Areas.
Security
security.
Integrated cybersecurity strategies, processes, and technologies designed to protect corporate data, networks, and information systems from digital threats and unauthorized access.
protezione delle informazioni.
Integrated data protection services designed to safeguard corporate data, ensuring its confidentiality, integrity, and regulatory compliance at every stage of processing and storage.
ARTIFICIAL INTELLIGENCE.
Integration and control strategies designed to ensure that AI systems are transparent, secure, and compliant with regulatory and data protection requirements throughout their entire lifecycle.
-
ISO/IEC 27001:
It is the international standard of reference for establishing and managing an ISMS (Information Security Management System). It is based on a holistic approach (processes, people, and technology) and is ideal for obtaining official certification for the company. -
NIST Cybersecurity Framework (CSF):
Developed in the United States and adopted worldwide, it consists of five core functions: IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER. It is a highly flexible framework focused on dynamic risk management. -
COBIT (control Objectives for Information and Related Technologies):
Developed by ISACA, it is an IT governance and management framework that aligns cybersecurity strategies with the organization's overall business objectives. -
CIS Controls (Center for Internet Security):
A set of best practices and practical, priority guidelines for actively defending against and combating the main cyber threats (often categorized as Basic, Foundational, and Organizational) - National Cybersecurity Framework: Promoted in Italy by CSIRT Italia and the National Cybersecurity Agency (ACN), it adapts international standards (particularly NIST) to the Italian and European regulatory context.
-
ISO/IEC 27701:
It is the international benchmark standard for privacy management. Known as PIMS (Privacy Information Management System), it extends the information security requirements (ISO 27001) to include the protection of personal data, providing the ideal framework for demonstrating compliance with the GDPR. -
ISO/IEC 27555:
It provides guidelines for establishing policies on the retention and deletion of personal data, ensuring compliance with the principle of data minimization. -
ISO/IEC 27002:
A practical guide that sets forth best practices for implementing security controls. - Framework Nazionale per la Protezione delle Informazioni: Promoted in Italy by CSIRT Italia and the National Cybersecurity Agency (ACN), it adapts international standards (particularly NIST) to the Italian and European regulatory context.
-
ISO/IEC 42001:
It is the first certifiable international standard for an AI Management System (AIMS), designed to ensure the responsible and transparent development and use of AI in compliance with applicable regulations.
framework.
BY WAY OF EXAMPLE ONLY AND NOT AS AN EXHAUSTIVE LIST.
-
NIS2 Directive - (EU) 2022/2025 and Legislative Decree 138/2024 - Transposition of NIS2 in Italy:
Harmonized European Framework for Cybersecurity: risk management requirements, technical and organizational measures, incident reporting, and penalties, accompanied by the transposition law that defines essential and important entities, security requirements, the responsibilities of governing bodies, and the incident reporting process. -
National Cybersecurity Perimeter (Decree-Law 105/2019):
Italian legislation that identifies entities and critical infrastructure deemed strategic for national security. It establishes requirements for the protection, monitoring, and reporting of cyber incidents. It aligns with NIS2 and the European cybersecurity strategy. -
DORA (EU Regulation 2022/2554):
It imposes stringent requirements for ICT security, risk management, resilience testing, and critical supplier management. Relevant for banks, insurance companies, fintech firms, and financial infrastructure providers. -
Cyber Resilience Act (CRA) - EU Regulation 2024/2847:
A European regulation that establishes mandatory security requirements for hardware and software products placed on the market. It affects manufacturers, developers, importers, and distributors.
-
GDPR - Regulation (EU) 2016/679 + Legislative Decree 101/2018:
As the European framework for personal data protection, it establishes the principles governing data processing and the adoption of security measures, while also introducing obligations regarding the reporting of data breaches within 72 hours and the rights of data subjects.
-
AI Act (EU Regulation 2024/1689):
The world's first regulatory framework for AI: risk classification, safety requirements, governance, and obligations for high-risk systems. It includes cybersecurity measures to ensure the robustness and reliability of systems. -
Digital Omnibus (EU Regulation 2024/1744):
The Digital Omnibus Regulation on AI, adopted in July 2026, amends the previous AI Act by introducing administrative simplifications, reducing compliance burdens, and improving coordination with existing digital regulations
regulations.
BY WAY OF EXAMPLE ONLY AND NOT AS AN EXHAUSTIVE LIST.
Sign up for the PF ADVISORY newsletter!
Receive our periodic analysis of trends, regulations, and threats in information security, as well as articles on compliance and cybersecurity.
Transform Governance
and compliance
in growth accelerators.
The evolution of GRC mechanisms among your top business partners, giving rise to a new organizational approach.