UPDATE 2026
GDPR (General Data Protection Regulation) - Answers EU regulation governing data protection,
privacy rights, and requirements for processing personal data of EU residents.
CCPA / CPRA (California) - Answers California laws granting consumers rights over their personal data,
including access, deletion, and opt-out of selling/sharing.
HIPPA (Health Insurance Portability and Accountability Act) - Answers U.S. law regulating the
protection and privacy of health information (PHI).
FISMA (Federal Information Security Management Act) - Answers U.S. federal law requiring
government agencies to develop, document, and implement information security programs.
FedRAMP (Federal Risk and Authorization Management Program) - Answers U.S. government
program providing standardized security assessment and authorization for cloud services used by
federal agencies.
CMMC (Cybersecurity Maturity Model Certification) - Answers Security standard required for U.S.
Department of Defense contractors to protect controlled unclassified information (CUI).
ISO/IEC 27001 - Answers An international standard for establishing, implementing, maintaining, and
improving an Information Security Management System (ISMS).
ISO/IEC 27002 - Answers A code of practice offering security controls and guidance for implementing
an ISMS.
ISO/IEC 27018 - Answers A standard describing controls for protecting personal data in public cloud
environments.
SOC 2 - Answers An attestation standard evaluating a service provider's controls related to security,
availability, processing integrity, confidentiality, and privacy.
CSA STAR (Cloud Security Alliance Security, Trust & Assurance Registry) - Answers A cloud provider
assurance program that documents the security posture of cloud services.
NIST Cybersecurity Framework (CSF) - Answers A set of guidelines and best practices for managing
cybersecurity risk, structured around identify-protect-detect-respond-recover.
NIST SP 800-53 - Answers A catalog of security and privacy controls for information systems used by
U.S. federal agencies and contractors.
ENISA - European Union Agency for Cybersecurity - Answers EU agency providing cybersecurity
guidance, threat analysis, and policy support.
CNCF (Cloud Native Computing Foundation) - Answers Industry foundation that hosts and governs
cloud-native open-source projects such as Kubernetes and Prometheus.
IaaS (Infrastructure as a Service) - Answers Cloud model providing virtualized compute, storage, and
networking resources on demand.
PaaS (Platform as a Service) - Answers Cloud model providing managed platforms for application
development without managing underlying infrastructure.
SaaS (Software as a Service) - Answers Cloud model delivering fully hosted and managed applications
to end users.
Shared Responsibility Model - Answers Framework dividing security responsibilities between cloud
provider (infrastructure) and customer (data, configuration).
Identity and Access Management (IAM) Systems - Answers Tools/services enforcing authentication
and authorization policies for users, applications, and devices.
Identity and Access Management (IAM) Breaches - Answers Security incidents where unauthorized
users gain access due to weak identities, misconfigurations, or credential compromise.
Zero Trust - Answers Security approach assuming no implicit trust—every access request must be
verified continuously.
Least Privilege - Answers Principle restricting accounts and systems to the minimum access
necessary.
API Calls - Answers Requests made to an application programming interface, used for communication
between services or cloud resources.
CRM (Customer Relationship Management) - Answers Systems for managing customer interactions,
data, and sales processes.
Operating Expenditure (OpEx) - Answers Ongoing operating costs such as subscriptions or usage-
based cloud spending.