Cyber, critical infrastructure & AI standards — all in one place.

The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.

Browse by industry

Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.

Explore all industries

Content Library

Showing 20 of 97

CybersecurityControl setGuideline

ITSG-33 — IT Security Risk Management: A Lifecycle Approach (ITSG-33)

ITSG-33 is a guideline developed by the Canadian Centre for Cyber Security to help government departments manage IT security risks effectively. It outlines activities at both departmental and project levels, providing a structured process for integrating security considerations into IT environments and maintaining authorization to operate.

Canadian Centre for Cyber Security • Canada

View details
PrivacyRegulation

201 CMR 17.00 — Massachusetts: Standards for the protection of personal information of residents of the Commonwealth

201 CMR 17.00 is a Massachusetts information security regulation that establishes minimum requirements for protecting the personal information of Massachusetts residents through administrative, technical, and physical security safeguards.

Office of Consumer Affairs and Business Regulation • Massachusetts, USA

View details
CybersecurityStandard

ESMA Minimum Standard IT Security Controls

The ESMA Minimum Standard IT Security Controls is a cybersecurity and compliance framework that defines the minimum security requirements service providers must implement to protect ESMA systems, applications, data, and information services.

European Securities and Markets Authority (ESMA) • EU

View details
PrivacyLaw

Maine Notice of Risk to Personal Data — Title 10, Chapter 210-B: Notice of Risk to Personal Data

Maine's Title 10, Chapter 210-B establishes regulations around personal data protection and security breach notifications. It includes provisions on prohibited use of personal data, mandatory breach notification, enforcement mechanisms, and rules for reporting identity theft.

State of Maine • Maine, USA

View details
CybersecurityStandardFramework

DISP 2020 — Defence Industry Security Program (DISP)– Suitability Assessment (2020)

The Defence Industry Security Program (DISP) is an Australian Defence membership program that helps organizations implement and demonstrate appropriate security controls for participating in Defence projects and managing Defence-related information and assets.

Australian Department of Defence • Australia • v2020

View details
CybersecurityStandardFramework

DISP 2022 — Defence Industry Security Program – Suitability Requirements (2022)

The Defence Industry Security Program (DISP) is an Australian Defence security assurance program that helps organizations meet security requirements for Defence contracts and projects by implementing appropriate governance, personnel, physical, and information security controls.

Australian Government • Australia • v2022

View details
CybersecurityLaw

Alabama Data Breach Notification Act of 2018 — Chapter 38 Data Breach Notification Act of 2018

The Alabama Data Breach Notification Act of 2018 is a state data protection law that requires organizations to safeguard sensitive personal information, investigate security breaches, and provide timely notification to affected individuals and regulatory authorities when personal data is compromised.

State of Alabama • Alabama, USA • vPolicy 621-01

View details
PrivacyLaw

Arkansas PIPA — Arkansas Personal Information Protection Act

The Arkansas Personal Information Protection Act (PIPA) is a data privacy and security law that requires organizations to protect personal information, implement reasonable security measures, and notify affected individuals in the event of a qualifying data breach.

State of Arkansas • Arkansas, USA

View details
CybersecurityStandard

NZISM — New Zealand Information Security Manual

The New Zealand Information Security Manual (NZISM) is the New Zealand Government’s information security framework that provides baseline security controls, processes, and guidance to help organizations protect information systems and manage cybersecurity risks effectively.

New Zealand Government Communications Security Bureau (GCSB) • New Zealand • version 3.9

View details
PrivacyRegulation

Nevada Chapter 603A — Security and Privacy of Personal Information

Nevada Chapter 603A - Security and Privacy of Personal Information is a Nevada privacy and data security law that requires organizations to safeguard personal information, notify individuals of certain data breaches, and comply with consumer privacy requirements relating to the collection, use, and protection of personal data.

State of Nevada • Nevada, USA

View details
PrivacyLaw

Hawaii - Security Breach of Personal Information Chapter 487N

Hawaii Security Breach of Personal Information (Chapter 487N) is a Hawaii state law that requires businesses and government agencies to notify affected individuals of data breaches involving personal information and establishes requirements for protecting and managing sensitive personal data.

State of Hawaii • Hawaii

View details
PrivacyLaw

Pakistan EDPA 2005 — Pakistan The Electronic Data Protection Act, 2005

The Electronic Data Protection Act, 2005 is a law enacted in Pakistan to address the processing and protection of electronic data. It aims to ensure the privacy, security, and rights of data subjects, with provisions for data processing, security measures, and penalties for violations.

Government of Pakistan • Pakistan

View details
CybersecurityFramework

DESE ISMS Scheme — DESE Information Security Management Systems (ISMS) Scheme

The DESE ISMS Scheme is an information security certification framework that combines ISO/IEC 27001, the Australian Government Information Security Manual (ISM), and the Right Fit For Risk (RFFR) framework to help service providers manage cyber risks and protect sensitive information.

Australian Department of Employment and Workplace Relations (DEWR) • Australia

View details
GRCLaw

South Africa Electronic Communications and Transactions Act 25 of 2002

The Electronic Communications and Transactions Act 25 of 2002 establishes legal and policy frameworks for regulating electronic communications and transactions in South Africa. It aims to facilitate universal access to electronic services, prevent abuse of information systems, and promote the use of e-government services and small business technology adoption.

Government of South Africa • South Africa

View details
CybersecurityStandard

Cert NZ Top 10 Critical Controls — Cert New Zealand Top Ten Critical Controls

The CERT NZ Top Ten Critical Controls is a cybersecurity framework that outlines ten essential security controls organizations can implement to reduce cyber risk, improve resilience, and protect systems, data, and services from common cyber attacks.

National Cyber Security Centre (NCSC) • New Zealand • v2021

View details
PrivacyLaw

Brazilian LGPD — Brazilian General Data Protection Law

The LGPD is Brazil’s first comprehensive data protection regulation, aligned with principles of the EU GDPR. It governs the processing, storage, and sharing of personal data of individuals within Brazil, including data security and breach notifications.

Brazilian government • Brazil

View details
PrivacyLaw

New York Privacy Act

The New York Privacy Act aims to provide state-level consumer privacy protections similar to California’s CCPA. It introduces rights like access, correction, and challenging automated decision-making, while requiring businesses to implement security measures and obtain consent for specific practices.

New York State Legislature • New York, United States

View details
CybersecurityFramework

Spain ENS — Spain - National Security Framework

The National Security Framework (ENS) is Spain's national cybersecurity framework that defines security principles and controls for public sector organizations and their suppliers to protect information systems and ensure the confidentiality, integrity, availability, authenticity, and traceability of digital services.

Government of Spain • Spain • v5 May 2022

View details
PrivacyLaw

Dubai HDPR — Dubai Health Data Protection Regulation - DHCC Regulation No. 7 of 2013

The Dubai Health Data Protection Regulation is a healthcare privacy regulation that governs the protection, use, disclosure, and management of patient health information within Dubai Healthcare City, ensuring the confidentiality and security of health data.

Dubai Healthcare City Authority (DHCA) • Dubai • v21 October 2013

View details
GRCLaw

Criminal Code Act 1995

The Criminal Code Act 1995 is an Australian federal law that establishes the legal framework for addressing criminal offenses. It outlines principles of criminal responsibility, specific offenses such as terrorism and espionage, and provisions for external and corporate liabilities.

Attorney-General's Department • Australia • vNo. 137, 17 February 2021

View details

Partner directory

Certified resellers, integrators and advisors to help you implement and manage your GRC program.

Explore all partners (88)

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call