CyberClaw Learn

Learn before you engage

Plain-language guides for business owners and teams preparing for security testing or compliance work.

🛡️

Pen Test education

Understand authorized testing, define a safe scope, and make the resulting report useful.

Planned curriculum

Future Pen Test lessons

Short, business-friendly lessons will be added gradually. They describe authorized defensive testing only.

Beginner

Security foundations

  • Asset inventories and attack surface
  • What “scope” and authorization mean
  • How to read risk ratings
Intermediate

Planning a useful engagement

  • Web, API, cloud, and network test types
  • Rules of engagement and safe testing windows
  • Evidence, validation, and remediation tickets
Advanced

Reducing real-world exposure

  • Threat modeling with business context
  • Identity, access, and segmentation review
  • Retesting and measuring remediation progress
Master

Program leadership

  • Testing programs across vendors and teams
  • Board-ready risk communication
  • Connecting findings to control assurance
âś“

Compliance education

Explore common privacy laws, security obligations, and assurance frameworks. Open a directory only when it is relevant to your business.

This directory is an orientation tool, not legal advice or a certification decision. Applicability depends on your data, customers, contracts, and location. Each entry links to the organization that publishes or explains the primary guidance.

Browse by regionPrivacy and security obligations by geography
European Union & EEA

GDPR

The EU’s General Data Protection Regulation governs personal-data processing and requires organizations to demonstrate compliance with core data-protection principles.

European Commission guidance ↗

NIS2 Directive

An EU cybersecurity directive that sets risk-management and incident-reporting requirements for covered essential and important entities.

Official EU legal text ↗
United Kingdom

UK GDPR & Data Protection Act 2018

The UK’s data-protection regime governs the use of personal information and is explained for organizations by the ICO.

ICO guidance ↗
United States
Canada
Australia
Browse by industrySecurity obligations and assurance standards by business activity
Payments & commerce

PCI DSS

A global payment-card security standard with baseline technical and operational requirements for environments that store, process, transmit, or can affect payment account data.

PCI Security Standards Council ↗
Healthcare

HIPAA Security Rule

U.S. covered entities and business associates use the HIPAA Security Rule to safeguard electronic protected health information with administrative, physical, and technical safeguards.

U.S. HHS guidance ↗
Public companies & financial services

Sarbanes-Oxley Act (SOX)

A U.S. federal law that strengthened public-company financial reporting, accountability, and internal-control obligations.

U.S. SEC resources ↗

GLBA Safeguards Rule

For covered financial institutions, the FTC Safeguards Rule requires an information-security program to protect customer information.

FTC GLBA guidance ↗

NYDFS Cybersecurity Regulation

New York’s financial-services cybersecurity regulation establishes program, governance, risk, and reporting requirements for covered entities.

New York DFS guidance ↗
Government & defense

FedRAMP

A U.S. government program that standardizes security assessment, authorization, and continuous monitoring for cloud products and services used by federal agencies.

FedRAMP official site ↗

CMMC

The U.S. Department of Defense program that assesses contractor implementation of cybersecurity requirements for protecting federal contract information and controlled unclassified information.

DoD CMMC program ↗
Education & critical infrastructure

NERC CIP

Mandatory reliability standards for the protection of the North American bulk electric system’s critical cyber assets.

NERC CIP standards ↗
Cross-industry assurance

ISO/IEC 27001

An international standard for establishing, implementing, maintaining, and continually improving an information security management system. It is a standard, not a law.

ISO/IEC 27001 overview ↗

SOC 2

An AICPA assurance-reporting framework for service organizations; it is not a government regulation or a certification.

AICPA SOC resources ↗
↗

Ready to discuss your scope?

CyberClaw can discuss a defined Pen Test or Compliance Review. Pricing is based on your systems, framework, evidence requirements, timeline, and testing needs.