Cyber, critical infrastructure & AI standards — all in one place.

The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.

Browse by industry

Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.

Explore all industries

Content Library

Showing 20 of 37

PrivacyRegulation

201 CMR 17.00 — Massachusetts: Standards for the protection of personal information of residents of the Commonwealth

201 CMR 17.00 is a Massachusetts information security regulation that establishes minimum requirements for protecting the personal information of Massachusetts residents through administrative, technical, and physical security safeguards.

Office of Consumer Affairs and Business Regulation • Massachusetts, USA

View details
CybersecurityStandard

ESMA Minimum Standard IT Security Controls

The ESMA Minimum Standard IT Security Controls is a cybersecurity and compliance framework that defines the minimum security requirements service providers must implement to protect ESMA systems, applications, data, and information services.

European Securities and Markets Authority (ESMA) • EU

View details
CybersecurityLaw

Alabama Data Breach Notification Act of 2018 — Chapter 38 Data Breach Notification Act of 2018

The Alabama Data Breach Notification Act of 2018 is a state data protection law that requires organizations to safeguard sensitive personal information, investigate security breaches, and provide timely notification to affected individuals and regulatory authorities when personal data is compromised.

State of Alabama • Alabama, USA • vPolicy 621-01

View details
PrivacyLaw

Arkansas PIPA — Arkansas Personal Information Protection Act

The Arkansas Personal Information Protection Act (PIPA) is a data privacy and security law that requires organizations to protect personal information, implement reasonable security measures, and notify affected individuals in the event of a qualifying data breach.

State of Arkansas • Arkansas, USA

View details
CybersecurityStandard

NZISM — New Zealand Information Security Manual

The New Zealand Information Security Manual (NZISM) is the New Zealand Government’s information security framework that provides baseline security controls, processes, and guidance to help organizations protect information systems and manage cybersecurity risks effectively.

New Zealand Government Communications Security Bureau (GCSB) • New Zealand • version 3.9

View details
PrivacyRegulation

Nevada Chapter 603A — Security and Privacy of Personal Information

Nevada Chapter 603A - Security and Privacy of Personal Information is a Nevada privacy and data security law that requires organizations to safeguard personal information, notify individuals of certain data breaches, and comply with consumer privacy requirements relating to the collection, use, and protection of personal data.

State of Nevada • Nevada, USA

View details
PrivacyLaw

Hawaii - Security Breach of Personal Information Chapter 487N

Hawaii Security Breach of Personal Information (Chapter 487N) is a Hawaii state law that requires businesses and government agencies to notify affected individuals of data breaches involving personal information and establishes requirements for protecting and managing sensitive personal data.

State of Hawaii • Hawaii

View details
CybersecurityFramework

DESE ISMS Scheme — DESE Information Security Management Systems (ISMS) Scheme

The DESE ISMS Scheme is an information security certification framework that combines ISO/IEC 27001, the Australian Government Information Security Manual (ISM), and the Right Fit For Risk (RFFR) framework to help service providers manage cyber risks and protect sensitive information.

Australian Department of Employment and Workplace Relations (DEWR) • Australia

View details
CybersecurityStandard

Cert NZ Top 10 Critical Controls — Cert New Zealand Top Ten Critical Controls

The CERT NZ Top Ten Critical Controls is a cybersecurity framework that outlines ten essential security controls organizations can implement to reduce cyber risk, improve resilience, and protect systems, data, and services from common cyber attacks.

National Cyber Security Centre (NCSC) • New Zealand • v2021

View details
CybersecurityFramework

Spain ENS — Spain - National Security Framework

The National Security Framework (ENS) is Spain's national cybersecurity framework that defines security principles and controls for public sector organizations and their suppliers to protect information systems and ensure the confidentiality, integrity, availability, authenticity, and traceability of digital services.

Government of Spain • Spain • v5 May 2022

View details
PrivacyLaw

Dubai HDPR — Dubai Health Data Protection Regulation - DHCC Regulation No. 7 of 2013

The Dubai Health Data Protection Regulation is a healthcare privacy regulation that governs the protection, use, disclosure, and management of patient health information within Dubai Healthcare City, ensuring the confidentiality and security of health data.

Dubai Healthcare City Authority (DHCA) • Dubai • v21 October 2013

View details
CybersecurityRegulation

Dubai ISR — Dubai Government Information Security Regulation

The Dubai Government Information Security Regulation (ISR) provides standards to ensure the continuity of critical business processes and minimize information security risks for Dubai Government Entities. It defines minimum requirements for information security controls and aims to maintain confidentiality, integrity, and availability of government information.

Dubai Government • Dubai • v3

View details
CybersecurityStandard

WLA-SCS:2020 — World Lottery Association Security Control Standard 2020

The World Lottery Association Security Control Standard (WLA-SCS:2020) offers a framework specifically designed for the lottery and gaming industry to safeguard information security and ensure operational compliance. It includes guidelines for security management, risk assessments, and audit processes and provides a benchmark for organizations seeking WLA certification.

World Lottery Association • Global • v2020

View details
Critical InfrastructureRegulation

EASA Part-IS — European Union Aviation Safety Agency (EASA) - Part IS - Easy Access Rules for Information Security

The EASA Part-IS Regulation mandates information security measures within the aviation sector to address digital threats that impact safety. It provides a framework for managing risks, responding to incidents, and safeguarding aviation systems.

European Union • EU • vDecember 2025

View details
CybersecurityFramework

TGISF — Tasmanian Government Information Security Framework

The Tasmanian Government Information Security Framework (TGISF) is a government-wide information security and risk management framework that provides principles, guidelines, and controls to help Tasmanian Government agencies protect information assets and manage security risks effectively.

Tasmanian Government • Tasmania

View details
CybersecurityFramework

PSPF 2026 — Protective Security Policy Framework Release 2026

Protective Security Policy Framework (PSPF) Release 2026 is the Australian Government's updated protective security framework that sets mandatory requirements across six security domains to help government entities protect their people, information, assets, and resources through effective risk management and security practices.

Australian Government • Australia • v2026

View details
CybersecurityFramework

SACSF V2.0 — South Australian Cyber Security Framework V2.0

The South Australian Cyber Security Framework (SACSF) is a cybersecurity governance framework developed by Security SA to help South Australian Government agencies manage cyber risks and protect information, systems, and digital services. It consists of 18 policy statements across four core principles—Governance, Information Security, Personnel Security, and Physical Security—and uses a four-tier risk-based approach to implement security controls proportionate to agency risk exposure.

Australian Government • South Australia • v2.0

View details
CybersecurityStandardControl set

ASD Essential 8 Maturity Model - 2023 — Australian Signals Directorate (ASD) Essential Eight Maturity Model 2023

The ASD Essential 8 Maturity Model is a framework developed by the Australian Signals Directorate (ASD) to guide organizations in implementing prioritized cyber security mitigation strategies. It provides structured maturity levels to help organizations progressively strengthen their defenses against common cyber threats. The model ensures consistency, accountability, and resilience by aligning practices across all eight strategies.

Australian Signals Directorate (ASD) • Australia • vNovember 2023

View details
CybersecurityStandard

ISO/IEC 27018:2025 — ISO/IEC 27018:2025 Information security, cybersecurity and privacy protection — Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors

ISO/IEC 27018:2025 is the global standard for managing personally identifiable information (PII) in public cloud services. It provides cloud providers with a framework to ensure privacy, security, and compliance when processing customer data.

International Organization for Standardization (ISO) • v2025

View details
CybersecurityStandard

ISM CCM — Information Security Manual Cloud Controls Matrix Template

The Cloud Controls Matrix (CCM) Template is a comprehensive framework for mapping cloud security controls to industry standards and compliance requirements. It helps organizations assess, implement, and demonstrate effective cloud security practices across diverse environments.

Australian Government • Australia • vJune 2026

View details

Partner directory

Certified resellers, integrators and advisors to help you implement and manage your GRC program.

Explore all partners (88)

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call