Cyber, critical infrastructure & AI standards — all in one place.
The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.
Browse by industry
Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.
Explore all industriesContent Library
Showing 18 of 18
APS 222 — Prudential Standard APS 222: Associations with Related Entities
APS 222 is a prudential standard issued by the Australian Prudential Regulation Authority (APRA) aimed at ensuring that authorised deposit-taking institutions (ADIs) identify, monitor, and control risks related to their associations and dealings with related entities. It mandates policies and limits on exposures to mitigate contagion and step-in risks.
Australian Prudential Regulation Authority (APRA) • Australia • vJanuary 2015
APS 220 — Prudential Standard APS 220 Credit Risk Management
APS 220 sets requirements for authorised deposit-taking institutions (ADIs) to establish a comprehensive credit risk management framework. The standard includes strategies, policies, and procedures for identifying, assessing, and mitigating credit risks.
Australian Prudential Regulation Authority (APRA) • Australia • vSeptember 2020
APS 210 — Prudential Standard APS 210 Liquidity
APS 210 Liquidity is a prudential standard issued by APRA requiring authorised deposit-taking institutions (ADIs) to adopt prudent practices in managing liquidity risks. It mandates maintaining adequate liquidity to meet obligations under various operating scenarios, including severe stress situations.
Australian Prudential Regulation Authority (APRA) • Australia
3PS 221- Aggregate Risk Exposures — Banking, Insurance and Life Insurance (prudential standard) determination No. 2 of 2016 - Prudential Standard 3PS 221 Aggregate Risk Exposures
This legislative determination establishes prudential requirements for managing and reporting aggregate risk exposures within banking, insurance, and life insurance sectors. It aims to ensure robust risk management practices across these industries.
Australian Prudential Regulation Authority (APRA) • Australia • v13 September 2016
SIS Act — Superannuation Industry (Supervision) Act 1993
The Superannuation Industry (Supervision) Act 1993 establishes the regulatory framework for superannuation funds in Australia. It defines compliance standards for trustees, funds, and associated entities, aiming to ensure proper administration and protection of member benefits.
Australian Government • Australia • vNo. 78, 1993
LGOIMA — Local Government Official Information and Meetings Act 1987 - New Zealand
The Local Government Official Information and Meetings Act 1987 (LGOIMA) is a New Zealand law that provides public access to information held by local authorities and council-controlled organizations. It also sets transparency standards for local government meetings, ensuring public notification and accessibility.
New Zealand Government • New Zealand • v23 December 2023
Cyber Essentials Danzell Question Set — Cyber Essentials Question Set v3.3 (Danzell) April 2026
Cyber Essentials: Requirements for IT Infrastructure v3.3 Question Set is a structured self-assessment designed to help organizations evaluate their cyber security practices. It focuses on five key technical control areas—firewalls, secure configuration, user access control, malware protection, and patch management. By completing the question set, organizations can demonstrate compliance with baseline security standards and strengthen resilience against common cyber threats.
National Cyber Security Centre (NCSC) • v3.3
ISO/IEC 27018:2025 — ISO/IEC 27018:2025 Information security, cybersecurity and privacy protection — Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors
ISO/IEC 27018:2025 is the global standard for managing personally identifiable information (PII) in public cloud services. It provides cloud providers with a framework to ensure privacy, security, and compliance when processing customer data.
International Organization for Standardization (ISO) • v2025
ISM CCM — Information Security Manual Cloud Controls Matrix Template
The Cloud Controls Matrix (CCM) Template is a comprehensive framework for mapping cloud security controls to industry standards and compliance requirements. It helps organizations assess, implement, and demonstrate effective cloud security practices across diverse environments.
Australian Government • Australia • vJune 2026
ISM SSP — Information Security Manual System Security Plan Annex Template
The System Security Plan (SSP) Annex Template is a structured document used to capture detailed information about an organization’s cyber security controls and implementation. It supports accreditation processes by providing evidence of compliance, risk management, and system-specific security measures.
Australian Government • Australia • vJune 2026
RFFR ISM SoA — Right Fit for Risk Information Security Manual Statement of Applicability
The Right Fit for Risk (RFFR) Statement of Applicability (SoA) is a structured template used to document how organizations meet cyber security accreditation requirements. It outlines applicable controls, their implementation status, and provides assurance of compliance with the RFFR framework.
Australian Government • Australia • vJune 2026
ISM — Information Security Manual
The Australian ISM is the nationally recognized cybersecurity framework developed by the Australian Signals Directorate. It provides organizations with structured guidance to safeguard information and operational technology systems against evolving cyber threats.
Australian Government • Australia • vJune 2026
DCC-1:2022 — Data Cybersecurity Controls
The Data Cybersecurity Controls (DCC-1:2022) establish minimum cybersecurity requirements to protect data throughout its lifecycle. Issued by the Saudi National Cybersecurity Authority, the controls build on existing cybersecurity frameworks to enhance the Kingdom's overall cybersecurity maturity.
National Cybersecurity Authority (NCA) • Kingdom of Saudi Arabia • v1:2022
ISO 9001 — ISO 9001:2015 Quality Management Systems — Requirements
ISO 9001:2015 is an international standard for quality management systems. It provides requirements for organizations to establish, implement, maintain, and continually improve a quality management system to enhance customer satisfaction and operational efficiency.
International Organization for Standardization (ISO) • v2015 (Edition 5)
ISO 45001 — ISO 45001:2018 - Occupational Health and Safety Management Systems — Requirements with Guidance for Use
ISO 45001:2018 is an international standard that specifies requirements for an occupational health and safety (OH&S) management system. It helps organizations improve workplace safety, reduce risks, and enhance overall OH&S performance.
International Organization for Standardization (ISO) • v2018
ITSP.10.171 — Protecting Specified Information in Non-Government of Canada Systems and Organizations
ITSP.10.171 sets out security requirements for protecting 'specified information' when it resides in non-Government of Canada systems or organizations. It aligns with NIST standards but adapts them to the Canadian regulatory environment.
Canadian Centre for Cyber Security • Canada • vFirst release
AIUC-1 — AIUC-1
AIUC-1 is a standard focused on the security, safety, and reliability of AI agents used in enterprises. It addresses risks related to data privacy, security, accountability, and societal concerns while providing certification for compliant organizations.
Artificial Intelligence Underwriting Company (AIUC) • vApril 15, 2026
CPG 234 — CPG 234 Information Security
This standard provides information security guidance for Australian financial institutions regulated by APRA. It aims to ensure operational resilience and protect against information security threats.
Australian Prudential Regulation Authority (APRA) • Australia • vJune 2019
Partner directory
Certified resellers, integrators and advisors to help you implement and manage your GRC program.

1886 Consulting
- Region
- Australia
Tap into our knowledge of wealth.
Governance • Risk Management • Compliance Management • GRC Advisory

19eighty Advisory
- Region
- Australia
Business ownership is the most powerful calling.

3 Lights
- Region
- 4001, Brisbane, Australia
Finance & Professional Services, Healthcare, Technology & Telecommunications Energy & Utilities
ISO27001 • NIST • SMB1001

3Quotes
- Region
- Canada
Your IT Procurement Partner

A1 Hrvatska d.o.o.
- Region
- Croatia
Croatia's leading telecommunications provider offering mobile, internet, TV, and managed security services.
Managed Security Services • Security Operations • Cloud Security

Accenture
- Region
- Australia
De-risk tomorrow by infusing cybersecurity into strategy, resilience, and protection at global scale.
GRC Advisory • Risk Management • Compliance Management • Security Operations

AfterDark Technology
- Region
- Australia
ISO 27001-certified managed IT services provider keeping Australian businesses secure, reliable, and running.
IT Managed Services • Managed Security Services • Essential Eight • ISO 27001

Archer & Round
- Region
- Australia
Cybersecurity that keeps you one step ahead with 24/7 managed SOC, vCISO, and GRC services.
Managed Security Services • Governance • Risk Management • Incident Response
Ready to manage these frameworks?
6clicks maps regulations to controls, evidence and risks — automatically.