Skip to content
Home / Sector / Cross-Sector

Cross-Sector

A wide range of documents provides universally applicable guidance and requirements for organizations across industries. These include laws and regulations like the General Data Protection Regulation and NIS2 Directive, standards such as ISO/IEC 27001, frameworks like the NIST Cybersecurity Framework, practical guidelines from authorities such as European Union Agency for Cybersecurity, contractual obligations, mapping documents reconciling multiple issuers, and tools—online or downloadable—that help operationalize these requirements. Their broad applicability across sectors ensures organizations can implement consistent, auditable cybersecurity practices that meet both legal obligations and industry-agnostic best practices.

NIST SP 800-18 Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems

NIST SP 800-18 Revision 2, “Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems,” provides a structured framework for creating comprehensive security plans for federal information systems,… Read More »NIST SP 800-18 Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems

CISA Primary Mitigations to Reduce Cyber Threats to Operational Technology

The CISA “Primary Mitigations to Reduce Cyber Threats to Operational Technology” fact sheet outlines five core strategies for critical infrastructure operators to strengthen the cybersecurity of their operational technology (OT)… Read More »CISA Primary Mitigations to Reduce Cyber Threats to Operational Technology

OWASP Application Security Verification Standard (ASVS) 5.0

The OWASP Application Security Verification Standard (ASVS) is a comprehensive framework that defines security requirements for designing, developing, and testing web applications and APIs. It is organized into 14 chapters,… Read More »OWASP Application Security Verification Standard (ASVS) 5.0