Security Frameworks & Regulations
At a Glance — ISO/IEC 27000 · FISMA · PCI DSS · HIPAA · SOX · NIST · GDPR
FRAMEWORK TYPE PRIMARY SCOPE APPLIES TO STATUS
International standard Information security management (ISMS) Any organization globally
ISO/IEC 27000 Voluntary
Family of standards for establishing,
implementing, and maintaining an ISMS.
ISO 27001 is the certifiable core; ISO 27002 provides control guidance.
US federal law Federal IT & data security US agencies & contractors
FISMA Mandatory
Requires federal agencies and
contractors to protect information
systems through risk categorization, control implementation, and ongoing assessment aligned with NIST.
Industry standard Payment card data protection Card data handlers worldwide
PCI DSS Mandatory
12 core requirements governing any
organization that stores, processes, or
transmits cardholder data. Compliance validated via QSA audits or self-assessment.
US federal law Health data privacy & security Healthcare entities (US)
HIPAA Mandatory
Covers administrative, physical, and
technical safeguards for electronic PHI
(ePHI). Includes Security Rule, Privacy Rule, and Breach Notification Rule.
US federal law Financial data integrity & IT controls US public companies
Sarbanes-Oxley Mandatory
Sections 302 & 404 require documented
internal controls over financial reporting.
IT implications include access control, audit trails, and data integrity.
US gov framework Cybersecurity risk management Fed agencies; widely adopted
NIST Standards Voluntary*
Includes CSF (5 functions: Identify,
Protect, Detect, Respond, Recover), SP
800-53 (controls catalog), and SP 800-171 (CUI protection). Backbone of FISMA.
EU regulation Personal data privacy rights Any org handling EU data
GDPR Mandatory
Broad extraterritorial reach. Grants data
subject rights (access, erasure,
portability). Requires privacy by design, DPO appointment, 72-hr breach notification.
* NIST is mandatory for US federal agencies under FISMA; voluntary for the private sector but widely adopted as best practice.
Key focus areas: Risk management Gov & federal Payments Healthcare Finance Privacy Best practices
Security Frameworks Reference · ISO/IEC 27000 · FISMA · PCI DSS · HIPAA · SOX · NIST · GDPR Page 1 of 1