Skip to content

Cybersecurity

What is Cybersecurity?

The practice of protecting systems, networks, and programs from digital attacks that aim to access, change, or destroy sensitive information.

Information Security

Each of these is named in at least one of the same controls as cybersecurity. The number is how many controls name both.

What the standards actually require on cybersecurity

Requirements naming cybersecurity across 6 standards, quoted from the control text.

The organizational mission is understood and informs cybersecurity risk management

NIST-CSF-GV.OC-01 · The organizational mission is understood and informs cybersecurity risk management

Provide periodic training to officers, members of the disclosure committee, IR leaders, and the board on cybersecurity disclosure requirements, materiality factors, and timing obligations.

SEC-CYB-19 · Training for Material Cybersecurity Disclosure Decision Makers

Establish a program to proactively test and regularly audit the effectiveness of cybersecurity measures.

SD-02-10 · Cybersecurity Assessment Program

Article 25 establishes the MEMBER STATE cybersecurity risk assessment - the third level of the four-level cascade. Member State competent authorities conduct national cybersecurity risk assessments for their in-scope electricity entities, building on the Union...

NCCS-Art.25_26 · Member State cybersecurity risk assessment (NCCS Articles 25-26) - third level of the cascade

Logging, monitoring, anomaly detection, and EDR with documented coverage and tuning.

FFIEC-CAT-CC-3 · Cybersecurity Controls - Detective Controls
ISO/SAE 2143416 controls

Cybersecurity validation confirms cybersecurity goals are achieved at item level under representative operating conditions.

21434-11 · Cybersecurity Validation

Questions people ask about cybersecurity

What is Cybersecurity?
The practice of protecting systems, networks, and programs from digital attacks that aim to access, change, or destroy sensitive information.
Why is Cybersecurity important for compliance?
Cybersecurity is a key concept in Information Security. Understanding cybersecurity helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Cybersecurity?
Cybersecurity appears in the requirement text of NIST Cybersecurity Framework 2.0, SEC Cybersecurity Disclosure Rule, TSA Pipeline Cybersecurity Directives, EU Network Code on Cybersecurity for the Electricity Sector, FFIEC Cybersecurity Assessment Tool (CAT). Across these standards we have identified 150 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Cybersecurity?
Explore our compliance framework pages to see how cybersecurity applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Cybersecurity applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.