Cyber, critical infrastructure & AI standards — all in one place.
The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.
Browse by industry
Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.
Explore all industriesContent Library
Showing 20 of 80
ITSG-33 — IT Security Risk Management: A Lifecycle Approach (ITSG-33)
ITSG-33 is a guideline developed by the Canadian Centre for Cyber Security to help government departments manage IT security risks effectively. It outlines activities at both departmental and project levels, providing a structured process for integrating security considerations into IT environments and maintaining authorization to operate.
Canadian Centre for Cyber Security • Canada
ISO 9001:2026 QMS — ISO 9001:2026 Quality Management Systems (QMS)
ISO 9001:2026 Quality Management Systems (QMS) is an internationally recognized standard that specifies requirements for establishing, implementing, maintaining, and continually improving a quality management system. It helps organizations consistently deliver products and services that meet customer, regulatory, and stakeholder requirements while enhancing operational performance and customer satisfaction. Applicable to organizations of all sizes and sectors, ISO 9001:2026 promotes a process-based approach, risk management, continual improvement, and a strong focus on quality outcomes.
International Organization for Standardization (ISO) • Global • vEdition 6, 2026
NDIS Practice Standards and Quality Indicators v4
The NDIS Practice Standards and Quality Indicators v4 is Australia's quality and compliance framework for registered NDIS providers, defining the standards and quality indicators required to deliver safe, person-centred, and high-quality disability supports and services.
NDIS Quality and Safeguards Commission • Australia • v4
NDIS SIL Module — NDIS Supported Independent Living Module
The NDIS Supported Independent Living (SIL) Module is a supplementary NDIS Practice Standards module that sets quality and safety requirements for providers delivering Supported Independent Living services, ensuring participants receive person-centred supports that promote independence, choice, inclusion, and wellbeing.
NDIS Quality and Safeguards Commission • Australia
CCC-2: 2024 — Cloud Cybersecurity Controls
The Cloud Cybersecurity Controls (CCC – 2: 2024) define minimum cybersecurity requirements for cloud computing services used by Cloud Service Providers (CSPs) and Cloud Service Tenants (CSTs) in Saudi Arabia. The controls aim to enhance national cybersecurity goals and mitigate cyber risks.
National Cybersecurity Authority (NCA) • Saudi Arabia • v2: 2024
OTCC-1:2022 — Operational Technology Cybersecurity Controls
The Operational Technology Cybersecurity Controls (OTCC-1:2022), developed by Saudi Arabia’s National Cybersecurity Authority (NCA), establish minimum cybersecurity requirements for Operational Technology (OT) and Industrial Control Systems (ICS) environments. The framework aims to protect critical infrastructure from cyber threats and enhance operational resilience, safety, and security. OTCC consists of 4 domains, 23 subdomains, 47 controls, and 122 sub-controls, with requirements categorized across three control levels (L1, L2, and L3) based on facility criticality and risk.
National Cybersecurity Authority (NCA) • Saudi Arabia • v2022
ESMA Minimum Standard IT Security Controls
The ESMA Minimum Standard IT Security Controls is a cybersecurity and compliance framework that defines the minimum security requirements service providers must implement to protect ESMA systems, applications, data, and information services.
European Securities and Markets Authority (ESMA) • EU
DISP 2020 — Defence Industry Security Program (DISP)– Suitability Assessment (2020)
The Defence Industry Security Program (DISP) is an Australian Defence membership program that helps organizations implement and demonstrate appropriate security controls for participating in Defence projects and managing Defence-related information and assets.
Australian Department of Defence • Australia • v2020
DISP 2022 — Defence Industry Security Program – Suitability Requirements (2022)
The Defence Industry Security Program (DISP) is an Australian Defence security assurance program that helps organizations meet security requirements for Defence contracts and projects by implementing appropriate governance, personnel, physical, and information security controls.
Australian Government • Australia • v2022
Alabama Data Breach Notification Act of 2018 — Chapter 38 Data Breach Notification Act of 2018
The Alabama Data Breach Notification Act of 2018 is a state data protection law that requires organizations to safeguard sensitive personal information, investigate security breaches, and provide timely notification to affected individuals and regulatory authorities when personal data is compromised.
State of Alabama • Alabama, USA • vPolicy 621-01
NDPR 2019 — Nigeria Data Protection Regulation
The Nigeria Data Protection Regulation (NDPR) 2019 is Nigeria's data protection framework that establishes requirements for the lawful processing, protection, and transfer of personal data while safeguarding the privacy rights of individuals and promoting responsible data management practices.
Government of Nigeria • Nigeria • v2019
NZISM — New Zealand Information Security Manual
The New Zealand Information Security Manual (NZISM) is the New Zealand Government’s information security framework that provides baseline security controls, processes, and guidance to help organizations protect information systems and manage cybersecurity risks effectively.
New Zealand Government Communications Security Bureau (GCSB) • New Zealand • version 3.9
DESE ISMS Scheme — DESE Information Security Management Systems (ISMS) Scheme
The DESE ISMS Scheme is an information security certification framework that combines ISO/IEC 27001, the Australian Government Information Security Manual (ISM), and the Right Fit For Risk (RFFR) framework to help service providers manage cyber risks and protect sensitive information.
Australian Department of Employment and Workplace Relations (DEWR) • Australia
Cert NZ Top 10 Critical Controls — Cert New Zealand Top Ten Critical Controls
The CERT NZ Top Ten Critical Controls is a cybersecurity framework that outlines ten essential security controls organizations can implement to reduce cyber risk, improve resilience, and protect systems, data, and services from common cyber attacks.
National Cyber Security Centre (NCSC) • New Zealand • v2021
Spain ENS — Spain - National Security Framework
The National Security Framework (ENS) is Spain's national cybersecurity framework that defines security principles and controls for public sector organizations and their suppliers to protect information systems and ensure the confidentiality, integrity, availability, authenticity, and traceability of digital services.
Government of Spain • Spain • v5 May 2022
BDSG — Germany Federal Data Protection Act
The Federal Data Protection Act (BDSG) is Germany's national data protection law that complements the GDPR by establishing rules for personal data processing, privacy protection, regulatory oversight, and compliance obligations for public and private sector organizations.
v23 June 2021
PPG 511 — Prudential Practice Guide 511 - Remuneration
Prudential Practice Guide (PPG) 511 - Remuneration is APRA guidance that helps regulated institutions design and manage remuneration arrangements that support prudent risk management, strong governance, and sustainable organisational performance.
Australian Prudential Regulation Authority (APRA) • Australia • v30 November 2009
NIST SP 800-172 — Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171
NIST SP 800-172 elaborates enhanced security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations. It aims to mitigate risks posed by Advanced Persistent Threats (APT) through a defense-in-depth approach, building on the foundational requirements in NIST SP 800-171.
National Institute of Standards and Technology (NIST) • United States
Dubai ISR — Dubai Government Information Security Regulation
The Dubai Government Information Security Regulation (ISR) provides standards to ensure the continuity of critical business processes and minimize information security risks for Dubai Government Entities. It defines minimum requirements for information security controls and aims to maintain confidentiality, integrity, and availability of government information.
Dubai Government • Dubai • v3
DSPF — Defence Security Principles Framework
The Defence Security Principles Framework (DSPF) is the Australian Department of Defence's principles-based security framework that provides governance, security principles, and controls to help Defence personnel manage risks and protect Defence people, information, assets, and operations in alignment with the PSPF.
Australian Government • Australia • v2 July 2018
Partner directory
Certified resellers, integrators and advisors to help you implement and manage your GRC program.

1886 Consulting
- Region
- Australia
Tap into our knowledge of wealth.
Governance • Risk Management • Compliance Management • GRC Advisory

19eighty Advisory
- Region
- Australia
Business ownership is the most powerful calling.

3 Lights
- Region
- 4001, Brisbane, Australia
Finance & Professional Services, Healthcare, Technology & Telecommunications Energy & Utilities
ISO27001 • NIST • SMB1001

3Quotes
- Region
- Canada
Your IT Procurement Partner

A1 Hrvatska d.o.o.
- Region
- Croatia
Croatia's leading telecommunications provider offering mobile, internet, TV, and managed security services.
Managed Security Services • Security Operations • Cloud Security

Accenture
- Region
- Australia
De-risk tomorrow by infusing cybersecurity into strategy, resilience, and protection at global scale.
GRC Advisory • Risk Management • Compliance Management • Security Operations

AfterDark Technology
- Region
- Australia
ISO 27001-certified managed IT services provider keeping Australian businesses secure, reliable, and running.
IT Managed Services • Managed Security Services • Essential Eight • ISO 27001

Archer & Round
- Region
- Australia
Cybersecurity that keeps you one step ahead with 24/7 managed SOC, vCISO, and GRC services.
Managed Security Services • Governance • Risk Management • Incident Response
Ready to manage these frameworks?
6clicks maps regulations to controls, evidence and risks — automatically.