Frameworks and Regulations
Questions here turn on which document applies to the situation described. A framework is voluntary guidance, a regulation carries legal force, and an audit report is evidence about a third party.
Frameworks and Regulations · firsttry.app/cheatsheets/frameworks-and-regulations · original reference written from published exam objectives. Not affiliated with any certification body.
Frameworks
| Framework | Published by | What it is for |
|---|---|---|
| NIST Cybersecurity Framework | NIST | Govern, Identify, Protect, Detect, Respond, Recover |
| NIST SP 800-53 | NIST | Control catalogue for federal systems |
| NIST SP 800-37 (RMF) | NIST | The risk management lifecycle |
| NIST SP 800-171 | NIST | Protecting controlled unclassified information at contractors |
| ISO/IEC 27001 | ISO | Certifiable information security management system |
| ISO/IEC 27002 | ISO | The control guidance behind 27001 |
| ISO 31000 | ISO | Risk management, not security specific |
| CIS Controls | Center for Internet Security | Prioritised control list, implementation groups |
| CIS Benchmarks | Center for Internet Security | Per-product hardening configuration |
| MITRE ATT&CK | MITRE | Catalogue of adversary tactics and techniques |
| OWASP Top 10 | OWASP | The most critical web application risks |
| Cloud Controls Matrix | Cloud Security Alliance | Cloud control framework mapped to others |
Regulations and standards
| Name | Applies to | Governs |
|---|---|---|
| GDPR | EU residents' data, wherever processed | Consent, subject rights, 72-hour breach notice |
| HIPAA | US health information | Protected health information, safeguards |
| PCI DSS | Anyone handling card data | Cardholder data environment. A contract, not a law |
| SOX | US public companies | Financial reporting controls |
| GLBA | US financial institutions | Customer financial privacy |
| FERPA | US education records | Student record privacy |
| CCPA / CPRA | California residents | Disclosure and opt-out rights |
| COPPA | US children under 13 | Parental consent for data collection |
Audit reports and agreements
| Term | What it is |
|---|---|
| SOC 1 | Controls over financial reporting |
| SOC 2 Type I | Control design at a point in time |
| SOC 2 Type II | Control operation over a period. The one to ask for |
| SOC 3 | Public summary of a SOC 2 |
| SLA | Service levels, with remedies |
| MSA | Master agreement, the terms under which work happens |
| SOW | Statement of work, what is being delivered |
| NDA | Confidentiality obligation |
| BPA | Business partnership agreement |
| Right-to-audit clause | Contractual permission to inspect a supplier |
Now test yourself
Memorizing a table is a start. Practice questions are what make it stick, and every answer carries the full explanation.