The PCI Security Standards Council has released a new information supplement titled "PCI DSS v4.x: Guidance for Compensating Controls and the Customized Approach" to help organizations …
FedRAMP has published Public Notice NTC-0012, which documents the outcome of Request for Comment (RFC-0031) concerning updated incident communications procedures. This notice formalizes the changes and …
PCI SSC has published the Secure Software Standard – Sensitive Asset Identification, a new standard for secure software development. This standard provides requirements for identifying and …
FedRAMP has renamed all 'FedRAMP Authorization' designations to 'FedRAMP Certification' and replaced impact level designations with a new classification system using classes A, B, C, and …
FedRAMP has published NOTICE-0010 as an official response to CISA V1: ED 25-03. This notice provides FedRAMP's position and guidance on how the CISA directive applies …
FedRAMP has added RFC-0031 Updated Incident Communications Procedures to its compliance framework. This new procedure updates how cloud service providers must communicate security incidents to government …
FedRAMP has published NOTICE-0009 detailing the initial outcome of RFC-0024 concerning FedRAMP Rev5 machine-readable packages, and released information about the FedRAMP Cybersecurity Service. This notice provides …
FedRAMP has published five new Requests for Comments (RFCs 0026-0030) related to Rev5 updates and improvements. These RFCs provide guidance on proposed changes to the FedRAMP …
FedRAMP published a public notice with the initial outcome of RFC-0023 Rev5 regarding Program Certifications that do not require a sponsor. This update reflects FedRAMP's evolving …
PCI Security Standards Council has published new guidance on Mobile Point of Contact (MPoC) requirements. This guidance clarifies expectations for organizations handling mobile payment transactions and …
FedRAMP has published a public notice outlining the initial outcomes of RFC-0022, which addresses the use of external security frameworks within the FedRAMP authorization process. This …
CISA has published a public notice for Emergency Directive 26-03. This announcement makes the directive publicly available for federal agencies and contractors using federal information systems. …
PCI Security Standards Council has updated the PIN Security Requirements and Testing Procedures document. This update addresses current security practices and testing methodologies for PIN protection …
PCI Security Standards Council has published Derivative Test Requirements. This document provides guidance on testing procedures for derivative implementations of PCI standards. The requirements establish baseline …
PCI SSC has published the Point of Interaction (POI) Modular Security Requirements along with a summary of changes document. This new guidance provides modular security requirements …
PCI SSC has published the Point of Interaction (POI) Modular Security Requirements standard. This document establishes security requirements for systems and devices that handle payment transactions …
PCI Security Standards Council has published Card Production and Provisioning Physical Security Requirements as a new standard to establish physical security controls for card production and …
PCI SSC has published the Card Production and Provisioning Logical Security Requirements, a new standard addressing security controls for logical systems involved in card production and …
PCI Security Standards Council has published the Case First PIN guidance document. This resource provides guidance on implementing PIN (Personal Identification Number) security measures with a …
PCI SSC has published the Secure Software Standard, establishing requirements for organizations developing and managing software to ensure security throughout the development lifecycle. This standard applies …
The European Commission has proposed a new regulation (Cybersecurity Act 2) to replace the current Regulation (EU) 2019/881 on ENISA and cybersecurity certification. The proposal aims …
The European Commission has proposed amendments to Directive (EU) 2022/2555 (NIS 2 Directive) to introduce simplification measures and ensure alignment with the proposed Cybersecurity Act 2. …
The European Commission proposes amendments to the medical device regulations (MDR and IVDR) aimed at simplifying rules and reducing the compliance burden for manufacturers and competent …
FedRAMP has released updates to certain revision 5 templates. These updates reflect refinements to the compliance and assessment documentation requirements for cloud service providers operating under …