Regulatory Change
What is Regulatory Change?
A modification to existing regulations or introduction of new regulations that may affect an organization's compliance obligations.
Terms that appear alongside regulatory change
Each of these is named in at least one of the same controls as regulatory change. The number is how many controls name both.
- policy 4 shared controls
- lessons learned 4 shared controls
- nist 4 shared controls
- continuous improvement 2 shared controls
- benchmarking 2 shared controls
- audit 2 shared controls
- access control 2 shared controls
- change management 2 shared controls
Frameworks that govern regulatory change
What the standards actually require on regulatory change
Requirements naming regulatory change across 6 standards, quoted from the control text.
Establish cybersecurity governance and policy structures appropriate to retail industry characteristics per the NRF Cybersecurity and Data Privacy Framework guidance and supporting NIST CSF alignment.
NRFCS-1 · Retail Cybersecurity Governance, Policy, and Regulatory Change Management →Have subject matter experts review the security policies and instructions for adequacy at least once a year, weighing organisational and technical changes in how the cloud service is delivered and legal or regulatory change, and approve revised versions before...
C5-SP-02 · Review and Approval of Policies and Instructions →ISMAP Assessment positions ISMAP within the comprehensive Japanese and international cloud security regulatory landscape. (1) External Assessment by ISMAP-Approved Auditor: CSP must undergo annual third-party assessment by ISMAP-approved audit organisation inc...
ISMAP-Assessment-ExternalAuditor-AnnualReview-CustomerTransparency-Coord-FedRAMP-IRAP-GCloud-PIPA-ISO27017 · ISMAP Assessment - External ISMAP-Approved Auditor + Annual Review + Customer Information and Transparency + Coordination FedRAMP/UK G-Cloud/Australia IRAP/Singapore MTCS + ISO 27017 + PIPA + Japan Digital Agency →Defines events that trigger information updates, such as maintenance activities, renovations, and regulatory changes.
ISO-19650-3-5.3 · Trigger events for information exchange →Monitor privacy risks continuously through KRIs, incident data, regulatory changes, and processing changes.
ISO27557-9.1 · Privacy Risk Monitoring →Address Mandatory Criterion 5 of Modern Slavery Statement under Section 16(1)(e) - describe how reporting entity assesses effectiveness of actions to assess and address modern slavery risks.
AU-MSA-Mandatory-Criterion-5-Effectiveness-Section-16-1e-Assurance-KPIs-Continuous-Improvement · Australia MSA Mandatory Criterion 5 + Effectiveness + Section 16(1)(e) + Independent Assurance + KPIs + Continuous Improvement →Questions people ask about regulatory change
What is Regulatory Change?
Why is Regulatory Change important for compliance?
Which compliance frameworks address Regulatory Change?
Where can I learn more about Regulatory Change?
See how Regulatory Change applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.