OWASP Top Ten ★★★★★
The OWASP Top Ten is a widely recognized list that highlights the ten most critical security risks facing web applications today. Updated every few years by security experts, the list… Read More »OWASP Top Ten ★★★★★
In cybersecurity, there are different types of documents that together structure governance and compliance: laws and regulations (e.g., binding legal texts such as the EU’s General Data Protection Regulation) impose mandatory requirements and sanctions; contractual obligations translate security expectations into enforceable commitments between parties (such as security clauses in supplier agreements); standards (like ISO/IEC 27001) define certifiable best practices; frameworks (for example, the NIST Cybersecurity Framework) provide structured guidance to assess and improve security posture; guidelines offer non-binding recommendations and practical interpretation; and tools support implementation through technical or methodological means (e.g., risk assessment or vulnerability scanning tools). Together, these instruments differ in legal force, level of prescriptiveness, and operational purpose, but collectively shape an organization’s cybersecurity posture.
The OWASP Top Ten is a widely recognized list that highlights the ten most critical security risks facing web applications today. Updated every few years by security experts, the list… Read More »OWASP Top Ten ★★★★★
The DSL serves as a fundamental pillar of China’s national security framework, regulating data processing activities across all sectors to safeguard state sovereignty and public interest. It establishes a mandatory… Read More »China Data Security Law (DSL)
The Cloud Security Alliance Cloud Controls Matrix (CSA CCM) is a comprehensive cybersecurity control framework specifically designed for cloud computing environments. It consists of 197 control objectives organized into 17… Read More »CSA Cloud Controls Matrix (CCM) v4 ★★★★★
NIST Special Publication 1800-26, titled “Data Integrity: Detecting and Responding to Ransomware and Other Destructive Events,” provides a practical, standards-based reference guide to help organizations maintain the integrity and availability… Read More »NIST SP 1800-26 Data Integrity: Detecting and Responding to Ransomware and Other Destructive Events
NIST Special Publication 1800-11, titled “Data Integrity: Recovering from Ransomware and Other Destructive Events,” is a cybersecurity practice guide that demonstrates how organizations can develop and implement strategies to quickly… Read More »NIST SP 1800-11 Data Integrity: Recovering from Ransomware and Other Destructive Events
NIST Special Publication 800-53 (NIST SP 800-53) provides a comprehensive catalog of security and privacy controls designed to protect federal information systems and organizations from a wide range of risks. The… Read More »NIST SP 800-53 Rev. 5 Security and Privacy Controls for Information Systems and Organizations
NIST SP 800-207, titled “Zero Trust Architecture,” is a comprehensive guidance document from the National Institute of Standards and Technology that outlines the principles, components, and strategies for implementing Zero… Read More »NIST SP 800-207 Zero Trust Architecture
NIST SP 1800-25, titled “Data Integrity: Identifying and Protecting Assets Against Ransomware and Other Destructive Events,” provides practical guidance for organizations to identify, protect, and manage their critical assets against… Read More »NIST SP 1800-25 Data Integrity: Identifying and Protecting Assets Against Ransomware and Other Destructive Events
The BSI Cloud Computing Compliance Criteria Catalogue (C5) defines a mandatory baseline for the secure operation of cloud services, providing a transparent and verifiable framework for cloud service providers and… Read More »BSI Cloud Security (C5)
The EBA Guidelines on ICT and Security Risk Management provide a comprehensive framework for credit institutions, investment firms, and payment service providers to identify, assess, and mitigate ICT and security… Read More »EBA Guidelines on ICT and security risk management