Frameworks
What each one requires.
And what people fail.
Reference pages, written by the people who run the audits. No marketing in the factual sections, just what the standard actually asks for, and the controls we watch companies fail again and again.
ISO/IEC 27001GlobalISO/IEC 27001 is the international standard for an information security management system (ISMS): a documented, risk-driven management process for securing information, against which an organisation can be independently certified by an accredited body.→SOC 2USSOC 2 is a US attestation report, issued by an independent licensed CPA firm, describing a service organisation's controls against the AICPA Trust Services Criteria. It is a report on your controls, not a certification.→GDPREUThe GDPR is the European Union's data protection regulation, governing how personal data of people in the EU is collected, processed, secured, transferred and deleted. It applies to organisations outside the EU, including in Israel, whenever they target or monitor people in the EU.→Amendment 13 (Israeli Privacy Law)IsraelAmendment 13 is the most significant overhaul of Israeli privacy law in decades: it hands the Privacy Protection Authority real administrative enforcement powers, and it makes the appointment of a Data Protection Officer and of an information security officer a legal duty for defined categories of organisation.→HIPAAUSHIPAA is the US federal law governing the privacy and security of protected health information (PHI), binding both healthcare organisations and the vendors that handle health data on their behalf, including non-US companies acting as business associates.→NIST CSF 2.0USThe NIST Cybersecurity Framework is a voluntary, outcome-based framework for organising and communicating cybersecurity risk. It describes what good looks like, and unlike ISO 27001 it cannot be certified against.→DORAEUDORA is the EU regulation that makes digital operational resilience a supervised obligation for the financial sector. It reaches directly into the technology vendors that financial entities depend on, including those outside the EU.→NIS2EUNIS2 is the EU directive that turns cybersecurity into a regulated duty for entire sectors of the economy. Uniquely, it makes senior management personally accountable for the organisation's cyber risk-management measures.→ISO/IEC 42001GlobalISO/IEC 42001 is the first certifiable international standard for an AI management system (AIMS): the governance process an organisation operates to develop or use AI responsibly, and the only credential currently available to prove AI governance to a customer.→PCI DSSGlobalPCI DSS is the payment card industry's security standard for any organisation that stores, processes or transmits cardholder data, enforced not by a regulator but contractually, by the card brands and acquiring banks.→