Sarbanes Oxley- The Sarbanes Oxley Act of 2002 (SOX) has very specific stipulations and requirements related to information security and data governance that apply to all publicly held U.S. companies, international companies with SEC registered securities and to third-party firms that provide financial services to these companies such as CPAs.

FFIEC- The Federal Financial Institutions Examination Council sets cybersecurity standards.

ISO27001- A framework for organizations to implement a standardized approach to information security.

NIST- The National Institute of Standards and Technology provides cybersecurity standards.

PCI DSS- The Payment Card Industry Data Security Standard sets requirements for organizations handling payment card data.

SEC Cybersecurity- The Office of Compliance Inspections and Examinations (OCIE) and the U.S. Securities and Exchange Commission (SEC) conduct cybersecurity examinations that apply to financial institutions including investment advisors, investments companies, broker-dealers, transfer agents, and private fund advisors.

State Cybersecurity Regulations- All 50 states, the District of Columbia, Puerto Rico, Guam and the Virgin Islands have laws pertaining to data breaches and cybersecurity. Certain entities that operate in the state of New York must comply with that state's latest cybersecurity regulation.