Key Takeaways - US Federal Data Security Laws & Regulations
- Procedures (also known as control activities) are the most overlooked compliance requirement. But they are the minimum expectation auditors look for.
- Organizations that lack procedures will earn control deficiencies and possibly fail audits (e.g. SOX, CMMC, ISO 27001).
- Writing procedures from scratch takes considerable time. ComplianceForge developed a 90% solution so you only need to fine-tune the remaining 10%.
- The CSOP (Cybersecurity Standardized Operating Procedures) is available in four framework-aligned versions. SCF, NIST 800-53, ISO 27002, and NIST CSF.
- Each procedure template provides who, what, when, where, why and how guidance with fill-in-the-blank customization.
NIST 800-53 Is King!With US Federal Legal Requirements
We were the industry's first source for a customized, on-demand Cybersecurity & Data Protection Program (CDPP) that is specifically tailored for small and medium sized business. Our NIST 800-53 rev Cybersecurity & Data Protection Program (CDPP) follows industry-recognized best practices (e.g. NIST, ISO and CIS) and we reference applicable laws, requirements, standards, and best practices that businesses need to follow to be considered compliant.

We Take The Hassle Of The Guesswork Away From US Federal LawsYou Can Focus On Growing Your Business
As information security professionals, we know the policies you need to have in place to meet the requirements with NIST 800-53 rev 5. The likelihood that your local “IT guy” knows these compliance requirements is unlikely since information security is a very specific skill set.
We follow proven, internationally recognized standards for what security policies should consist of. Many competitor sites unfortunately offer solutions that will leave you exposed and unprepared - when keeping your company in business and protected is the priority, there is no room for amateur solutions. The NIST-based Cybersecurity & Data Protection Program (CDPP) stands out from the competition in its coverage, depth, and price. Additionally, the turnaround for a NIST 800-53 Cybersecurity & Data Protection Program (CDPP) is generally 1-2 business days.
Common QuestionsFrequently-Asked Questions
Here are answers to common questions about US federal data security laws:
Is there one federal law that governs data security in the United States?
No, the United States has no single federal law that covers data security for every organization. Requirements come from sector-specific laws, including the Gramm-Leach-Bliley Act (GLBA) for financial institutions, HIPAA for health plans, clearinghouses, providers and their business associates, the Fair Credit Reporting Act as amended by FACTA for consumer report information, and the Sarbanes-Oxley Act (SOX) for public company financial reporting controls. The FTC also uses Section 5 of the FTC Act to act against unfair or deceptive data security practices.
Which federal laws require a written information security program?
Several federal rules require written security documentation. The FTC Safeguards Rule under GLBA requires covered financial institutions to maintain a written information security program. The HIPAA Security Rule requires covered entities and business associates to keep security policies and procedures in written form and retain that documentation for 6 years. The FTC Red Flags Rule under FACTA requires financial institutions and creditors with covered accounts to implement a written Identity Theft Prevention Program approved by the board or a board committee.
Which agencies enforce US federal data security laws?
Enforcement depends on the law and the type of organization. The Federal Trade Commission enforces the GLBA Safeguards Rule for non-bank financial institutions under its jurisdiction, the FACTA Disposal Rule, and Section 5 of the FTC Act. The HHS Office for Civil Rights enforces the HIPAA Privacy and Security Rules. Federal banking agencies set GLBA safeguarding standards for the banks they supervise, and the SEC oversees SOX reporting and has oversight authority over the PCAOB.
Do federal data security laws require documented procedures?
In many cases, yes. The HIPAA Security Rule at 45 CFR 164.316 requires reasonable and appropriate policies and procedures, kept in written form, along with written records of required actions and assessments. The FTC Safeguards Rule requires a written information security program and, for most covered institutions, a written incident response plan. Procedures are often the most overlooked part of compliance documentation, and ComplianceForge offers the Cybersecurity Standardized Operating Procedures (CSOP) as editable procedure templates aligned to several frameworks.
How can one set of policies address HIPAA, GLBA, FACTA and SOX?
The usual approach is to build policies and standards on a control framework that maps to multiple laws, then document where a specific law adds its own requirement. The Secure Controls Framework (SCF) is a free metaframework that maps its controls to more than 200 laws, regulations and frameworks. ComplianceForge aligns the Security, Compliance & Resilience Program (SCRP) to the SCF, and you can also get our Cybersecurity & Data Protection Program (CDPP) in NIST CSF 2.0, ISO 27001/27002 and NIST 800-53 versions.