Industry-Specific Compliance
Guide to industry-specific compliance frameworks including NERC CIP for energy, FERPA for education, DFARS for defense contractors, and more. Understand sector-specific requirements and implementation.
CJIS
CJIS Security Policy: Criminal Justice Information Security Guide
The CJIS Security Policy governs access to FBI criminal justice data. This guide covers authentication, encryption, personnel security, and compliance requirements for agencies and technology vendors.
Learn moreCOPPA
COPPA: Children's Online Privacy Protection Guide
COPPA regulates the online collection of personal information from children under 13. This guide covers consent mechanisms, privacy policies, FTC enforcement, and compliance for apps, games, and websites.
Learn moreDFARS
DFARS: Defense Federal Acquisition Regulation Supplement Guide
DFARS cybersecurity requirements mandate protection of Controlled Unclassified Information in the defense supply chain. This guide covers NIST 800-171, CMMC 2.0, and compliance for defense contractors.
Learn moreEAR
EAR: Export Administration Regulations Guide
The EAR control exports of dual-use items, software, and technology from the United States. This guide covers ECCN classification, license requirements, screening obligations, and compliance for technology companies.
Learn moreFERPA
FERPA: Education Data Privacy Compliance Guide
FERPA protects the privacy of student education records in the United States. This guide covers consent requirements, directory information, vendor obligations, and compliance for educational institutions and EdTech.
Learn moreIEC 62443
IEC 62443: Industrial Automation Cybersecurity Guide
IEC 62443 is the global standard for industrial automation and control system cybersecurity. This guide covers security levels, zones and conduits, roles, certification, and OT security implementation.
Learn moreISO 21434
ISO 21434: Automotive Cybersecurity Engineering Guide
ISO 21434 establishes cybersecurity engineering requirements for road vehicles. This guide covers TARA methodology, cybersecurity management systems, UNECE compliance, and implementation for OEMs and suppliers.
Learn moreISO 27799
ISO 27799: Health Informatics Security Management Guide
ISO 27799 provides health-sector-specific guidance for implementing ISO 27001. This guide covers health data security, patient privacy controls, clinical system protection, and implementation alongside ISO 27001.
Learn moreITAR
ITAR: International Traffic in Arms Regulations Guide
ITAR controls the export of defense articles, services, and technical data. This guide covers USML classification, licensing, technology control plans, and compliance for defense industry companies.
Learn moreNERC CIP
NERC CIP: Critical Infrastructure Protection for Energy
NERC CIP standards protect North America's bulk electric system from cyber threats. This guide covers BES asset categorization, electronic security perimeters, compliance requirements, and enforcement.
Learn more