ZenGRC

Infosec Standards and Regulations: A Primer

The article uses the Hogwarts houses as a metaphor to categorize information security standards and regulations, describing Gryffindor as courageous, free-guidance frameworks like NIST and OWASP; Slytherin as ambitious, paid compliance standards like ISO; and implying other houses represent different infosec philosophies and approaches.

Sorting infosec standards and regulations into Hogwarts houses may seem whimsical, but the analogy helps categorize the different approaches and philosophies behind various standards and regulations. The Hogwarts Houses—Gryffindor, Slytherin, Hufflepuff, and Ravenclaw—each represent distinct traits, which can be mapped to the organizations and frameworks that shape information security compliance.

Categorizing Infosec Standards and Regulations Using Hogwarts Houses

The Gryffindors of Infosec Standards and Regulations

Gryffindor values courage, bravery, and determination. In the context of infosec, Gryffindor-like organizations bravely lead the charge in security, providing guidance and best practices to make the world more cybersafe.

  • NIST: The National Institute of Standards and Technology publishes its Cybersecurity Framework for free, offering guidance rather than punishment. The NIST 800-53 and the Framework Core provide organizations with a way to organize best practices without significant upfront costs.

  • Security Policy Framework UK: Published by the UK Cabinet Office and related agencies, this document guides the protection of government assets through twenty mandatory requirements across seven areas, including governance, risk management, information security, and business continuity.

  • OWASP: The Open Web Application Security Project is an open international community focused on developing trusted applications. While less about compliance and more about resources, OWASP's peer-driven standards and frameworks are innovative and provide valuable guidance.

The Slytherins of Infosec Standards and Regulations

Slytherin is associated with pride, ambition, and cunning. This category includes standards and frameworks that are respected but require payment for compliance, reflecting ambition and monetization.

  • ISO: The International Organization for Standardization offers widely recognized standards like ISO/IEC 27000. The prescriptive nature of these standards means access to the documents is necessary for compliance, and ISO has built a business around this expertise.

  • COBIT: Created by ISACA, the Control Objectives for Information Related Technology (COBIT) framework bridges business needs and technical issues. It breaks down processes into domains and offers maturity models for business growth.

  • COSO: The Committee of Sponsoring Organizations of the Treadway Commission developed frameworks for internal control and enterprise risk management. These frameworks identify components and objectives for effective risk management and control.

The Hufflepuffs of Infosec Standards and Regulations

Hufflepuff values hard work, patience, loyalty, and fair play. Industry-specific guidelines that support their communities fit this house.

  • HITRUST: The Health Information Trust Alliance provides baselines for the healthcare industry, allowing HIPAA-covered entities to tailor programs through the Common Security Framework. HITRUST aims to support its community with broad access to risk and compliance frameworks.

  • PCI-DSS: The Payment Card Industry Data Security Standard is the compliance standard for payment processors. It requires vendors to assess risk, map networks, and follow industry-specific guidelines, offering resources like lists of approved assessors and devices.

The Ravenclaws of Infosec Standards and Regulations

Ravenclaw values wit, learning, and wisdom. Regulations that emphasize factual correctness, accountability, and the rule of law fit this house.

  • SOX: The Sarbanes-Oxley Act was enacted to address corporate fraud. Section 404 requires businesses to evaluate IT environments for financial reporting risks and controls, with conclusions published in SEC filings.

  • GDPR: The General Data Protection Regulation establishes a single set of rules for EU member states and expands scope to organizations handling EU resident data. It emphasizes accountability, governance, and data protection principles.

  • HIPAA: The Health Insurance Portability and Accountability Act requires administrative, physical, and technical safeguards to protect health information, with regulatory requirements for businesses handling such data.


How do you think we fared sorting the infosec standards and regulations into houses? Do you agree with our assessment? What would you suggest be added?