Cybersecurity & Infrastructure Security Agency — the nation's cyber defense agency.
Payment Card Industry Data Security Standard v4.0 — mandatory for all entities handling cardholder data.
Health Insurance Portability and Accountability Act — federal law protecting patient health information.
FTC Safeguards Rule — requires non-banking financial institutions to implement information security programs.
Cybersecurity Maturity Model Certification — required for DoD contractors handling CUI or FCI.
Center for Internet Security Controls v8.1 — prescriptive, prioritized set of security best practices.
National Institute of Standards and Technology — the gold standard for cybersecurity frameworks and SP 800-series publications.
Direct links to CISA's current alert channels and news streams. Updated continuously by CISA.