Security professionals must work within the law. Understanding the legal landscape keeps you, and your organisation, on the right side of it.
Compliance Frameworks
The standards and regulations that shape security.
Tap or hover a part to learn more.
ISMS standard.
An international standard for an Information Security Management System (ISMS) — a risk-based, auditable framework organisations get certified against.
Check your understanding
1. What is ISO 27001?
2. Is compliance the same as security?
Keep learning
Key areas
- Computer misuse laws — unauthorised access is illegal; security testing needs explicit written authorisation (scope matters — this is the line between pen testing and crime).
- Data protection — GDPR/UK GDPR governs personal data, with breach notification duties (often 72 hours) and significant fines (GRC).
- Sector regulation — PCI DSS (cards), HIPAA (US health) and others impose specific duties.
- Evidence & admissibility — proper forensics and chain of custody matter if a case goes legal.
Ethics and legality are inseparable in security — "can I?" is a different question from "am I allowed to?".
