


Information Security Resources
USA
Federal Laws and Regulations
Industry News
Industry Standards
-
Higher Education Information Security Council
Federal Laws & Regulations
USA
The following are federal laws and regulations that relate to information resources security and privacy.
Industry News
USA
The following Web Sites offers News and Articles related to Information Security.
Industry Standards
USA
The following organizations offer requirements for establishing and maintaining an information security program. These standards are periodically reviewed, revised, and updated. It is critical that the most current version of a published standard be used or referenced.
Higher Education Information Security Council (HEISC)
The HEISC mission is to support and enhance higher education institutions as they improve information security governance, compliance, data protection, and privacy programs.
Professional Organizations
USA
The following organizations offer certifications, conferences, and other resources for information security professionals.
-
Center for Education and Research in Information Assurance and Security
-
Indiana University Center for Applied Cybersecurity Research
-
Markle Foundation Task Force on National Security in the Information Age
-
National Information Assurance Training and Education Center
-
National Institute of Standards and Technology (NIST) Computer Security Resource Center
-
US Department of Justice Computer Crime and Intellectual Property Section
Regulatory Entities
USA
The following entities regulate laws related to information resources security and privacy.
Information Security Resources
FRANCE
ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information):
-
Website: ANSSI / https://cyber.gouv.fr/
CERT-FR (Computer Emergency Response Team for France):
-
Website: CERT-FR / https://www.cert.ssi.gouv.fr/
CLUSIF (Club de la Sécurité de l'Information Français):
-
Website: CLUSIF
OSSIR (Observatoire de la Sécurité des Systèmes d'Information et des Réseaux):
-
Website: OSSIR
CNIL (Commission Nationale de l'Informatique et des Libertés):
-
Website: CNIL
CEIS (Compagnie Européenne d'Intelligence Stratégique):
-
Website: CEIS
ACN (Alliance pour la Confiance Numérique):
-
Website: ACN / https://www.confiance-numerique.fr/
CIGREF (Club Informatique des Grandes Entreprises Françaises):
-
Website: CIGREF / https://www.cigref.fr/
Hexatrust:
-
Website: HEXATRUST / https://www.hexatrust.com/a-propos/
FFIEC (Fédération Française pour les Études et la Certification en Sécurité des Systèmes d'Information):
-
Website: FFIEC / https://www.ffiec.gov/
CYBERZEN (Centre de Cyberdéfense et de Sécurité des Systèmes d'Information):
-
Website: CYBERZEN / https://www.cyberzen.com/
Industry News
FRANCE
The following Web Sites offers News and Articles related to Information Security.
Industry Standards
FRANCE
The following organizations offer requirements for establishing and maintaining an information security program. These standards are periodically reviewed, revised, and updated. It is critical that the most current version of a published standard be used or referenced.
ANSSI's Security Recommendations:
-
Website: ANSSI / https://cyber.gouv.fr/
RGS (Référentiel Général de Sécurité):
-
Website: RGS / https://cyber.gouv.fr/le-referentiel-general-de-securite-rgs
PSSIE (Politique de Sécurité des Systèmes d'Information de l'État):
-
Website: PSSIE / https://cyber.gouv.fr/publications/pssi-guide-delaboration-de-politiques-de-securite-des-systemes-dinformation
LPM (Loi de Programmation Militaire):
ISO/IEC 27001:
-
Website: ISO/IEC 27001 / https://www.iso.org/fr/standard/27001
PCI DSS (Payment Card Industry Data Security Standard):
-
Website: PCI DSS / https://www.pcisecuritystandards.org/standards
RGPD (Règlement Général sur la Protection des Données):
-
The General Data Protection Regulation (GDPR) is enforced in France, establishing stringent standards for data protection and privacy.
-
Website: GDPR / https://www.cnil.fr/fr/reglement-europeen-protection-donnees
NIS Directive (Network and Information Systems Directive):
-
Transposed into French law, this directive aims to achieve a high common level of security for network and information systems across the EU.
-
Website: NIS Directive / https://cyber.gouv.fr/la-directive-nis-2
HDS (Hébergement de Données de Santé):
-
Specific to healthcare, HDS certification ensures that providers of health data hosting services meet high security and privacy standards.
-
Website: HDS / https://esante.gouv.fr/produits-services/hds
EBIOS (Expression des Besoins et Identification des Objectifs de Sécurité):
-
A French risk management methodology used to identify and assess cybersecurity risks.
-
Website: EBIOS / https://cyber.gouv.fr/la-methode-ebios-risk-manager
SecNumCloud:
-
A certification scheme for cloud service providers to ensure they meet French security requirements.
-
Website: SecNumCloud / https://cyber.gouv.fr/secnumcloud-pour-les-fournisseurs-de-services-cloud
Higher Education Information Security
Renater CERT (Computer Emergency Response Team):
-
Website: Renater CERT / https://www.renater.fr/securite/le-cert-renater/
ANSSI Guidelines:
-
Website: ANSSI / https://cyber.gouv.fr/
RGS (Référentiel Général de Sécurité):
EBIOS (Expression des Besoins et Identification des Objectifs de Sécurité):
-
Website: EBIOS / https://www.enisa.europa.eu/topics/risk-management/current-risk/risk-management-inventory/rm-ra-methods/m_ebios.html
ISO/IEC 27001:
-
Website: ISO/IEC 27001 / https://www.iso.org/fr/standard/27001
GDPR (General Data Protection Regulation):
-
Website: GDPR
SecNumCloud:
-
A certification for cloud service providers meeting French security requirements. Higher education institutions using cloud services ensure compliance with this standard.
-
Website: SecNumCloud / https://cyber.gouv.fr/secnumcloud-pour-les-fournisseurs-de-services-cloud
NIS Directive (Network and Information Systems Directive):
-
Transposed into French law, this directive aims to improve the cybersecurity of network and information systems across the EU, including higher education.
-
Website: NIS Directive
ITIL (Information Technology Infrastructure Library):
-
Many higher education institutions implement ITIL practices for effective IT service management and aligning IT services with institutional needs.
-
Website: ITIL
HDS (Hébergement de Données de Santé):
-
For higher education institutions involved in health research, HDS certification ensures compliance with high security and privacy standards for hosting health data.
-
Website: HDS / https://esante.gouv.fr/produits-services/hds
Professional Organizations
FRANCE
France has several professional organizations dedicated to cybersecurity, each focusing on various aspects such as research, best practices, industry collaboration, and awareness. Here are some of the key professional cybersecurity organizations in France:
ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information):
-
Website: ANSSI
CLUB EBIOS:
-
Website: CLUB EBIOS
CLUSIF (Club de la Sécurité de l'Information Français):
-
Website: CLUSIF
OSSIR (Observatoire de la Sécurité des Systèmes d'Information et des Réseaux):
-
Website: OSSIR
ACN (Alliance pour la Confiance Numérique):
-
Website: ACN
CESIN (Club des Experts de la Sécurité de l'Information et du Numérique):
-
Website: CESIN
Hexatrust:
-
Website: Hexatrust
CIGREF (Club Informatique des Grandes Entreprises Françaises):
-
Website: CIGREF
AFCDP (Association Française des Correspondants à la protection des Données à caractère Personnel):
-
Website: AFCDP
FNTC (Fédération Nationale des Tiers de Confiance):
-
Website: FNTC
CERT-FR (Computer Emergency Response Team for France):
-
Website: CERT-FR
Regulatory Entities
FRANCE
In France, several regulatory entities are responsible for overseeing and implementing cybersecurity policies, regulations, and standards. These entities ensure the security of information systems across various sectors, from government to private industry. Here are the key regulatory entities for cybersecurity in France:
ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information):
-
Website: ANSSI
CNIL (Commission Nationale de l'Informatique et des Libertés):
-
Website: CNIL
ARCEP (Autorité de Régulation des Communications Électroniques, des Postes et de la Distribution de la Presse):
-
Website: ARCEP
ACN (Autorité de Contrôle Prudentiel et de Résolution):
-
Website: ACPR
DGSI (Direction Générale de la Sécurité Intérieure):
-
Website: DGSI
DGE (Direction Générale des Entreprises):
-
Website: DGE
ANSM (Agence Nationale de Sécurité du Médicament et des Produits de Santé):
-
Website: ANSM
HAS (Haute Autorité de Santé):
-
Website: HAS
Ministry of Armed Forces (Ministère des Armées):
-
Website: Ministry of Armed Forces
CERT-FR (Computer Emergency Response Team for France):
-
Website: CERT-FR
Federal Laws & Regulations
FRANCE
The following are federal laws and regulations that relate to information resources security and privacy.
General Data Protection Regulation (GDPR):
-
Website: GDPR
Loi pour une République numérique (Digital Republic Act):
-
Website: Digital Republic Act
LCEN (Loi pour la Confiance dans l'Économie Numérique):
-
Website: LCEN
RGS (Référentiel Général de Sécurité):
-
Website: RGS
Loi Informatique et Libertés (Data Protection Act):
-
Website: Data Protection Act
Cybersecurity Act (Loi de Programmation Militaire):
-
Website: Cybersecurity Act
Loi Hadopi:
-
Website: Loi Hadopi
NIS Directive (Directive on Security of Network and Information Systems):
-
Website: NIS Directive
E-IDAS Regulation:
-
Website: E-IDAS
Code de la Consommation (Consumer Code):
-
Website: Consumer Code
Laws and Regulations
FRANCE
These laws and regulations form a comprehensive legal framework to protect information systems, ensure data privacy, and promote cybersecurity resilience in France.
Loi pour la Confiance dans l'Économie Numérique (LCEN)
-
Website: LCEN
Loi de Programmation Militaire (LPM)
-
Website: LPM
Loi Informatique et Libertés
-
Website: Loi Informatique et Libertés
RGS (Référentiel Général de Sécurité)
-
Website: RGS
RGPD (Règlement Général sur la Protection des Données)
-
Website: GDPR
NIS Directive (Network and Information Systems Directive)
-
Website: NIS Directive
E-IDAS Regulation
-
Website: E-IDAS
Cybersecurity Act
-
Website: Cybersecurity Act
HDS (Hébergement de Données de Santé)
-
Website: HDS
Digital Republic Act (Loi pour une République numérique)
-
Website: Digital Republic Act