Cyber, critical infrastructure & AI standards — all in one place.

The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.

Browse by industry

Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.

Explore all industries

Content Library

Showing 20 of 230

GRCStandardControl set

ISO 9001 — ISO 9001:2015 Quality Management Systems — Requirements

ISO 9001:2015 is an international standard for quality management systems. It provides requirements for organizations to establish, implement, maintain, and continually improve a quality management system to enhance customer satisfaction and operational efficiency.

International Organization for Standardization (ISO) • v2015 (Edition 5)

View details
GRCStandardControl set

ISO 45001 — ISO 45001:2018 - Occupational Health and Safety Management Systems — Requirements with Guidance for Use

ISO 45001:2018 is an international standard that specifies requirements for an occupational health and safety (OH&S) management system. It helps organizations improve workplace safety, reduce risks, and enhance overall OH&S performance.

International Organization for Standardization (ISO) • v2018

View details
Critical InfrastructureRegulation

EU Regulation 2022/1645 — Commission Delegated Regulation (EU) 2022/1645

EU Regulation 2022/1645 establishes mandatory cybersecurity management requirements for Part 21 Design Organisations (DOs) and Production Organisations (POs) in the aviation sector. It introduces the implementation of an Information Security Management System (ISMS) to protect critical systems, data, and processes from cyber threats.

European Commission • EU

View details
PrivacyLaw

UAE Personal Data Protection Law — Federal Decree Law No. 45 of 2021 Regarding the Protection of Personal Data

The UAE Personal Data Protection Law establishes an integrated framework to ensure the confidentiality of information and protect individual privacy in the UAE. It governs the processing of personal data, defines the rights of data owners, sets requirements for cross-border data transfer, and outlines obligations for businesses handling personal data.

UAE Data Office • United Arab Emirates • v20 Sep 2021

View details
GRCRegulation

EU 2016/1675 — Commission Delegated Regulation (EU) 2016.1675 on High Risk Third Countries

This regulation identifies high-risk third countries with strategic deficiencies in the area of anti-money laundering (AML) and countering the financing of terrorism (CFT). It supplements Directive (EU) 2015/849, providing a legal framework for such identifications.

European Commission • EU • v14 July 2016

View details
CybersecurityStandard

OWASP ASVS — OWASP Application Security Verification Standard

The OWASP Application Security Verification Standard (ASVS) is an open standard for testing and verifying the security of web applications. It provides developers with a comprehensive list of requirements for secure development and helps establish confidence in application security.

OWASP Foundation • v4.0.2

View details
GRCFrameworkControl set

COBIT 2019 — COBIT 2019 Framework

The COBIT 2019 Framework, developed by ISACA, is a globally recognized standard for optimizing enterprise IT governance and management. It provides flexible, detailed guidance for organizations aiming to achieve effective governance over information and technology.

ISACA • v2019

View details
CybersecurityFramework

CMMC — Cybersecurity Maturity Model Certification

The Cybersecurity Maturity Model Certification (CMMC) Assessment Guide defines how organizations are evaluated for compliance with cybersecurity requirements when working with the U.S. Department of Defense. It outlines assessment methods, evidence expectations, and control validation aligned with standards like NIST SP 800-171. The guide ensures consistent and rigorous verification of an organization’s ability to protect sensitive information.

US Government • United States • v2.13

View details
GRCStandard

SPS 521 — Prudential Standard SPS 521 - Conflicts of Interest

Prudential Standard SPS 521 is a legislative instrument under the Superannuation Industry (Supervision) Act 1993. It sets requirements for superannuation entities in Australia to appropriately manage conflicts of interest to ensure compliance and trust in their operations.

Australian Prudential Regulation Authority (APRA) • Australia

View details
CybersecurityFrameworkControl set

SOC2 — SOC2 Trusted Services Criteria

SOC 2 is a framework for managing and reporting on controls at service organizations relevant to security, availability, processing integrity, confidentiality, and privacy. It aims to provide detailed information and assurance to stakeholders about how these controls are implemented to protect user data.

American Institute of Certified Public Accountants (AICPA) • United States

View details
GRCStandard

SPS 310 — Prudential Standard SPS 310 Audit and Related Matters

Prudential Standard SPS 310 establishes requirements for conducting audits and related matters for the superannuation industry in Australia. It ensures compliance with financial reporting and auditing practices in accordance with regulatory standards.

Australian Prudential Regulation Authority (APRA) • Australia

View details
GRCLaw

Corporations Act 2001 — Corporations Act 2001

The Corporations Act 2001 is Australia’s primary legislation regulating companies and other business entities. It outlines fiduciary duties for directors, including acting in good faith, exercising care and diligence, avoiding improper use of information or position, and disclosing certain interests.

Australian Government • Australia • v28 September 2017

View details
Critical InfrastructureLaw

Renewable Energy (Electricity) Act 2000

The Renewable Energy (Electricity) Act 2000 establishes a legal framework to encourage the generation of electricity from renewable energy sources in Australia. It creates a system for renewable energy certificates and mandates a Renewable Power Percentage to ensure participation by electricity retailers.

Australian Government • Australia

View details
GRCLaw

Workplace Relations Act 1996

The Workplace Relations Act 1996 was an Australian federal law governing employment relations, setting frameworks for workplace agreements, wage-setting, and employee entitlements. It covered topics such as the Australian Fair Pay Commission, industrial relations, and minimum workplace standards.

Australian Government • Australia

View details
CybersecurityFramework

FSSCP — The Financial Services Sector Cybersecurity Profile

The Financial Services Sector Cybersecurity Profile is a scalable and extensible assessment tool designed to help financial institutions manage cyber risks and demonstrate regulatory compliance. It is based on the NIST Cybersecurity Framework and offers a tailored approach to streamline cybersecurity assessments globally.

Financial Services Sector Coordinating Council (FSSCC) • Global

View details
Critical InfrastructureLaw

Ozone Protection and Synthetic Greenhouse Gas Management Act 1989

The Ozone Protection and Synthetic Greenhouse Gas Management Act 1989 is Australian legislation designed to manage the use, import, and export of ozone-depleting substances (ODS) and synthetic greenhouse gases (SGGs). It aligns with Australia's obligations under the Montreal Protocol, emphasizing environmental protection through licensing, quotas, and controls on substances and equipment.

Australian Government • Australia • v7, 1989

View details
CybersecurityStandard

SMB1001 — SMB1001 Cybersecurity Standard

The SMB1001 Cybersecurity Standard provides small and medium-sized businesses, including law firms, with a clear and achievable framework to enhance their cybersecurity defenses and demonstrate due diligence. It aims to help practitioners protect client confidentiality, reduce cyber risks, and meet stakeholder requirements.

Dynamic Standards International (DSI) • Australia • v2026

View details
CybersecurityFramework

QCF — Qatar Cybersecurity Framework

The Qatar Cybersecurity Framework (QCF) provides structured guidelines to help organizations manage and strengthen their cybersecurity practices across governance, risk, protection, detection, response, and recovery. It promotes a proactive, coordinated approach to mitigating cyber threats while enhancing national and organizational resilience.

Qatar National Cyber Security Committee (NCSC) • Qatar

View details
GRCStandard

CPS 520 — Prudential Standard CPS 520 Fit and Proper

The Prudential Standard CPS 520 sets out the requirements for assessing the fitness and propriety of responsible persons in APRA-regulated institutions, including banks, insurers, and private health insurers. It ensures that key positions are held by individuals who meet high standards of integrity and competence.

Australian Prudential Regulation Authority (APRA) • Australia

View details
PrivacyLaw

Qatar PDPPL — Qatar Personal Data Privacy Protection Law (Law No. (13) of 2016)

The Qatar Personal Data Privacy Protection Law (PDPPL), formally Law No. 13 of 2016, is the primary data protection framework in Qatar. It governs how organizations collect, process, store, transfer, and secure personal data belonging to individuals in the country.

Qatar National Cyber Security Agency (NCSA) • Qatar

View details

Partner directory

Certified resellers, integrators and advisors to help you implement and manage your GRC program.

Explore all partners (88)

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call