Skip to content

Cybersecurity Policy and Standards

Cybersecurity policy and standards cover the rules and guidelines that shape how agencies, businesses, and operators protect computer systems and data. Some are binding laws and regulations. Others are voluntary frameworks published by technical agencies such as the National Institute of Standards and Technology.

People usually ask which frameworks organizations follow, when a company must report a breach, and how public companies disclose cyber risk. They also ask how technical standards are written, who keeps them current, and how they connect to government contracts and oversight.

3articles
February 1last updated

An independent team explaining how government works

GovFacts is a nonpartisan site that makes government concepts, policies and programs easier to understand and use.

Referenced by Brookings, CNN, Forbes, Fox News, Pew Research, Snopes, The Hill and USA Today.

The Webby-recognized AI behind our articles »

All Articles on Cybersecurity Policy and Standards

SEC Disclosure Rules for Public Companies Hit by Supply Chain Breaches

American executives faced an immediate problem: Does our company need to file a public disclosure with the SEC within four business days? The Securities…

15 Min Read

The NIST Cybersecurity Framework: A Guide for U.S. Businesses

The National Institute of Standards and Technology Cybersecurity Framework is a voluntary set of guidelines, standards, and best practices designed to help any organization—regardless…

37 Min Read

The History of NIST: The National Institute of Standards and Technology

Your smartphone knows the time down to a billionth of a second. Your credit card transactions are protected by codes that would take supercomputers…

39 Min Read