<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>International on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/international/</link><description>Recent content in International on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/international/index.xml" rel="self" type="application/rss+xml"/><item><title>CIS Benchmarks</title><link>https://lesitedefrancois.be/en/compliance/cis-benchmarks/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/cis-benchmarks/</guid><description>&lt;p&gt;&lt;strong&gt;CIS Benchmarks&lt;/strong&gt; are detailed, prescriptive security configuration guidelines published by the &lt;strong&gt;Center for Internet Security (CIS)&lt;/strong&gt;, a US-based non-profit organization. They are developed through a consensus process involving cybersecurity practitioners, vendors, and government agencies, and cover over 100 technology families — operating systems (Linux, Windows, macOS), cloud platforms (AWS, Azure, GCP), container orchestrators (Kubernetes, Docker), databases, web servers, and network devices. CIS Benchmarks are &lt;strong&gt;international&lt;/strong&gt; in applicability — they are not tied to any single jurisdiction — and are referenced by regulatory frameworks worldwide (NIST, PCI-DSS, HIPAA, FedRAMP, NIS2 national implementations). Each benchmark provides two recommendation levels: &lt;strong&gt;Level 1&lt;/strong&gt; (practical hardening that does not significantly impact functionality) and &lt;strong&gt;Level 2&lt;/strong&gt; (defense-in-depth settings for high-security environments). CIS Benchmarks are &lt;strong&gt;voluntary&lt;/strong&gt; — no law mandates CIS compliance directly — but they are frequently required by procurement contracts, industry standards, and as evidence of &amp;ldquo;reasonable security measures&amp;rdquo; in regulatory audits. The CIS also offers &lt;strong&gt;CIS Controls&lt;/strong&gt; (formerly the SANS Top 20), a prioritized set of cybersecurity best practices, and the &lt;strong&gt;CIS Hardened Images&lt;/strong&gt; program for pre-configured virtual machine images.&lt;/p&gt;</description></item><item><title>GSMA NESAS</title><link>https://lesitedefrancois.be/en/compliance/gsma-nesas/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/gsma-nesas/</guid><description>&lt;p&gt;The &lt;strong&gt;GSMA Network Equipment Security Assurance Scheme (NESAS)&lt;/strong&gt; is a &lt;strong&gt;voluntary, global&lt;/strong&gt; security assurance framework jointly led by the &lt;strong&gt;GSMA&lt;/strong&gt; and &lt;strong&gt;3GPP&lt;/strong&gt;. It was established to provide a universal, industry-driven security evaluation for mobile network equipment — primarily targeting 4G/LTE and 5G infrastructure — that avoids the fragmentation of country-specific security requirements. NESAS operates through two complementary components: first, an &lt;strong&gt;audit of the vendor&amp;rsquo;s development and product lifecycle processes&lt;/strong&gt; (covering secure design, implementation, testing, and vulnerability handling), conducted by GSMA-appointed auditing organizations; second, a &lt;strong&gt;product evaluation&lt;/strong&gt; against 3GPP-defined Security Assurance Specifications (SCAS), performed by ISO/IEC 17025 accredited security test laboratories. The GSMA manages scheme governance (accreditation, dispute resolution, publication of results), while 3GPP&amp;rsquo;s SA3 working group defines the technical security requirements and test cases in SCAS documents. The scheme is currently at &lt;strong&gt;NESAS v3.0&lt;/strong&gt; (specifications published early 2025), which introduces revised security requirements and expands coverage to include virtualized network functions. NESAS is &lt;strong&gt;voluntary&lt;/strong&gt; — no government mandates it — but it is increasingly referenced by national 5G security reviews and procurement requirements (including the EU 5G Toolbox), and major operators use NESAS assessment results as a procurement criterion. Evaluated vendors and their results are publicly listed on the GSMA website.&lt;/p&gt;</description></item><item><title>ISO/IEC 27001</title><link>https://lesitedefrancois.be/en/compliance/iso-27001/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/iso-27001/</guid><description>&lt;p&gt;&lt;strong&gt;ISO/IEC 27001&lt;/strong&gt; is the world&amp;rsquo;s most widely recognized standard for Information Security Management Systems (ISMS). It is published jointly by &lt;strong&gt;ISO&lt;/strong&gt; (International Organization for Standardization) and &lt;strong&gt;IEC&lt;/strong&gt; (International Electrotechnical Commission) — making it a truly international standard, not tied to any single country or jurisdiction. The current version is &lt;strong&gt;ISO/IEC 27001:2022&lt;/strong&gt;, which replaced the 2013 edition and restructured its Annex A controls to align with the updated ISO/IEC 27002:2022 guidance (93 controls organized in 4 themes: Organizational, People, Physical, Technological). The standard specifies &lt;strong&gt;requirements&lt;/strong&gt; (clauses 4–10) for establishing, implementing, maintaining, and continually improving an ISMS — covering context analysis, leadership commitment, risk assessment, treatment planning, operational controls, performance evaluation, and continuous improvement. Certification is &lt;strong&gt;voluntary&lt;/strong&gt; but has become a global market expectation: ISO 27001 certification is required by countless procurement policies, regulatory frameworks (NIS2 references it, ENS aligns with it, E-ITS accepts it as equivalent, BSI IT-Grundschutz enables ISO 27001 certification), and customer contracts. Certification is issued by accredited certification bodies (accredited under ISO/IEC 17021) following a two-stage audit process, valid for &lt;strong&gt;3 years&lt;/strong&gt; with annual surveillance audits. Over 70,000 organizations worldwide hold ISO 27001 certification. Unlike prescriptive frameworks (DISA STIG, CIS Benchmarks), ISO 27001 is &lt;strong&gt;risk-based and outcome-oriented&lt;/strong&gt; — it specifies what must be achieved but not how, allowing organizations to tailor implementations to their context.&lt;/p&gt;</description></item><item><title>PCI-DSS</title><link>https://lesitedefrancois.be/en/compliance/pci-dss/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/pci-dss/</guid><description>&lt;p&gt;The &lt;strong&gt;Payment Card Industry Data Security Standard (PCI-DSS)&lt;/strong&gt; is a global security standard developed and maintained by the &lt;strong&gt;PCI Security Standards Council (PCI SSC)&lt;/strong&gt;, which was founded in 2006 by the five major payment card brands (Visa, Mastercard, American Express, Discover, JCB). The current version is &lt;strong&gt;PCI-DSS v4.0.1&lt;/strong&gt; (published June 2024, with mandatory compliance required from 31 March 2025 for all new requirements). PCI-DSS is &lt;strong&gt;not government legislation&lt;/strong&gt; but a contractual obligation — compliance is enforced through the agreements between merchants/service providers and their acquiring banks. Failure to comply results in fines (up to $100,000/month from card brands), increased transaction fees, and ultimately loss of the ability to process card payments. PCI-DSS applies to &lt;strong&gt;any organization worldwide&lt;/strong&gt; that stores, processes, or transmits cardholder data (CHD) or sensitive authentication data (SAD), regardless of size or transaction volume. The standard defines &lt;strong&gt;12 requirements&lt;/strong&gt; organized in 6 control objectives: build and maintain secure networks (firewalls, secure configurations), protect cardholder data (encryption, key management), maintain a vulnerability management program (patching, anti-malware), implement strong access controls (least privilege, MFA, physical access), regularly monitor and test networks (logging, penetration testing), and maintain an information security policy. Compliance is validated through either a &lt;strong&gt;Qualified Security Assessor (QSA)&lt;/strong&gt; on-site assessment (Level 1 merchants) or a &lt;strong&gt;Self-Assessment Questionnaire (SAQ)&lt;/strong&gt; for smaller entities.&lt;/p&gt;</description></item><item><title>SOC 2</title><link>https://lesitedefrancois.be/en/compliance/soc2/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/soc2/</guid><description>&lt;p&gt;&lt;strong&gt;SOC 2&lt;/strong&gt; (System and Organization Controls 2) is an auditing framework developed by the &lt;strong&gt;AICPA&lt;/strong&gt; (American Institute of Certified Public Accountants). It is not government legislation or a certification scheme but a &lt;strong&gt;voluntary attestation standard&lt;/strong&gt; — however, it has become a de facto market requirement for any technology company, cloud service provider, or SaaS vendor serving enterprise customers, particularly in the US. A SOC 2 report is produced by an independent &lt;strong&gt;CPA firm&lt;/strong&gt; that evaluates an organization&amp;rsquo;s controls against the AICPA&amp;rsquo;s &lt;strong&gt;Trust Services Criteria (TSC)&lt;/strong&gt;, organized in five categories: &lt;strong&gt;Security&lt;/strong&gt; (mandatory for all SOC 2 reports, covering Common Criteria CC1–CC9), &lt;strong&gt;Availability&lt;/strong&gt;, &lt;strong&gt;Processing Integrity&lt;/strong&gt;, &lt;strong&gt;Confidentiality&lt;/strong&gt;, and &lt;strong&gt;Privacy&lt;/strong&gt; (each optional depending on the organization&amp;rsquo;s services and customer commitments). The Common Criteria (CC1–CC9) are derived from the COSO Internal Control Framework and cover control environment, risk assessment, monitoring, logical/physical access, system operations, change management, and risk mitigation. There are two report types: &lt;strong&gt;Type I&lt;/strong&gt; (evaluates control design at a point in time) and &lt;strong&gt;Type II&lt;/strong&gt; (evaluates both design and operating effectiveness over 6–12 months — the standard enterprise customers demand). SOC 2 reports are restricted-use documents shared with customers under NDA. While not legally mandatory, major enterprises, financial institutions, and regulated industries routinely require SOC 2 Type II reports from their vendors before signing contracts, making it an essential market-access requirement for technology service providers.&lt;/p&gt;</description></item></channel></rss>