Frameworks and Regulations
Questions here turn on which document applies to the situation described. A framework is voluntary guidance, a regulation carries legal force, and an audit report is evidence about a third party.
Frameworks and Regulations · firsttry.app/cheatsheets/frameworks-and-regulations · original reference written from published exam objectives. Not affiliated with any certification body.
Frameworks
| Framework | Published by | What it is for |
|---|---|---|
| NIST Cybersecurity Framework | NIST | Govern, Identify, Protect, Detect, Respond, Recover |
| NIST SP 800-53 | NIST | Control catalog for federal systems |
| NIST SP 800-37 (RMF) | NIST | The risk management lifecycle |
| NIST SP 800-171 | NIST | Protecting controlled unclassified information at contractors |
| ISO/IEC 27001 | ISO | Certifiable information security management system |
| ISO/IEC 27002 | ISO | The control guidance behind 27001 |
| ISO 31000 | ISO | Risk management, not security specific |
| CIS Controls | Center for Internet Security | Prioritized control list, implementation groups |
| CIS Benchmarks | Center for Internet Security | Per-product hardening configuration |
| MITRE ATT&CK | MITRE | Catalog of adversary tactics and techniques |
| OWASP Top 10 | OWASP | The most critical web application risks |
| Cloud Controls Matrix | Cloud Security Alliance | Cloud control framework mapped to others |
Regulations and standards
| Name | Applies to | Governs |
|---|---|---|
| GDPR | EU residents' data, wherever processed | Consent, subject rights, 72-hour breach notice |
| HIPAA | US health information | Protected health information, safeguards |
| PCI DSS | Anyone handling card data | Cardholder data environment. A contract, not a law |
| SOX | US public companies | Financial reporting controls |
| GLBA | US financial institutions | Customer financial privacy |
| FERPA | US education records | Student record privacy |
| CCPA / CPRA | California residents | Disclosure and opt-out rights |
| COPPA | US children under 13 | Parental consent for data collection |
Audit reports and agreements
| Term | What it is |
|---|---|
| SOC 1 | Controls over financial reporting |
| SOC 2 Type I | Control design at a point in time |
| SOC 2 Type II | Control operation over a period. The one to ask for |
| SOC 3 | Public summary of a SOC 2 |
| SLA | Service levels, with remedies |
| MSA | Master agreement, the terms under which work happens |
| SOW | Statement of work, what is being delivered |
| NDA | Confidentiality obligation |
| BPA | Business partnership agreement |
| Right-to-audit clause | Contractual permission to inspect a supplier |
Try it here
Three verified practice questions on this material. Answer one, and see the official page behind the answer.
4-1Security Operations
What is the minimum amount of entropy a session identifier should contain to resist brute-force guessing attacks?
Security Assessment and Testing
How many phases does the Penetration Testing Execution Standard define?
Describe capabilities of Microsoft Entra
A help desk spends much of each Monday unlocking accounts and resetting forgotten passwords. Which Microsoft Entra feature lets users fix this themselves?
Five free questions on every practice exam. No account, no card.