TechKnowSurge
CompTIA Security+ 5.1 ISC2 CISSP 1.3 ISC2 CISSP 1.4 NIST CSF GV.OC-03 CompTIA Security+ 5.4 ISC2 CISSP 2.6 NIST NICE K0879 NIST NICE K0918
VideoSecurityFree

Regulation, Accreditations, and Standards

Regulations, standards, accreditation, compliance, and frameworks are distinct but closely related concepts that shape how organizations build and measure their security programs. Key examples include GDPR, PCI DSS, COPPA, CSA STAR, Common Criteria, CMMI, ISO 27000 series, and NIST.

Complete this video to capture a CTF flag worth 1 point.

About this video

Regulations, standards, accreditation, compliance, and frameworks are related but distinct concepts that govern how organizations approach security and risk management. Regulations are rules or laws imposed by a governing authority that organizations are legally required to follow. Accreditation, by contrast, is voluntary and provides external validation of an organization's practices — similar to how colleges and universities seek accreditation to demonstrate the legitimacy of their programs. Standards define the specific criteria an organization must satisfy to achieve compliance or earn accreditation, and they underpin both regulatory requirements and security frameworks alike. Compliance and frameworks are closely intertwined, and the boundary between them often overlaps. Compliance means adhering to a defined set of standards, typically those mandated by law or regulation. A framework is a structured blueprint that guides how a security program is designed and operated, and it is also built on standards. Some instruments serve both roles simultaneously — PCI DSS, for example, is a mandatory compliance requirement for organizations that process payment card data and is also structured as a comprehensive security framework. Similarly, GDPR applies to any organization collecting data from individuals in the European Union, and COPPA governs services used by children under the age of 13. Beyond mandatory requirements, several widely recognized frameworks and measurement tools help organizations assess and improve their security posture. The Cloud Security Alliance's Security Trust Assurance and Risk controls provide guidance for implementing network security measures. Common Criteria offers a standardized basis for evaluating security capabilities. The Capability Maturity Model Integration, or CMMI, provides a tiered model for measuring how mature an organization's IT and cybersecurity efforts are relative to defined benchmarks. At a broader level, the ISO 27000 series represents an internationally recognized set of standards covering IT and cybersecurity, while the National Institute of Standards and Technology defines much of the standardization landscape for organizations operating in the United States. Together, these bodies and frameworks form a layered ecosystem that organizations draw on to build, evaluate, and continuously improve their security programs.

What you'll learn

What's covered

Regulations & Frameworks

Aligned to

CompTIA Security+
5.1 Summarize elements of effective security governance.
5.4 Summarize elements of effective security compliance.
ISC2 CISSP
1.3 Evaluate and apply security governance principles
1.4 Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context
2.6 Determine data security controls and compliance requirements
NIST CSF
GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed.
NIST NICE
K0879 Knowledge of industry cybersecurity models and frameworks
K0918 Knowledge of Payment Card Industry (PCI) data security standards and best practices

Key terms

Regulation
A legally binding rule or requirement issued by a governing authority that organizations must follow.
Accreditation
A voluntary process through which an organization demonstrates it meets a defined set of standards, lending legitimacy to its operations.
Standard
A mandatory, specific requirement derived from a policy that defines how the policy is to be implemented.
Compliance
The act of adhering to the laws, regulations, standards, and internal policies that govern how an organization handles data and security. Compliance programs use audits and controls to demonstrate that requirements are being met.
Framework
A structured set of standards and best practices that serves as a blueprint for building and managing a security program.
General Data Protection Regulation
GDPR
A European Union regulation that establishes comprehensive data protection and privacy rights for individuals within the EU and EEA, and imposes obligations on organizations that process EU residents' personal data regardless of where the organization is located. GDPR introduced concepts such as data minimization, the right to erasure, and mandatory breach notification.
Payment Card Industry Data Security Standard
PCI DSS
A set of security requirements mandated by major credit card brands that organizations must follow to process, store, or transmit cardholder data. PCI DSS covers controls such as encryption, access restriction, and regular security testing.
Children's Online Privacy Act
COPPA
A U.S. federal law that imposes requirements on operators of websites and online services directed at children under 13, restricting the collection and use of personal information from minors. It requires verifiable parental consent before collecting children's data.
Cloud Security Alliance Security Trust Assurance and Risk
CSA STAR
A set of controls developed by the Cloud Security Alliance to help organizations implement and assess security in cloud environments.
ISO 27000
A family of international standards published by the International Organization for Standardization that defines requirements and best practices for IT and cybersecurity.
National Institute of Standards and Technology
NIST
A U.S. federal agency within the Department of Commerce that develops and promotes measurement standards, guidelines, and best practices for technology, manufacturing, and cybersecurity. NIST's cybersecurity publications — including the CSF, SP 800-53, and SP 800-37 — are foundational references for federal agencies and organizations worldwide.
Capability Maturity Model Integration
CMMI
A framework that measures and rates the maturity level of an organization's IT or cybersecurity processes against defined standards.

Topics

Cybersecurity Governance Regulatory Compliance Security Frameworks Gdpr Nist Iso 27000 Pci Dss

Transcript

Regulation, Accreditation and Standards

First of all, regulation is those things where some sort of authority has put rules or laws into place that we have to follow. Those are the laws and regulations.

Accreditation is something we opt in for. We're going to get accredited so that it gives some validity to what we're doing. A good example of this is that a lot of colleges and universities will get accredited so that it gives legitimacy to the education that they're offering.

Then we have standards. Standards is just the bar that you're going to set, that people have to meet to become accredited or have to meet to become compliant.

Compliance Compared to Frameworks

What compliance is, is that we're complying to a set of standards. What a framework is, essentially, is a set of standards — a framework is that blueprint for our security program, how we're going to set up our security program. When we talk about complying, we're complying to a set of standards, so for instance legal or regulatory standards; that's what we're complying to.

There's this strong correlation between compliance and frameworks. In fact, we can see that there's a big overlap between those: there are things that we have to comply to, and there are frameworks that are out there, and some of them act as both. A great example of this is PCI DSS. PCI DSS is, if we're processing credit cards, we have to comply with this — well, it's a set of standards, and so we consider it a framework as well. We could call it both compliance and we could call it a framework.

Some Specific Examples

GDPR is something we have to comply with if we have users, or if we're collecting data from anybody, in the European Union. Then we have to comply with GDPR.

I've already mentioned that if we're processing credit cards then we need to comply with the PCI DSS, which is also a framework.

If we have services that children under 13 are going to be using, then we have to comply with CA.

Another set of standards was created by the Cloud Security Alliance, or the CSA, and this is the security trust assurance and risk. This is a set of controls that you could use to implement some security on your network.

Similarly, common criteria is a set of standards, a set of standards that we can use to measure up our security program as well.

The capabilities maturity model integration, or CMMI, is somewhat of a measurement — a measurement of how far we have progressed, the maturity level of our IT department or our cyber security efforts. We measure it up against the standards here to give us somewhat of a rating. There are different maturity levels that we'd have, and we'd rate where we're at with these different maturity levels across all the different standards.

The Standards Organizations

ISO stands for International Organization for Standardization. They have a lot of different standards that they've created. One of them is in the IT and related technology field, or safety, security and risk, so we see these different standards that they've created out there. They play a big role in this, and this 27,000 range is the set of standards that define a lot of IT and cyber security.

Where ISO is a little more international and accepted more internationally, we also have the National Institute of Standards and Technology, and they define a lot of what happens in the US, the standardization for US companies.

Ultimately there's a lot of resources out there and a lot to go over, and I'm not going to cover it all. But this just gives you a glimpse into some of the organizations out there that are creating these standards, and some of the standards that they're creating.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →