HIPAA Security Rule
Baseline cybersecurity obligation for covered entities and business associates that create, receive, maintain, or transmit ePHI.
Cybersecurity resource map
Browse by industry first, then jump to the relevant laws, standards, controls, official guidance, free training, and reporting resources.
01
Baseline cybersecurity obligation for covered entities and business associates that create, receive, maintain, or transmit ePHI.
Healthcare-sector threat briefings, practice guides, and operational resources for hospitals, clinics, providers, and health partners.
Healthcare-specific CISA resources plus cross-sector goals that help prioritize minimum viable cyber defense practices.
02
Start here for federal contract information, covered defense information, cyber incident reporting, and NIST SP 800-171 assessment clauses.
Official DoD CMMC resource library for model guidance, scoping guides, assessment guides, and program references.
Core CUI control requirements and assessment procedures used by defense contractors and other nonfederal organizations handling CUI.
DISA STIG baselines and government training resources for teams implementing defense-sector security requirements.
03
Federal systems typically start with risk management, impact categorization, and minimum security requirements.
Federal control catalog used for security and privacy controls, baselines, assessment planning, and framework mappings.
Authorization resources for cloud services used by federal agencies and federal data environments.
Acquisition and policy references that often sit next to technical control work in federal cybersecurity programs.
04
Information security management standards for ISMS requirements, control selection, and security program governance.
Cloud assurance resources for provider transparency, questionnaire mapping, and cloud-specific control coverage.
Configuration hardening baselines for cloud platforms, operating systems, network devices, containers, and SaaS environments.
Application verification, API security, and secure development references for cloud-delivered products.
05
Supervisory resources for financial institutions, third-party technology risk, cloud, authentication, exercises, and resilience planning.
Security program obligations for covered financial institutions under FTC jurisdiction and related customer information safeguards.
EU digital operational resilience references for financial entities with ICT risk, incident reporting, testing, and third-party exposure.
06
Cross-sector baseline security practices for critical infrastructure owners and operators.
Free industrial control system cybersecurity training and CISA resources for operational technology defenders.
Reliability standards for bulk electric system cybersecurity and electric-sector security operations.
CISA and federal reporting entry points for critical infrastructure incidents, vulnerabilities, phishing, malware, and ransomware.
07
Security and privacy references for K-12, higher education, student records, cloud services, and education data handling.
Cybersecurity coordination, alerts, and shared services for public-sector organizations outside the federal enterprise.
References for law enforcement cybercrime reporting, public safety awareness, and criminal justice information security.
08
Common application risks, verification requirements, developer guidance, and API security references.
Developer-focused cheat sheets and weakness lists for authentication, authorization, crypto, logging, and secure coding review.
Secure software development practices for organizing requirements, implementation, verification, release, and response work.
09
Practical cybersecurity basics for smaller organizations, general staff awareness, and non-specialist leadership.
Prioritized controls, hardening benchmarks, templates, and practitioner resources that apply across most industries.
10
Government-wide and DoD training for recognizing, marking, safeguarding, decontrolling, destroying, and reporting CUI incidents.
No-cost cybersecurity training, workforce development courses, and searchable learning paths.
Free and low-cost cybersecurity learning content aligned to workforce development and practitioner growth.
11
U.S. and Canada cyber agencies, standards, cybercrime reporting, and national cybersecurity guidance.
Pacific and Asia-Pacific national cyber agencies and CERTs for advisories, reporting, and regional guidance.
Latin America and Caribbean coordination, CSIRT networks, and national incident response resources.
EU cybersecurity agency, institutional CERT, cybercrime support, and resilience regulation references.
12
Federal cybersecurity advisories and known exploited vulnerabilities for remediation prioritization.
Vulnerability records, identifiers, scoring references, and adversary technique knowledge base.
Product-specific update portals for tracking security releases and remediation guidance.
Cybercrime, identity theft, and ransomware reporting or recovery resources for public-facing support situations.