Cyber, critical infrastructure & AI standards — all in one place.
The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.
Browse by industry
Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.
Explore all industriesContent Library
Showing 20 of 145
CPG 1.0 — Cross-Sector Cybersecurity Performance Goals
The Cross-Sector Cybersecurity Performance Goals (CPGs) are a set of baseline cybersecurity practices developed by CISA to help organizations of all sizes and sectors strengthen their resilience against common cyber threats. They provide prioritized, actionable measures that align with the NIST Cybersecurity Framework and are designed to be achievable, cost-effective, and impactful.
Cybersecurity and Infrastructure Security Agency (CISA) • United States • v1.0.1
ASIC Act — Australian Securities and Investments Commission Act 2001
This Act establishes the legal framework for the operation of the Australian Securities and Investments Commission (ASIC), which is responsible for regulating company, financial services, and consumer protection laws in Australia. It outlines ASIC's powers, functions, and responsibilities while detailing provisions for consumer protection and fair competition in financial services industries.
Australian Government • Australia • vNo. 91, 1 July 2023
WA Cyber Security Policy — Western Australian Government Cyber Security Policy
The 2024 WA Government Cyber Security Policy outlines the baseline requirements for cyber security practices within Western Australian Government entities. It aims to reduce cyber security risks through a comprehensive and systematic approach to safeguarding digital information, information systems, and assets.
Department of the Premier and Cabinet - Office of Digital Government • Western Australia • v2024
CSA IoT Controls v2 — CSA IoT Security Controls Framework v2
The CSA IoT Security Controls Framework v2 provides a structured approach to securing enterprise IoT systems, including connected devices, cloud services, and networking technologies. It is suitable for systems ranging from low-impact data processes to highly sensitive critical services.
Cloud Security Alliance (CSA) • v2
Anti-Discrimination Act 1991 (Qld) — Queensland Anti-Discrimination Act 1991
The Anti-Discrimination Act 1991 is legislation enacted by the Queensland Government to promote equality of opportunity, prohibit discrimination, and encourage tolerance in the state of Queensland, Australia. It covers areas such as work, education, and the provision of goods and services.
Queensland Government • Queensland
RG 132 — Regulatory Guide 132: Funds management: Compliance and oversight
This regulatory guide outlines compliance and oversight obligations for managed investment schemes, retail and wholesale corporate collective investment vehicles, and other related entities. It helps responsible entities understand their obligations under the Corporations Act and other relevant laws.
Australian Securities & Investments Commission (ASIC) • Australia
RG 78 — Regulatory Guide 78: Breach Reporting by AFS Licensees and Credit Licensees
This guide provides Australian Financial Services (AFS) licensees and credit licensees with instructions on reporting certain legal breaches to ASIC, as required under the Corporations Act 2001 and the National Consumer Credit Protection Act 2009.
Australian Securities and Investments Commission (ASIC) • Australia
RG 205 — Regulatory Guide 205: Credit Licensing: General Conduct Obligations
RG 205 is a regulatory guide issued by ASIC detailing the general conduct obligations for credit licensees, license applicants, and unlicensed carried-over instrument lenders. It helps entities comply with the National Credit Act and outlines specific areas of focus during compliance assessments.
Australian Securities & Investments Commission (ASIC) • Australia
RG 207 — Regulatory Guide 207: Credit licensing: Financial requirements
RG 207 outlines the minimum expectations for Australian credit licensees to comply with the financial resource requirements under the National Consumer Credit Protection Act 2009. It provides guidance on how licensees should demonstrate adequate financial resources to ASIC during license application and annual compliance certification.
Australian Securities & Investments Commission (ASIC) • Australia
RG 206 — Regulatory Guide 206: Credit licensing: Competence and training
Regulatory Guide 206 outlines the minimum expectations for credit licensees in demonstrating organisational competence as required by the National Credit Act. It covers compliance obligations related to qualifications, experience, training, and competence for individuals involved in credit activities.
Australian Securities and Investments Commission (ASIC) • Australia
RG 273 — Regulatory Guide 273: Mortgage brokers: Best interests duty
RG 273 is a regulatory guide issued by ASIC that provides guidance for mortgage brokers and Australian credit licensees on complying with best interests obligations outlined in Part 3-5A of the National Consumer Credit Protection Act 2009. It includes steps to minimize the risk of non-compliance.
Australian Securities & Investments Commission (ASIC) • Australia • v2020
WLA-SCS:2020 — World Lottery Association Security Control Standard 2020
The World Lottery Association Security Control Standard (WLA-SCS:2020) offers a framework specifically designed for the lottery and gaming industry to safeguard information security and ensure operational compliance. It includes guidelines for security management, risk assessments, and audit processes and provides a benchmark for organizations seeking WLA certification.
World Lottery Association • Global • v2020
RG 210 — Regulatory Guide 210: Compensation and Insurance Arrangements for Credit Licensees
ASIC Regulatory Guide 210 outlines the compensation and insurance arrangements required for credit licensees in Australia. It primarily mandates professional indemnity insurance to ensure financial resources are available for consumer compensation claims.
Australian Securities and Investments Commission (ASIC) • Australia • vMarch 2010
RG 209 — Regulatory Guide 209 Credit licensing: Responsible lending conduct
RG 209 is a regulatory guide issued by the Australian Securities & Investments Commission (ASIC). It outlines responsible lending obligations for credit licensees and applicants under Chapter 3 of the National Consumer Credit Protection Act 2009, providing steps to ensure compliance and reduce risks.
Australian Securities & Investments Commission (ASIC) • Australia • v2019
CR code v2.1 — Privacy (Credit Reporting) Code 2014 (Version 2.1)
The Privacy (Credit Reporting) Code 2014 (Version 2.1) provides a framework for credit reporting practices under Australia's Privacy Act. It outlines obligations for Credit Reporting Bodies (CRBs), Credit Providers (CPs), and other affected entities to ensure compliance with privacy regulations.
Australian Government • Australia • v2.1
NCCP Regulations — National Consumer Credit Protection Regulations 2010
This regulation provides detailed requirements under the National Consumer Credit Protection Act 2009 to govern the licensing, responsible lending, credit contracts, and compliance monitoring for entities providing credit services in Australia. It aims to ensure transparency and protection for consumers in financial and credit transactions.
Australian Government • Australia • v2021-12
ISO 31000 — ISO 31000:2018 Risk management — Guidelines
ISO 31000:2018 is an international standard providing principles and guidelines for risk management across organizations. It outlines processes for identifying, analyzing, evaluating, monitoring, and communicating risks, helping entities manage uncertainty proactively.
International Organization for Standardization (ISO) • v2018
SIS Act — Superannuation Industry (Supervision) Act 1993
The Superannuation Industry (Supervision) Act 1993 establishes the regulatory framework for superannuation funds in Australia. It defines compliance standards for trustees, funds, and associated entities, aiming to ensure proper administration and protection of member benefits.
Australian Government • Australia • vNo. 78, 1993
POPIA — Protection of Personal Information Act
The Protection of Personal Information Act (POPIA) is South African legislation that governs the lawful processing of personal information. It establishes principles and rights for data subjects, conditions for processing, obligations for responsible parties, and enforcement mechanisms.
Government of South Africa • South Africa
EASA Part-IS — European Union Aviation Safety Agency (EASA) - Part IS - Easy Access Rules for Information Security
The EASA Part-IS Regulation mandates information security measures within the aviation sector to address digital threats that impact safety. It provides a framework for managing risks, responding to incidents, and safeguarding aviation systems.
European Union • EU • vDecember 2025
Ready to manage these frameworks?
6clicks maps regulations to controls, evidence and risks — automatically.