Cyber, critical infrastructure & AI standards — all in one place.
The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.
Browse by industry
Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.
Explore all industriesContent Library
Showing 20 of 222
201 CMR 17.00 — Massachusetts: Standards for the protection of personal information of residents of the Commonwealth
201 CMR 17.00 is a Massachusetts information security regulation that establishes minimum requirements for protecting the personal information of Massachusetts residents through administrative, technical, and physical security safeguards.
Office of Consumer Affairs and Business Regulation • Massachusetts, USA
Croatia - Personal Data Protection Act
The Act governs the implementation of the EU General Data Protection Regulation (GDPR) in Croatia. It outlines specific roles such as the responsibilities of the supervisory authority, the Croatian Data Protection Agency (AZOP), and sets additional national measures related to GDPR compliance.
Government of Croatia • Croatia
Maine Notice of Risk to Personal Data — Title 10, Chapter 210-B: Notice of Risk to Personal Data
Maine's Title 10, Chapter 210-B establishes regulations around personal data protection and security breach notifications. It includes provisions on prohibited use of personal data, mandatory breach notification, enforcement mechanisms, and rules for reporting identity theft.
State of Maine • Maine, USA
France Act no. 78-17 of 6 January 1978 — Act no. 78-17 of 6 January 1978 on Data Processing, Data Files and Individual Liberties
This French law governs the protection of personal data and the rights of individuals in relation to data processing. It sets principles for the use of information technology to ensure it serves citizens without violating human rights, privacy, or individual liberties.
Government of France • France
COBIT 5 — COBIT 5
COBIT 5 is a comprehensive framework for the governance and management of enterprise IT, designed to maximize the value organizations derive from their information systems. It incorporates principles, practices, and tools to align IT with business strategies and goals.
ISACA • Global • v5
DISP 2020 — Defence Industry Security Program (DISP)– Suitability Assessment (2020)
The Defence Industry Security Program (DISP) is an Australian Defence membership program that helps organizations implement and demonstrate appropriate security controls for participating in Defence projects and managing Defence-related information and assets.
Australian Department of Defence • Australia • v2020
DISP 2022 — Defence Industry Security Program – Suitability Requirements (2022)
The Defence Industry Security Program (DISP) is an Australian Defence security assurance program that helps organizations meet security requirements for Defence contracts and projects by implementing appropriate governance, personnel, physical, and information security controls.
Australian Government • Australia • v2022
Law No.59 — Vietnam - Law on Protection of Consumers' Rights
The Vietnam Law on Protection of Consumers' Rights is a consumer protection framework that establishes consumer rights, business obligations, consumer information protection requirements, and mechanisms for resolving disputes between consumers and traders.
Government of Vietnam • Vietnam • vLaw No.59/2010/QH12
Alabama Data Breach Notification Act of 2018 — Chapter 38 Data Breach Notification Act of 2018
The Alabama Data Breach Notification Act of 2018 is a state data protection law that requires organizations to safeguard sensitive personal information, investigate security breaches, and provide timely notification to affected individuals and regulatory authorities when personal data is compromised.
State of Alabama • Alabama, USA • vPolicy 621-01
Arkansas PIPA — Arkansas Personal Information Protection Act
The Arkansas Personal Information Protection Act (PIPA) is a data privacy and security law that requires organizations to protect personal information, implement reasonable security measures, and notify affected individuals in the event of a qualifying data breach.
State of Arkansas • Arkansas, USA
NIST Privacy Framework v 1.0 — NIST Privacy Framework: A Tool for Improving Privacy Through Enterprise Risk Management
The NIST Privacy Framework Version 1.0 is a voluntary framework that helps organizations integrate privacy risk management into enterprise risk management by providing a structured approach for managing privacy risks, protecting personal data, and improving privacy governance.
National Institute of Standards and Technology (NIST) • Global • version 1.0
NDPR 2019 — Nigeria Data Protection Regulation
The Nigeria Data Protection Regulation (NDPR) 2019 is Nigeria's data protection framework that establishes requirements for the lawful processing, protection, and transfer of personal data while safeguarding the privacy rights of individuals and promoting responsible data management practices.
Government of Nigeria • Nigeria • v2019
NZISM — New Zealand Information Security Manual
The New Zealand Information Security Manual (NZISM) is the New Zealand Government’s information security framework that provides baseline security controls, processes, and guidance to help organizations protect information systems and manage cybersecurity risks effectively.
New Zealand Government Communications Security Bureau (GCSB) • New Zealand • version 3.9
Nevada Chapter 603A — Security and Privacy of Personal Information
Nevada Chapter 603A - Security and Privacy of Personal Information is a Nevada privacy and data security law that requires organizations to safeguard personal information, notify individuals of certain data breaches, and comply with consumer privacy requirements relating to the collection, use, and protection of personal data.
State of Nevada • Nevada, USA
Maine - An Act To Protect the Privacy of Online Customer Information
This law establishes privacy protections for broadband Internet access service customers in Maine. Providers are prohibited from using, disclosing, selling or allowing access to customer personal information unless explicit consent is given, with certain exceptions for service provision, emergency scenarios, and lawful orders. The law also mandates providers to adopt reasonable security measures for customer data and gives customers rights regarding consent and notification requirements.
Maine Legislature • Maine, USA
Kenya DPA — Kenya Data Protection Act No. 24 OF 2019
The Data Protection Act, 2019 is Kenya’s national data protection law that regulates the processing of personal data, establishes privacy rights for individuals, and sets obligations for organizations to protect personal information through secure and lawful data handling practices.
Government of Kenya • Kenya
Israel - Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001
The Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001 establish Israel's requirements for cross-border transfers of personal data, ensuring that personal information transferred outside Israel remains subject to adequate privacy and data protection safeguards.
Government of Israel • Israel
PP 82/2012 — Indonesia - Peraturan Pemerintah No.82 Tahun 2012 - Government Regulation - Data Protection Regulation
This regulation specifies the requirements for electronic system and transaction operations in Indonesia, including provisions for electronic agents, signatures, certification, and data management. It aims to ensure security, transparency, and accountability in the use and management of electronic systems and information.
Government of the Republic of Indonesia • Indonesia
Hawaii - Security Breach of Personal Information Chapter 487N
Hawaii Security Breach of Personal Information (Chapter 487N) is a Hawaii state law that requires businesses and government agencies to notify affected individuals of data breaches involving personal information and establishes requirements for protecting and managing sensitive personal data.
State of Hawaii • Hawaii
Greece Law 2472/1997 — Greece Law 2472/1997 on the Protection of Individuals with regard to the Processing of Personal Data
Law 2472/1997 is a legal framework from Greece designed to safeguard individual privacy rights in relation to the processing of personal data. It aligns with principles outlined in the EU Charter of Fundamental Rights, specifically addressing data protection and privacy issues.
Government of Greece • Greece
Partner directory
Certified resellers, integrators and advisors to help you implement and manage your GRC program.

1886 Consulting
- Region
- Australia
Tap into our knowledge of wealth.
Governance • Risk Management • Compliance Management • GRC Advisory

19eighty Advisory
- Region
- Australia
Business ownership is the most powerful calling.

3 Lights
- Region
- 4001, Brisbane, Australia
GRC | Information Security | Cyber | Advisory Services | Operations
Risk Management • ISO 27001 • NIST CSF • Essential Eight

3Quotes
- Region
- Canada
Your IT Procurement Partner

A1 Hrvatska d.o.o.
- Region
- Croatia
Croatia's leading telecommunications provider offering mobile, internet, TV, and managed security services.
Managed Security Services • Security Operations • Cloud Security

Accenture
- Region
- Australia
De-risk tomorrow by infusing cybersecurity into strategy, resilience, and protection at global scale.
GRC Advisory • Risk Management • Compliance Management • Security Operations

AfterDark Technology
- Region
- Australia
ISO 27001-certified managed IT services provider keeping Australian businesses secure, reliable, and running.
IT Managed Services • Managed Security Services • Essential Eight • ISO 27001

Archer & Round
- Region
- Australia
Cybersecurity that keeps you one step ahead with 24/7 managed SOC, vCISO, and GRC services.
Managed Security Services • Governance • Risk Management • Incident Response
Ready to manage these frameworks?
6clicks maps regulations to controls, evidence and risks — automatically.