Frameworks tracked in the briefing.
Every framework the briefing maps stories to in plain English. Open a card to see today’s news tagged with the rules your team owns.
HIPAA
US health-data privacy and security law. The Security Rule sets administrative, physical, and technical safeguards for ePHI; the Breach Notification Rule triggers HHS, media, and affected-individual reporting past the 500-record threshold; and the Privacy Rule governs uses and disclosures. Covered entities and business associates are both bound, with BAA chains extending accountability downstream. Attention spikes on ransomware affecting unencrypted ePHI and on a failed risk analysis under 45 CFR 164.308(a)(1)(ii)(A).
PCI-DSS
Payment Card Industry Data Security Standard, currently v4.0. Governs cardholder data inside the cardholder data environment, from point-of-sale to back-office processing. Merchants, processors, acquirers, and QSAs are all in scope, and v4.0 added explicit requirements on script integrity, web redirect hygiene, e-commerce 3DS, and targeted risk analyses. Attention is triggered by skimmer deployment, payment-script tampering, tokenization gaps, and any data-flow change that brings new systems into the CDE.
NIST CSF
NIST Cybersecurity Framework, currently 2.0 with the new Govern function. A voluntary framework that nonetheless becomes de-facto compliance language across many regulators and contract reviewers. Any organization that adopts it is on the hook for the control catalogue (Identify, Protect, Detect, Respond, Recover, plus Govern), and most revised regs (SEC cyber disclosure, NYDFS, HHS HPH proposed rule) now map directly into its subcategories. Attention lands on control gaps in PR.AC access control, DE.CM continuous monitoring, and RS.RP response planning.
SEC 8-K
SEC Form 8-K Item 1.05, the US material-cyber-incident disclosure rule for public companies. A four-business-day clock runs from materiality determination, not from incident detection, and the disclosure must describe the nature, scope, timing, and material impact of the incident along with remediation status. Attention is triggered by materiality-scope debates after a partial restoration, by incomplete remediation disclosures, by unnamed executive accountability for the response, and by the parallel discovery of related incidents that may in retrospect be material.
FTC Safeguards Rule
FTC Standards for Safeguarding Customer Information, updated under the GLBA rulemaking authority (16 CFR Part 314) to require financial institutions to maintain a comprehensive information security program. Applies to a broad swath of "financial institutions" — not just banks — including lenders, brokerages, and personal-finance apps. Attention is triggered by gaps in the designated qualified individual office, by 30-day notification deadlines for unauthorized acquisitions affecting 500+ consumers, by missing annual reporting to the board, and by an absent written incident response plan.
GLBA
Gramm-Leach-Bliley Act, the US umbrella for safeguarding nonpublic personal information held by financial institutions. Drives the Safeguards Rule (16 CFR Part 314) and the privacy notices regime; FTC and the federal banking regulators each enforce the parts that touch their jurisdiction. Attention is triggered by a vendor sharing of NPI without an opt-out hook, by missing opt-out disclosure on a privacy notice, by an unaccounted-for data-flow in a joint marketing arrangement, and by the failure to deliver an annual privacy notice to existing customers within the prescribed period.
CCPA / CPRA
California Consumer Privacy Act as amended by the California Privacy Rights Act, with enforcement shared by the California Privacy Protection Agency and the Attorney General. Carves out HIPAA/CMIA health data and GLBA-covered financial data, then captures everything else — employee, B2B, and consumer personal information. Attention is triggered by an unfulfilled consumer right-to-know or right-to-delete request, by a data-broker registration miss at the CPPA registry, by an unconsented sensitive personal information use, and by an opt-out signal that the front-end JS does not honor.
SOX
Sarbanes-Oxley Act, the US financial-reporting integrity statute. Section 404 places internal-control over financial reporting (ICFR) on the issuer, and a growing body of PCAOB and SEC commentary treats cyber controls over financial systems as part of ICFR. Attention is triggered by a material weakness disclosure on a 10-K Item 9A, by a restatement precipitated by an IT control failure, by an external-auditor finding on segregation of duties in a close-the-books system, and by a Form SD / supply-chain finding that touches a financially material vendor.
CMMC
Cybersecurity Maturity Model Certification, administered by the DoD to gate defense industrial base (DIB) contractors handling Federal Contract Information and Controlled Unclassified Information. CMMC 2.0 collapses the prior five levels to three (Level 1 self-attestation through Level 3 C3PAO assessment). Attention is triggered by a Level breakdown that lets the prime contractor lose flow-down eligibility, by an SPRS score that drops below the solicitation threshold, by a missing NIST SP 800-171 control assessment, and by an incident that requires a 72-hour cyber-incident reporting under DFARS 252.204-7012.
SOC 2
AICPA System and Organization Controls (SOC) 2, the US attestation standard for service organizations handling customer data. Reports cover security, availability, processing integrity, confidentiality, and privacy, with Trust Services Criteria maps. Attention is triggered by a qualified opinion on a Type II report, by an exception count that exhausts the AICPA materiality threshold, by a carved-out control the customer auditor flags, and by an off-cycle complementary-user-entity-controls (CUEC) gap that the customer cannot satisfy without internal changes.
NYDFS Part 500
New York Department of Financial Services 23 NYCRR Part 500, the US cybersecurity regulation for covered financial institutions operating under a DFS license. Drives the CISO designation, the 72-hour notification clock, the annual certification of compliance, and the risk-based program elements. Attention is triggered by late 72-hour notifications, by incomplete annual certifications on the prior calendar year, by missing third-party service provider security due-diligence, and by a Class A DFS-regulated entity that fails the multi-factor authentication or privileged-access-monitoring signal in 500.12.
FedRAMP
Federal Risk and Authorization Management Program, the US standard for cloud service offerings used by federal agencies. Drives the FedRAMP authorization baselines (Low, Moderate, High, and the emerging Li-SaaS) once an agency sponsor signs on. Attention is triggered by a Continuously Monitoring (ConMon) finding that flips a "Significant Change" condition, by an overdue annual assessment, by a Plan of Action & Milestone on an inherited baseline control, and by a 3PAO finding that pushes the agency sponsor toward a Revocation.
HITRUST
HITRUST CSF, the US certifiable framework that maps HIPAA, NIST SP 800-53, NIST CSF, and PCI-DSS into a single control set. Healthcare entities and their business associates pursue HITRUST r2 certification as the cross-walk attestation weight in third-party-risk reviews. Attention is triggered by a control that is marked "Partially Compliant" rather than "Fully Compliant" during the validated assessment, by a corrective action plan (CAP) that is open past the HITRUST SLA window, by a maturity score drop on PRISMA-based scoring, and by a HITRUST inheritance chain that breaks because a sub-provider’s certification was withdrawn.
Per-framework RSS feeds — public, citation-ready
Every framework has a public RSS feed at /feed/<slug> so GRC teams, blogs, and SIEM aggregations can subscribe and cite upstream coverage. The site-wide /feed/all feed lists the 50 most recent stories regardless of framework, and /feed/frameworks.xml indexes the full feed catalogue.