Compliance Frameworks

Explore compliance frameworks and their control mappings

AS

Agile Security Framework - Baseline

ASF-Baseline

Quick overview of essential security domains - holistic baseline for custom framework

14 controls
Ba

Business Risk Controls

Basic Risk

Custom internal framework for general business risk controls.

1 controls
CC

CCB CyberFundamentals Framework

CCB-CFF-2023-03-01

Centre For Cybersecurity Belgium - CyberFundamentals Framework https://ccb.belgium.be

219 controls
CI

CIS IG3 All Controls

CIS IG3

117 controls
CJ

CJIS Security Policy

CJIS

Security policy for U.S. criminal justice information systems, focused on access, encryption, and audit.

0 controls
CO

COBIT

COBIT

IT governance framework aligning business goals with IT processes and risk management.

65 controls
CJ

Criminal Justice Information Services (CJIS) Security Policy

CJIS-POLICY-5.9.4

The Criminal Justice Information Services (CJIS) Security Policy is a set of standards and guidelines developed by the FBI to help secure criminal justice information (CJI), such as fingerprints, criminal histories, and other data. The policy aims to provide appropriate controls to protect the full lifecycle of CJI, ensuring that it is securely handled, stored, and transmitted.

994 controls
CS

CSA CCM

CSA-CCM

Cloud security control matrix covering data protection, compliance, and shared responsibility.

1 controls
Cy

Cyber Essentials v3.3

Cyber Essentials

UK government-backed certification scheme. Five technical controls: Firewalls, Secure Configuration, Security Update Management, User Access Control, Malware Protection.

0 controls
DO

Digital Operational Resilience Act

DORA

REGULATION (EU) 2022/2554 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011

222 controls
es

Essential Cybersecurity Controls

essential-cybersecurity-controls

The Saudi National Cybersecurity Authority developed the essential cybersecurity controls (ECC – 1: 2018) after conducting a comprehensive study of multiple national and international cybersecurity frameworks and standards. Reference: https://nca.gov.sa/en/legislation?item=191&slug=controls-list

114 controls
Es

Essential Eight Maturity Model

Essential Eight

The Australian Signals Directorate (ASD) has developed prioritised mitigation strategies, in the form of the Strategies to Mitigate Cyber Security Incidents, to help organisations protect themselves against various cyber threats. The most effective of these mitigation strategies are the Essential Eight. The Essential Eight has been designed to protect organisations’ internet-connected information technology networks. While the principles behind the Essential Eight may be applied to enterprise mobility and operational technology networks, it was not designed for such purposes and alternative mitigation strategies may be more appropriate to defend against unique cyber threats to these environments.

1 controls
AI

EU Artificial Intelligence Act (AI Act)

AI Act

REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act)

317 controls
FA

Federal Act on Data Protection

FADP

Federal Act on Data Protection (Data Protection Act, FADP) of 25 September 2020 (Status as of 1 September 2023) by the Federal Assembly of the Swiss Confederation source: https://www.fedlex.admin.ch/eli/cc/2022/491/en

171 controls
Fe

FedRAMP

FedRAMP

U.S. government program for securing cloud services through standardized assessments and continuous monitoring.

0 controls
FF

FFIEC

FFIEC

Cybersecurity assessment tool and guidance for U.S. financial institutions.

0 controls
FI

FISMA

FISMA

Federal framework mandating agencies to develop, document, and implement information security programs.

0 controls
FT

FTC 314.4 Code of Federal Regulations

FTC Safeguards

48 controls
FT

FTC Safeguards Rule

FTC Rules

0 controls
GD

GDPR checklist for data controllers

GDPR-checklist

GDPR.EU checklist for data controllers (https://gdpr.eu/checklist/)

0 controls
GD

General Data Protection Regulation (GDPR)

GDPR

EU regulation for data protection and privacy of individuals in the European Union and the European Economic Area.

186 controls
GL

GLBA

GLBA

Regulation for financial institutions to explain data-sharing practices and protect sensitive data.

1 controls
GS

GSA FedRAMP Rev5

GSA-FEDRAMP-rev5

The Federal Risk and Authorization Management Program (FedRAMP) provides a standardized approach to security authorizations for Cloud Service Offerings.

410 controls
HI

HIPAA Security Rule

HIPAA Security

U.S. regulations for protecting electronic health information and ensuring privacy and security safeguards.

92 controls
IS

ISO/IEC 27001

ISO 27001

International standard for information security management, focused on risk-based controls and continuous improvement.

86 controls
IT

ITIL

ITIL

Best practices for IT service management with a focus on value creation and service delivery.

24 controls
MI

MITRE ATT&CK

MITRE

Knowledge base of adversary tactics and techniques used in cyberattacks.

1 controls
NI

NIS 2 directive requirements

NIS2-directive

Requirements from article 21 of directive 2022/2555 of the european parliament and of the council of 14 December 2022 on measures for a high common level of cybersecurity across the Union.

13 controls
NI

NIST AI RMF 1.0

NIST-AI-RMF-1.0

National Institute of Standards and Technology - Artificial Intelligence Risk Management Framework

72 controls
NI

NIST CSF version 1.1

NIST-CSF-1.1

National Institute of Standards and Technology - Cybersecurity Framework

108 controls
NI

NIST CSF version 2.0

NIST-CSF-2.0

National Institute of Standards and Technology - Cybersecurity Framework

106 controls
NI

NIST Cybersecurity Framework 2.0

NIST 2.0

Voluntary framework based on existing standards, guidelines, and practices for improving critical infrastructure cybersecurity.

1 controls
NI

NIST PRIVACY FRAMEWORK 1.0

NIST-PRIVACY-1.0

NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management. Details and credits on https://www.nist.gov/privacy-framework

100 controls
NI

NIST SP 800-171 Rev. 2 Level 1 (CMMC)

NIST SP 800-171 Revision 2 Level 1 - CMMC 2.0 assessment objectives (59 granular requirements)

59 controls
NI

NIST SP 800-171 Rev. 2 Level 2 (CMMC)

NIST SP 800-171 Revision 2 Level 2 - CMMC 2.0 assessment objectives (320 granular requirements)

320 controls
ni

NIST SP 800-171 Rev. 3

nist-800-171-rev3

Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations https://csrc.nist.gov/pubs/sp/800/171/r3/final

97 controls
NI

NIST SP 800-53 revision 5

NIST-SP-800-53-rev5

National Institute of Standards and Technology - Special Publication 800-53 - Security and Privacy Controls for Information Systems and Organizations

1189 controls
NI

NIST SP-800-66 rev2 (HIPAA)

NIST-SP-800-66-rev2

Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide, 2.0.0 Source: https://csrc.nist.gov/Projects/cprt/catalog#/cprt/framework/version/SP800_66_2_0_0/home

0 controls
DF

NY DFS 500 with 2023-11 amendments

DFS-500-2023-11

NEW YORK STATE DEPARTMENT OF FINANCIAL SERVICES SECOND AMENDMENT TO 23 NYCRR 500 CYBERSECURITY REQUIREMENTS FOR FINANCIAL SERVICES COMPANIES On November 1, 2023, DFS announced amendments to Cybersecurity Regulation, 23 NYCRR Part 500.

160 controls
OT

Operational Technology Cybersecurity Controls

OTCC

The NCA publishes the Operational Technology Cybersecurity Controls (OTCC-1:2022). These controls are aligned with related international cybersecurity standards, frameworks, controls, and best practices. https://www.nca.gov.sa/otcc_en.pdf

150 controls
OW

OWASP ASVS 4.0.3

OWASP-ASVS-4.0.3

OWASP Application Security Verification Standard. https://owasp.org/www-project-application-security-verification-standard/

278 controls
ow

OWASP MASVS 2.1.0

owasp-masvs-v2.1.0

OWASP Mobile Application Security Verification Standard v2.1.0

24 controls
OW

OWASP top 10 Web

OWASP top 10 Web

Top 10 appsec risks determined by OWASP - 2021

0 controls
PC

Payment Card Industry Data Security Standard

PCI DSS 4.0

Payment Card Industry Data Security Standard: Requirements and Testing Procedures, v4.0

351 controls
PI

PCI DSS

PIC DSS

Standards for securing cardholder data and reducing credit card fraud risks.

252 controls
PS

Protective Security Policy Framework

PSPF

The Protective Security Policy Framework (PSPF) helps Australian Government entities to protect their people, information and assets, both at home and overseas. It sets out government protective security policy and supports entities to effectively implement the policy across the following outcomes: security governance information security personnel security physical security.

51 controls
mc

PSSI-MCAS v1.0

mcas-1.0

Politique de sécurité des systèmes d’information pour les ministères chargés des affaires sociales

183 controls
Ai

Public AirCyber Maturity Level Matrix

AirCyber-v1.5.2

AirCyber is the AeroSpace and Defense official standard for Cybersecurity maturity evaluation and increase built by Airbus, Dassault Aviation, Safran and Thales to help the AeroSpace SupplyChain to be more resilient. Their joint venture BoostAeroSpace is offering this extract of the AirCyber maturity level matrix to provide further details on this standard, the questions and the AirCyber maturity levels they are associated to. AirCyber program uses this maturity level matrix as the base of the cyber maturity evaluation as is the evaluation activity is the very starting point for any cyber maturity progression. Being aware of the problems is the mandatory very first knowledge a company shall know to decide to launch a cybersecurity company program. Source: https://boostaerospace.com/aircyber/

221 controls
ni

Secure Software Development Framework (SSDF)

nist-ssdf-1.1

The Secure Software Development Framework (SSDF), SP 800-218, is a set of fundamental, sound, and secure software development practices based on established secure software development practice documents from organizations such as BSA, OWASP, and SAFECode

42 controls
SO

SOC 2 (SSAE-18)

SOC 2

Trust Services Criteria-based framework for service organizations, focusing on security, availability, and confidentiality.

62 controls
SO

SOC2-2017 Trust Services Criteria

SOC2-2017

TSP Section 100 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy

358 controls
SO

SOX

SOX

U.S. law enforcing internal controls and financial reporting integrity in public companies.

0 controls
TI

TISAX

TISAX

Automotive industry framework for assessing information security based on ISO/IEC 27001.

1 controls