Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

US Federal Data Protection / Cybersecurity Laws

There is quite an assortment of statutory and regulatory requirements within the United States. However, there is no single cybersecurity law that governs all aspects of cybersecurity and privacy.

PCI DSS
Icon Reasons Non Regulatory PCI DSS
Payment Card Industry Data Security Standard (PCI DSS) Version 3.1
US Federal Laws
Icon Reasons Statutory Cybersecurity Requirements US Federal Laws
HIPAA, FACTA, GLBA, SOX
US State Laws
Icon Reasons Statutory Cybersecurity Requirements US State Laws
CA SB1386 MA 200 CMR 17.00 OR 646.200 & Others
EU GDPR
Icon Reasons Compliance EU GDPR Compliance Solution
EU GDPR
International Laws
Icon Reasons Statutory Cybersecurity Requirements UK DPA
UK Data Protection Act & Others
Key Takeaways - US Federal Data Security Laws & Regulations
  • Procedures (also known as control activities) are the most overlooked compliance requirement. But they are the minimum expectation auditors look for.
  • Organizations that lack procedures will earn control deficiencies and possibly fail audits (e.g. SOX, CMMC, ISO 27001).
  • Writing procedures from scratch takes considerable time. ComplianceForge developed a 90% solution so you only need to fine-tune the remaining 10%.
  • The CSOP (Cybersecurity Standardized Operating Procedures) is available in four framework-aligned versions. SCF, NIST 800-53, ISO 27002, and NIST CSF.
  • Each procedure template provides who, what, when, where, why and how guidance with fill-in-the-blank customization.
NIST 800-53 Is King!

With US Federal Legal Requirements

We were the industry's first source for a customized, on-demand Cybersecurity & Data Protection Program (CDPP) that is specifically tailored for small and medium sized business. Our NIST 800-53 rev Cybersecurity & Data Protection Program (CDPP) follows industry-recognized best practices (e.g. NIST, ISO and CIS) and we reference applicable laws, requirements, standards, and best practices that businesses need to follow to be considered compliant.

Reasons Understanding Information Security Risk Mitigation
We Take The Hassle Of The Guesswork Away From US Federal Laws

You Can Focus On Growing Your Business

As information security professionals, we know the policies you need to have in place to meet the requirements with NIST 800-53 rev 5. The likelihood that your local “IT guy” knows these compliance requirements is unlikely since information security is a very specific skill set.

We follow proven, internationally recognized standards for what security policies should consist of. Many competitor sites unfortunately offer solutions that will leave you exposed and unprepared - when keeping your company in business and protected is the priority, there is no room for amateur solutions. The NIST-based Cybersecurity & Data Protection Program (CDPP) stands out from the competition in its coverage, depth, and price. Additionally, the turnaround for a NIST 800-53 Cybersecurity & Data Protection Program (CDPP) is generally 1-2 business days.

Common Questions

Frequently-Asked Questions

Here are answers to common questions about US federal data security laws:

Is there one federal law that governs data security in the United States?
No, the United States has no single federal law that covers data security for every organization. Requirements come from sector-specific laws, including the Gramm-Leach-Bliley Act (GLBA) for financial institutions, HIPAA for health plans, clearinghouses, providers and their business associates, the Fair Credit Reporting Act as amended by FACTA for consumer report information, and the Sarbanes-Oxley Act (SOX) for public company financial reporting controls. The FTC also uses Section 5 of the FTC Act to act against unfair or deceptive data security practices.
Which federal laws require a written information security program?
Several federal rules require written security documentation. The FTC Safeguards Rule under GLBA requires covered financial institutions to maintain a written information security program. The HIPAA Security Rule requires covered entities and business associates to keep security policies and procedures in written form and retain that documentation for 6 years. The FTC Red Flags Rule under FACTA requires financial institutions and creditors with covered accounts to implement a written Identity Theft Prevention Program approved by the board or a board committee.
Which agencies enforce US federal data security laws?
Enforcement depends on the law and the type of organization. The Federal Trade Commission enforces the GLBA Safeguards Rule for non-bank financial institutions under its jurisdiction, the FACTA Disposal Rule, and Section 5 of the FTC Act. The HHS Office for Civil Rights enforces the HIPAA Privacy and Security Rules. Federal banking agencies set GLBA safeguarding standards for the banks they supervise, and the SEC oversees SOX reporting and has oversight authority over the PCAOB.
Do federal data security laws require documented procedures?
In many cases, yes. The HIPAA Security Rule at 45 CFR 164.316 requires reasonable and appropriate policies and procedures, kept in written form, along with written records of required actions and assessments. The FTC Safeguards Rule requires a written information security program and, for most covered institutions, a written incident response plan. Procedures are often the most overlooked part of compliance documentation, and ComplianceForge offers the Cybersecurity Standardized Operating Procedures (CSOP) as editable procedure templates aligned to several frameworks.
How can one set of policies address HIPAA, GLBA, FACTA and SOX?
The usual approach is to build policies and standards on a control framework that maps to multiple laws, then document where a specific law adds its own requirement. The Secure Controls Framework (SCF) is a free metaframework that maps its controls to more than 200 laws, regulations and frameworks. ComplianceForge aligns the Security, Compliance & Resilience Program (SCRP) to the SCF, and you can also get our Cybersecurity & Data Protection Program (CDPP) in NIST CSF 2.0, ISO 27001/27002 and NIST 800-53 versions.