Kernel of Truth

Regulatory Compliance Standards: At a Glance

⚖️ Regulatory Compliance Standards: At a Glance

In an increasingly regulated digital landscape, understanding and aligning with key cybersecurity and data protection standards is essential for organisations of all sizes. Below is a summary of major regulatory and compliance frameworks relevant to IT, data security, and cloud infrastructure professionals.


📄 Index of Key Compliance Standards

AcronymFull NameScope / IndustryPurpose
GDPRGeneral Data Protection RegulationEU, GlobalGoverns collection and processing of personal data of EU/EEA residents.
HIPAAHealth Insurance Portability and Accountability ActUS HealthcareProtects electronic Protected Health Information (ePHI) and mandates privacy/security controls.
SOXSarbanes-Oxley ActUS Public CompaniesPrevents financial fraud and enforces internal control over financial reporting.
PCI DSSPayment Card Industry Data Security StandardPayment processors, merchants, and providersSecures cardholder data and prevents credit card fraud.
NIST CSFNational Institute of Standards and Technology Cybersecurity FrameworkUS Government, Critical InfrastructureProvides a framework for improving cybersecurity posture.
ISO 27001International Organisation for Standardisation 27001Global, cross-sectorSpecifies requirements for an Information Security Management System (ISMS).
FISMAFederal Information Security Management ActUS Federal AgenciesMandates federal agencies to implement information security programs.
CCPA / CPRACalifornia Consumer Privacy Act / Rights ActCalifornia, USAGives consumers control over personal data; US equivalent of GDPR.
DORADigital Operational Resilience ActEU Financial SectorEnsures IT resilience and incident response in the financial industry.
SOC 1 & SOC 2System and Organisation Controls ReportsSaaS, Cloud ProvidersIndependent audits to assess security, availability, processing integrity, confidentiality, and privacy.
FedRAMPFederal Risk and Authorization Management ProgramUS Federal Cloud ProvidersStandardises cloud security assessments for federal use.
CMMCCybersecurity Maturity Model CertificationUS Defense ContractorsEnsures contractors meet cybersecurity requirements to protect federal CUI (Controlled Unclassified Information).

NCSC Latest