Compliance & Cybersecurity Blog

Practical insights on security frameworks, risk management, and regulatory compliance

By Jim Venuto

About This Blog

A resource covering cybersecurity assurance, compliance frameworks, and risk management standards. These articles provide practical guidance for business leaders, security professionals, and compliance practitioners navigating the complex landscape of regulatory requirements and industry standards.

Each article translates technical compliance requirements into actionable business insights, helping organizations of all sizes build effective security programs and demonstrate accountability to stakeholders.

Agentic AI & Compliance

AICPA Standards & SOC Reporting

SOC 2 & Trust Services Published

Service Organization Controls for security, availability, processing integrity, confidentiality, and privacy

ISO Standards

ISO 27001 & 27K Series Published

Information Security Management Systems (ISMS) and the ISO 27000 family of standards

ISO 42001 Published

Artificial Intelligence Management System standard

ISO/SAE 21434 Published

Road vehicles - Cybersecurity engineering

NIST Frameworks & Standards

NIST Cybersecurity Framework Published

CSF 1.1 and CSF 2.0 - Framework for improving critical infrastructure cybersecurity

NIST AI Risk Management Published

AI Risk Management Framework (AI RMF) for trustworthy AI systems

NIST Secure Software Development Published

NIST SSDF - Secure Software Development Framework

NIST SP 800-53 Published

Security and Privacy Controls for Information Systems and Organizations

NIST SP 800-171 Published

Protecting Controlled Unclassified Information (CUI) in nonfederal systems

EU Regulations

EU AI Act 2024 Published

European Union's comprehensive AI regulation framework

GDPR Published

General Data Protection Regulation - EU data privacy and protection

NIS2 Directive Published

Network and Information Security Directive - EU cybersecurity requirements

US Federal Regulations

FFIEC Published

Federal Financial Institutions Examination Council cybersecurity guidance

FTC Safeguards Rule Published

Federal Trade Commission data security requirements for financial institutions

CJIS Security Policy Published

Criminal Justice Information Services security requirements

US State Regulations

NYS DFS Cybersecurity Published

New York State Department of Financial Services cybersecurity requirements (23 NYCRR 500)

CCPA/CPRA Published

California Consumer Privacy Act - California data privacy requirements

Healthcare Compliance

HIPAA Security Rule Published

Health Insurance Portability and Accountability Act security requirements

HITRUST CSF Published

Health Information Trust Alliance Common Security Framework

Payment Card Security

PCI-DSS Published

Payment Card Industry Data Security Standard including v4.0.1

UK Cybersecurity Frameworks

Cyber Essentials Published

UK government-backed cybersecurity certification scheme including v3.2

NCSC CAF Published

National Cyber Security Centre Cyber Assessment Framework v3.2

DoD Cybersecurity Maturity Model Certification

CMMC Levels 1 & 2 Published

Department of Defense cybersecurity requirements for defense contractors

CIS Controls

CIS Critical Security Controls Published

Center for Internet Security Controls v8 and v8.1