Cybersecurity and Privacy
33 references
Information security management, cybersecurity frameworks, data protection regulations, and privacy standards. Covers the ISO 27000 series, Common Criteria, industrial control system security (IEC 62443), NIST publications, threat intelligence databases, and global data protection laws (GDPR, CCPA, HIPAA, LGPD, and others).
| ID | Title | Label |
|---|---|---|
| Standard | ||
IEC-62443 |
Industrial communication networks — IT security for networks and systems | Standard |
ISO-15408 |
Information technology — Security techniques — Evaluation criteria for IT security | Standard |
ISO-27001 |
Information security, cybersecurity and privacy protection — Information security management systems | Standard |
ISO-27002 |
Information security, cybersecurity and privacy protection — Information security controls | Standard |
ISO-27005 |
Information security, cybersecurity and privacy protection — Guidance on managing information security risks | Standard |
ISO-27017 |
Information technology — Security techniques — Code of practice for information security controls based on ISO/IEC 27002 for cloud services | Standard |
ISO-27018 |
Information technology — Code of practice for protection of personally identifiable information (PII) in public clouds | Standard |
ISO-27034 |
Information technology — Application security | Standard |
ISO-27701 |
Security techniques — Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management | Standard |
ISO-29100 |
Information technology — Privacy framework | Standard |
ISO-29134 |
Information technology — Guidelines for privacy impact assessment | Standard |
PCI-DSS |
Payment Card Industry Data Security Standard | Standard |
SOC-2 |
Service Organization Control 2 | Standard |
| Regulation | ||
APPI |
Act on the Protection of Personal Information | Regulation |
CCPA |
California Consumer Privacy Act | Regulation |
DPDP-Act |
Digital Personal Data Protection Act (India) | Regulation |
EU-CRA |
Cyber Resilience Act | Regulation |
EU-DORA |
Digital Operational Resilience Act | Regulation |
EU-NIS2 |
Directive on measures for a high common level of cybersecurity across the Union | Regulation |
GDPR |
General Data Protection Regulation | Regulation |
HIPAA |
Health Insurance Portability and Accountability Act | Regulation |
LGPD |
Lei Geral de Protecao de Dados Pessoais | Regulation |
PIPA |
Personal Information Protection Act (South Korea) | Regulation |
PIPEDA |
Personal Information Protection and Electronic Documents Act | Regulation |
UK-DPA-2018 |
Data Protection Act 2018 | Regulation |
| Publication | ||
CWE |
Common Weakness Enumeration | Publication |
FedRAMP |
Federal Risk and Authorization Management Program | Publication |
MITRE-ATTCK |
MITRE ATT&CK — Adversarial Tactics, Techniques, and Common Knowledge | Publication |
NIST-CSF |
NIST Cybersecurity Framework | Publication |
NIST-SP-800-171 |
Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations | Publication |
NIST-SP-800-53 |
Security and Privacy Controls for Information Systems and Organizations | Publication |
NIST-SP-800-82 |
Guide to Operational Technology (OT) Security | Publication |
OWASP-ASVS |
Application Security Verification Standard | Publication |