Regulations, standards, accreditation, compliance, and frameworks are distinct but closely related concepts that shape how organizations build and measure their security programs. Key examples include GDPR, PCI DSS, COPPA, CSA STAR, Common Criteria, CMMI, ISO 27000 series, and NIST.
Regulations & Frameworks
First of all, regulation is those things where some sort of authority has put rules or laws into place that we have to follow. Those are the laws and regulations.
Accreditation is something we opt in for. We're going to get accredited so that it gives some validity to what we're doing. A good example of this is that a lot of colleges and universities will get accredited so that it gives legitimacy to the education that they're offering.
Then we have standards. Standards is just the bar that you're going to set, that people have to meet to become accredited or have to meet to become compliant.
What compliance is, is that we're complying to a set of standards. What a framework is, essentially, is a set of standards — a framework is that blueprint for our security program, how we're going to set up our security program. When we talk about complying, we're complying to a set of standards, so for instance legal or regulatory standards; that's what we're complying to.
There's this strong correlation between compliance and frameworks. In fact, we can see that there's a big overlap between those: there are things that we have to comply to, and there are frameworks that are out there, and some of them act as both. A great example of this is PCI DSS. PCI DSS is, if we're processing credit cards, we have to comply with this — well, it's a set of standards, and so we consider it a framework as well. We could call it both compliance and we could call it a framework.
GDPR is something we have to comply with if we have users, or if we're collecting data from anybody, in the European Union. Then we have to comply with GDPR.
I've already mentioned that if we're processing credit cards then we need to comply with the PCI DSS, which is also a framework.
If we have services that children under 13 are going to be using, then we have to comply with CA.
Another set of standards was created by the Cloud Security Alliance, or the CSA, and this is the security trust assurance and risk. This is a set of controls that you could use to implement some security on your network.
Similarly, common criteria is a set of standards, a set of standards that we can use to measure up our security program as well.
The capabilities maturity model integration, or CMMI, is somewhat of a measurement — a measurement of how far we have progressed, the maturity level of our IT department or our cyber security efforts. We measure it up against the standards here to give us somewhat of a rating. There are different maturity levels that we'd have, and we'd rate where we're at with these different maturity levels across all the different standards.
ISO stands for International Organization for Standardization. They have a lot of different standards that they've created. One of them is in the IT and related technology field, or safety, security and risk, so we see these different standards that they've created out there. They play a big role in this, and this 27,000 range is the set of standards that define a lot of IT and cyber security.
Where ISO is a little more international and accepted more internationally, we also have the National Institute of Standards and Technology, and they define a lot of what happens in the US, the standardization for US companies.
Ultimately there's a lot of resources out there and a lot to go over, and I'm not going to cover it all. But this just gives you a glimpse into some of the organizations out there that are creating these standards, and some of the standards that they're creating.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →