Compliance Frameworks
Explore compliance frameworks and their control mappings
Agile Security Framework - Baseline
ASF-Baseline
Quick overview of essential security domains - holistic baseline for custom framework
Business Risk Controls
Basic Risk
Custom internal framework for general business risk controls.
CCB CyberFundamentals Framework
CCB-CFF-2023-03-01
Centre For Cybersecurity Belgium - CyberFundamentals Framework https://ccb.belgium.be
CIS IG3 All Controls
CIS IG3
CJIS Security Policy
CJIS
Security policy for U.S. criminal justice information systems, focused on access, encryption, and audit.
COBIT
COBIT
IT governance framework aligning business goals with IT processes and risk management.
Criminal Justice Information Services (CJIS) Security Policy
CJIS-POLICY-5.9.4
The Criminal Justice Information Services (CJIS) Security Policy is a set of standards and guidelines developed by the FBI to help secure criminal justice information (CJI), such as fingerprints, criminal histories, and other data. The policy aims to provide appropriate controls to protect the full lifecycle of CJI, ensuring that it is securely handled, stored, and transmitted.
CSA CCM
CSA-CCM
Cloud security control matrix covering data protection, compliance, and shared responsibility.
Cyber Essentials v3.3
Cyber Essentials
UK government-backed certification scheme. Five technical controls: Firewalls, Secure Configuration, Security Update Management, User Access Control, Malware Protection.
Digital Operational Resilience Act
DORA
REGULATION (EU) 2022/2554 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011
Essential Cybersecurity Controls
essential-cybersecurity-controls
The Saudi National Cybersecurity Authority developed the essential cybersecurity controls (ECC – 1: 2018) after conducting a comprehensive study of multiple national and international cybersecurity frameworks and standards. Reference: https://nca.gov.sa/en/legislation?item=191&slug=controls-list
Essential Eight Maturity Model
Essential Eight
The Australian Signals Directorate (ASD) has developed prioritised mitigation strategies, in the form of the Strategies to Mitigate Cyber Security Incidents, to help organisations protect themselves against various cyber threats. The most effective of these mitigation strategies are the Essential Eight. The Essential Eight has been designed to protect organisations’ internet-connected information technology networks. While the principles behind the Essential Eight may be applied to enterprise mobility and operational technology networks, it was not designed for such purposes and alternative mitigation strategies may be more appropriate to defend against unique cyber threats to these environments.
EU Artificial Intelligence Act (AI Act)
AI Act
REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act)
Federal Act on Data Protection
FADP
Federal Act on Data Protection (Data Protection Act, FADP) of 25 September 2020 (Status as of 1 September 2023) by the Federal Assembly of the Swiss Confederation source: https://www.fedlex.admin.ch/eli/cc/2022/491/en
FedRAMP
FedRAMP
U.S. government program for securing cloud services through standardized assessments and continuous monitoring.
FFIEC
FFIEC
Cybersecurity assessment tool and guidance for U.S. financial institutions.
FISMA
FISMA
Federal framework mandating agencies to develop, document, and implement information security programs.
FTC 314.4 Code of Federal Regulations
FTC Safeguards
FTC Safeguards Rule
FTC Rules
GDPR checklist for data controllers
GDPR-checklist
GDPR.EU checklist for data controllers (https://gdpr.eu/checklist/)
General Data Protection Regulation (GDPR)
GDPR
EU regulation for data protection and privacy of individuals in the European Union and the European Economic Area.
GLBA
GLBA
Regulation for financial institutions to explain data-sharing practices and protect sensitive data.
GSA FedRAMP Rev5
GSA-FEDRAMP-rev5
The Federal Risk and Authorization Management Program (FedRAMP) provides a standardized approach to security authorizations for Cloud Service Offerings.
HIPAA Security Rule
HIPAA Security
U.S. regulations for protecting electronic health information and ensuring privacy and security safeguards.
ISO/IEC 27001
ISO 27001
International standard for information security management, focused on risk-based controls and continuous improvement.
ITIL
ITIL
Best practices for IT service management with a focus on value creation and service delivery.
MITRE ATT&CK
MITRE
Knowledge base of adversary tactics and techniques used in cyberattacks.
NIS 2 directive requirements
NIS2-directive
Requirements from article 21 of directive 2022/2555 of the european parliament and of the council of 14 December 2022 on measures for a high common level of cybersecurity across the Union.
NIST AI RMF 1.0
NIST-AI-RMF-1.0
National Institute of Standards and Technology - Artificial Intelligence Risk Management Framework
NIST CSF version 1.1
NIST-CSF-1.1
National Institute of Standards and Technology - Cybersecurity Framework
NIST CSF version 2.0
NIST-CSF-2.0
National Institute of Standards and Technology - Cybersecurity Framework
NIST Cybersecurity Framework 2.0
NIST 2.0
Voluntary framework based on existing standards, guidelines, and practices for improving critical infrastructure cybersecurity.
NIST PRIVACY FRAMEWORK 1.0
NIST-PRIVACY-1.0
NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management. Details and credits on https://www.nist.gov/privacy-framework
NIST SP 800-171 Rev. 2 Level 1 (CMMC)
NIST SP 800-171 Revision 2 Level 1 - CMMC 2.0 assessment objectives (59 granular requirements)
NIST SP 800-171 Rev. 2 Level 2 (CMMC)
NIST SP 800-171 Revision 2 Level 2 - CMMC 2.0 assessment objectives (320 granular requirements)
NIST SP 800-171 Rev. 3
nist-800-171-rev3
Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations https://csrc.nist.gov/pubs/sp/800/171/r3/final
NIST SP 800-53 revision 5
NIST-SP-800-53-rev5
National Institute of Standards and Technology - Special Publication 800-53 - Security and Privacy Controls for Information Systems and Organizations
NIST SP-800-66 rev2 (HIPAA)
NIST-SP-800-66-rev2
Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide, 2.0.0 Source: https://csrc.nist.gov/Projects/cprt/catalog#/cprt/framework/version/SP800_66_2_0_0/home
NY DFS 500 with 2023-11 amendments
DFS-500-2023-11
NEW YORK STATE DEPARTMENT OF FINANCIAL SERVICES SECOND AMENDMENT TO 23 NYCRR 500 CYBERSECURITY REQUIREMENTS FOR FINANCIAL SERVICES COMPANIES On November 1, 2023, DFS announced amendments to Cybersecurity Regulation, 23 NYCRR Part 500.
Operational Technology Cybersecurity Controls
OTCC
The NCA publishes the Operational Technology Cybersecurity Controls (OTCC-1:2022). These controls are aligned with related international cybersecurity standards, frameworks, controls, and best practices. https://www.nca.gov.sa/otcc_en.pdf
OWASP ASVS 4.0.3
OWASP-ASVS-4.0.3
OWASP Application Security Verification Standard. https://owasp.org/www-project-application-security-verification-standard/
OWASP MASVS 2.1.0
owasp-masvs-v2.1.0
OWASP Mobile Application Security Verification Standard v2.1.0
OWASP top 10 Web
OWASP top 10 Web
Top 10 appsec risks determined by OWASP - 2021
Payment Card Industry Data Security Standard
PCI DSS 4.0
Payment Card Industry Data Security Standard: Requirements and Testing Procedures, v4.0
PCI DSS
PIC DSS
Standards for securing cardholder data and reducing credit card fraud risks.
Protective Security Policy Framework
PSPF
The Protective Security Policy Framework (PSPF) helps Australian Government entities to protect their people, information and assets, both at home and overseas. It sets out government protective security policy and supports entities to effectively implement the policy across the following outcomes: security governance information security personnel security physical security.
PSSI-MCAS v1.0
mcas-1.0
Politique de sécurité des systèmes d’information pour les ministères chargés des affaires sociales
Public AirCyber Maturity Level Matrix
AirCyber-v1.5.2
AirCyber is the AeroSpace and Defense official standard for Cybersecurity maturity evaluation and increase built by Airbus, Dassault Aviation, Safran and Thales to help the AeroSpace SupplyChain to be more resilient. Their joint venture BoostAeroSpace is offering this extract of the AirCyber maturity level matrix to provide further details on this standard, the questions and the AirCyber maturity levels they are associated to. AirCyber program uses this maturity level matrix as the base of the cyber maturity evaluation as is the evaluation activity is the very starting point for any cyber maturity progression. Being aware of the problems is the mandatory very first knowledge a company shall know to decide to launch a cybersecurity company program. Source: https://boostaerospace.com/aircyber/
Secure Software Development Framework (SSDF)
nist-ssdf-1.1
The Secure Software Development Framework (SSDF), SP 800-218, is a set of fundamental, sound, and secure software development practices based on established secure software development practice documents from organizations such as BSA, OWASP, and SAFECode
SOC 2 (SSAE-18)
SOC 2
Trust Services Criteria-based framework for service organizations, focusing on security, availability, and confidentiality.
SOC2-2017 Trust Services Criteria
SOC2-2017
TSP Section 100 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy
SOX
SOX
U.S. law enforcing internal controls and financial reporting integrity in public companies.
TISAX
TISAX
Automotive industry framework for assessing information security based on ISO/IEC 27001.