Articles
Frameworks, explained plainly.
The standards, regulations and directives that shape Nordic security work — written plainly, without the technical labyrinth.
SOC 2Published SOC 2SOC 2 is a framework for the information security of service providers, especially those storing customer data in the cloud. In 2017, the audit body American Institute of Certified Public Accountants (AICPA) defined SOC…Read morePDLPublished Patientdatalagen (the Swedish Patient Data Act) governs how healthcare providers process personal dataPatientdatalagen (PDL) — the Swedish Patient Data Act — applies to all healthcare providers, both public and private. It supplements the General Data Protection Regulation (GDPR) with rules on how healthcare providers may process personal data.Read moreNCSPublished Sweden's National Cybersecurity StrategySweden's National Cybersecurity Strategy Seclight operates within the challenge areas set out in the national cybersecurity strategy from 2025: cybersecurity work, skills and knowledge, preventing and managing incidents, vulnerable…Read moreSoGPPublished Standard of Good Practice for Information Security (SoGP)The Standard of Good Practice for Information Security (SoGP) is an information security framework from the Information Security Forum (ISF).Read moreOWASPPublished Open Worldwide Application Security Project (OWASP)Under the motto "no more insecure software," the non-profit organisation Open Worldwide Application Security Project (OWASP) works to improve the security of software.Read moreNIST CSFPublished NIST Cybersecurity FrameworkIdentify, protect, detect, respond, recover — this is an approach many people recognise and use to address systematic IT security work. Here we go through what the framework involves and what it…Read moreISO 27000Published Effective security management with the ISO 27000 seriesNew technical solutions are being developed at a rapid pace in the field of digitalisation. It's essential to keep up while always taking IT security and information security into account, so as not to risk leaving your own organisation…Read moreCISPublished CIS ControlsThe CIS Controls are a set of control points with associated safeguards that guide organisations in addressing their IT security. The methodology can be a good complement to, and enabler for, ISO certification and…Read morePCI DSSPublished Protecting Card Payments with PCI DSSThe Payment Card Industry Data Security Standard (PCI DSS) is an international information security standard that all companies and organisations that process, store or transmit payment card data need to comply…Read more