Cybersecurity Policy and Standards
Cybersecurity policy and standards cover the rules and guidelines that shape how agencies, businesses, and operators protect computer systems and data. Some are binding laws and regulations. Others are voluntary frameworks published by technical agencies such as the National Institute of Standards and Technology.
People usually ask which frameworks organizations follow, when a company must report a breach, and how public companies disclose cyber risk. They also ask how technical standards are written, who keeps them current, and how they connect to government contracts and oversight.
An independent team explaining how government works
Referenced by Brookings, CNN, Forbes, Fox News, Pew Research, Snopes, The Hill and USA Today.
The Webby-recognized AI behind our articles »
All Articles on Cybersecurity Policy and Standards
SEC Disclosure Rules for Public Companies Hit by Supply Chain Breaches
American executives faced an immediate problem: Does our company need to file a public disclosure with the SEC within four business days? The Securities…
The NIST Cybersecurity Framework: A Guide for U.S. Businesses
The National Institute of Standards and Technology Cybersecurity Framework is a voluntary set of guidelines, standards, and best practices designed to help any organization—regardless…
The History of NIST: The National Institute of Standards and Technology
Your smartphone knows the time down to a billionth of a second. Your credit card transactions are protected by codes that would take supercomputers…