Cyber, critical infrastructure & AI standards — all in one place.
The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.
Browse by industry
Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.
Explore all industriesContent Library
Showing 20 of 75
ITSG-33 — IT Security Risk Management: A Lifecycle Approach (ITSG-33)
ITSG-33 is a guideline developed by the Canadian Centre for Cyber Security to help government departments manage IT security risks effectively. It outlines activities at both departmental and project levels, providing a structured process for integrating security considerations into IT environments and maintaining authorization to operate.
Canadian Centre for Cyber Security • Canada
ESMA Minimum Standard IT Security Controls
The ESMA Minimum Standard IT Security Controls is a cybersecurity and compliance framework that defines the minimum security requirements service providers must implement to protect ESMA systems, applications, data, and information services.
European Securities and Markets Authority (ESMA) • EU
DISP 2020 — Defence Industry Security Program (DISP)– Suitability Assessment (2020)
The Defence Industry Security Program (DISP) is an Australian Defence membership program that helps organizations implement and demonstrate appropriate security controls for participating in Defence projects and managing Defence-related information and assets.
Australian Department of Defence • Australia • v2020
DISP 2022 — Defence Industry Security Program – Suitability Requirements (2022)
The Defence Industry Security Program (DISP) is an Australian Defence security assurance program that helps organizations meet security requirements for Defence contracts and projects by implementing appropriate governance, personnel, physical, and information security controls.
Australian Government • Australia • v2022
Alabama Data Breach Notification Act of 2018 — Chapter 38 Data Breach Notification Act of 2018
The Alabama Data Breach Notification Act of 2018 is a state data protection law that requires organizations to safeguard sensitive personal information, investigate security breaches, and provide timely notification to affected individuals and regulatory authorities when personal data is compromised.
State of Alabama • Alabama, USA • vPolicy 621-01
NDPR 2019 — Nigeria Data Protection Regulation
The Nigeria Data Protection Regulation (NDPR) 2019 is Nigeria's data protection framework that establishes requirements for the lawful processing, protection, and transfer of personal data while safeguarding the privacy rights of individuals and promoting responsible data management practices.
Government of Nigeria • Nigeria • v2019
NZISM — New Zealand Information Security Manual
The New Zealand Information Security Manual (NZISM) is the New Zealand Government’s information security framework that provides baseline security controls, processes, and guidance to help organizations protect information systems and manage cybersecurity risks effectively.
New Zealand Government Communications Security Bureau (GCSB) • New Zealand • version 3.9
DESE ISMS Scheme — DESE Information Security Management Systems (ISMS) Scheme
The DESE ISMS Scheme is an information security certification framework that combines ISO/IEC 27001, the Australian Government Information Security Manual (ISM), and the Right Fit For Risk (RFFR) framework to help service providers manage cyber risks and protect sensitive information.
Australian Department of Employment and Workplace Relations (DEWR) • Australia
Cert NZ Top 10 Critical Controls — Cert New Zealand Top Ten Critical Controls
The CERT NZ Top Ten Critical Controls is a cybersecurity framework that outlines ten essential security controls organizations can implement to reduce cyber risk, improve resilience, and protect systems, data, and services from common cyber attacks.
National Cyber Security Centre (NCSC) • New Zealand • v2021
Spain ENS — Spain - National Security Framework
The National Security Framework (ENS) is Spain's national cybersecurity framework that defines security principles and controls for public sector organizations and their suppliers to protect information systems and ensure the confidentiality, integrity, availability, authenticity, and traceability of digital services.
Government of Spain • Spain • v5 May 2022
BDSG — Germany Federal Data Protection Act
The Federal Data Protection Act (BDSG) is Germany's national data protection law that complements the GDPR by establishing rules for personal data processing, privacy protection, regulatory oversight, and compliance obligations for public and private sector organizations.
v23 June 2021
PPG 511 — Prudential Practice Guide 511 - Remuneration
Prudential Practice Guide (PPG) 511 - Remuneration is APRA guidance that helps regulated institutions design and manage remuneration arrangements that support prudent risk management, strong governance, and sustainable organisational performance.
Australian Prudential Regulation Authority (APRA) • Australia • v30 November 2009
NIST SP 800-172 — Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171
NIST SP 800-172 elaborates enhanced security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations. It aims to mitigate risks posed by Advanced Persistent Threats (APT) through a defense-in-depth approach, building on the foundational requirements in NIST SP 800-171.
National Institute of Standards and Technology (NIST) • United States
Dubai ISR — Dubai Government Information Security Regulation
The Dubai Government Information Security Regulation (ISR) provides standards to ensure the continuity of critical business processes and minimize information security risks for Dubai Government Entities. It defines minimum requirements for information security controls and aims to maintain confidentiality, integrity, and availability of government information.
Dubai Government • Dubai • v3
DSPF — Defence Security Principles Framework
The Defence Security Principles Framework (DSPF) is the Australian Department of Defence's principles-based security framework that provides governance, security principles, and controls to help Defence personnel manage risks and protect Defence people, information, assets, and operations in alignment with the PSPF.
Australian Government • Australia • v2 July 2018
FedRAMP Controls — FedRAMP Security Controls Baseline rev 5
The FedRAMP Security Controls Baseline is a standardized set of cloud security requirements based on NIST SP 800-53 that defines the minimum security controls cloud service providers must implement to protect federal data and achieve FedRAMP authorization.
US Government • United States • vrev 5
CPG 1.0 — Cross-Sector Cybersecurity Performance Goals
The Cross-Sector Cybersecurity Performance Goals (CPGs) are a set of baseline cybersecurity practices developed by CISA to help organizations of all sizes and sectors strengthen their resilience against common cyber threats. They provide prioritized, actionable measures that align with the NIST Cybersecurity Framework and are designed to be achievable, cost-effective, and impactful.
Cybersecurity and Infrastructure Security Agency (CISA) • United States • v1.0.1
WA Cyber Security Policy — Western Australian Government Cyber Security Policy
The 2024 WA Government Cyber Security Policy outlines the baseline requirements for cyber security practices within Western Australian Government entities. It aims to reduce cyber security risks through a comprehensive and systematic approach to safeguarding digital information, information systems, and assets.
Department of the Premier and Cabinet - Office of Digital Government • Western Australia • v2024
CSA IoT Controls v2 — CSA IoT Security Controls Framework v2
The CSA IoT Security Controls Framework v2 provides a structured approach to securing enterprise IoT systems, including connected devices, cloud services, and networking technologies. It is suitable for systems ranging from low-impact data processes to highly sensitive critical services.
Cloud Security Alliance (CSA) • v2
WLA-SCS:2020 — World Lottery Association Security Control Standard 2020
The World Lottery Association Security Control Standard (WLA-SCS:2020) offers a framework specifically designed for the lottery and gaming industry to safeguard information security and ensure operational compliance. It includes guidelines for security management, risk assessments, and audit processes and provides a benchmark for organizations seeking WLA certification.
World Lottery Association • Global • v2020
Partner directory
Certified resellers, integrators and advisors to help you implement and manage your GRC program.

1886 Consulting
- Region
- Australia
Tap into our knowledge of wealth.
Governance • Risk Management • Compliance Management • GRC Advisory

19eighty Advisory
- Region
- Australia
Business ownership is the most powerful calling.

3 Lights
- Region
- 4001, Brisbane, Australia
GRC | Information Security | Cyber | Advisory Services | Operations
Risk Management • ISO 27001 • NIST CSF • Essential Eight

3Quotes
- Region
- Canada
Your IT Procurement Partner

A1 Hrvatska d.o.o.
- Region
- Croatia
Croatia's leading telecommunications provider offering mobile, internet, TV, and managed security services.
Managed Security Services • Security Operations • Cloud Security

Accenture
- Region
- Australia
De-risk tomorrow by infusing cybersecurity into strategy, resilience, and protection at global scale.
GRC Advisory • Risk Management • Compliance Management • Security Operations

AfterDark Technology
- Region
- Australia
ISO 27001-certified managed IT services provider keeping Australian businesses secure, reliable, and running.
IT Managed Services • Managed Security Services • Essential Eight • ISO 27001

Archer & Round
- Region
- Australia
Cybersecurity that keeps you one step ahead with 24/7 managed SOC, vCISO, and GRC services.
Managed Security Services • Governance • Risk Management • Incident Response
Ready to manage these frameworks?
6clicks maps regulations to controls, evidence and risks — automatically.