NIST has published Revision 3 of Special Publication 800-171A, which provides guidance for assessing security requirements for Controlled Unclassified Information (CUI) and includes a dedicated small…
Latest changes
Watching 52 official sources · all on schedule · last checked 10 minutes ago
CISA released new guidance titled "Using Cyber Decoys to Strengthen Detection and Response" to help critical infrastructure owners and operators implement cyber decoy systems that detect and disrupt …
The PCI Security Standards Council has published a new information supplement addressing security considerations for artificial intelligence systems. The document covers both the security aspects of …
The National Bank of Ukraine has made changes to the decision of the Board of the National Bank of Ukraine dated January 3, 2017 No. 2-рш. The update is published in the NBU's legal and regulatory ba…
CISA and NIST released Interagency Report (IR) 8587 providing comprehensive guidelines for federal agencies and cloud service providers to defend identity tokens and assertions used in single sign-on…
The PCI Security Standards Council has published the new PCI Key Management and Operations (KMO)™ Standard v1.0, establishing security and test requirements for entities managing cryptographic key sy…
CIS Security published updates to 19 CIS Benchmarks in September 2026, including significant revisions to Windows Server 2022, Windows 11, Windows Server 2025, Apache Tomcat, PostgreSQL, Chrome, Chro…
The French Data Protection Authority (CNIL) issued an administrative fine of €300,000 to EXTIA on 21 July 2026 for breaches of Articles 12 and 17 of the GDPR concerning data subject rights. Of 265 er…
As of 11 September 2026, Article 14 of the Cyber Resilience Act (EU Regulation 2024/2847) becomes applicable in the EU, establishing horizontal cybersecurity requirements for products with digital el…
The French Data Protection Authority (CNIL) fined Hôpital Privé de la Loire 500,000 EUR for GDPR violations following a summer 2025 data breach that exposed the personal and health data of 524,867 pa…
CISA released an updated version of its Insider Threat Mitigation Guide, originally published in 2020, to address evolving threats in the modern operational landscape. The updated guide includes new …
FedRAMP has opened 2 new Requests for Comment. This provides an opportunity for stakeholders to review and provide feedback on proposed changes or policies. Participants should submit their comments …
The European Commission proposes a new Public Procurement Act that consolidates the three 2014 procurement directives (2014/23/EU, 2014/24/EU, and 2014/25/EU) into a single regulation and amends mult…
The Data Protection Commission has issued a final decision against the Health Service Executive (HSE) following an inquiry into two unauthorised access incidents to paper medical records stored in ex…
The French Data Protection Authority (CNIL) fined MOBIUS SOLUTIONS LTD €1 million on 11 December 2025 following a data breach notification from DEEZER in November 2022 that exposed over 46 million us…
The CNIL fined NEXPUBLICA FRANCE €1.7 million for breaching Article 32 of the GDPR by failing to implement adequate technical and organizational security measures for its PCRM software used in social…
The CNIL issued combined fines of €42 million against FREE MOBILE and FREE following a January 2026 decision regarding an October 2024 data breach that exposed personal data of 24 million subscriber …
France Travail, a French public employment service, was fined €5 million by CNIL for inadequate technical and organisational security measures that failed to prevent a 2024 data breach. Hackers explo…
CISA has published the Logging Reference Architecture, an outcome-driven guide developed with OMB and the CISO Council to help federal civilian executive branch (FCEB) agencies establish enterprise l…
The UK National Cyber Security Centre (NCSC) has published official scheme documents for the Cyber Adversary Simulation (CyAS) program. These documents establish NCSC's expectations for how assured p…
The government adopted Resolution No. 1009, which changes the logic of ensuring resilience of state information systems and strengthens requirements for backup and protection of state information res…
CISA released the K-12 Cybersecurity Foundations Resource Package on August 12, 2026, providing guides, videos, and supplemental materials to help K-12 schools and districts prevent and respond to cy…
CIS Security published six updated benchmarks in August 2026 covering database, firewall, and network switch security. The CIS Microsoft Azure Database Services Benchmark v2.0.0 added 20 recommendati…
The NCSC has added new guidance featuring a water sector example to its Secure Connectivity Principles. This is the first content authored by the Industrial Control System Community of Interest to be…
The bill proposes amendments to Article 4 of the Law of Ukraine 'On Basic Principles of Ensuring Cybersecurity of Ukraine' to expand the definition of critical infrastructure enterprises. This provid…