NIST CSF 2.0 — the language of programs
Six functions: GOVERN (organizational context, risk strategy, roles, oversight — new in 2.0), IDENTIFY (asset & risk inventories), PROTECT (access control, awareness, data security), DETECT (monitoring, continuous), RESPOND (IR planning, analysis, reporting), RECOVER (backups, communications).
Use CSF Profiles: Current vs Target → the gap list IS your roadmap. Free, vendor-neutral, and understood by every auditor.
ISO/IEC 27001 — the certifiable one
An ISMS: risk assessment → Statement of Applicability (which Annex A controls apply & why) → policies/procedures → internal audit → management review → certification audit. Certification signals to partners (especially international) that your program is systematic. Many Pakistani software houses now require it for export clients.
PECA 2016 + 2025 Amendment — the law you operate under
Key sections to know cold: §3 unauthorized access · §4 copying data · §6 hate speech · §20 harming reputation/privacy · §21 sexual content & superimposed faces (deepfakes; heavier penalties for minors) · §24 cyberstalking · §26A false/fake information creating fear/panic (2025 addition) · §30 seizure powers.
Compliance duties that touch every org: report incidents (PKCERT for national-significance; NCCIA for crimes), protect minors' data, no unauthorized access even of "abandoned" accounts, and — for platforms — cooperation with lawful investigation.
Data protection: Pakistan's data-protection bill remains in legislative process; meanwhile, sector rules (SBP for banks, PTA for telcos, SECP for listed companies) apply. Design to GDPR-grade consent/minimization — it future-proofs you and builds user trust (our own portal follows this: privacy policy, data export/delete rights, no data sold, hosted in Pakistan).
