Pen Test Basics
What an authorized penetration test is, what it is not, and what a business should expect.
Read Pen Test Basics →CyberClaw Learn
Plain-language guides for business owners and teams preparing for security testing or compliance work.
Understand authorized testing, define a safe scope, and make the resulting report useful.
What an authorized penetration test is, what it is not, and what a business should expect.
Read Pen Test Basics →A practical checklist for choosing scope, contacts, safeguards, and next steps.
Read the preparation guide →Planned curriculum
Short, business-friendly lessons will be added gradually. They describe authorized defensive testing only.
Explore common privacy laws, security obligations, and assurance frameworks. Open a directory only when it is relevant to your business.
A practical introduction to frameworks, readiness, evidence, and the role of a pen test.
Read Compliance Basics →See how validated vulnerabilities can inform an auditable remediation plan.
Read the control-mapping guide →This directory is an orientation tool, not legal advice or a certification decision. Applicability depends on your data, customers, contracts, and location. Each entry links to the organization that publishes or explains the primary guidance.
The EU’s General Data Protection Regulation governs personal-data processing and requires organizations to demonstrate compliance with core data-protection principles.
European Commission guidance ↗An EU cybersecurity directive that sets risk-management and incident-reporting requirements for covered essential and important entities.
Official EU legal text ↗The UK’s data-protection regime governs the use of personal information and is explained for organizations by the ICO.
ICO guidance ↗California privacy laws give consumers rights over personal information and impose duties on covered businesses and service providers.
California Privacy Protection Agency ↗Several U.S. states have distinct consumer-privacy laws. Requirements, thresholds, and effective dates vary by state.
FTC privacy and security guidance ↗Canada’s federal private-sector privacy law sets rules for how covered organizations collect, use, and disclose personal information in commercial activities.
Office of the Privacy Commissioner of Canada ↗Australia’s Privacy Act includes principles governing the handling of personal information by covered agencies and organizations.
Office of the Australian Information Commissioner ↗A global payment-card security standard with baseline technical and operational requirements for environments that store, process, transmit, or can affect payment account data.
PCI Security Standards Council ↗U.S. covered entities and business associates use the HIPAA Security Rule to safeguard electronic protected health information with administrative, physical, and technical safeguards.
U.S. HHS guidance ↗A U.S. federal law that strengthened public-company financial reporting, accountability, and internal-control obligations.
U.S. SEC resources ↗For covered financial institutions, the FTC Safeguards Rule requires an information-security program to protect customer information.
FTC GLBA guidance ↗New York’s financial-services cybersecurity regulation establishes program, governance, risk, and reporting requirements for covered entities.
New York DFS guidance ↗The U.S. federal information-security law underpinning agency information-security programs and risk management.
NIST FISMA background ↗A U.S. government program that standardizes security assessment, authorization, and continuous monitoring for cloud products and services used by federal agencies.
FedRAMP official site ↗The U.S. Department of Defense program that assesses contractor implementation of cybersecurity requirements for protecting federal contract information and controlled unclassified information.
DoD CMMC program ↗A U.S. law protecting the privacy of student education records at institutions receiving applicable Department of Education funding.
U.S. Department of Education ↗Mandatory reliability standards for the protection of the North American bulk electric system’s critical cyber assets.
NERC CIP standards ↗An international standard for establishing, implementing, maintaining, and continually improving an information security management system. It is a standard, not a law.
ISO/IEC 27001 overview ↗An AICPA assurance-reporting framework for service organizations; it is not a government regulation or a certification.
AICPA SOC resources ↗CyberClaw can discuss a defined Pen Test or Compliance Review. Pricing is based on your systems, framework, evidence requirements, timeline, and testing needs.