Cyber, critical infrastructure & AI standards — all in one place.

The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.

Browse by industry

Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.

Explore all industries

Content Library

Showing 20 of 145

CybersecurityFramework

CPG 1.0 — Cross-Sector Cybersecurity Performance Goals

The Cross-Sector Cybersecurity Performance Goals (CPGs) are a set of baseline cybersecurity practices developed by CISA to help organizations of all sizes and sectors strengthen their resilience against common cyber threats. They provide prioritized, actionable measures that align with the NIST Cybersecurity Framework and are designed to be achievable, cost-effective, and impactful.

Cybersecurity and Infrastructure Security Agency (CISA) • United States • v1.0.1

View details
GRCLaw

ASIC Act — Australian Securities and Investments Commission Act 2001

This Act establishes the legal framework for the operation of the Australian Securities and Investments Commission (ASIC), which is responsible for regulating company, financial services, and consumer protection laws in Australia. It outlines ASIC's powers, functions, and responsibilities while detailing provisions for consumer protection and fair competition in financial services industries.

Australian Government • Australia • vNo. 91, 1 July 2023

View details
CybersecurityGuideline

WA Cyber Security Policy — Western Australian Government Cyber Security Policy

The 2024 WA Government Cyber Security Policy outlines the baseline requirements for cyber security practices within Western Australian Government entities. It aims to reduce cyber security risks through a comprehensive and systematic approach to safeguarding digital information, information systems, and assets.

Department of the Premier and Cabinet - Office of Digital Government • Western Australia • v2024

View details
CybersecurityFramework

CSA IoT Controls v2 — CSA IoT Security Controls Framework v2

The CSA IoT Security Controls Framework v2 provides a structured approach to securing enterprise IoT systems, including connected devices, cloud services, and networking technologies. It is suitable for systems ranging from low-impact data processes to highly sensitive critical services.

Cloud Security Alliance (CSA) • v2

View details
PrivacyLaw

Anti-Discrimination Act 1991 (Qld) — Queensland Anti-Discrimination Act 1991

The Anti-Discrimination Act 1991 is legislation enacted by the Queensland Government to promote equality of opportunity, prohibit discrimination, and encourage tolerance in the state of Queensland, Australia. It covers areas such as work, education, and the provision of goods and services.

Queensland Government • Queensland

View details
GRCGuideline

RG 132 — Regulatory Guide 132: Funds management: Compliance and oversight

This regulatory guide outlines compliance and oversight obligations for managed investment schemes, retail and wholesale corporate collective investment vehicles, and other related entities. It helps responsible entities understand their obligations under the Corporations Act and other relevant laws.

Australian Securities & Investments Commission (ASIC) • Australia

View details
GRCGuideline

RG 78 — Regulatory Guide 78: Breach Reporting by AFS Licensees and Credit Licensees

This guide provides Australian Financial Services (AFS) licensees and credit licensees with instructions on reporting certain legal breaches to ASIC, as required under the Corporations Act 2001 and the National Consumer Credit Protection Act 2009.

Australian Securities and Investments Commission (ASIC) • Australia

View details
GRCGuideline

RG 205 — Regulatory Guide 205: Credit Licensing: General Conduct Obligations

RG 205 is a regulatory guide issued by ASIC detailing the general conduct obligations for credit licensees, license applicants, and unlicensed carried-over instrument lenders. It helps entities comply with the National Credit Act and outlines specific areas of focus during compliance assessments.

Australian Securities & Investments Commission (ASIC) • Australia

View details
GRCGuideline

RG 207 — Regulatory Guide 207: Credit licensing: Financial requirements

RG 207 outlines the minimum expectations for Australian credit licensees to comply with the financial resource requirements under the National Consumer Credit Protection Act 2009. It provides guidance on how licensees should demonstrate adequate financial resources to ASIC during license application and annual compliance certification.

Australian Securities & Investments Commission (ASIC) • Australia

View details
GRCGuideline

RG 206 — Regulatory Guide 206: Credit licensing: Competence and training

Regulatory Guide 206 outlines the minimum expectations for credit licensees in demonstrating organisational competence as required by the National Credit Act. It covers compliance obligations related to qualifications, experience, training, and competence for individuals involved in credit activities.

Australian Securities and Investments Commission (ASIC) • Australia

View details
GRCGuideline

RG 273 — Regulatory Guide 273: Mortgage brokers: Best interests duty

RG 273 is a regulatory guide issued by ASIC that provides guidance for mortgage brokers and Australian credit licensees on complying with best interests obligations outlined in Part 3-5A of the National Consumer Credit Protection Act 2009. It includes steps to minimize the risk of non-compliance.

Australian Securities & Investments Commission (ASIC) • Australia • v2020

View details
CybersecurityStandard

WLA-SCS:2020 — World Lottery Association Security Control Standard 2020

The World Lottery Association Security Control Standard (WLA-SCS:2020) offers a framework specifically designed for the lottery and gaming industry to safeguard information security and ensure operational compliance. It includes guidelines for security management, risk assessments, and audit processes and provides a benchmark for organizations seeking WLA certification.

World Lottery Association • Global • v2020

View details
GRCGuideline

RG 210 — Regulatory Guide 210: Compensation and Insurance Arrangements for Credit Licensees

ASIC Regulatory Guide 210 outlines the compensation and insurance arrangements required for credit licensees in Australia. It primarily mandates professional indemnity insurance to ensure financial resources are available for consumer compensation claims.

Australian Securities and Investments Commission (ASIC) • Australia • vMarch 2010

View details
GRCGuideline

RG 209 — Regulatory Guide 209 Credit licensing: Responsible lending conduct

RG 209 is a regulatory guide issued by the Australian Securities & Investments Commission (ASIC). It outlines responsible lending obligations for credit licensees and applicants under Chapter 3 of the National Consumer Credit Protection Act 2009, providing steps to ensure compliance and reduce risks.

Australian Securities & Investments Commission (ASIC) • Australia • v2019

View details
PrivacyRegulation

CR code v2.1 — Privacy (Credit Reporting) Code 2014 (Version 2.1)

The Privacy (Credit Reporting) Code 2014 (Version 2.1) provides a framework for credit reporting practices under Australia's Privacy Act. It outlines obligations for Credit Reporting Bodies (CRBs), Credit Providers (CPs), and other affected entities to ensure compliance with privacy regulations.

Australian Government • Australia • v2.1

View details
GRCRegulation

NCCP Regulations — National Consumer Credit Protection Regulations 2010

This regulation provides detailed requirements under the National Consumer Credit Protection Act 2009 to govern the licensing, responsible lending, credit contracts, and compliance monitoring for entities providing credit services in Australia. It aims to ensure transparency and protection for consumers in financial and credit transactions.

Australian Government • Australia • v2021-12

View details
GRCStandard

ISO 31000 — ISO 31000:2018 Risk management — Guidelines

ISO 31000:2018 is an international standard providing principles and guidelines for risk management across organizations. It outlines processes for identifying, analyzing, evaluating, monitoring, and communicating risks, helping entities manage uncertainty proactively.

International Organization for Standardization (ISO) • v2018

View details
GRCLaw

SIS Act — Superannuation Industry (Supervision) Act 1993

The Superannuation Industry (Supervision) Act 1993 establishes the regulatory framework for superannuation funds in Australia. It defines compliance standards for trustees, funds, and associated entities, aiming to ensure proper administration and protection of member benefits.

Australian Government • Australia • vNo. 78, 1993

View details
PrivacyLaw

POPIA — Protection of Personal Information Act

The Protection of Personal Information Act (POPIA) is South African legislation that governs the lawful processing of personal information. It establishes principles and rights for data subjects, conditions for processing, obligations for responsible parties, and enforcement mechanisms.

Government of South Africa • South Africa

View details
Critical InfrastructureRegulation

EASA Part-IS — European Union Aviation Safety Agency (EASA) - Part IS - Easy Access Rules for Information Security

The EASA Part-IS Regulation mandates information security measures within the aviation sector to address digital threats that impact safety. It provides a framework for managing risks, responding to incidents, and safeguarding aviation systems.

European Union • EU • vDecember 2025

View details

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call