Cyber, critical infrastructure & AI standards — all in one place.
The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.
Browse by industry
Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.
Explore all industriesContent Library
Showing 20 of 78
WLA-SCS:2020 — World Lottery Association Security Control Standard 2020
The World Lottery Association Security Control Standard (WLA-SCS:2020) offers a framework specifically designed for the lottery and gaming industry to safeguard information security and ensure operational compliance. It includes guidelines for security management, risk assessments, and audit processes and provides a benchmark for organizations seeking WLA certification.
World Lottery Association • Global • v2020
ISO 31000 — ISO 31000:2018 Risk management — Guidelines
ISO 31000:2018 is an international standard providing principles and guidelines for risk management across organizations. It outlines processes for identifying, analyzing, evaluating, monitoring, and communicating risks, helping entities manage uncertainty proactively.
International Organization for Standardization (ISO) • v2018
EASA Part-IS — European Union Aviation Safety Agency (EASA) - Part IS - Easy Access Rules for Information Security
The EASA Part-IS Regulation mandates information security measures within the aviation sector to address digital threats that impact safety. It provides a framework for managing risks, responding to incidents, and safeguarding aviation systems.
European Union • EU • vDecember 2025
TGISF — Tasmanian Government Information Security Framework
The Tasmanian Government Information Security Framework (TGISF) is a government-wide information security and risk management framework that provides principles, guidelines, and controls to help Tasmanian Government agencies protect information assets and manage security risks effectively.
Tasmanian Government • Tasmania
PSPF 2026 — Protective Security Policy Framework Release 2026
Protective Security Policy Framework (PSPF) Release 2026 is the Australian Government's updated protective security framework that sets mandatory requirements across six security domains to help government entities protect their people, information, assets, and resources through effective risk management and security practices.
Australian Government • Australia • v2026
SACSF V2.0 — South Australian Cyber Security Framework V2.0
The South Australian Cyber Security Framework (SACSF) is a cybersecurity governance framework developed by Security SA to help South Australian Government agencies manage cyber risks and protect information, systems, and digital services. It consists of 18 policy statements across four core principles—Governance, Information Security, Personnel Security, and Physical Security—and uses a four-tier risk-based approach to implement security controls proportionate to agency risk exposure.
Australian Government • South Australia • v2.0
NIST AI RMF — NIST AI Risk Management Framework
The AI Risk Management Framework (AI RMF) is a voluntary framework developed by NIST to help organizations design, develop, use, and evaluate AI systems with trustworthiness considerations. It addresses governance, mapping, measuring, and managing AI risks.
National Institute of Standards and Technology (NIST) • United States • v1.0
DORA — Regulation (EU) 2022/2554 - Digital Operational Resilience Act
Regulation (EU) 2022/2554, known as DORA, establishes a unified framework for digital operational resilience in the European Union's financial sector. It aims to ensure financial entities can withstand, recover, and adapt to ICT-related disruptions while safeguarding the stability and integrity of the financial system.
European Parliament and Council of the European Union • EU
CCM v4.1 — Cloud Controls Matrix v4.1
The Cloud Controls Matrix (CCM) v4.1 is a cybersecurity control framework that consists of 207 controls across 17 security domains, specifically tailored for cloud security and privacy. The Consensus Assessment Initiative Questionnaire (CAIQ) accompanies the CCM, offering a set of assessment questions to evaluate security controls.
Cloud Security Alliance (CSA) • v4.1
ASD Essential 8 Maturity Model - 2023 — Australian Signals Directorate (ASD) Essential Eight Maturity Model 2023
The ASD Essential 8 Maturity Model is a framework developed by the Australian Signals Directorate (ASD) to guide organizations in implementing prioritized cyber security mitigation strategies. It provides structured maturity levels to help organizations progressively strengthen their defenses against common cyber threats. The model ensures consistency, accountability, and resilience by aligning practices across all eight strategies.
Australian Signals Directorate (ASD) • Australia • vNovember 2023
Cyber Essentials Danzell Question Set — Cyber Essentials Question Set v3.3 (Danzell) April 2026
Cyber Essentials: Requirements for IT Infrastructure v3.3 Question Set is a structured self-assessment designed to help organizations evaluate their cyber security practices. It focuses on five key technical control areas—firewalls, secure configuration, user access control, malware protection, and patch management. By completing the question set, organizations can demonstrate compliance with baseline security standards and strengthen resilience against common cyber threats.
National Cyber Security Centre (NCSC) • v3.3
ISO/IEC 27018:2025 — ISO/IEC 27018:2025 Information security, cybersecurity and privacy protection — Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors
ISO/IEC 27018:2025 is the global standard for managing personally identifiable information (PII) in public cloud services. It provides cloud providers with a framework to ensure privacy, security, and compliance when processing customer data.
International Organization for Standardization (ISO) • v2025
ISM CCM — Information Security Manual Cloud Controls Matrix Template
The Cloud Controls Matrix (CCM) Template is a comprehensive framework for mapping cloud security controls to industry standards and compliance requirements. It helps organizations assess, implement, and demonstrate effective cloud security practices across diverse environments.
Australian Government • Australia • vJune 2026
ISM SSP — Information Security Manual System Security Plan Annex Template
The System Security Plan (SSP) Annex Template is a structured document used to capture detailed information about an organization’s cyber security controls and implementation. It supports accreditation processes by providing evidence of compliance, risk management, and system-specific security measures.
Australian Government • Australia • vJune 2026
RFFR ISM SoA — Right Fit for Risk Information Security Manual Statement of Applicability
The Right Fit for Risk (RFFR) Statement of Applicability (SoA) is a structured template used to document how organizations meet cyber security accreditation requirements. It outlines applicable controls, their implementation status, and provides assurance of compliance with the RFFR framework.
Australian Government • Australia • vJune 2026
ISM — Information Security Manual
The Australian ISM is the nationally recognized cybersecurity framework developed by the Australian Signals Directorate. It provides organizations with structured guidance to safeguard information and operational technology systems against evolving cyber threats.
Australian Government • Australia • vJune 2026
NIPG — National Identity Proofing Guidelines 2025
The National Identity Proofing Guidelines 2025 provide voluntary, risk-based best-practice guidance for verifying an individual's identity, aligned with Digital ID Accreditation Rules to promote consistency across physical and digital identity verification processes. The guidelines support organizations in strengthening identity-proofing practices, increasing trust through a standardized and transparent approach, and enabling more identity verification activities to be conducted online. By leveraging national identity verification services, organizations can reduce the need to store identity document copies, resulting in lower costs, improved privacy, reduced data breach risks, and stronger protection against identity fraud.
Australian Government • Australia
NIST SP 800-53 Rev. 5.2 — Security and Privacy Controls for Information Systems and Organizations
NIST Special Publication 800-53 Rev. 5 provides a comprehensive catalog of security and privacy controls designed to safeguard organizational operations, assets, and individuals from a broad spectrum of risks including cyberattacks, human mistakes, and natural disasters. It is widely used for implementing security measures as part of risk management frameworks.
NIST (National Institute of Standards and Technology) • United States • v5.2.0
AML/CTF Act — Anti-Money Laundering and Counter-Terrorism Financing Act 2006
This is an Australian law established to prevent money laundering and financing of terrorism. It imposes obligations on certain entities to implement anti-money laundering and counter-terrorism financing measures, including customer due diligence, reporting, and record-keeping.
Australian Government • Australia • vCompilation No. 60, 31 March 2026
India - DPDP Rules — India - Digital Personal Data Protection (DPDP) Rules
The Digital Personal Data Protection Rules, 2025 operationalize India’s Digital Personal Data Protection Act, 2023 by establishing detailed requirements for the collection, processing, storage, and protection of digital personal data. The Rules define obligations for organizations handling personal data, including consent management, breach notifications, data retention, and protections for children and vulnerable individuals. They also establish governance mechanisms such as the Data Protection Board and provide a phased implementation timeline for compliance.
Government of India • India • v2025
Partner directory
Certified resellers, integrators and advisors to help you implement and manage your GRC program.

1886 Consulting
- Region
- Australia
Tap into our knowledge of wealth.
Governance • Risk Management • Compliance Management • GRC Advisory

19eighty Advisory
- Region
- Australia
Business ownership is the most powerful calling.

3 Lights
- Region
- 4001, Brisbane, Australia
Finance & Professional Services, Healthcare, Technology & Telecommunications Energy & Utilities
ISO27001 • NIST • SMB1001

3Quotes
- Region
- Canada
Your IT Procurement Partner

A1 Hrvatska d.o.o.
- Region
- Croatia
Croatia's leading telecommunications provider offering mobile, internet, TV, and managed security services.
Managed Security Services • Security Operations • Cloud Security

Accenture
- Region
- Australia
De-risk tomorrow by infusing cybersecurity into strategy, resilience, and protection at global scale.
GRC Advisory • Risk Management • Compliance Management • Security Operations

AfterDark Technology
- Region
- Australia
ISO 27001-certified managed IT services provider keeping Australian businesses secure, reliable, and running.
IT Managed Services • Managed Security Services • Essential Eight • ISO 27001

Archer & Round
- Region
- Australia
Cybersecurity that keeps you one step ahead with 24/7 managed SOC, vCISO, and GRC services.
Managed Security Services • Governance • Risk Management • Incident Response
Ready to manage these frameworks?
6clicks maps regulations to controls, evidence and risks — automatically.