Cyber, critical infrastructure & AI standards — all in one place.

The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.

Browse by industry

Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.

Explore all industries

Content Library

Showing 5 of 5

CybersecurityFramework

CSA IoT Controls v2 — CSA IoT Security Controls Framework v2

The CSA IoT Security Controls Framework v2 provides a structured approach to securing enterprise IoT systems, including connected devices, cloud services, and networking technologies. It is suitable for systems ranging from low-impact data processes to highly sensitive critical services.

Cloud Security Alliance (CSA) • v2

View details
Critical InfrastructureGuideline

SMDDS — OWASP Secure Medical Devices Deployment Standard

The OWASP Secure Medical Devices Deployment Standard provides guidance for the secure deployment of medical devices within healthcare environments, addressing the rising threats such as botnets and malware targeting IoT devices. It emphasizes security measures across device purchasing, network security, interface controls, and incident handling.

OWASP

View details
CybersecurityFramework

CSA IoT Controls v1 — CSA IoT Security Controls Framework

The CSA IoT Security Controls Framework provides essential security controls to mitigate risks in IoT systems that include various connected devices, cloud services, and networks. It is designed to apply to a range of IoT systems, from handling low-value data to supporting critical services.

Cloud Security Alliance (CSA) • v1

View details
GRCRegulation

EU Data Act — Regulation on harmonised rules on fair access to and use of data (Data Act)

The Data Act is an EU regulation that aims to establish fair rules for access to and use of data generated by connected devices. It promotes data sharing, safeguards user rights, and prevents unfair practices while supporting innovation and the data economy.

European Commission • EU • v(EU) 2023/2854

View details
CybersecurityStandard

UAE IA V2 — UAE Information Assurance Standard Version 2

The UAE Information Assurance Standard Version 2 (UAE IA V2) is a national cybersecurity framework issued by the UAE Cyber Security Council in 2025. It builds upon the previous version with updated controls and integrations to address modern technologies, such as AI/ML, IoT, cloud, and post-quantum cryptography.

UAE Cyber Security Council • United Arab Emirates • v2.0

View details

Partner directory

Certified resellers, integrators and advisors to help you implement and manage your GRC program.

Explore all partners (88)

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call