Cyber, critical infrastructure & AI standards — all in one place.

The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.

Browse by industry

Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.

Explore all industries

Content Library

Showing 20 of 75

CybersecurityControl setGuideline

ITSG-33 — IT Security Risk Management: A Lifecycle Approach (ITSG-33)

ITSG-33 is a guideline developed by the Canadian Centre for Cyber Security to help government departments manage IT security risks effectively. It outlines activities at both departmental and project levels, providing a structured process for integrating security considerations into IT environments and maintaining authorization to operate.

Canadian Centre for Cyber Security • Canada

View details
CybersecurityStandard

ESMA Minimum Standard IT Security Controls

The ESMA Minimum Standard IT Security Controls is a cybersecurity and compliance framework that defines the minimum security requirements service providers must implement to protect ESMA systems, applications, data, and information services.

European Securities and Markets Authority (ESMA) • EU

View details
CybersecurityStandardFramework

DISP 2020 — Defence Industry Security Program (DISP)– Suitability Assessment (2020)

The Defence Industry Security Program (DISP) is an Australian Defence membership program that helps organizations implement and demonstrate appropriate security controls for participating in Defence projects and managing Defence-related information and assets.

Australian Department of Defence • Australia • v2020

View details
CybersecurityStandardFramework

DISP 2022 — Defence Industry Security Program – Suitability Requirements (2022)

The Defence Industry Security Program (DISP) is an Australian Defence security assurance program that helps organizations meet security requirements for Defence contracts and projects by implementing appropriate governance, personnel, physical, and information security controls.

Australian Government • Australia • v2022

View details
CybersecurityLaw

Alabama Data Breach Notification Act of 2018 — Chapter 38 Data Breach Notification Act of 2018

The Alabama Data Breach Notification Act of 2018 is a state data protection law that requires organizations to safeguard sensitive personal information, investigate security breaches, and provide timely notification to affected individuals and regulatory authorities when personal data is compromised.

State of Alabama • Alabama, USA • vPolicy 621-01

View details
CybersecurityLaw

NDPR 2019 — Nigeria Data Protection Regulation

The Nigeria Data Protection Regulation (NDPR) 2019 is Nigeria's data protection framework that establishes requirements for the lawful processing, protection, and transfer of personal data while safeguarding the privacy rights of individuals and promoting responsible data management practices.

Government of Nigeria • Nigeria • v2019

View details
CybersecurityStandard

NZISM — New Zealand Information Security Manual

The New Zealand Information Security Manual (NZISM) is the New Zealand Government’s information security framework that provides baseline security controls, processes, and guidance to help organizations protect information systems and manage cybersecurity risks effectively.

New Zealand Government Communications Security Bureau (GCSB) • New Zealand • version 3.9

View details
CybersecurityFramework

DESE ISMS Scheme — DESE Information Security Management Systems (ISMS) Scheme

The DESE ISMS Scheme is an information security certification framework that combines ISO/IEC 27001, the Australian Government Information Security Manual (ISM), and the Right Fit For Risk (RFFR) framework to help service providers manage cyber risks and protect sensitive information.

Australian Department of Employment and Workplace Relations (DEWR) • Australia

View details
CybersecurityStandard

Cert NZ Top 10 Critical Controls — Cert New Zealand Top Ten Critical Controls

The CERT NZ Top Ten Critical Controls is a cybersecurity framework that outlines ten essential security controls organizations can implement to reduce cyber risk, improve resilience, and protect systems, data, and services from common cyber attacks.

National Cyber Security Centre (NCSC) • New Zealand • v2021

View details
CybersecurityFramework

Spain ENS — Spain - National Security Framework

The National Security Framework (ENS) is Spain's national cybersecurity framework that defines security principles and controls for public sector organizations and their suppliers to protect information systems and ensure the confidentiality, integrity, availability, authenticity, and traceability of digital services.

Government of Spain • Spain • v5 May 2022

View details
CybersecurityLaw

BDSG — Germany Federal Data Protection Act

The Federal Data Protection Act (BDSG) is Germany's national data protection law that complements the GDPR by establishing rules for personal data processing, privacy protection, regulatory oversight, and compliance obligations for public and private sector organizations.

v23 June 2021

View details
CybersecurityGuideline

PPG 511 — Prudential Practice Guide 511 - Remuneration

Prudential Practice Guide (PPG) 511 - Remuneration is APRA guidance that helps regulated institutions design and manage remuneration arrangements that support prudent risk management, strong governance, and sustainable organisational performance.

Australian Prudential Regulation Authority (APRA) • Australia • v30 November 2009

View details
CybersecurityGuideline

NIST SP 800-172 — Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171

NIST SP 800-172 elaborates enhanced security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations. It aims to mitigate risks posed by Advanced Persistent Threats (APT) through a defense-in-depth approach, building on the foundational requirements in NIST SP 800-171.

National Institute of Standards and Technology (NIST) • United States

View details
CybersecurityRegulation

Dubai ISR — Dubai Government Information Security Regulation

The Dubai Government Information Security Regulation (ISR) provides standards to ensure the continuity of critical business processes and minimize information security risks for Dubai Government Entities. It defines minimum requirements for information security controls and aims to maintain confidentiality, integrity, and availability of government information.

Dubai Government • Dubai • v3

View details
CybersecurityFramework

DSPF — Defence Security Principles Framework

The Defence Security Principles Framework (DSPF) is the Australian Department of Defence's principles-based security framework that provides governance, security principles, and controls to help Defence personnel manage risks and protect Defence people, information, assets, and operations in alignment with the PSPF.

Australian Government • Australia • v2 July 2018

View details
CybersecurityStandard

FedRAMP Controls — FedRAMP Security Controls Baseline rev 5

The FedRAMP Security Controls Baseline is a standardized set of cloud security requirements based on NIST SP 800-53 that defines the minimum security controls cloud service providers must implement to protect federal data and achieve FedRAMP authorization.

US Government • United States • vrev 5

View details
CybersecurityFramework

CPG 1.0 — Cross-Sector Cybersecurity Performance Goals

The Cross-Sector Cybersecurity Performance Goals (CPGs) are a set of baseline cybersecurity practices developed by CISA to help organizations of all sizes and sectors strengthen their resilience against common cyber threats. They provide prioritized, actionable measures that align with the NIST Cybersecurity Framework and are designed to be achievable, cost-effective, and impactful.

Cybersecurity and Infrastructure Security Agency (CISA) • United States • v1.0.1

View details
CybersecurityGuideline

WA Cyber Security Policy — Western Australian Government Cyber Security Policy

The 2024 WA Government Cyber Security Policy outlines the baseline requirements for cyber security practices within Western Australian Government entities. It aims to reduce cyber security risks through a comprehensive and systematic approach to safeguarding digital information, information systems, and assets.

Department of the Premier and Cabinet - Office of Digital Government • Western Australia • v2024

View details
CybersecurityFramework

CSA IoT Controls v2 — CSA IoT Security Controls Framework v2

The CSA IoT Security Controls Framework v2 provides a structured approach to securing enterprise IoT systems, including connected devices, cloud services, and networking technologies. It is suitable for systems ranging from low-impact data processes to highly sensitive critical services.

Cloud Security Alliance (CSA) • v2

View details
CybersecurityStandard

WLA-SCS:2020 — World Lottery Association Security Control Standard 2020

The World Lottery Association Security Control Standard (WLA-SCS:2020) offers a framework specifically designed for the lottery and gaming industry to safeguard information security and ensure operational compliance. It includes guidelines for security management, risk assessments, and audit processes and provides a benchmark for organizations seeking WLA certification.

World Lottery Association • Global • v2020

View details

Partner directory

Certified resellers, integrators and advisors to help you implement and manage your GRC program.

Explore all partners (88)

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call