What each one actually is, why it exists, and which industry it covers, in plain terms, not legal language.
CIS Amazon Web Services Foundations Benchmark
AWS's default account settings alone don't guarantee a secure configuration. CIS brings together security practitioners to agree on a prescriptive, vendor-neutral baseline, specific IAM, logging, networking, and monitoring settings, that represent a reasonable security floor for any AWS account.
Read morePayment Card Industry Data Security Standard
To reduce credit card fraud by giving every business that touches payment card data a common set of technical and operational security requirements, rather than leaving each card brand to set its own rules.
Read moreSystem and Organization Controls 2
To give a service organization's customers and partners independent, CPA-audited assurance that its controls around security, availability, processing integrity, confidentiality, and privacy actually work, without each customer having to audit the vendor themselves.
Read moreISO/IEC 27001 Information Security Management
To give organizations of any size or sector a systematic, internationally recognized framework, an Information Security Management System (ISMS), for identifying, treating, and continually improving how they manage information security risk.
Read moreGeneral Data Protection Regulation
To give individuals in the EU/EEA real rights over their personal data (access, correction, erasure, portability) and to force any organization processing that data to justify why, secure it properly, and report breaches quickly.
Read moreHealth Insurance Portability and Accountability Act
To protect the privacy and security of individuals' health information while still allowing it to flow where it's legitimately needed, between providers, insurers, and the systems that keep healthcare running.
Read moreNIST Special Publication 800-53: Security and Privacy Controls
Originally built to secure US federal information systems under FISMA. It has since become the reference control catalog that other frameworks, including FedRAMP, build on, because it's exhaustive, regularly maintained, and free to use.
Read moreDigital Operational Resilience Act
Financial services now run almost entirely on digital infrastructure, including cloud providers who are themselves outside financial regulators' direct reach. DORA harmonizes ICT risk management, mandatory incident reporting, resilience testing, and, notably, direct oversight of critical third-party ICT providers across the EU financial sector.
Read moreFederal Financial Institutions Examination Council
To give US banking regulators, and the institutions they examine, a consistent, repeatable way to assess technology and cybersecurity risk across the banking system, instead of every examiner improvising their own standard.
Read moreKloudSec, built by the team behind Toc Consulting
What you just read is a manual, one-time check. KloudSec runs this and 400+ more automated checks across 90+ AWS services, continuously, agentless, live in about 5 minutes.