Skip to content
    Home / Sector / Cross-Sector

    Cross-Sector

    A wide range of documents provides universally applicable guidance and requirements for organizations across industries. These include laws and regulations like the General Data Protection Regulation and NIS2 Directive, standards such as ISO/IEC 27001, frameworks like the NIST Cybersecurity Framework, practical guidelines from authorities such as European Union Agency for Cybersecurity, contractual obligations, mapping documents reconciling multiple issuers, and tools—online or downloadable—that help operationalize these requirements. Their broad applicability across sectors ensures organizations can implement consistent, auditable cybersecurity practices that meet both legal obligations and industry-agnostic best practices.

    ISO/IEC 27000:2018 Information technology — Security techniques — Information security management systems — Overview and vocabulary

    The ISO 27000 standard provides an overview and introduction to the ISO 27000 family, which is a series of international standards focused on information security management systems (ISMS). These standards… Read More »ISO/IEC 27000:2018 Information technology — Security techniques — Information security management systems — Overview and vocabulary

    ISO/IEC 27003:2017 Information technology — Security techniques — Information security management systems — Guidance

    ISO/IEC 27003 provides detailed guidance for organizations on how to implement an Information Security Management System (ISMS) based on the requirements of ISO/IEC 27001. It covers the entire process from… Read More »ISO/IEC 27003:2017 Information technology — Security techniques — Information security management systems — Guidance

    ISO/IEC 27004:2016 Information technology — Security techniques — Information security management — Monitoring, measurement, analysis and evaluation

    ISO/IEC 27004 is an international standard that provides guidelines for monitoring, measuring, analyzing, and evaluating the performance and effectiveness of an Information Security Management System (ISMS) based on ISO/IEC 27001.… Read More »ISO/IEC 27004:2016 Information technology — Security techniques — Information security management — Monitoring, measurement, analysis and evaluation

    NIST SP 800-39 Managing Information Security Risk: Organization, Mission, and Information System View

    NIST SP 800-39 serves as the overarching flagship for information security risk management, providing the high-level governance necessary to align cybersecurity efforts with an organization’s core mission and business objectives.… Read More »NIST SP 800-39 Managing Information Security Risk: Organization, Mission, and Information System View