Cyber, critical infrastructure & AI standards — all in one place.

The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.

Browse by industry

Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.

Explore all industries

Content Library

Showing 20 of 51

GRCLaw

South Africa Electronic Communications and Transactions Act 25 of 2002

The Electronic Communications and Transactions Act 25 of 2002 establishes legal and policy frameworks for regulating electronic communications and transactions in South Africa. It aims to facilitate universal access to electronic services, prevent abuse of information systems, and promote the use of e-government services and small business technology adoption.

Government of South Africa • South Africa

View details
CybersecurityStandard

Cert NZ Top 10 Critical Controls — Cert New Zealand Top Ten Critical Controls

The CERT NZ Top Ten Critical Controls is a cybersecurity framework that outlines ten essential security controls organizations can implement to reduce cyber risk, improve resilience, and protect systems, data, and services from common cyber attacks.

National Cyber Security Centre (NCSC) • New Zealand • v2021

View details
CybersecurityStandard

Spain ENS — Spain - National Security Framework

The National Security Framework (ENS) is Spain's national cybersecurity framework that defines security principles and controls for public sector organizations and their suppliers to protect information systems and ensure the confidentiality, integrity, availability, authenticity, and traceability of digital services.

Government of Spain • Spain • v5 May 2022

View details
CybersecurityFramework

CPG 1.0 — Cross-Sector Cybersecurity Performance Goals

The Cross-Sector Cybersecurity Performance Goals (CPGs) are a set of baseline cybersecurity practices developed by CISA to help organizations of all sizes and sectors strengthen their resilience against common cyber threats. They provide prioritized, actionable measures that align with the NIST Cybersecurity Framework and are designed to be achievable, cost-effective, and impactful.

Cybersecurity and Infrastructure Security Agency (CISA) • United States • v1.0.1

View details
CybersecurityGuideline

WA Cyber Security Policy — Western Australian Government Cyber Security Policy

The 2024 WA Government Cyber Security Policy outlines the baseline requirements for cyber security practices within Western Australian Government entities. It aims to reduce cyber security risks through a comprehensive and systematic approach to safeguarding digital information, information systems, and assets.

Department of the Premier and Cabinet - Office of Digital Government • Western Australia • v2024

View details
Critical InfrastructureRegulation

EASA Part-IS — European Union Aviation Safety Agency (EASA) - Part IS - Easy Access Rules for Information Security

The EASA Part-IS Regulation mandates information security measures within the aviation sector to address digital threats that impact safety. It provides a framework for managing risks, responding to incidents, and safeguarding aviation systems.

European Union • EU • vDecember 2025

View details
Critical InfrastructureGuideline

SMDDS — OWASP Secure Medical Devices Deployment Standard

The OWASP Secure Medical Devices Deployment Standard provides guidance for the secure deployment of medical devices within healthcare environments, addressing the rising threats such as botnets and malware targeting IoT devices. It emphasizes security measures across device purchasing, network security, interface controls, and incident handling.

OWASP

View details
PrivacyLaw

Royal Decree 69/2008 — Electronic Transactions Law in Oman

The Electronic Transactions Law in Oman, enacted in 2008 through Royal Decree 69/2008, aims to streamline electronic transactions and ensure their security. It establishes provisions for authentication service providers, e-signature confidentiality, and data integrity.

Government of Oman • Oman

View details
CybersecurityStandard

SACSF V2.0 — South Australian Cyber Security Framework V2.0

The South Australian Cyber Security Framework (SACSF) is a cybersecurity governance framework developed by Security SA to help South Australian Government agencies manage cyber risks and protect information, systems, and digital services. It consists of 18 policy statements across four core principles—Governance, Information Security, Personnel Security, and Physical Security—and uses a four-tier risk-based approach to implement security controls proportionate to agency risk exposure.

Australian Government • South Australia • v2.0

View details
CybersecurityStandardFramework

CAIQ v4.1.0 — Consensus Assessment Initiative Questionnaire v4.1.0

The Consensus Assessments Initiative Questionnaire (CAIQ) v4.1.0 is a comprehensive cloud security assessment questionnaire developed by the Cloud Security Alliance (CSA) and aligned with the Cloud Controls Matrix (CCM) v4.1 to help organizations evaluate the security, privacy, and compliance practices of cloud service providers. It includes 261 assessment questions mapped to 207 controls across 17 security domains, supporting detailed vendor due diligence, third-party risk management, and cloud security assessments using a standardized industry framework.

Cloud Security Alliance (CSA) • v4.1.0

View details
CybersecurityFrameworkStandard

CCM v4.1 — Cloud Controls Matrix v4.1

The Cloud Controls Matrix (CCM) v4.1 is a cybersecurity control framework that consists of 207 controls across 17 security domains, specifically tailored for cloud security and privacy. The Consensus Assessment Initiative Questionnaire (CAIQ) accompanies the CCM, offering a set of assessment questions to evaluate security controls.

Cloud Security Alliance (CSA) • v4.1

View details
CybersecurityStandard

SOC-CMM — SOC-CMM Assessment Tool

The SOC-CMM model is a capability maturity model that can be used to perform a self-assessment of your Security Operations Center (SOC). The model is based on review conducted on literature regarding SOC setup and existing SOC models as well as literature on specific elements within a SOC. The literature analysis was then validated by questioning several Security Operations Centers in different sectors and on different maturity levels to determine which elements were actually in place. The output from the survey, combined with the initial analysis is the basis for this self-assessment. For more information regarding the scientific background and the literature used to create the SOC-CMM self-assessment tool, please refer to the thesis document as available through: https://www.soc-cmm.com/

SOC-CMM

View details
CybersecurityStandardControl set

ASD Essential 8 Maturity Model - 2023 — Australian Signals Directorate (ASD) Essential Eight Maturity Model 2023

The ASD Essential 8 Maturity Model is a framework developed by the Australian Signals Directorate (ASD) to guide organizations in implementing prioritized cyber security mitigation strategies. It provides structured maturity levels to help organizations progressively strengthen their defenses against common cyber threats. The model ensures consistency, accountability, and resilience by aligning practices across all eight strategies.

Australian Signals Directorate (ASD) • Australia • vNovember 2023

View details
CybersecurityStandard

Cyber Essentials v3.3 — Cyber Essentials: Requirements for IT Infrastructure

Cyber Essentials v3.3 is a UK government-backed cybersecurity scheme defining baseline security measures for businesses. The update, effective from 26th April 2026, refines requirements to close ambiguities and enforce stricter compliance on cloud services, MFA, and endpoint protection.

NCSC (National Cyber Security Centre) • United Kingdom • v3.3

View details
CybersecurityStandard

ISO/IEC 27018:2025 — ISO/IEC 27018:2025 Information security, cybersecurity and privacy protection — Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors

ISO/IEC 27018:2025 is the global standard for managing personally identifiable information (PII) in public cloud services. It provides cloud providers with a framework to ensure privacy, security, and compliance when processing customer data.

International Organization for Standardization (ISO) • v2025

View details
CybersecurityStandard

ISM CCM — Information Security Manual Cloud Controls Matrix Template

The Cloud Controls Matrix (CCM) Template is a comprehensive framework for mapping cloud security controls to industry standards and compliance requirements. It helps organizations assess, implement, and demonstrate effective cloud security practices across diverse environments.

Australian Government • Australia • vJune 2026

View details
CybersecurityRegulation

ISM SSP — Information Security Manual System Security Plan Annex Template

The System Security Plan (SSP) Annex Template is a structured document used to capture detailed information about an organization’s cyber security controls and implementation. It supports accreditation processes by providing evidence of compliance, risk management, and system-specific security measures.

Australian Government • Australia • vJune 2026

View details
CybersecurityRegulation

RFFR ISM SoA — Right Fit for Risk Information Security Manual Statement of Applicability

The Right Fit for Risk (RFFR) Statement of Applicability (SoA) is a structured template used to document how organizations meet cyber security accreditation requirements. It outlines applicable controls, their implementation status, and provides assurance of compliance with the RFFR framework.

Australian Government • Australia • vJune 2026

View details
CybersecurityRegulation

ISM — Information Security Manual

The Australian ISM is the nationally recognized cybersecurity framework developed by the Australian Signals Directorate. It provides organizations with structured guidance to safeguard information and operational technology systems against evolving cyber threats.

Australian Government • Australia • vJune 2026

View details
PrivacyControl set

NIST SP 800-53 Rev. 5.2 — Security and Privacy Controls for Information Systems and Organizations

NIST Special Publication 800-53 Rev. 5 provides a comprehensive catalog of security and privacy controls designed to safeguard organizational operations, assets, and individuals from a broad spectrum of risks including cyberattacks, human mistakes, and natural disasters. It is widely used for implementing security measures as part of risk management frameworks.

NIST (National Institute of Standards and Technology) • United States • v5.2.0

View details

Partner directory

Certified resellers, integrators and advisors to help you implement and manage your GRC program.

Explore all partners (88)

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call