Cyber, critical infrastructure & AI standards — all in one place.

The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.

Browse by industry

Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.

Explore all industries

Content Library

Showing 14 of 14

CybersecurityRegulation

RFFR ISM PSP-A — RFFR ISM Provider Security Plan Annex Template

The RFFR Provider Security Plan Annex (PSP-A) Template is a DEWR security assurance template used to document the implementation and status of security controls that protect departmental information and support the secure delivery of services under the Right Fit For Risk (RFFR) framework.

Australian Government • Australia • vSeptember 2026

View details
CybersecurityStandard

NZISM — New Zealand Information Security Manual

The New Zealand Information Security Manual (NZISM) is the New Zealand Government’s information security framework that provides baseline security controls, processes, and guidance to help organizations protect information systems and manage cybersecurity risks effectively.

New Zealand Government Communications Security Bureau (GCSB) • New Zealand • version 3.9

View details
CybersecurityFramework

DESE ISMS Scheme — DESE Information Security Management Systems (ISMS) Scheme

The DESE ISMS Scheme is an information security certification framework that combines ISO/IEC 27001, the Australian Government Information Security Manual (ISM), and the Right Fit For Risk (RFFR) framework to help service providers manage cyber risks and protect sensitive information.

Australian Department of Employment and Workplace Relations (DEWR) • Australia

View details
GRCLaw

Criminal Code Act 1995

The Criminal Code Act 1995 is an Australian federal law that establishes the legal framework for addressing criminal offenses. It outlines principles of criminal responsibility, specific offenses such as terrorism and espionage, and provisions for external and corporate liabilities.

Attorney-General's Department • Australia • vNo. 137, 17 February 2021

View details
PrivacyLaw

Charter of the United Nations Act 1945

The Charter of the United Nations Act 1945 provides a legal framework for implementing United Nations Security Council Resolutions in Australia. It regulates the application of sanctions, the listing and proscription of individuals or entities, and addresses offenses related to UN sanctions.

Australian Government • Australia • vNo. 14, 1 July 2016

View details
Critical InfrastructureRegulation

EASA Part-IS — European Union Aviation Safety Agency (EASA) - Part IS - Easy Access Rules for Information Security

The EASA Part-IS Regulation mandates information security measures within the aviation sector to address digital threats that impact safety. It provides a framework for managing risks, responding to incidents, and safeguarding aviation systems.

European Union • EU • vDecember 2025

View details
CybersecurityStandard

ISO/IEC 27018:2025 — ISO/IEC 27018:2025 Information security, cybersecurity and privacy protection — Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors

ISO/IEC 27018:2025 is the global standard for managing personally identifiable information (PII) in public cloud services. It provides cloud providers with a framework to ensure privacy, security, and compliance when processing customer data.

International Organization for Standardization (ISO) • v2025

View details
CybersecurityStandard

ISM CCM — Information Security Manual Cloud Controls Matrix Template

The Cloud Controls Matrix (CCM) Template is a comprehensive framework for mapping cloud security controls to industry standards and compliance requirements. It helps organizations assess, implement, and demonstrate effective cloud security practices across diverse environments.

Australian Government • Australia • vJune 2026

View details
PrivacyControl set

NIST SP 800-53 Rev. 5.2 — Security and Privacy Controls for Information Systems and Organizations

NIST Special Publication 800-53 Rev. 5 provides a comprehensive catalog of security and privacy controls designed to safeguard organizational operations, assets, and individuals from a broad spectrum of risks including cyberattacks, human mistakes, and natural disasters. It is widely used for implementing security measures as part of risk management frameworks.

NIST (National Institute of Standards and Technology) • United States • v5.2.0

View details
GRCLaw

AML/CTF Act — Anti-Money Laundering and Counter-Terrorism Financing Act 2006

This is an Australian law established to prevent money laundering and financing of terrorism. It imposes obligations on certain entities to implement anti-money laundering and counter-terrorism financing measures, including customer due diligence, reporting, and record-keeping.

Australian Government • Australia • vCompilation No. 60, 31 March 2026

View details
GRCLaw

AML/CTF Rules — Anti-Money Laundering and Counter-Terrorism Financing Rules 2025

The Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 provide detailed obligations on reporting entities in Australia to prevent financial crimes, including money laundering and terrorism financing. Administered by the Department of Home Affairs, it supports compliance with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006.

Australian Government • Australia • vCompilation No. 1, 31 March 2026

View details
CybersecurityGuideline

NIST SP 800-171A Rev. 3 — NIST Special Publication 800-171A Rev. 3 - Assessing Security Requirements for Controlled Unclassified Information

This publication provides a methodology and assessment procedures for evaluating security requirements associated with the protection of Controlled Unclassified Information (CUI). It supports compliance with NIST SP 800-171 in nonfederal systems and organizations.

National Institute of Standards and Technology (NIST) • United States • vRevision 3

View details
CybersecurityStandardControl set

ISO/IEC 27001:2013 — ISO/IEC 27001:2013 - Information technology — Security techniques — Information security management systems — Requirements

ISO/IEC 27001:2013 specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). It also includes guidelines for assessing and addressing information security risks in organizations.

ISO/IEC • Global • v2013

View details
CybersecurityStandardControl set

ISO/IEC 27001:2022 — ISO/IEC 27001:2022 - Information security, cybersecurity and privacy protection — Information security management systems — Requirements

ISO/IEC 27001:2022 is an international standard defining requirements for an information security management system (ISMS). It helps organizations establish, implement, maintain, and continually improve their information security processes to manage data-related risks.

ISO/IEC • Global • v2022

View details

Partner directory

Certified resellers, integrators and advisors to help you implement and manage your GRC program.

Explore all partners (88)

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call