Cyber, critical infrastructure & AI standards — all in one place.

The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.

Browse by industry

Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.

Explore all industries

Content Library

Showing 20 of 58

CybersecurityControl setGuideline

ITSG-33 — IT Security Risk Management: A Lifecycle Approach (ITSG-33)

ITSG-33 is a guideline developed by the Canadian Centre for Cyber Security to help government departments manage IT security risks effectively. It outlines activities at both departmental and project levels, providing a structured process for integrating security considerations into IT environments and maintaining authorization to operate.

Canadian Centre for Cyber Security • Canada

View details
CybersecurityStandard

ESMA Minimum Standard IT Security Controls

The ESMA Minimum Standard IT Security Controls is a cybersecurity and compliance framework that defines the minimum security requirements service providers must implement to protect ESMA systems, applications, data, and information services.

European Securities and Markets Authority (ESMA) • EU

View details
GRCFramework

COBIT 5 — COBIT 5

COBIT 5 is a comprehensive framework for the governance and management of enterprise IT, designed to maximize the value organizations derive from their information systems. It incorporates principles, practices, and tools to align IT with business strategies and goals.

ISACA • Global • v5

View details
PrivacyFramework

NIST Privacy Framework v 1.0 — NIST Privacy Framework: A Tool for Improving Privacy Through Enterprise Risk Management

The NIST Privacy Framework Version 1.0 is a voluntary framework that helps organizations integrate privacy risk management into enterprise risk management by providing a structured approach for managing privacy risks, protecting personal data, and improving privacy governance.

National Institute of Standards and Technology (NIST) • Global • version 1.0

View details
CybersecurityStandard

NZISM — New Zealand Information Security Manual

The New Zealand Information Security Manual (NZISM) is the New Zealand Government’s information security framework that provides baseline security controls, processes, and guidance to help organizations protect information systems and manage cybersecurity risks effectively.

New Zealand Government Communications Security Bureau (GCSB) • New Zealand • version 3.9

View details
CybersecurityFramework

DESE ISMS Scheme — DESE Information Security Management Systems (ISMS) Scheme

The DESE ISMS Scheme is an information security certification framework that combines ISO/IEC 27001, the Australian Government Information Security Manual (ISM), and the Right Fit For Risk (RFFR) framework to help service providers manage cyber risks and protect sensitive information.

Australian Department of Employment and Workplace Relations (DEWR) • Australia

View details
CybersecurityStandard

Cert NZ Top 10 Critical Controls — Cert New Zealand Top Ten Critical Controls

The CERT NZ Top Ten Critical Controls is a cybersecurity framework that outlines ten essential security controls organizations can implement to reduce cyber risk, improve resilience, and protect systems, data, and services from common cyber attacks.

National Cyber Security Centre (NCSC) • New Zealand • v2021

View details
CybersecurityFramework

Spain ENS — Spain - National Security Framework

The National Security Framework (ENS) is Spain's national cybersecurity framework that defines security principles and controls for public sector organizations and their suppliers to protect information systems and ensure the confidentiality, integrity, availability, authenticity, and traceability of digital services.

Government of Spain • Spain • v5 May 2022

View details
GRCStandard

APS 222 — Prudential Standard APS 222: Associations with Related Entities

APS 222 is a prudential standard issued by the Australian Prudential Regulation Authority (APRA) aimed at ensuring that authorised deposit-taking institutions (ADIs) identify, monitor, and control risks related to their associations and dealings with related entities. It mandates policies and limits on exposures to mitigate contagion and step-in risks.

Australian Prudential Regulation Authority (APRA) • Australia • vJanuary 2015

View details
GRCRegulation

APS 220 — Prudential Standard APS 220 Credit Risk Management

APS 220 sets requirements for authorised deposit-taking institutions (ADIs) to establish a comprehensive credit risk management framework. The standard includes strategies, policies, and procedures for identifying, assessing, and mitigating credit risks.

Australian Prudential Regulation Authority (APRA) • Australia • vSeptember 2020

View details
GRCRegulation

APS 221 Large Exposures — Banking (prudential standard) determination No. 4 of 2019

This is a prudential regulatory instrument issued under the Banking Act 1959 in Australia, focusing on controlling large exposures and risk concentrations within the banking sector. It includes provisions for boards, measurement, limits, and notification requirements related to large exposures.

Australian Prudential Regulation Authority (APRA) • Australia • v09 December 2019

View details
GRCRegulation

3PS 221- Aggregate Risk Exposures — Banking, Insurance and Life Insurance (prudential standard) determination No. 2 of 2016 - Prudential Standard 3PS 221 Aggregate Risk Exposures

This legislative determination establishes prudential requirements for managing and reporting aggregate risk exposures within banking, insurance, and life insurance sectors. It aims to ensure robust risk management practices across these industries.

Australian Prudential Regulation Authority (APRA) • Australia • v13 September 2016

View details
GRCGuideline

APG 223 — Prudential Practice Guide APG 223 Residential Mortgage Lending

APG 223 is a detailed guidance document issued by the Australian Prudential Regulation Authority (APRA) to assist authorized deposit-taking institutions (ADIs) in managing risks associated with residential mortgage lending. It provides recommendations on best practices for loan serviceability assessments and setting buffer and floor rates.

Australian Prudential Regulation Authority (APRA) • Australia

View details
CybersecurityGuideline

PPG 511 — Prudential Practice Guide 511 - Remuneration

Prudential Practice Guide (PPG) 511 - Remuneration is APRA guidance that helps regulated institutions design and manage remuneration arrangements that support prudent risk management, strong governance, and sustainable organisational performance.

Australian Prudential Regulation Authority (APRA) • Australia • v30 November 2009

View details
GRCRegulation

Work Health and Safety Regulations 2011

The Work Health and Safety Regulations 2011 establish detailed requirements for workplace health and safety in compliance with the Work Health and Safety Act 2011. They cover topics such as risk management, workplace conditions, hazardous materials, emergency plans, and licensing for high-risk activities.

Australian Government • Australia • vNo. 15, 1 July 2020

View details
CybersecurityFramework

DSPF — Defence Security Principles Framework

The Defence Security Principles Framework (DSPF) is the Australian Department of Defence's principles-based security framework that provides governance, security principles, and controls to help Defence personnel manage risks and protect Defence people, information, assets, and operations in alignment with the PSPF.

Australian Government • Australia • v2 July 2018

View details
CybersecurityStandard

FedRAMP Controls — FedRAMP Security Controls Baseline rev 5

The FedRAMP Security Controls Baseline is a standardized set of cloud security requirements based on NIST SP 800-53 that defines the minimum security controls cloud service providers must implement to protect federal data and achieve FedRAMP authorization.

US Government • United States • vrev 5

View details
CybersecurityFramework

CPG 1.0 — Cross-Sector Cybersecurity Performance Goals

The Cross-Sector Cybersecurity Performance Goals (CPGs) are a set of baseline cybersecurity practices developed by CISA to help organizations of all sizes and sectors strengthen their resilience against common cyber threats. They provide prioritized, actionable measures that align with the NIST Cybersecurity Framework and are designed to be achievable, cost-effective, and impactful.

Cybersecurity and Infrastructure Security Agency (CISA) • United States • v1.0.1

View details
CybersecurityStandard

WLA-SCS:2020 — World Lottery Association Security Control Standard 2020

The World Lottery Association Security Control Standard (WLA-SCS:2020) offers a framework specifically designed for the lottery and gaming industry to safeguard information security and ensure operational compliance. It includes guidelines for security management, risk assessments, and audit processes and provides a benchmark for organizations seeking WLA certification.

World Lottery Association • Global • v2020

View details
GRCStandard

ISO 31000 — ISO 31000:2018 Risk management — Guidelines

ISO 31000:2018 is an international standard providing principles and guidelines for risk management across organizations. It outlines processes for identifying, analyzing, evaluating, monitoring, and communicating risks, helping entities manage uncertainty proactively.

International Organization for Standardization (ISO) • v2018

View details

Partner directory

Certified resellers, integrators and advisors to help you implement and manage your GRC program.

Explore all partners (88)

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call