No frameworks match your search.
Cybersecurity Framework v2.0 — NIST
Voluntary framework organized around six core functions: Govern, Identify, Protect, Detect, Respond, Recover. GV function added in v2.0 addresses governance explicitly. Primary vocabulary for any GRC program.
Risk Management Framework — NIST
7-step RMF lifecycle: Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor. The ATO process for federal systems. Step 6 produces the authorization decision.
AI Risk Management Framework v1.0 — NIST
4 functions: Govern, Map, Measure, Manage. Voluntary framework for managing risks unique to AI systems. Mirrors NIST CSF structure.
Payment Card Industry Data Security Standard — PCI SSC
12 requirements across 6 goals. Mandatory for merchants and service providers handling cardholder data. Segmentation reduces scope. Non-compliance after breach can end card processing.
Security Rule — ePHI Protection — HHS OCR
Administrative (§164.308), Physical (§164.310), and Technical (§164.312) safeguards for electronic PHI. Applies to covered entities and business associates.
Service Organization Control 2 — AICPA
5 Trust Service Criteria: Security (required), Availability, Processing Integrity, Confidentiality, Privacy. Type II covers a period of at least 6 months. Common SaaS vendor requirement.
Security Categorization of Federal Information — NIST
Defines Low, Moderate, High impact levels across Confidentiality, Integrity, and Availability. High water mark rule: system category equals the highest individual value.
General Data Protection Regulation — EU/EDPB
99 articles. 7 processing principles (Art. 5). 6 lawful bases (Art. 6). 72-hour breach notification (Art. 33). Fines up to €20M or 4% global annual turnover. Extraterritorial scope.
Privacy Guidelines — OECD
8 principles: Collection Limitation, Data Quality, Purpose Specification, Use Limitation, Security Safeguards, Openness, Individual Participation, Accountability. Foundational to GDPR.
Generally Accepted Privacy Principles — AICPA
10 principles including Management, Notice, Choice & Consent, Collection, Use/Retention/Disposal, Access, Disclosure, Security, Quality, and Monitoring. Underpins SOC 2 Privacy TSC.
Digital Identity Guidelines (Parent) — NIST
Defines the digital identity model and 3 independent assurance dimensions: IAL, AAL, FAL. Each assigned separately based on risk. Parent document for the 800-63 suite.
Enrollment and Identity Proofing — NIST
IAL1: no proofing. IAL2: remote/in-person + documentary evidence. IAL3: in-person + biometrics. Defines how to verify identity before issuing credentials.
Authentication and Lifecycle Management — NIST
AAL1/2/3. No mandatory password rotation unless compromised. Min 8 chars, check breach lists. Cite this against legacy 90-day rotation policies. Most-referenced 800-63 document.
Federation and Assertions — NIST
FAL1/2/3 for federated identity. Covers SAML, OIDC, and OAuth assertion requirements. FAL2 commonly required for federal systems handling sensitive data.
