Cyber, critical infrastructure & AI standards — all in one place.

The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.

Browse by industry

Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.

Explore all industries

Content Library

Showing 20 of 170

GRCRegulation

NCCP Regulations — National Consumer Credit Protection Regulations 2010

This regulation provides detailed requirements under the National Consumer Credit Protection Act 2009 to govern the licensing, responsible lending, credit contracts, and compliance monitoring for entities providing credit services in Australia. It aims to ensure transparency and protection for consumers in financial and credit transactions.

Australian Government • Australia • v2021-12

View details
GRCStandard

ISO 31000 — ISO 31000:2018 Risk management — Guidelines

ISO 31000:2018 is an international standard providing principles and guidelines for risk management across organizations. It outlines processes for identifying, analyzing, evaluating, monitoring, and communicating risks, helping entities manage uncertainty proactively.

International Organization for Standardization (ISO) • v2018

View details
GRCLaw

SIS Act — Superannuation Industry (Supervision) Act 1993

The Superannuation Industry (Supervision) Act 1993 establishes the regulatory framework for superannuation funds in Australia. It defines compliance standards for trustees, funds, and associated entities, aiming to ensure proper administration and protection of member benefits.

Australian Government • Australia • vNo. 78, 1993

View details
PrivacyLaw

POPIA — Protection of Personal Information Act

The Protection of Personal Information Act (POPIA) is South African legislation that governs the lawful processing of personal information. It establishes principles and rights for data subjects, conditions for processing, obligations for responsible parties, and enforcement mechanisms.

Government of South Africa • South Africa

View details
Critical InfrastructureRegulation

EASA Part-IS — European Union Aviation Safety Agency (EASA) - Part IS - Easy Access Rules for Information Security

The EASA Part-IS Regulation mandates information security measures within the aviation sector to address digital threats that impact safety. It provides a framework for managing risks, responding to incidents, and safeguarding aviation systems.

European Union • EU • vDecember 2025

View details
PrivacyRegulation

FCA BCOBS — Banking: Conduct of Business Sourcebook (BCOBS)

The FCA's Banking: Conduct of Business Sourcebook (BCOBS) applies to firms accepting deposits from banking customers, focusing on protecting retail customers in banking and payment services. It includes key recordkeeping requirements, such as notifications of cancellation rights.

Financial Conduct Authority (FCA) • United Kingdom • vFebruary 2026

View details
PrivacyLaw

NCCP Act 2009 — National Consumer Credit Protection Act 2009

The National Consumer Credit Protection Act 2009 is an Australian law that regulates the provision of consumer credit and financial services in the country. It outlines licensing requirements for entities engaged in credit activities and includes protections for consumers against unsuitable credit agreements.

Australian Government • Australia • vNo. 134

View details
PrivacyLaw

LGOIMA — Local Government Official Information and Meetings Act 1987 - New Zealand

The Local Government Official Information and Meetings Act 1987 (LGOIMA) is a New Zealand law that provides public access to information held by local authorities and council-controlled organizations. It also sets transparency standards for local government meetings, ensuring public notification and accessibility.

New Zealand Government • New Zealand • v23 December 2023

View details
GRCLaw

CCA 2010 — Competition and Consumer Act 2010

The Competition and Consumer Act 2010 is a legislative act of the Australian Parliament that governs competition law and consumer protection in Australia. It is administered by the Australian Competition & Consumer Commission (ACCC) and aims to promote fair trading and prevent anti-competitive practices, while providing protections for consumers.

Australian Government • Australia • vCompilation No. 129

View details
GRCGuideline

RG 96 — Regulatory Guide 96: Debt Collection Guideline: For Collectors and Creditors

This guideline was jointly produced by the Australian Competition and Consumer Commission (ACCC) and the Australian Securities and Investments Commission (ASIC) to outline how Commonwealth consumer protection laws apply to debt collection. It applies to creditors and external agencies involved in debt collection, and provides guidance to debtors.

Australian Securities and Investments Commission (ASIC) • Australia • v13 April 2021

View details
CybersecurityGuideline

WA Digital Security Policy — Western Australia Digital Security Policy

The West Australian Whole of Government Digital Security Policy provides guidelines for adopting and maintaining security controls in digital information and systems. It addresses confidentiality, integrity, and availability, relying on both Australian and international standards.

Australian Government • Australia

View details
CybersecurityStandard

TGISF — Tasmanian Government Information Security Framework

The Tasmanian Government Information Security Framework (TGISF) is a government-wide information security and risk management framework that provides principles, guidelines, and controls to help Tasmanian Government agencies protect information assets and manage security risks effectively.

Tasmanian Government • Tasmania

View details
Critical InfrastructureGuideline

SMDDS — OWASP Secure Medical Devices Deployment Standard

The OWASP Secure Medical Devices Deployment Standard provides guidance for the secure deployment of medical devices within healthcare environments, addressing the rising threats such as botnets and malware targeting IoT devices. It emphasizes security measures across device purchasing, network security, interface controls, and incident handling.

OWASP

View details
PrivacyLaw

Royal Decree 69/2008 — Electronic Transactions Law in Oman

The Electronic Transactions Law in Oman, enacted in 2008 through Royal Decree 69/2008, aims to streamline electronic transactions and ensure their security. It establishes provisions for authentication service providers, e-signature confidentiality, and data integrity.

Government of Oman • Oman

View details
CybersecurityFramework

PSPF 2026 — Protective Security Policy Framework Release 2026

Protective Security Policy Framework (PSPF) Release 2026 is the Australian Government's updated protective security framework that sets mandatory requirements across six security domains to help government entities protect their people, information, assets, and resources through effective risk management and security practices.

Australian Government • Australia • v2026

View details
CybersecurityStandard

SACSF V2.0 — South Australian Cyber Security Framework V2.0

The South Australian Cyber Security Framework (SACSF) is a cybersecurity governance framework developed by Security SA to help South Australian Government agencies manage cyber risks and protect information, systems, and digital services. It consists of 18 policy statements across four core principles—Governance, Information Security, Personnel Security, and Physical Security—and uses a four-tier risk-based approach to implement security controls proportionate to agency risk exposure.

Australian Government • South Australia • v2.0

View details
AIFramework

NIST AI RMF — NIST AI Risk Management Framework

The AI Risk Management Framework (AI RMF) is a voluntary framework developed by NIST to help organizations design, develop, use, and evaluate AI systems with trustworthiness considerations. It addresses governance, mapping, measuring, and managing AI risks.

National Institute of Standards and Technology (NIST) • United States • v1.0

View details
Critical InfrastructureRegulation

DORA — Regulation (EU) 2022/2554 - Digital Operational Resilience Act

Regulation (EU) 2022/2554, known as DORA, establishes a unified framework for digital operational resilience in the European Union's financial sector. It aims to ensure financial entities can withstand, recover, and adapt to ICT-related disruptions while safeguarding the stability and integrity of the financial system.

European Parliament and Council of the European Union • European Union

View details
CybersecurityStandardFramework

CAIQ v4.1.0 — Consensus Assessment Initiative Questionnaire v4.1.0

The Consensus Assessments Initiative Questionnaire (CAIQ) v4.1.0 is a comprehensive cloud security assessment questionnaire developed by the Cloud Security Alliance (CSA) and aligned with the Cloud Controls Matrix (CCM) v4.1 to help organizations evaluate the security, privacy, and compliance practices of cloud service providers. It includes 261 assessment questions mapped to 207 controls across 17 security domains, supporting detailed vendor due diligence, third-party risk management, and cloud security assessments using a standardized industry framework.

Cloud Security Alliance (CSA) • v4.1.0

View details
CybersecurityStandard

CAIQ Lite v4.1.0 — Consensus Assessments Initiative Questionnaire Lite v4.1.0

Consensus Assessments Initiative Questionnaire (CAIQ) Lite v4.1.0 is a streamlined cloud security assessment questionnaire developed by the Cloud Security Alliance (CSA) and aligned with the Cloud Controls Matrix (CCM) v4.1 to help organizations evaluate cloud service providers using a standardized approach. It includes 138 focused questions across 17 security domains, enabling efficient vendor due diligence, third-party risk management, and security posture assessments.

Cloud Security Alliance (CSA) • v4.1.0

View details

Partner directory

Certified resellers, integrators and advisors to help you implement and manage your GRC program.

Explore all partners (91)

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call