01 — The frameworks
What applies to you, and why.
Highlighted cards are our core practice areas. Most organizations answer to two or three of these at once, which is why we assess each on its own terms and use the overlap so you never do the same work twice.
Healthcare · Federal regulation
HIPAA
45 CFR Part 164 · Security, Privacy & Breach Notification Rules
Requires safeguards for patient information, starting with an accurate, organization-wide risk analysis. Some safeguards are "required"; others are "addressable", meaning you implement them or document why an alternative is reasonable.
- Applies to
- Providers that bill electronically, health plans, clearinghouses, and their business associates
Payments · Industry standard
PCI DSS
Payment Card Industry Data Security Standard v4.0.1
Twelve requirement areas protecting cardholder data. Most small merchants validate annually through a self-assessment questionnaire (SAQ). Choosing the right one depends on how you take payments.
- Applies to
- Any business that stores, processes or transmits card data, through its acquirer agreement
All sectors · Voluntary framework
NIST CSF
NIST Cybersecurity Framework 2.0
Six functions (Govern, Identify, Protect, Detect, Respond, Recover) that give boards and staff a shared language. It's our default lens for local government and for board reporting.
- Applies to
- Anyone; widely used by public-sector and critical-infrastructure organizations
Credit unions · Federal regulation
NCUA
12 CFR Part 748 · ACET
Requires a written information security program, board oversight and member-notice procedures, plus reporting of cyber incidents to NCUA within 72 hours. Examiners review it during information security examinations.
- Applies to
- Federally insured credit unions
Education · Federal law
FERPA
20 U.S.C. § 1232g · 34 CFR Part 99
Protects student education records and limits disclosure. Ed-tech vendors typically get access under the "school official" exception, which makes data sharing agreements essential.
- Applies to
- Schools and districts receiving U.S. Department of Education funds
Pennsylvania · State law
PA BPINA
Breach of Personal Information Notification Act
Pennsylvania's breach notification law. Amendments in 2024 added Attorney General notice and credit-monitoring requirements in certain breaches.
- Applies to
- Organizations holding personal information of Pennsylvania residents, including public entities
Pennsylvania · Commonwealth policy
ITP-SEC023
Commonwealth IT policy on technical security assessments
Requires independent, third-party technical security assessments for agencies supporting critical functions, and for vendors that serve them.
- Applies to
- Commonwealth agencies and their vendors and contractors
Global · Certifiable standard
ISO 27001
ISO/IEC 27001:2022
An international standard for an information security management system, certified by an accredited body. Usually driven by customers who require certification.
- Applies to
- Voluntary; common for service providers selling to larger enterprises
Service providers · Attestation
SOC 2
AICPA Trust Services Criteria
A CPA firm's report on a service organization's controls. We provide readiness: getting your controls and evidence in shape before the auditor arrives.
- Applies to
- Voluntary; often requested of MSPs and software vendors