Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

Cybersecurity Compliance — It Starts With The Framework!

It is important to understand that to "get compliant" with a cybersecurity requirement, it is generally more involved than just addressing a checklist. With that in mind, selecting a cybersecurity framework is more of a business decision and less of a technical decision. Realistically, the process of selecting a cybersecurity framework must be driven by a fundamental understanding of what your organization needs to comply with from a statutory, regulatory and contractual perspective, since that understanding establishes the minimum set of requirements necessary to (1) not be considered negligent with reasonable expectations for security & privacy; (2) comply with applicable laws, regulations and contracts; and (3) implement the proper controls to secure your systems, applications and processes from reasonable threats. This understanding makes it pretty easy to determine the appropriate external framework to align with.

Spectrum Common Cybersecurity Framework Comparison
Key Takeaways - Common Compliance Requirements
  • Getting compliant is more involved than addressing a checklist. It starts with selecting the right cybersecurity framework based on your business obligations.
  • Your framework choice must be driven by understanding your statutory, regulatory and contractual requirements, not just technical preferences.
  • This understanding establishes the minimum controls needed to avoid negligence, comply with laws, regulations and contracts, and secure your systems from reasonable threats.
  • A single negligent breach could close your business. Liability insurance does not cover professional negligence.
  • ComplianceForge provides editable, expert-written documentation aligned to all major compliance requirements.
Explore By Requirement

Where Do You Fit In The Mandatory Compliance Puzzle?

A single negligent breach could close your businesses forever, because liability insurance does not cover professional negligence! Below are several examples of how compliance with information security requirements affects common businesses:

HIPAA and PCI DSS Compliance

Example #1: Physical Therapist

Compliance Requirements: HIPAA, PCI DSS & State Breach Laws

Why? This physical therapist office deals with electronic Protected Health Information (ePHI) of clients so it falls under HIPAA. The office also accepts co-payments by credit card so it falls under PCI DSS. Since the state requires a breach notification plan, the office must also adhere to state-specific compliance requirements for data breaches.

PCI DSS and GLBA Compliance

Example #2: Certified Public Accountant (CPA)

Compliance Requirements: GLBA, PCI DSS & State Breach Laws

Why? Like most CPAs, this CPA deals with private financial information of clients, so it falls under GLBA. The CPA works for clients that accept credit cards and has access to their QuickBooks accounts (containing cardholder information), so the CPA must meet PCI DSS requirements. Most states waive state-sponsored breach laws if the company is GLBA compliant, so there are no additional requirements by the state.

GLBA and PCI DSS Compliance in Oregon    

Example #3: Lawyer

Compliance Requirements: HIPAA, FACTA, GLBA, PCI DSS & State Breach Laws

Why? This law offices deal with Protected Health Information (PHI) for injury claims so its falls under HIPAA as a Business Associate. Since the office also performs real estate closings and is responsible for private financial information, it falls under both FACTA and GLBA. The office accepts payment by credit card so it falls under PCI DSS. This state waives its breach notification law if the law office is GLBA compliant, so there are no additional requirements by the state.

PCI DSS Compliance for Level 3 and Level 4 Merchants

Example #1: Coffee Shop

Compliance Requirements: HIPAA, PCI DSS & State Breach Laws

Why? This coffee shop accepts payment by credit and debit cards so it falls under PCI DSS. This specific state does not have any specific laws for breach notification, so the coffee shop only has to focus on PCI DSS compliance.

State Identity Theft Law Compliance

Example #1: Construction Company

Compliance Requirements: State Breach Laws

Why? The construction company operates in a state that has a law requiring both client and employee Personal Identifying Information (PII) to be protected and for notification in the event of a breach.

Common Questions

Frequently-Asked Questions

Here are answers to common questions about meeting common compliance requirements:

What are cybersecurity compliance requirements?
Cybersecurity compliance requirements are the statutory, regulatory and contractual obligations that define how an organization must protect its systems and the data it handles. Common examples include HIPAA for electronic protected health information, the GLBA Safeguards Rule for customer financial information, PCI DSS for payment card data, and state laws that require reasonable safeguards for personal information. These obligations set the minimum controls an organization needs to avoid negligence, which is why they should be identified before any security framework is chosen.
How do I know which compliance requirements apply to my business?
Start with the data you collect, store, process or transmit and the contracts you sign, because those two factors drive most obligations. Health information can trigger HIPAA, accepting credit cards brings PCI DSS, customer financial data can bring the GLBA Safeguards Rule, and federal contracts can add FAR clauses, plus DFARS clauses for defense work. Businesses that hold personal information are also likely to fall under state data security and breach notification laws. Document the resulting list and have legal counsel confirm it before selecting controls.
Can a business be subject to multiple compliance requirements at once?
Yes, and it is common for one organization to face several at once. A law firm whose legal services to a health plan involve access to protected health information is a HIPAA business associate, and if it also accepts card payments it is expected to meet PCI DSS, while state breach notification laws cover the personal information it holds. Instead of building a separate program for each, organizations can map overlapping requirements to a single control set, such as the Secure Controls Framework (SCF), and implement each control once.
Should compliance requirements drive which cybersecurity framework I use?
Yes, a framework should be selected after the organization understands its statutory, regulatory and contractual obligations, not based on technical preference alone. For example, a defense contractor whose contract includes DFARS 252.204-7012 must implement the security requirements in NIST SP 800-171, so a framework that does not map cleanly to those requirements can leave gaps that surface during an assessment. Picking the framework that best covers the actual obligations reduces rework and makes it easier to demonstrate due diligence.
Which procedure templates cover multiple compliance requirements?
ComplianceForge's Security, Compliance & Resilience Program (SCRP) version of the Cybersecurity Standardized Operating Procedures (CSOP) is built to cover multiple requirements, since it's a hybrid set of procedures spanning dozens of statutory, regulatory and contractual frameworks. Our other CSOP versions align to a single framework, such as NIST CSF 2.0, ISO 27001/27002, NIST 800-53 R5 or CORE Fundamentals. Each CSOP comes as an editable Microsoft Word document, and you'll still need to tailor each procedure to your actual technologies and staff.