (CC7.1-CC7.5)
CC7 is the System Operations series of the SOC 2 Common Criteria (CC7.1-CC7.5). It requires the entity to use detection and monitoring procedures to identify configuration changes and vulnerabilities, to monitor system… - AICPA SOC 2 Common Criteria CC8 - Change Management (CC8.1)
CC8 is the Change Management series of the SOC 2 Common Criteria. Its single criterion, CC8.1, requires the entity to authorize, design, develop or acquire, configure, document, test, approve, and implement changes to… - AICPA SOC 2 Common Criteria CC9 - Risk Mitigation (CC9.1-CC9.2)
CC9 is the Risk Mitigation series of the SOC 2 Common Criteria (CC9.1-CC9.2). It requires the entity to identify, select, and develop risk mitigation activities for risks arising from potential business disruptions, and… - AICPA SOC 2 Trust Services Criteria - Availability Category (Additional Criteria A1.1-A1.3)
The AICPA SOC 2 Availability Trust Services Category requires an entity to maintain controls ensuring its information and systems are available for operation and use to meet its objectives, as committed or agreed. This… - AICPA SOC 2 Trust Services Criteria - Confidentiality Category (C1.1-C1.2)
The AICPA SOC 2 Confidentiality principle requires entities to protect information designated as confidential throughout its lifecycle, from creation to destruction, as committed or agreed. The Confidentiality category… - AICPA SOC 2 Trust Services Criteria - Privacy Category (P1.0-P8.0 Privacy Notice and Choice)
The AICPA SOC 2 Privacy Category requires service organizations to provide a clear privacy notice detailing their personal information practices (P1.0) and to offer choices to individuals regarding the collection, use,… - AICPA SOC 2 Trust Services Criteria - Processing Integrity Category (PI1.1-PI1.5)
This regulation requires service organizations to implement controls ensuring that system processing is complete, valid, accurate, timely, and authorized to meet the entity's objectives. The core criteria, PI1.1 through… - AICPA SOC for Cybersecurity - Cybersecurity Risk Management Reporting Framework
SOC for Cybersecurity is an AICPA reporting framework for an examination of an entity-wide cybersecurity risk management program. Unlike SOC 2, which covers a defined system at a service organization, SOC for… - Alberta Personal Information Protection Act (PIPA) 2003
Alberta's private-sector data protection law, substantially similar to federal PIPEDA, governs collection, use, and disclosure of personal information by private-sector organizations in Alberta under OIPC Alberta… - Algeria Personal Data Protection Law - ANPDP Compliance Framework
Algeria Law No. 18-07 on Personal Data Protection (2018) establishes a CNIL-influenced framework of consent-based processing, mandatory prior authorization for sensitive data, and data subject rights. The Autorité… - American Samoa - Territorial Privacy Rights and Federal Data Protection Framework
American Samoa is an unincorporated unorganised territory of the United States located in the South Pacific Ocean. Unlike other US territories such as Puerto Rico, Guam, and the US Virgin Islands, American Samoa is… - An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts - Part 2: Critical Cyber Systems Protection Act
This regulation requires operators of vital services or systems designated by the Governor in Council to establish and maintain cyber security programs, report cyber security incidents, mitigate supply-chain risks, and… - An Introduction to Information Security (NIST Special Publication 800-12 Revision 1)
This publication serves as a starting-point for those new to information security and for those unfamiliar with NIST information security publications and guidelines. Its intent is to provide a high-level overview of… - Andorra Qualified Law No. 29/2021 on Personal Data Protection - AAPD
Andorra's Qualified Law No. 29/2021 on Personal Data Protection (Llei qualificada de protecció de dades personals), adopted by the General Council (Consell General) of Andorra and entered into force in 2021, is… - Angola Law No. 22/11 on Personal Data Protection
Angola enacted Law No. 22/11 of 17 June 2011 on Personal Data Protection (Lei da Protecção de Dados Pessoais), establishing a comprehensive framework modelled on the Portuguese data protection regime and Council of… - Anguilla Data Protection Act 2018
Anguilla, a British Overseas Territory, enacted the Data Protection Act 2018 aligned with UK and EU data protection standards. Administered by the Anguilla Information Commissioner, the Act establishes data protection… - Antigua and Barbuda Data Protection Act 2013
Antigua and Barbuda enacted the Data Protection Act 2013, establishing a comprehensive framework for the protection of personal data held by public and private bodies. The Act is administered by the Data Protection… - API1:2023 Broken Object Level Authorization
OWASP API Security Top 10 (2023) API1:2023 Broken Object Level Authorization. Object level authorization is an access control mechanism that is usually implemented at the code level to validate that a user can only… - API10:2023 Unsafe Consumption of APIs
OWASP API Security Top 10 (2023) API10:2023 Unsafe Consumption of APIs. Developers tend to trust data received from third-party APIs more than user input. This is especially true for APIs offered by well-known… - API2:2023 Broken Authentication
OWASP API Security Top 10 (2023) API2:2023 Broken Authentication. Authentication endpoints and flows are assets that need to be protected. Additionally, "Forgot password / reset password" should be treated the same way… - API3:2023 Broken Object Property Level Authorization
OWASP API Security Top 10 (2023) API3:2023 Broken Object Property Level Authorization. When allowing a user to access an object using an API endpoint, it is important to validate that the user has access to the specific… - API4:2023 Unrestricted Resource Consumption
OWASP API Security Top 10 (2023) API4:2023 Unrestricted Resource Consumption. Satisfying API requests requires resources such as network bandwidth, CPU, memory, and storage. Sometimes required resources are made… - API5:2023 Broken Function Level Authorization
OWASP API Security Top 10 (2023) API5:2023 Broken Function Level Authorization. The best way to find broken function level authorization issues is to perform a deep analysis of the authorization mechanism while keeping… - API6:2023 Unrestricted Access to Sensitive Business Flows
OWASP API Security Top 10 (2023) API6:2023 Unrestricted Access to Sensitive Business Flows. When creating an API Endpoint, it is important to understand which business flow it exposes. Some business flows are more… - API7:2023 Server Side Request Forgery
OWASP API Security Top 10 (2023) API7:2023 Server Side Request Forgery. Server-Side Request Forgery (SSRF) flaws occur when an API is fetching a remote resource without validating the user-supplied URL. It enables an… - API8:2023 Security Misconfiguration
OWASP API Security Top 10 (2023) API8:2023 Security Misconfiguration. The API might be vulnerable if: * Appropriate security hardening is missing across any part of the API stack, or if there are improperly configured… - API9:2023 Improper Inventory Management
OWASP API Security Top 10 (2023) API9:2023 Improper Inventory Management. The sprawled and connected nature of APIs and modern applications brings new challenges. It is important for organizations not only to have a… - Application Container Security Guide
Application container technologies are a form of operating system virtualization combined with application software packaging that provide a portable, reusable, and automatable way to package and run applications. This… - Applying 5G Cybersecurity and Privacy Capabilities Introduction to the White Paper Series
This document introduces the white paper series titled Applying 5G Cybersecurity and Privacy Capabilities, published by the National Cybersecurity Center of Excellence (NCCoE) 5G Cybersecurity project. The series… - Argentina Personal Data Protection Act - Ley 25.326 de Protección de los Datos Personales
Argentina's Personal Data Protection Act (Ley 25.326 de Protección de los Datos Personales), enacted 4 October 2000 (promulgated 30 October 2000, published in the Official Gazette 2 November 2000), is Latin America's… - Armenia Law on Protection of Personal Data 2015 - Data Protection Agency
Armenia's Law on Protection of Personal Data (Հայաստանի Հանրապետության «Անձնական տվյալների պաշտպանության մասին» օրենք, Law No. HO-49-N) - adopted on 18 May 2015 and entering into force on 1 July 2016 - is Armenia's… - Aruba National Ordinance on Personal Records (Landsverordening Persoonsregistratie), 2011
Aruba, a constituent country of the Kingdom of the Netherlands, regulates personal data through the National Ordinance on Personal Records (Landsverordening Persoonsregistratie), the national ordinance of 19 May 2011,… - Assessing Enhanced Security Requirements for Controlled Unclassified Information
This publication provides federal agencies and nonfederal organizations with assessment procedures to carry out assessments of the requirements in NIST Special Publication 800-172, Enhanced Security Requirements for… - Assessing Security and Privacy Controls in Information Systems and Organizations
This publication provides a methodology and a set of procedures for conducting assessments of security and privacy controls employed within systems and organizations as part of an effective risk management framework.… - Asset Management Strategy (NIST CSF 2.0 ID.AM)
Effective governance over the enterprise environment necessitates a comprehensive asset management strategy grounded in the NIST Cybersecurity Framework 2.0 Identify function. This approach mandates the maintenance of… - Audit Event Logging (NIST 800-53)
NIST SP 800-53 Rev 5 Control AU-2 (Event Logging) requires organizations to identify the types of events that the system is capable of logging in support of the audit function, coordinate the event logging function with… - Australia ACSC Essential Eight Mitigation Strategies Maturity Model (2023 Update)
The Australian Cyber Security Centre's (ACSC) Essential Eight is a prioritized baseline of eight mitigation strategies designed to help organizations protect their systems against a range of cyber threats. Compliance,… - Australia Cyber Security Act 2024
Australia's Cyber Security Act 2024, which received Royal Assent on November 29, 2024, mandates ransomware payment reporting to ASD within 72 hours for businesses with annual turnover of AUD 3 million or more,… - Australia Digital ID Act 2024
Australia's Digital ID Act 2024, which received Royal Assent on May 30, 2024, establishes a voluntary economy-wide digital identity accreditation framework administered by the Australian Competition and Consumer… - Australia Digital ID Act 2024 (Cth) and Australian Government Digital ID System Trust Framework
The Digital ID Act 2024 (Cth) is Australia's primary digital identity statute, replacing the prior administrative Trusted Digital Identity Framework (TDIF) with a binding legislative regime. The Act establishes the… - Australia Online Safety Act 2021 (Cth)
The Online Safety Act 2021 (Cth) establishes Australia's comprehensive framework for online safety, replacing the Enhancing Online Safety Act 2015. The Act empowers the eSafety Commissioner to administer online safety… - Australia Online Safety Act 2021 Phase 2 Industry Codes 2025 - Class 1C and Class 2 Material Age Assurance and Reporting
Online service providers in scope of the Australian Online Safety Act 2021 must, from 27 December 2025 (hosting services, internet carriage services, internet search engine services) and from 9 March 2026 (equipment… - Australia Online Safety Amendment (Social Media Minimum Age) Act 2024 - Prohibition of Under-16 Social Media Accounts, Effective 10 December 2025
Designated social media platforms operating in Australia (initially Facebook, Instagram, Reddit, Snapchat, TikTok, Twitter, Threads, Twitch, Kick, and YouTube as of 10 December 2025, with more potentially added) must… - Australia Privacy and Other Legislation Amendment Act 2024
Australia's Privacy and Other Legislation Amendment Act 2024 introduces a statutory tort for serious invasions of privacy, strengthens children's online privacy protections, enhances OAIC enforcement powers, and creates… - Australia Security of Critical Infrastructure Act 2018
Australia's Security of Critical Infrastructure Act imposes mandatory cyber security incident reporting obligations - 12 hours for significant incidents, 72 hours for others - positive security obligations on operators… - Australia Security of Critical Infrastructure Act 2018 (as Amended 2022) - Positive Security Obligations, Enhanced Cyber Security Obligations (Systems of National Significance), Government Assistance and 12-Hour Incident Reporting
This Act requires responsible entities of Australian critical infrastructure assets to adopt a risk management program (Part 2A), maintain a register of critical assets, and mandatorily report significant cyber security… - Australia Security of Critical Infrastructure Act 2018 (SOCI) - Positive Security Obligations
The Security of Critical Infrastructure Act 2018 (Cth) imposes positive security obligations on owners and operators of 22 critical infrastructure asset classes across 11 sectors. Responsible entities must register… - Australia SOCI Act Critical Infrastructure Risk Management Program Rules 2023 (LIN 23/210)
The Security of Critical Infrastructure (Critical infrastructure risk management program) Rules LIN 23/210 commenced February 17, 2023 require responsible entities for critical infrastructure assets to adopt and… - Australia Spam Act 2003 (Cth)
Australia's Spam Act 2003 (Cth) effective April 10, 2004 prohibits sending unsolicited commercial electronic messages to Australian electronic addresses without express or inferred consent, requires sender… - Australian Cyber Security Centre Essential Eight Maturity Model 2023 - Patch Applications, MFA, Application Control and Daily Backups: Four Maturity Level Definitions
This regulation outlines four maturity levels for implementing the Essential Eight mitigation strategies, with Maturity Level 2 requiring organisations to apply patches within 48 hours for internet-facing services and… - Australian Signals Directorate Essential Eight Maturity Model 2023
The ASD Essential Eight Maturity Model updated November 2023 defines eight prioritised cybersecurity mitigation strategies across four maturity levels - application control, patch applications, macro settings,… - Austria Data Protection Act 2018 (Datenschutzgesetz - DSG) - GDPR National Implementation
Austria's Data Protection Act (Datenschutzgesetz - DSG, Federal Act on the Protection of Natural Persons with Regard to the Processing of Personal Data), as amended by the Datenschutz-Anpassungsgesetz 2018 (Federal Law… - Automated Secure Configuration Guidance from the macOS Security Compliance Project (mSCP)
This publication introduces the macOS Security Compliance Project (mSCP), an open-source initiative by the National Institute of Standards and Technology (NIST) designed to provide security configuration guidance for… - Automation Support for Security Control Assessments Volume 1: Overview
This volume introduces concepts to support automated assessment of security controls detailed in NIST Special Publication (SP) 800-53. The ability to assess all implemented information security controls as frequently as… - Azerbaijan Law on Personal Data 2010 - Supervisory Executive Authority
Azerbaijan's Law on Personal Data (Fərdi məlumatlar haqqında Qanun) - Law No. 998-IIIQ, adopted by the Milli Majlis (National Assembly) of the Republic of Azerbaijan on 11 May 2010 and signed by President Ilham Aliyev,… - Bahamas Data Protection (Privacy of Personal Information) Act 2003
The Bahamas enacted the Data Protection (Privacy of Personal Information) Act, 2003 (Chapter 324A), one of the earliest comprehensive data protection statutes in the Caribbean. The Act is administered by the Data… - Bahrain Personal Data Protection Law 2018 - PDPA
Bahrain's Personal Data Protection Law (PDPL) - Legislative Decree No. 30 of 2018, issued by His Majesty King Hamad bin Isa Al Khalifa on 12 July 2018 and published in the Official Gazette - is Bahrain's comprehensive… - Bangladesh Cyber Security Act 2023
Bangladesh's Cyber Security Act 2023, enacted in September 2023 to replace the Digital Security Act 2018, establishes a framework for cybercrime prevention and prosecution in Bangladesh, criminalises unauthorised… - Barbados Data Protection Act 2019
Barbados enacted the Data Protection Act 2019, a GDPR-aligned statute administered by the Data Protection Commissioner. It mandates lawful bases for processing, grants data subjects rights of access, rectification,… - Belarus Law on Personal Data Protection - NCPDP Compliance Framework
Belarus Law on Personal Data Protection (No. 99-Z, 2021, in force November 2021) establishes GDPR-influenced data subject rights, 72-hour breach notification, and mandatory registration for operators processing… - Belize Data Protection Act 2021
Belize enacted the Data Protection Act 2021, establishing a comprehensive data protection framework for the country. The Act is administered by the Data Protection Commissioner of Belize and establishes principles for… - Benin Personal Data Protection Law - APDP Compliance Framework
Benin Law No. 2009-09 on Protection of Personal Data establishes data subject rights, mandatory controller registration, and prior authorization requirements for sensitive data processing. The Autorité de Protection des… - Bermuda Personal Information Protection Act 2016
Bermuda enacted the Personal Information Protection Act 2016 (PIPA), which came into force on 1 January 2017. Administered by the Privacy Commissioner for Bermuda, PIPA establishes rights-based protections for… - Bhutan Information, Communications and Media Act 2018 - Data Privacy Provisions
Bhutan enacted the Information, Communications and Media Act 2018 (ICMA 2018), which includes provisions for the protection of personal information in electronic communications and digital services. The Act is… - Blockchain and Related Technologies to Support Manufacturing Supply Chain Traceability: Needs and Industry Perspectives
This publication explores the issues surrounding supply chain traceability, assessing the role blockchain and related technologies can play in its improvement. It targets all stakeholders in the U.S. national… - Bolivia Supreme Decree No. 1793 on Protection of Personal Data in Information Systems (2013)
Bolivia enacted Supreme Decree No. 1793 of 13 November 2013 on the Protection of Personal Data in Information Systems, providing a regulatory framework for the processing of personal data by public and private entities… - Botswana Data Protection Act No. 32 of 2018 - Information and Data Protection Commission
Botswana's Data Protection Act No. 32 of 2018 (DPA) - assented to on 3 August 2018, published in the Botswana Government Gazette Extraordinary No. 64 of 3 August 2018, and brought into force through a Presidential… - Boundary Protection (NIST 800-53)
NIST SP 800-53 Rev 5 Control SC-7 (Boundary Protection) requires organizations to monitor and control communications at the external boundary of the system and at key internal boundaries, implement subnetworks for… - Brazil ANPD Regulations 2021-2023 - DPO Nomination Obligations, Legitimate Interest Guidance, Simplified Regulations for Micro-Enterprises, Security Incident Reporting Rules (2-Day Window), International Transfer Clauses and Code of Conduct Accreditation
This regulation establishes obligations for data protection officers, incident reporting within 2 days, and age assurance mechanisms for protecting children online. It applies to all agents of processing handling… - British Columbia Personal Information Protection Act (PIPA BC) 2003
The British Columbia Personal Information Protection Act (PIPA BC) was enacted as SBC 2003 c. 63 and came into force on 1 January 2004. PIPA BC governs the collection, use, and disclosure of personal information by… - Brunei Personal Data Protection Order 2025 - AITI Compliance Framework
Brunei Darussalam Personal Data Protection Order 2025 (PDPO, Gazette S 1 of 2025, approved by the Sultan on 8 January 2025) establishes a consent-based framework of data subject rights, mandatory data user registration,… - Budapest Convention on Cybercrime 2001 - International Cybercrime Cooperation Treaty (ETS No. 185)
The Convention on Cybercrime (ETS No. 185, Budapest, 23 November 2001) is the first and primary international treaty harmonising cybercrime laws and enabling cross-border cooperation in cybercrime investigations. It… - Building a Cybersecurity and Privacy Learning Program
This publication provides guidance for federal agencies and organizations to develop and manage a life cycle approach to building a Cybersecurity and Privacy Learning Program (CPLP). The program is intended to address… - Burkina Faso Personal Data Protection Law - CIL Compliance Framework
Burkina Faso Law No. 010-2004/AN on Protection of Personal Data (2004) established one of West Africa's earliest data protection frameworks, creating the Commission de l'Informatique et des Libertés (CIL) as the… - Burundi Law on Personal Data Protection 2020
Burundi enacted the Law on Personal Data Protection in 2020, establishing a comprehensive legal framework for the protection of personal data in the Republic of Burundi. The law is administered by the Agence de… - C1: Implement Access Control
OWASP Top 10 Proactive Controls 2024, C1: Implement Access Control. Access Control (or Authorization) is allowing or denying specific requests from a user, program, or process. This is one of the OWASP Top 10 Proactive… - C10: Stop Server Side Request Forgery
OWASP Top 10 Proactive Controls 2024, C10: Stop Server Side Request Forgery. While Injection Attacks typically target the victim server itself, Server-Side Request Forgery (SSRF) attacks try to coerce the server to… - C2: Use Cryptography to Protect Data
OWASP Top 10 Proactive Controls 2024, C2: Use Cryptography to Protect Data. Sensitive data such as passwords, credit card numbers, health records, personal information and business secrets require extra protection,… - C3: Validate all Input & Handle Exceptions
OWASP Top 10 Proactive Controls 2024, C3: Validate all Input & Handle Exceptions. Input validation is a programming technique that ensures only properly formatted data may enter a software system component. This is one… - C4: Address Security from the Start
OWASP Top 10 Proactive Controls 2024, C4: Address Security from the Start. When designing a new application, creating a secure architecture prevents vulnerabilities before they even become part of the application. This… - C5: Secure By Default Configurations
OWASP Top 10 Proactive Controls 2024, C5: Secure By Default Configurations. Secure-by-Default means products are resilient against prevalent exploitation techniques out of the box without additional charge. This is one… - C6: Keep your Components Secure
OWASP Top 10 Proactive Controls 2024, C6: Keep your Components Secure. It is a common practice in software development to leverage libraries and frameworks. Secure libraries and software frameworks with embedded… - C7: Secure Digital Identities
OWASP Top 10 Proactive Controls 2024, C7: Secure Digital Identities. Digital Identity is a unique representation of an individual, organization (or another subject) as they engage in an online transaction.… - C8: Leverage Browser Security Features
OWASP Top 10 Proactive Controls 2024, C8: Leverage Browser Security Features. Browsers are the gateway to the web for most users. As such, it's critical to employ robust security measures to protect the user from… - C9: Implement Security Logging and Monitoring
OWASP Top 10 Proactive Controls 2024, C9: Implement Security Logging and Monitoring. Logging is a concept that most developers already use for debugging and diagnostic purposes. Security logging is an equally basic… - California Delete Act 2023 (SB 362)
California SB 362 signed October 10, 2023 requires data brokers to register with the California Privacy Protection Agency and mandates the CPPA to create a universal deletion mechanism by January 1, 2026 enabling… - Cambodia Personal Data Protection Framework - Sub-Decree No. 252 (2021), Constitutional Privacy and Draft PDP Law
Cambodia has not yet enacted a comprehensive personal data protection law and is one of the last ASEAN states without one. Personal data protection currently rests on the constitutional protection of privacy, on… - Cameroon Cybersecurity and Personal Data Law - ANTIC Compliance Framework
Cameroon Law No. 2010/012 on Cybersecurity and Cybercriminality (2010) includes comprehensive personal data protection provisions governing consent, data subject rights, controller obligations, and cross-border transfer… - Canada Anti-Spam Legislation 2014 (CASL)
Canada's Anti-Spam Legislation (S.C. 2010, c. 23) effective July 1, 2014 prohibits sending commercial electronic messages to Canadians without express or implied consent, requires clear identification of the sender and… - Canada Consumer Privacy Protection Act - Bill C-27 (Proposed, 2022)
Canada Bill C-27 tabled November 16, 2020 and reintroduced June 16, 2022 proposes replacing PIPEDA with the Consumer Privacy Protection Act (CPPA) establishing modern consent requirements, data portability rights,… - Cape Verde Personal Data Protection Law - CNPD Compliance Framework
Cape Verde Law No. 133/V/2001 on Protection of Personal Data establishes a Portuguese-influenced framework of consent-based processing, data subject rights, and mandatory controller registration. The Comissão Nacional… - Cayman Islands Data Protection Law 2017
The Cayman Islands enacted the Data Protection Law 2017 (revised 2021), a comprehensive GDPR-aligned statute that came fully into force on 30 September 2019. Administered by the Ombudsman, it establishes eight data… - Central African Republic ARTP Framework - AU Malabo Convention and Constitutional Privacy Obligations
The Central African Republic (CAR) has established the Autorité de Régulation des Télécommunications et des Postes (ARTP) as the national regulatory authority for electronic communications and postal services. The… - Chad ARCEP Framework - AU Malabo Convention and Constitutional Privacy Obligations
The Republic of Chad has established the Autorité de Régulation des Communications Electroniques et des Postes (ARCEP) as the national regulatory authority for electronic communications, digital services, and postal… - Chile Data Protection Law 21.719 - Ley Marco de Datos Personales and CPLT Enforcement
Chile's Ley Marco de Datos Personales (Framework Law on Personal Data) - Law No. 21.719, published in the Diario Oficial de la República de Chile on 13 December 2024 and entering into force on 13 December 2026 (a… - China Algorithm Recommendation Management Provisions 2022
China's Provisions on the Management of Algorithm Recommendation in Internet Information Services, effective March 1, 2022, impose transparency, labelling, and user rights obligations on internet services using… - China Cybersecurity Law 2017
China's Cybersecurity Law establishes a foundational network security framework requiring real-name registration for internet users, data localisation for critical information infrastructure operators, network security… - China Data Security Law 2021
China's Data Security Law establishes a hierarchical national data classification system designating core data, important data, and general data with progressively stringent security requirements, restricts overseas… - China Network Data Security Management Regulations 2024
China's Network Data Security Management Regulations, promulgated by the State Council on September 24, 2024 and effective January 1, 2025, implement and operationalise the Data Security Law and Personal Information… - China Provisions on the Administration of Deep Synthesis Internet Information Services 2022
China's CAC, MIIT and MPS mandate that deep synthesis service providers label all AI-generated synthetic media, implement real-name verification for users, prohibit non-consensual identity impersonation, and file new… - Christmas Island - Australian Privacy Act and OAIC Supervisory Framework
Christmas Island is an Australian external territory located in the Indian Ocean south of the Indonesian island of Java. The island is administered by the Australian Government through the Department of Infrastructure,… - CIS Controls v8.1 Control 1: Inventory and Control of Enterprise Assets
CIS Controls v8.1 Control 1: Inventory and Control of Enterprise Assets. CIS Controls 1 focuses on actively managing (inventory, track, and correct) all enterprise assets connected to the infrastructure. Control 1 is… - CIS Controls v8.1 Control 10: Malware Defenses
CIS Controls v8.1 Control 10: Malware Defenses. CIS Control 10 focuses on preventing or controlling the installation, spread, & execution of malicious applications, code, or scripts on enterprise assets. Control 10 is… - CIS Controls v8.1 Control 11: Data Recovery
CIS Controls v8.1 Control 11: Data Recovery. CIS Control 11 focuses on establishing and maintaining data recovery practices to restore in-scope enterprise assets to a pre-incident and trusted state. Control 11 is one of… - CIS Controls v8.1 Control 12: Network Infrastructure Management
CIS Controls v8.1 Control 12: Network Infrastructure Management. CIS Control 12 focuses on establishing, implementing, and actively managing network devices to prevent attackers from exploiting vulnerable network… - CIS Controls v8.1 Control 13: Network Monitoring and Defense
CIS Controls v8.1 Control 13: Network Monitoring and Defense. CIS Controls 13 focuses on processes and tooling to establish and maintain comprehensive network monitoring and defense against security threats. Control 13… - CIS Controls v8.1 Control 14: Security Awareness and Skills Training
CIS Controls v8.1 Control 14: Security Awareness and Skills Training. CIS Controls 14 focuses on establishing and maintaining a security awareness program to be security conscious to reduce cybersecurity risks. Control… - CIS Controls v8.1 Control 15: Service Provider Management
CIS Controls v8.1 Control 15: Service Provider Management. CIS Controls 15 focuses on developing a process to evaluate service providers to ensure platforms and data are protected appropriately. Control 15 is one of 18… - CIS Controls v8.1 Control 16: Application Software Security
CIS Controls v8.1 Control 16: Application Software Security. CIS Controls 16 focuses on managing the security life cycle of software to prevent, detect, and remediate security weaknesses. Control 16 is one of 18 CIS… - CIS Controls v8.1 Control 17: Incident Response Management
CIS Controls v8.1 Control 17: Incident Response Management. CIS Controls 17 focuses on establishing a program to develop and maintain an incident response capability to prepare, detect, and respond to an attack. Control… - CIS Controls v8.1 Control 18: Penetration Testing
CIS Controls v8.1 Control 18: Penetration Testing. CIS Controls 18 focuses on test the effectiveness and resiliency of enterprise assets through identifying and exploiting weaknesses in controls. Control 18 is one of 18… - CIS Controls v8.1 Control 2: Inventory and Control of Software Assets
CIS Controls v8.1 Control 2: Inventory and Control of Software Assets. CIS Control 2 focuses on actively managing (inventory, track, and correct) all software (operating systems and applications) on the network. Control… - CIS Controls v8.1 Control 3: Data Protection
CIS Controls v8.1 Control 3: Data Protection. CIS Controls 3 focuses on developing processes and technical controls to identify, classify, securely handle, retain, and dispose of data. Control 3 is one of 18 CIS… - CIS Controls v8.1 Control 4: Secure Configuration of Enterprise Assets and Software
CIS Controls v8.1 Control 4: Secure Configuration of Enterprise Assets and Software. CIS Control 4 focuses on establishing and maintaining the secure configuration of enterprise assets and software. Control 4 is one of… - CIS Controls v8.1 Control 5: Account Management
CIS Controls v8.1 Control 5: Account Management. CIIS Control 5 focuses on using processes and tools to assign and manage authorization to credentials for user accounts. Control 5 is one of 18 CIS Controls in version… - CIS Controls v8.1 Control 6: Access Control Management
CIS Controls v8.1 Control 6: Access Control Management. CIS Control 6 focuses on using processes and tools to create, assign, manage, and revoke access credentials and privileges for user, administrator, and service… - CIS Controls v8.1 Control 7: Continuous Vulnerability Management
CIS Controls v8.1 Control 7: Continuous Vulnerability Management. CIS Control 7 focusing on developing a plan to continuously assess & track vulnerabilities on all enterprise assets within the enterprise's… - CIS Controls v8.1 Control 8: Audit Log Management
CIS Controls v8.1 Control 8: Audit Log Management. CIS Controls 8 focuses on collecting, alerting, reviewing, and retaining audit logs of events that could help detect, understand, or recover from an attack. Control 8… - CIS Controls v8.1 Control 9: Email and Web Browser Protections
CIS Controls v8.1 Control 9: Email and Web Browser Protections. CIS Control 9 focuses on improving protections and detections of threats from email and web vectors. Control 9 is one of 18 CIS Controls in version 8.1… - CIS Critical Security Controls Version 8
Compliance with the Center for Internet Security (CIS) Critical Security Controls Version 8 provides a prioritized, risk-based framework for cyber defense, with this node mandating the foundational requirements of… - CIS Critical Security Controls Version 8 - 18 Safeguard Groups, Implementation Groups (IG1/IG2/IG3) and Mappings to NIST CSF, ISO 27001 and CMMC for Prioritised Security Actions
The CIS Critical Security Controls v8 provides a prioritized set of safeguards to defend against prevalent cyber attacks, applicable to organizations across all sectors seeking to improve their cybersecurity posture. It… - CISA Binding Operational Directive 22-01 - Known Exploited Vulnerabilities Catalog: Federal Agency Mandatory Patch Deadlines (14-Day Critical, 30-Day High), KEV Catalog Methodology, Vendor Coordination, Private Sector Voluntary Adoption and Metrics Reporting
Federal civilian executive branch agencies must remediate vulnerabilities listed in the CISA Known Exploited Vulnerabilities (KEV) Catalog within 14 days for critical severity and 30 days for high severity per Binding… - CISA Critical Infrastructure Cybersecurity - 16 Sector Protection Framework
CISA designates 16 critical infrastructure sectors under Presidential Policy Directive 21 (PPD-21). Each sector has a designated Sector Risk Management Agency (SRMA) responsible for coordinating cybersecurity plans,… - CISA Cross-Sector Cybersecurity Performance Goals (CPGs) 2023 - 37 Baseline Security Practices for Critical Infrastructure Operators
The CISA Cross-Sector Cybersecurity Performance Goals (CPGs) establish a voluntary, common set of 37 baseline cybersecurity practices for critical infrastructure operators to meaningfully reduce risks to critical… - CISA Cross-Sector Cybersecurity Performance Goals 2022 - Baseline Cybersecurity Practices for Critical Infrastructure
This voluntary guidance from CISA establishes a common set of baseline cybersecurity goals for critical infrastructure owners and operators to reduce risks across both Information Technology (IT) and Operational… - CISA Known Exploited Vulnerabilities Catalog - Binding Operational Directive 22-01 and Mandatory Remediation Timelines
Binding Operational Directive (BOD) 22-01 requires U.S. Federal Civilian Executive Branch (FCEB) agencies to remediate vulnerabilities listed in the CISA-managed Known Exploited Vulnerabilities (KEV) catalog within… - CISA Secure by Design Principles 2023 - Product Security Obligations for Software Manufacturers: Default Security Settings, Vulnerability Elimination and Transparency
This guidance requires software manufacturers to take ownership of customer security outcomes, embrace radical transparency and accountability, and lead from the top by implementing secure-by-design practices. It… - CISA Zero Trust Maturity Model 2.0 - Identity, Devices, Networks, Applications and Data Pillars with Traditional, Advanced and Optimal Stages
This model provides a roadmap for U.S. federal agencies and other organizations to implement a zero trust architecture, as directed by Executive Order 14028. It outlines a maturity continuum across five pillars… - Clarifying Lawful Overseas Use of Data (CLOUD) Act - US Provider Obligation to Produce Data Stored Abroad, Executive Agreement Framework for Bilateral Data Access, Comity Challenge Procedure, Conflict of Laws Analysis and DOJ Guidance on Qualifying Executive Agreements
The CLOUD Act enables the U.S. to enter into bilateral executive agreements with foreign countries that have robust privacy and civil liberties protections, allowing those countries to request electronic data directly… - Clinger-Cohen Act 1996 - 40 USC 11101 Information Technology Management Reform
Section 11101 and following of title 40 of the United States Code codify the Clinger-Cohen Act (Information Technology Management Reform Act of 1996, Public Law 104-106 Divisions D and E), the principal federal statute… - Cocos (Keeling) Islands - Australian Privacy Act and OAIC Supervisory Framework
The Cocos (Keeling) Islands are an Australian external territory comprising 27 small coral islands in the Indian Ocean. The territory has a resident population of approximately 600 people, primarily members of the Cocos… - Colombia Statutory Law 1581 of 2012 - Ley de Habeas Data and SIC Enforcement
Colombia's Ley Estatutaria de Protección de Datos Personales (Statutory Law on the Protection of Personal Data) - Ley Estatutaria 1581 of 2012, passed by the Colombian Congress and signed into law on 17 October 2012,… - Colorado Privacy Act 2021 (CPA)
Colorado SB 190 signed July 7, 2021 effective July 1, 2023 (sensitive data provisions January 1, 2024) grants Colorado residents rights to access, correction, deletion, portability, and opt-out of targeted advertising,… - Commission Delegated Regulation (EU) 2025/1190 supplementing Regulation (EU) 2022/2554 with regard to regulatory technical standards specifying the criteria for identifying financial entities required to perform threat-led penetration testing (TLPT)
This DORA regulatory technical standard sets the criteria by which TLPT authorities identify the financial entities required to perform threat-led penetration testing, combining size and systemic-importance thresholds… - Commission Delegated Regulation (EU) 2025/301 supplementing Regulation (EU) 2022/2554 with regard to regulatory technical standards specifying the content and time limits for the initial notification of, and intermediate and final report on, major ICT-related incidents, and the content of the voluntary notification for significant cyber threats
This DORA regulatory technical standard sets the content and time limits for reporting major ICT-related incidents: an initial notification within four hours of classification (and no later than 24 hours from… - Commission Delegated Regulation (EU) 2025/532 supplementing Regulation (EU) 2022/2554 with regard to regulatory technical standards specifying the elements a financial entity has to determine and assess when subcontracting ICT services supporting critical or important functions
This DORA regulatory technical standard sets the elements a financial entity must determine and assess before and during the subcontracting of ICT services that support critical or important functions, including due… - Commission Implementing Regulation (EU) 2024/2690 laying down rules for the application of Directive (EU) 2022/2555 as regards the technical and methodological requirements for cybersecurity risk-management measures
This regulation establishes the specific technical and methodological requirements for the cybersecurity risk-management measures that essential and important entities must implement under Article 21 of the NIS2… - Commission Implementing Regulation (EU) 2024/2956 - DORA Implementing Technical Standards for the standard templates for the register of information on ICT third-party arrangements
This Commission Implementing Regulation lays down the standard templates that financial entities must use to maintain the DORA register of information on all contractual arrangements for the use of ICT services provided… - Commission Implementing Regulation (EU) 2024/2979 - eIDAS rules on the integrity and core functionalities of European Digital Identity Wallets
This Commission Implementing Regulation specifies the integrity and core functionalities that European Digital Identity Wallets must provide under the eIDAS framework. Wallet instances must use at least one wallet… - Commission Implementing Regulation (EU) 2024/2981 - eIDAS rules on the certification of European Digital Identity Wallets
This Commission Implementing Regulation sets out the reference standards, specifications and procedures for the certification of European Digital Identity Wallets under the eIDAS framework. National certification… - Commission Implementing Regulation (EU) 2025/2392 on the technical description of the categories of important and critical products with digital elements pursuant to Regulation (EU) 2024/2847 (Cyber Resilience Act)
This Implementing Regulation provides the technical description of the important (class I and class II) and critical product categories with digital elements under the Cyber Resilience Act, where the core functionality… - Commission Recommendation (EU) 2021/1052 of 23 June 2021 on building a Joint Cyber Unit
This framework establishes a platform for structured cooperation between EU bodies (ENISA, CERT-EU), Member States' authorities, and private sector partners to ensure a coordinated response to large-scale cybersecurity… - Comoros ANRTIC Regulatory Framework - Constitutional Privacy Rights and Personal Data Obligations
The Union of the Comoros has established the Agence Nationale de Régulation des Technologies de l'Information et de la Communication (ANRTIC) as the national authority for regulating information and communication… - Computer Misuse Act 1990, Section 1: Unauthorised access to computer material
This regulation establishes a criminal offence for any person who intentionally causes a computer to perform a function to secure unauthorised access to any program or data, knowing that the access is unauthorised. - Computer Security Incident Handling Guide
Computer security incident response has become an important component of information technology (IT) programs. Because performing incident response effectively is a complex undertaking, establishing a successful… - Computer Security Incident Handling Guide (NIST Special Publication 800-61 Revision 3)
This publication provides guidelines for preparing for, detecting, analyzing, containing, eradicating, and recovering from cybersecurity incidents. It applies to all organizations that own, operate, or support federal… - Contingency Planning (NIST 800-53)
NIST SP 800-53 Rev 5 Control CP-2 (Contingency Plan) requires organizations to develop a contingency plan for the information system that identifies essential missions and business functions, provides recovery… - Contingency Planning Guide for Federal Information Systems
This guide provides instructions, recommendations, and considerations for federal information system contingency planning. Contingency planning refers to a coordinated strategy involving plans, procedures, and technical… - Contingency Planning Guide for Federal Information Systems
NIST Special Publication 800-34, Rev. 1, provides instructions, recommendations, and considerations for federal information system contingency planning. Contingency planning refers to interim measures to recover… - Contingency Planning Guide for Federal Information Systems
NIST Special Publication 800-34, Rev. 1, provides instructions, recommendations, and considerations for federal information system contingency planning. Contingency planning refers to interim measures to recover… - Contingency Planning Guide for Federal Information Systems
NIST Special Publication 800-34, Rev. 1, provides instructions, recommendations, and considerations for federal information system contingency planning. Contingency planning refers to interim measures to recover… - Contingency Planning Guide for Federal Information Systems
NIST Special Publication 800-34, Rev. 1 provides instructions, recommendations, and considerations for federal information system contingency planning. Contingency planning refers to interim measures and a coordinated… - Contingency Planning Guide for Federal Information Systems
NIST Special Publication 800-34, Rev. 1 provides instructions, recommendations, and considerations for federal information system contingency planning. Contingency planning refers to a coordinated strategy involving… - Control Baselines for Information Systems and Organizations
This publication provides security and privacy control baselines for the Federal Government. It establishes three security control baselines, one for each system impact level-low-impact, moderate-impact, and… - Corrigendum to Commission Delegated Regulation (EU) 2025/20 on safe provision of ground handling services
This is a Corrigendum to Commission Delegated Regulation (EU) 2025/20 of 19 December 2024, which supplements Regulation (EU) 2018/1139 by laying down requirements for the safe provision of ground handling services and… - Corrigendum to Commission Implementing Regulation (EU) 2025/23 on oversight of ground handling services and organisations
This corrigendum corrects Commission Implementing Regulation (EU) 2025/23 of 19 December 2024, which lays down rules for the application of Regulation (EU) 2018/1139 as regards requirements for the oversight of ground… - Costa Rica Personal Data Protection Law No. 8968 2011 - PRODHAB
Costa Rica's Ley de Protección de la Persona frente al Tratamiento de sus Datos Personales (Personal Data Protection Law) - Law No. 8968 of 5 July 2011, published in La Gaceta (official gazette) No. 170 on 5 September… - Côte d'Ivoire Personal Data Protection Law No. 2013-450 - ARTCI
Côte d'Ivoire's Loi No. 2013-450 du 19 juin 2013 relative à la protection des données à caractère personnel (Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data) - published in the Journal Officiel de la… - Criminal Code (R.S.C., 1985, c. C-46), Section 342.1: Unauthorized use of computer
Organizations must prevent the fraudulent and unauthorized obtaining of computer services, interception of computer system functions, use of computer systems to commit related offenses, and the misuse of computer… - Cross-Sector Cybersecurity Performance Goals
The Cross-Sector Cybersecurity Performance Goals (CPGs) provide an approachable common set of IT and OT cybersecurity protections that are clearly defined, straightforward to implement, and aimed at addressing some of… - Cuba - Constitutional Privacy Rights and Ministry of Communications Data Governance Framework
The Republic of Cuba is an independent socialist state in the Caribbean governed under the Constitution of Cuba (2019), which establishes fundamental rights including the inviolability of the home and correspondence,… - Curaçao National Ordinance on Personal Data Protection 2010
Curaçao, a constituent country of the Kingdom of the Netherlands, enacted the National Ordinance on Personal Data Protection (Landsverordening bescherming persoonsgegevens, LBP) upon achieving autonomous status in 2010… - CVE Program with CNA Hierarchy and Record Format 5.2.0 (CISA-Sponsored, MITRE Secretariat, 400+ CVE Numbering Authorities, JSON Schema, ADPs, CVE Services REST API)
The Common Vulnerabilities and Exposures (CVE) Program is the canonical international vulnerability identifier system sponsored by the United States Cybersecurity and Infrastructure Security Agency (CISA) with The MITRE… - Cyber Essentials Plus: Illustrative Test Specification (Montpellier v3.1, April 2023)
Cyber Essentials Plus is a UK government-backed, independently verified certification requiring organizations to demonstrate compliance with five key technical controls through rigorous hands-on testing. This node… - Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) mandates that covered entities in critical infrastructure sectors report covered cyber incidents to the Cybersecurity and Infrastructure… - Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) - Reporting Requirements
This act requires covered entities to report covered cyber incidents and ransomware payments to the Cybersecurity and Infrastructure Security Agency (CISA) to enable rapid assistance and information sharing. - Cybercrime Prevention Act of 2012
This Act criminalizes illegal access, data interference, system interference, and misuse of devices in computer systems or networks, and establishes procedures for real-time data collection and preservation. It applies… - Cybercrimes Act 19 of 2020
This Act criminalizes a wide range of cyber offenses in South Africa and imposes a mandatory reporting duty on electronic communications service providers and financial institutions to report specific offenses to the… - Cybercrimes Act 19 of 2020 (Republic of South Africa) - Cybercrime Offences, Reporting Obligations, Investigation Powers, and Mutual Assistance (Gazette 45562 of 30 November 2021; Chapters 1-4, 7-9 commenced 1 December 2021)
The Cybercrimes Act 19 of 2020 of the Republic of South Africa is the country's foundational cybercrime statute. Chapters 1, 2 (excluding Part VI), 3, 4 (excluding sections 38(1)(d), (e) and (f), 40(3) and (4), 41 to… - Cybersecurity Act 2018 - Part 4 RESPONSES TO CYBERSECURITY THREATS AND INCIDENTS
Organizations must comply with directions from the Commissioner of Cybersecurity and incident response officers during the investigation and remediation of cybersecurity threats and incidents, including providing… - Cybersecurity Act 2018 of Singapore
The Singapore Cybersecurity Act 2018 establishes a legal framework for the oversight and maintenance of national cybersecurity, imposing duties on owners of Critical Information Infrastructure (CII) to secure their… - Cybersecurity Framework Profile for Hybrid Satellite Networks (HSN)
This Cybersecurity Profile identifies an approach to assess the cybersecurity posture of Hybrid Satellite Networks (HSN) that provide services such as satellite-based systems for communications, position, navigation,… - Cybersecurity Framework Profile for Hybrid Satellite Networks (HSN)
The objective of this Cybersecurity Profile is to identify an approach to assess the cybersecurity posture of Hybrid Satellite Networks (HSN) that provide services such as satellite-based systems for communications,… - Cybersecurity Framework Profile for Hybrid Satellite Networks (HSN)
The space sector is transitioning towards Hybrid Satellite Networks (HSN), which are an aggregation of independently owned and operated terminals, antennas, satellites, payloads, or other components that comprise a… - Cybersecurity Information Sharing Act 2015 - 6 USC 1501 Federal-Private Threat Intelligence
Sections 1500 through 1525 of title 6 of the United States Code codify the Cybersecurity Information Sharing Act of 2015, enacted as Title I of the Cybersecurity Act of 2015 (Division N of the Consolidated… - Cybersecurity Law of the People's Republic of China (CSL)
This law mandates broad cybersecurity obligations for all 'network operators' in China and imposes stricter requirements, including data localization and mandatory security reviews, on operators of 'Critical Information… - Cybersecurity Risk-Management Measures (Article 21, NIS2 Directive 2022/2555)
Under Article 21 of the NIS2 Directive, essential and important entities must implement appropriate and proportionate technical, operational, and organisational measures to manage cybersecurity risks to their network…
+ 2,583 more nodes in this pillar — see the full registry at /intelligence or the discovery index at /api/v1/nodes/index.json.