ELI5: What are Regulations and Frameworks?

Regulations are like traffic laws — the government says you must stop at red lights, and you’ll get a ticket if you don’t. Frameworks are more like a coach’s playbook — a set of best plays you can choose to follow to win the game. Companies use both: they have to follow the laws (regulations), and they choose proven playbooks (frameworks) to build a strong security program. Together, these give the company a clear set of instructions to keep data safe.

Overview

Regulations are legally binding requirements imposed by governments, while frameworks are structured best-practice guidelines that organizations adopt voluntarily or as part of contractual obligations. Together, they provide the blueprint for building and measuring a security program. The SY0-701 exam requires familiarity with major regulations and frameworks and when each applies.

Key Concepts

  • NIST Cybersecurity Framework (CSF) — Identify, Protect, Detect, Respond, Recover; voluntary, widely adopted in the US
  • NIST SP 800-53 — comprehensive catalog of security and privacy controls for federal systems
  • 27002 — international standard for information security management systems (ISMS); 27001 is certifiable
  • GDPR — EU regulation protecting personal data; applies to any org processing EU residents’ data; heavy fines
  • HIPAA — US law protecting health information (PHI); applies to covered entities and business associates
  • PCI DSS — payment card industry standard; required for any organization handling cardholder data
  • SOX (Sarbanes-Oxley) — US law requiring financial reporting integrity and internal controls
  • GLBA — US law requiring financial institutions to protect customer information
  • FERPA — US law protecting student education records
  • CIS Controls — prioritized list of cybersecurity best practices (formerly SANS Top 20)
  • CSA Cloud Controls Matrix (CCM) — cloud-specific security control framework
  • Benchmarks vs. frameworks — benchmarks are specific configuration guides; frameworks are broader programs
  • ISO 27701 — privacy information management extension to ISO 27001/27002
  • ISO 31000 — risk management framework and guidelines
  • SSAE SOC 2 — audit standard for service organizations covering security, availability, processing integrity, confidentiality, privacy
  • CSA (Cloud Security Alliance) — organization providing best practices for cloud security
  • CIS Benchmarks — prescriptive configuration guides for hardening systems
  • NIST RMF (Risk Management Framework) — 7-step process: Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor

Exam Tips

Remember

NIST CSF = voluntary framework, broad adoption. ISO 27001 = certifiable international standard. PCI DSS = mandatory for card data. HIPAA = healthcare. GDPR = EU data + right to be forgotten. Know which applies where.

Connections

  • Provides the external requirements that compliance programs must satisfy
  • Works alongside governance to shape internal security policies and standards
  • See also audits-and-assessments for how adherence to frameworks is verified

Practice Questions

Scenario

See case-regulations-and-frameworks for a practical DevOps scenario applying these concepts.