Cyber, critical infrastructure & AI standards — all in one place.
The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.
Browse by industry
Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.
Explore all industriesContent Library
Showing 20 of 86
FedRAMP Controls — FedRAMP Security Controls Baseline rev 5
The FedRAMP Security Controls Baseline is a standardized set of cloud security requirements based on NIST SP 800-53 that defines the minimum security controls cloud service providers must implement to protect federal data and achieve FedRAMP authorization.
US Government • United States • vrev 5
ASIC Act — Australian Securities and Investments Commission Act 2001
This Act establishes the legal framework for the operation of the Australian Securities and Investments Commission (ASIC), which is responsible for regulating company, financial services, and consumer protection laws in Australia. It outlines ASIC's powers, functions, and responsibilities while detailing provisions for consumer protection and fair competition in financial services industries.
Australian Government • Australia • vNo. 91, 1 July 2023
RG 132 — Regulatory Guide 132: Funds management: Compliance and oversight
This regulatory guide outlines compliance and oversight obligations for managed investment schemes, retail and wholesale corporate collective investment vehicles, and other related entities. It helps responsible entities understand their obligations under the Corporations Act and other relevant laws.
Australian Securities & Investments Commission (ASIC) • Australia
RG 78 — Regulatory Guide 78: Breach Reporting by AFS Licensees and Credit Licensees
This guide provides Australian Financial Services (AFS) licensees and credit licensees with instructions on reporting certain legal breaches to ASIC, as required under the Corporations Act 2001 and the National Consumer Credit Protection Act 2009.
Australian Securities and Investments Commission (ASIC) • Australia
RG 205 — Regulatory Guide 205: Credit Licensing: General Conduct Obligations
RG 205 is a regulatory guide issued by ASIC detailing the general conduct obligations for credit licensees, license applicants, and unlicensed carried-over instrument lenders. It helps entities comply with the National Credit Act and outlines specific areas of focus during compliance assessments.
Australian Securities & Investments Commission (ASIC) • Australia
RG 207 — Regulatory Guide 207: Credit licensing: Financial requirements
RG 207 outlines the minimum expectations for Australian credit licensees to comply with the financial resource requirements under the National Consumer Credit Protection Act 2009. It provides guidance on how licensees should demonstrate adequate financial resources to ASIC during license application and annual compliance certification.
Australian Securities & Investments Commission (ASIC) • Australia
RG 206 — Regulatory Guide 206: Credit licensing: Competence and training
Regulatory Guide 206 outlines the minimum expectations for credit licensees in demonstrating organisational competence as required by the National Credit Act. It covers compliance obligations related to qualifications, experience, training, and competence for individuals involved in credit activities.
Australian Securities and Investments Commission (ASIC) • Australia
RG 273 — Regulatory Guide 273: Mortgage brokers: Best interests duty
RG 273 is a regulatory guide issued by ASIC that provides guidance for mortgage brokers and Australian credit licensees on complying with best interests obligations outlined in Part 3-5A of the National Consumer Credit Protection Act 2009. It includes steps to minimize the risk of non-compliance.
Australian Securities & Investments Commission (ASIC) • Australia • v2020
WLA-SCS:2020 — World Lottery Association Security Control Standard 2020
The World Lottery Association Security Control Standard (WLA-SCS:2020) offers a framework specifically designed for the lottery and gaming industry to safeguard information security and ensure operational compliance. It includes guidelines for security management, risk assessments, and audit processes and provides a benchmark for organizations seeking WLA certification.
World Lottery Association • Global • v2020
RG 209 — Regulatory Guide 209 Credit licensing: Responsible lending conduct
RG 209 is a regulatory guide issued by the Australian Securities & Investments Commission (ASIC). It outlines responsible lending obligations for credit licensees and applicants under Chapter 3 of the National Consumer Credit Protection Act 2009, providing steps to ensure compliance and reduce risks.
Australian Securities & Investments Commission (ASIC) • Australia • v2019
CR code v2.1 — Privacy (Credit Reporting) Code 2014 (Version 2.1)
The Privacy (Credit Reporting) Code 2014 (Version 2.1) provides a framework for credit reporting practices under Australia's Privacy Act. It outlines obligations for Credit Reporting Bodies (CRBs), Credit Providers (CPs), and other affected entities to ensure compliance with privacy regulations.
Australian Government • Australia • v2.1
SIS Act — Superannuation Industry (Supervision) Act 1993
The Superannuation Industry (Supervision) Act 1993 establishes the regulatory framework for superannuation funds in Australia. It defines compliance standards for trustees, funds, and associated entities, aiming to ensure proper administration and protection of member benefits.
Australian Government • Australia • vNo. 78, 1993
NCCP Act 2009 — National Consumer Credit Protection Act 2009
The National Consumer Credit Protection Act 2009 is an Australian law that regulates the provision of consumer credit and financial services in the country. It outlines licensing requirements for entities engaged in credit activities and includes protections for consumers against unsuitable credit agreements.
Australian Government • Australia • vNo. 134
RG 96 — Regulatory Guide 96: Debt Collection Guideline: For Collectors and Creditors
This guideline was jointly produced by the Australian Competition and Consumer Commission (ACCC) and the Australian Securities and Investments Commission (ASIC) to outline how Commonwealth consumer protection laws apply to debt collection. It applies to creditors and external agencies involved in debt collection, and provides guidance to debtors.
Australian Securities and Investments Commission (ASIC) • Australia • v13 April 2021
TGISF — Tasmanian Government Information Security Framework
The Tasmanian Government Information Security Framework (TGISF) is a government-wide information security and risk management framework that provides principles, guidelines, and controls to help Tasmanian Government agencies protect information assets and manage security risks effectively.
Tasmanian Government • Tasmania
PSPF 2026 — Protective Security Policy Framework Release 2026
Protective Security Policy Framework (PSPF) Release 2026 is the Australian Government's updated protective security framework that sets mandatory requirements across six security domains to help government entities protect their people, information, assets, and resources through effective risk management and security practices.
Australian Government • Australia • v2026
CAIQ v4.1.0 — Consensus Assessment Initiative Questionnaire v4.1.0
The Consensus Assessments Initiative Questionnaire (CAIQ) v4.1.0 is a comprehensive cloud security assessment questionnaire developed by the Cloud Security Alliance (CSA) and aligned with the Cloud Controls Matrix (CCM) v4.1 to help organizations evaluate the security, privacy, and compliance practices of cloud service providers. It includes 261 assessment questions mapped to 207 controls across 17 security domains, supporting detailed vendor due diligence, third-party risk management, and cloud security assessments using a standardized industry framework.
Cloud Security Alliance (CSA) • v4.1.0
CAIQ Lite v4.1.0 — Consensus Assessments Initiative Questionnaire Lite v4.1.0
Consensus Assessments Initiative Questionnaire (CAIQ) Lite v4.1.0 is a streamlined cloud security assessment questionnaire developed by the Cloud Security Alliance (CSA) and aligned with the Cloud Controls Matrix (CCM) v4.1 to help organizations evaluate cloud service providers using a standardized approach. It includes 138 focused questions across 17 security domains, enabling efficient vendor due diligence, third-party risk management, and security posture assessments.
Cloud Security Alliance (CSA) • v4.1.0
CCM v4.1 — Cloud Controls Matrix v4.1
The Cloud Controls Matrix (CCM) v4.1 is a cybersecurity control framework that consists of 207 controls across 17 security domains, specifically tailored for cloud security and privacy. The Consensus Assessment Initiative Questionnaire (CAIQ) accompanies the CCM, offering a set of assessment questions to evaluate security controls.
Cloud Security Alliance (CSA) • v4.1
ASD Essential 8 Maturity Model - 2023 — Australian Signals Directorate (ASD) Essential Eight Maturity Model 2023
The ASD Essential 8 Maturity Model is a framework developed by the Australian Signals Directorate (ASD) to guide organizations in implementing prioritized cyber security mitigation strategies. It provides structured maturity levels to help organizations progressively strengthen their defenses against common cyber threats. The model ensures consistency, accountability, and resilience by aligning practices across all eight strategies.
Australian Signals Directorate (ASD) • Australia • vNovember 2023
Partner directory
Certified resellers, integrators and advisors to help you implement and manage your GRC program.

1886 Consulting
- Region
- Australia
Tap into our knowledge of wealth.
Governance • Risk Management • Compliance Management • GRC Advisory

19eighty Advisory
- Region
- Australia
Business ownership is the most powerful calling.

3 Lights
- Region
- 4001, Brisbane, Australia
GRC | Information Security | Cyber | Advisory Services | Operations
Risk Management • ISO 27001 • NIST CSF • Essential Eight

3Quotes
- Region
- Canada
Your IT Procurement Partner

A1 Hrvatska d.o.o.
- Region
- Croatia
Croatia's leading telecommunications provider offering mobile, internet, TV, and managed security services.
Managed Security Services • Security Operations • Cloud Security

Accenture
- Region
- Australia
De-risk tomorrow by infusing cybersecurity into strategy, resilience, and protection at global scale.
GRC Advisory • Risk Management • Compliance Management • Security Operations

AfterDark Technology
- Region
- Australia
ISO 27001-certified managed IT services provider keeping Australian businesses secure, reliable, and running.
IT Managed Services • Managed Security Services • Essential Eight • ISO 27001

Archer & Round
- Region
- Australia
Cybersecurity that keeps you one step ahead with 24/7 managed SOC, vCISO, and GRC services.
Managed Security Services • Governance • Risk Management • Incident Response
Ready to manage these frameworks?
6clicks maps regulations to controls, evidence and risks — automatically.