security-alliance / frameworks

Official repository for the Security Frameworks by SEAL. Currently under development, not a release.
https://frameworks.securityalliance.org
17 stars 5 forks source link

Extend the best practices for regulatory compliance #53

Open mattaereal opened 3 months ago

mattaereal commented 3 months ago

What content are you looking to modify or update?

The regulatory compliance category under governance.

Why do you think this update or modification is needed?

First of all, it's really scarce, but then I think it should be a category on its own, laws and regulations itself.

Can you justify your argument and provide additional resources

Really scarce almost empty, not sure it's the best way to put it there if it's going to be a broad subject.

mattaereal commented 3 months ago

Best Practices for Regulatory Compliance in Terms of Security

1. Understand Applicable Regulations

2. Develop a Robust Security Policy Framework

3. Data Protection and Privacy

4. Access Management and Control

5. Incident Response Planning

6. Continuous Monitoring and Auditing

7. Employee Training and Awareness

8. Third-Party Risk Management

9. Data Encryption and Secure Communication

10. Documentation and Record-Keeping

Useful Resources

Here are some useful resources where you can follow and learn more about the best practices mentioned:

  1. National Institute of Standards and Technology (NIST)

    • NIST Cybersecurity Framework: A comprehensive resource for implementing cybersecurity best practices and complying with regulatory requirements.
    • URL: https://www.nist.gov/cyberframework
  2. International Organization for Standardization (ISO)

  3. Center for Internet Security (CIS)

    • CIS Controls: A prioritized set of actions that help organizations comply with regulatory requirements and improve their cybersecurity posture.
    • URL: https://www.cisecurity.org/controls/
  4. General Data Protection Regulation (GDPR)

    • Official GDPR Portal: Provides detailed information on GDPR requirements, including guidelines, tools, and resources for compliance.
    • URL: https://gdpr.eu/
  5. Health Insurance Portability and Accountability Act (HIPAA)

    • HIPAA Journal: Offers news, resources, and guidelines for ensuring compliance with HIPAA regulations, particularly in the healthcare sector.
    • URL: https://www.hipaajournal.com/
  6. Payment Card Industry Data Security Standard (PCI DSS)

    • Official PCI Security Standards Council: Provides comprehensive resources, including guidelines and tools for complying with PCI DSS requirements.
    • URL: https://www.pcisecuritystandards.org/
  7. Cybersecurity & Infrastructure Security Agency (CISA)

  8. Cloud Security Alliance (CSA)

  9. International Association of Privacy Professionals (IAPP)

    • IAPP Resource Center: Offers a wealth of resources, including whitepapers, research, and tools, to help organizations comply with data protection regulations.
    • URL: https://iapp.org/resources/
  10. SANS Institute

    • SANS Security Resources: Provides extensive resources, including guides, whitepapers, and training courses, for improving security and regulatory compliance.
    • URL: https://www.sans.org/security-resources/