# 6clicks Marketplace — full content > Complete metadata for every published catalog entry. Each section includes the canonical 6clicks URL, summary, description and key facts. Use this when you need to ground a response in the full text of a regulation rather than a one-line summary. Generated by Orbit for 6clicks · last updated 2026-08-13 · 224 entries · index at https://marketplace.6clicks.com/llms.txt --- ## AIUC-1 — AIUC-1 URL: https://marketplace.6clicks.com/c/aiuc-1 Domain: AI Type: standard Issued by: Artificial Intelligence Underwriting Company (AIUC) Version: April 15, 2026 Industries: Cybersecurity Tags: ai standards, security, data privacy, reliability, ai risk management Source: https://www.aiuc-1.com/ Available in the 6clicks app: yes Summary: AIUC-1 is a standard focused on the security, safety, and reliability of AI agents used in enterprises. It addresses risks related to data privacy, security, accountability, and societal concerns while providing certification for compliant organizations. Description: AIUC-1 is a comprehensive standard designed to facilitate trusted adoption of AI agents in enterprise settings. Created in collaboration with industry experts, Fortune 500 CISOs, and academic institutions, it provides concrete controls to address the key risks associated with AI adoption. The standard includes specific guidelines across six core domains: Data & Privacy, Security, Accountability, Reliability, Safety, and Society. It emphasizes third-party testing, continuous updates, and alignment with other frameworks like MITRE ATLAS, NIST AI RMF, and ISO 42001. AIUC-1 offers certifications for organizations that meet its rigorous criteria and is updated quarterly to remain aligned with technological advancements and regulatory trends. --- ## EU AI Act — EU Artificial Intelligence Act URL: https://marketplace.6clicks.com/c/eu-ai-act Domain: AI Type: regulation Issued by: European Union Jurisdiction: EU Version: January 2024 Last updated: 2021-04-21 Tags: artificial intelligence, trustworthy ai, high-risk systems, european union, regulation, safety, fundamental rights Source: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 Document: https://data.consilium.europa.eu/doc/document/ST-5662-2024-INIT/en/pdf Available in the 6clicks app: yes Summary: The EU AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive law regulating artificial intelligence. It establishes a risk-based framework that classifies AI systems into four categories—unacceptable, high-risk, limited-risk, and minimal-risk—with stricter obligations applied to higher-risk systems. Description: The EU AI Act (Regulation (EU) 2024/1689) establishes a comprehensive, risk-based framework for regulating artificial intelligence across the European Union, applying to both EU and non-EU providers whose systems impact EU users. It categorizes AI systems into unacceptable, high-risk, limited-risk, and minimal-risk tiers, with stricter obligations—such as risk management, data governance, transparency, and human oversight—imposed on higher-risk applications. The regulation aims to protect fundamental rights, ensure safety, and promote trustworthy, human-centric AI while supporting innovation and market growth. It also introduces governance structures, conformity assessments, and significant penalties for non-compliance, reinforcing accountability across the AI lifecycle. Overall, the Act sets a global benchmark for balancing AI innovation with ethical and legal safeguards. --- ## ISO/IEC 42001 — ISO/IEC 42001:2023 - Artificial Intelligence Management System URL: https://marketplace.6clicks.com/c/iso-iec-42001 Domain: AI Type: standard Issued by: ISO/IEC Version: 2023 Effective: 2023-12-18 Last updated: 2023-12-18 Industries: Cybersecurity, Risk Management, Legal, Risk and Compliance Tags: artificial intelligence, risk management, governance, ethics, responsible ai, compliance, transparency Source: https://www.iso.org/standard/42001 Available in the 6clicks app: yes Summary: ISO/IEC 42001:2023 is the first international standard for Artificial Intelligence Management Systems (AIMS). It provides requirements for establishing, implementing, maintaining, and improving AIMS, focusing on the responsible use, governance, and risk management of AI across organizations. Description: ISO/IEC 42001:2023 outlines a structured framework for organizations to manage the risks and opportunities related to AI systems. It is designed to ensure responsible AI development and use, addressing key challenges such as ethics, transparency, traceability, and compliance. The standard uses the Plan-Do-Check-Act methodology to guide organizations in implementing an Artificial Intelligence Management System tailored to various AI applications. It supports ethical AI practices, enhances trust, and ensures compliance with regulatory standards while encouraging innovation. ISO/IEC 42001 applies to any organization involved in developing, providing, or utilizing AI technologies. --- ## NIST AI RMF — NIST AI Risk Management Framework URL: https://marketplace.6clicks.com/c/nist-ai-rmf Domain: AI Type: framework Issued by: National Institute of Standards and Technology (NIST) Jurisdiction: United States Version: 1.0 Effective: 2023-01-26 Industries: Critical infrastructure Tags: ai risks, trustworthiness, governance, risk management, framework, ai lifecycle Source: https://airc.nist.gov/airmf-resources/airmf/ Document: https://nvlpubs.nist.gov/nistpubs/ai/NIST-AI-RMF-1.0.pdf Available in the 6clicks app: yes Summary: The AI Risk Management Framework (AI RMF) is a voluntary framework developed by NIST to help organizations design, develop, use, and evaluate AI systems with trustworthiness considerations. It addresses governance, mapping, measuring, and managing AI risks. Description: The AI RMF is intended to improve the integration of trustworthiness into the lifecycle of AI systems. Developed through collaboration with over 240 organizations across private industry, academia, and government, the framework includes guidelines for understanding AI risks, ensuring trustworthiness, and implementing effective risk management practices. It is structured around four core functions—Govern, Map, Measure, and Manage—with use-case profiles customizable to specific applications and settings. Appendices provide in-depth details like how AI risks differ from traditional software risks and tasks performed by AI actors. The AI RMF aims to create effective risk dialogues and guidelines for trustworthy AI. --- ## DORA — Regulation (EU) 2022/2554 - Digital Operational Resilience Act URL: https://marketplace.6clicks.com/c/dora Domain: Critical Infrastructure Type: regulation Issued by: European Parliament and Council of the European Union Jurisdiction: EU Effective: 2022-12-27 Last updated: 2022-12-27 Industries: Finance Sector Tags: digital resilience, financial sector, ict risk, incident reporting, cross border, european union Source: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554#cpt_II Document: http://data.europa.eu/eli/reg/2022/2554/oj Available in the 6clicks app: yes Summary: Regulation (EU) 2022/2554, known as DORA, establishes a unified framework for digital operational resilience in the European Union's financial sector. It aims to ensure financial entities can withstand, recover, and adapt to ICT-related disruptions while safeguarding the stability and integrity of the financial system. Description: DORA introduces consistent rules across EU member states to address ICT risks, enhance oversight of third-party ICT service providers, streamline incident reporting, and ensure operational resilience testing in the financial sector. It highlights the critical role of ICT in financial systems and seeks to close gaps in regulation while addressing disparities that hinder market function. DORA complements the Single Rulebook by integrating ICT risk management requirements and strengthens mandates for supervisory authorities to oversee the implementation of its provisions. --- ## EASA Part-IS — European Union Aviation Safety Agency (EASA) - Part IS - Easy Access Rules for Information Security URL: https://marketplace.6clicks.com/c/easa-part-is Domain: Critical Infrastructure Type: regulation Issued by: European Union Jurisdiction: EU Version: December 2025 Industries: Critical infrastructure Tags: aviation safety, cybersecurity, information security, risk management, incident response, isms Source: https://part-is.eu/regulation/?v=da984e42a589 Document: https://part-is.eu/regulation/?v=da984e42a589 Available in the 6clicks app: yes Summary: The EASA Part-IS Regulation mandates information security measures within the aviation sector to address digital threats that impact safety. It provides a framework for managing risks, responding to incidents, and safeguarding aviation systems. Description: The EASA Part-IS Regulation addresses the increasing threats posed by digital vulnerabilities and cyber risks in the aviation domain. It applies to a variety of stakeholders, including airlines, airports, maintenance organizations, and civil aviation authorities within the European ecosystem. The regulation requires organizations to adopt an Information Security Management System (ISMS) tailored to their operational needs, conduct regular risk assessments, and implement robust incident detection, response, and recovery processes. Reporting security incidents to both internal and external authorities is emphasized, alongside collaborative efforts within the aviation ecosystem to enhance resiliency. Continuous improvement is central to compliance, comprising regular audits, threat monitoring, and staff training. Smaller operators may have tailored proportional requirements, ensuring focus on entities posing higher risks. --- ## EU Regulation 2022/1645 — Commission Delegated Regulation (EU) 2022/1645 URL: https://marketplace.6clicks.com/c/eu-regulation-2022-1645 Domain: Critical Infrastructure Type: regulation Issued by: European Commission Jurisdiction: EU Last updated: 2022-01-14 Industries: Critical infrastructure Tags: cybersecurity, aviation, regulation, information security, easa Source: https://www.easa.europa.eu/en/document-library/regulations/commission-delegated-regulation-eu-20221645 Document: https://www.easa.europa.eu/en/document-library/regulations/commission-delegated-regulation-eu-20221645 Available in the 6clicks app: yes Summary: EU Regulation 2022/1645 establishes mandatory cybersecurity management requirements for Part 21 Design Organisations (DOs) and Production Organisations (POs) in the aviation sector. It introduces the implementation of an Information Security Management System (ISMS) to protect critical systems, data, and processes from cyber threats. Description: Commission Delegated Regulation (EU) 2022/1645 is an amendment to Regulation (EU) No 748/2012, introducing cybersecurity management requirements in Subparts J and G of Part 21 for Design Organisations (DOs) and Production Organisations (POs). These entities are required to implement and maintain an Information Security Management System (ISMS) to identify and manage security risks impacting aviation safety, establish incident reporting mechanisms, and ensure continuous improvement in cybersecurity. Key challenges include integrating ISMS with existing safety systems, managing compliance with evolving regulations, and addressing supply chain and cultural resistance issues. The regulation aligns with EASA cybersecurity rulemaking and addresses risks like legacy system vulnerabilities, remote work security, and insider threats. --- ## FBTAA 1986 — Fringe Benefits Tax Assessment Act 1986 URL: https://marketplace.6clicks.com/c/fbtaa-1986 Domain: Critical Infrastructure Type: law Issued by: Australian Government Jurisdiction: Australia Version: Compilation No. 84, 1 April 2019 Effective: 1986-06-24 Last updated: 2019-04-01 Industries: Finance Sector, Government Tags: Fringe Benefits Tax, FBTAA 1986, Australian Tax Law, Employer Benefits, Tax Compliance, Taxation Source: https://www.legislation.gov.au/C2004A03280/2019-04-01/text Available in the 6clicks app: yes Summary: The Fringe Benefits Tax Assessment Act 1986 is the Australian legislation that governs the taxation of non-cash benefits provided by employers to employees, establishing the rules for identifying, valuing, and taxing fringe benefits. Description: The Fringe Benefits Tax Assessment Act 1986 (FBTAA 1986) is an Australian Commonwealth law that establishes the framework for the taxation of fringe benefits provided by employers to employees and their associates in respect of employment. Administered by the Department of the Treasury and the Australian Taxation Office (ATO), the Act defines what constitutes a fringe benefit, sets out the rules for valuing taxable benefits, identifies exemptions and concessions, and specifies employers' fringe benefits tax (FBT) obligations. The legislation ensures that non-cash employment benefits, such as company cars, expense payments, housing, entertainment, and other benefits, are appropriately taxed as part of Australia's taxation system. --- ## NIST SP 800-82 Rev. 3 — NIST Special Publication 800-02 Rev. 3 - Guide to Operational Technology (OT) Security URL: https://marketplace.6clicks.com/c/sp-800-82-rev-3 Domain: Critical Infrastructure Type: guideline Issued by: National Institute of Standards and Technology (NIST) Jurisdiction: United States Version: Revision 3 Effective: 2023-09-28 Industries: Cybersecurity, Risk Management Tags: operational-technology, industrial-control-systems, cybersecurity, risk-management, security-controls, scada, network-security Source: https://csrc.nist.gov/pubs/sp/800/82/r3/final Document: https://doi.org/10.6028/NIST.SP.800-82r3 Available in the 6clicks app: yes Summary: This document provides guidance on securing operational technology (OT) systems, which include programmable devices interacting with the physical environment. It addresses unique performance, reliability, and safety requirements, identifies threats, and recommends security measures. Description: NIST SP 800-82 Rev. 3 is a guide to securing operational technology (OT), such as industrial control systems, transportation systems, and building automation systems. It includes an overview of OT systems and their topologies, explores common threats and vulnerabilities, and provides detailed security countermeasures to mitigate risks. The standard emphasizes the need to balance security with the unique performance, reliability, and safety needs of OT systems. This revision, finalized in September 2023, supersedes Rev. 2 and includes updates reflecting advancements in OT and emerging security challenges. It serves industries that rely on OT systems and aims to improve their resilience against cyber threats. --- ## SMDDS — OWASP Secure Medical Devices Deployment Standard URL: https://marketplace.6clicks.com/c/owasp-secure-medical-devices-deployment-standard Domain: Critical Infrastructure Type: guideline Issued by: OWASP Effective: 2018-08-07 Industries: Critical infrastructure Tags: medical devices, cybersecurity, iot, healthcare, deployment, incident response Source: https://cloudsecurityalliance.org/artifacts/owasp-secure-medical-devices-deployment-standard Document: https://cloudsecurityalliance.org/artifacts/owasp-secure-medical-devices-deployment-standard Available in the 6clicks app: yes Summary: The OWASP Secure Medical Devices Deployment Standard provides guidance for the secure deployment of medical devices within healthcare environments, addressing the rising threats such as botnets and malware targeting IoT devices. It emphasizes security measures across device purchasing, network security, interface controls, and incident handling. Description: This standard highlights the critical importance of incorporating security measures in the deployment of medical devices, which have traditionally focused solely on patient safety while often neglecting cybersecurity risks. Given the growing risk posed by botnets, malware, and other threats to IoT devices, the standard prescribes actionable controls across areas like procurement processes, perimeter and network security, device-specific measures, and interface and central station configurations. It also advises regular security testing and robust incident response mechanisms to maintain operational integrity in healthcare facilities. --- ## SOCIA 2018 — Security of Critical Infrastructure Act 2018 URL: https://marketplace.6clicks.com/c/socia-2018 Domain: Critical Infrastructure Type: law Issued by: Australian Department of Home Affairs Jurisdiction: Australia Version: No. 29, 2018 Effective: 2018-04-11 Industries: Critical infrastructure, Cybersecurity, Government Tags: critical infrastructure, cybersecurity, risk management, australia, national security Source: https://www.legislation.gov.au/C2018A00029/latest/text Document: https://www.legislation.gov.au/C2018A00029/latest/text Available in the 6clicks app: yes Summary: The Security of Critical Infrastructure Act 2018 (SOCIA) establishes a regulatory framework for managing national security risks to Australia’s critical infrastructure sectors. It introduces statutory obligations, reporting requirements, and oversight mechanisms for critical assets. Description: The Security of Critical Infrastructure Act 2018 (SOCIA), administered by the Australian Department of Home Affairs, is designed to safeguard critical infrastructure in Australia from national security risks. The Act mandates the creation and maintenance of a Register of Critical Infrastructure Assets, obligatory risk management programs for responsible entities, and notification of cyber security incidents. Key sectors covered include energy, telecommunications, data storage, financial services, and transportation. Enhanced powers are granted to ministers for issuing directives in response to serious incidents, ensuring heightened security standards for telecommunications assets, and mandating code exercises and vulnerability assessments. It also introduces robust penalty mechanisms for non-compliance and unauthorized disclosures. --- ## Agricultural and Veterinary Chemicals Code Act 1994 URL: https://marketplace.6clicks.com/c/agricultural-and-veterinary-chemicals-code-act-1994 Domain: Critical Infrastructure Type: law Issued by: Australian Government Jurisdiction: Australia Version: Compilation No. 29, 21 October 2016 Effective: 1994-06-15 Last updated: 2016-10-21 Industries: Critical infrastructure, Government Tags: chemical regulation, law, veterinary, agriculture, compliance, safety, approval, manufacturing Source: https://www.legislation.gov.au/C2004A04723/2016-10-21/text Document: https://www.legislation.gov.au/C2004A04723/2016-10-21/text Available in the 6clicks app: yes Summary: This Australian law establishes the framework for regulating agricultural and veterinary chemical products. It governs approvals, registrations, manufacturing, use, labeling, distribution, and enforcement actions to ensure safety, efficacy, and compliance across the chemicals sector. Description: The Agricultural and Veterinary Chemicals Code Act 1994 provides a comprehensive regulatory framework for managing agricultural and veterinary chemical products in Australia. The act defines standards for approving active ingredients, registering chemical products, and approving their labels. The Australian Pesticides and Veterinary Medicines Authority (APVMA) is tasked with implementing and enforcing these standards, including product recalls, monitoring compliance, and imposing penalties for breaches. The law ensures alignment with trade, safety, efficacy, and labeling criteria. It also regulates the manufacture and supply of both approved and restricted chemical products, establishes rules related to compensation for information use, and implements investigative powers. --- ## Clean Energy Act 2011 URL: https://marketplace.6clicks.com/c/clean-energy-act-2011 Domain: Critical Infrastructure Type: law Issued by: Parliament of Australia Jurisdiction: Australia Effective: 2011-11-18 Industries: Environment, Government Tags: carbon pricing, climate change, emissions trading, energy efficiency, environmental law Source: https://www.aph.gov.au/Parliamentary_Business/Bills_Legislation/Bills_Search_Results/Result?bId=r4653 Document: https://www.legislation.gov.au/Details/C2011A00131 Available in the 6clicks app: yes Summary: The Clean Energy Act 2011 establishes the framework for implementing a carbon pricing mechanism in Australia. It includes provisions for covered entities, emission obligations, and limits on emissions units. Description: The Clean Energy Act 2011 is part of a broader package of 18 bills aiming to create a carbon pricing mechanism in Australia. The Act details the entities and emissions subject to the mechanism, obligations to surrender eligible emissions units, the issuance and allocation of carbon units, cost-containment mechanisms, and provisions for linking with other emissions trading schemes. It also includes assistance measures for emissions-intensive and trade-exposed activities, coal-fired electricity generators, and establishes frameworks for monitoring, enforcement, and administrative review. The Act further provides for reviews of various aspects of the mechanism to ensure its effectiveness. --- ## Commission Implementing Regulation (EU) 2023/203 URL: https://marketplace.6clicks.com/c/commission-implementing-regulation-eu-2023-203 Domain: Critical Infrastructure Type: regulation Issued by: European Union Aviation Safety Agency (EASA) Jurisdiction: EU Version: 2023/203 Tags: aviation, information security, risk management, aviation safety, easa, regulation, cybersecurity Source: https://www.easa.europa.eu/en/document-library/regulations/commission-implementing-regulation-eu-2023203 Available in the 6clicks app: yes Summary: This regulation outlines requirements for the management of information security risks that could impact aviation safety. It applies to organisations and competent authorities operating in the aviation sector to ensure secure operations. Description: Commission Implementing Regulation (EU) 2023/203 establishes mandatory requirements for managing information security risks in the aviation industry. It is designed to ensure that organizations and competent authorities identify, evaluate, and mitigate information security risks that could impact aviation safety. The regulation mandates the adoption of structured processes and measures to safeguard critical aviation systems and data. By addressing the specific risks related to cyber threats in aviation, the regulation aims to enhance resilience within a highly interconnected and increasingly digitized industry. This framework supports robust management practices and aligns stakeholders around common safety objectives. --- ## Independent Contractors Act 2006 URL: https://marketplace.6clicks.com/c/independent-contractors-act-2006 Domain: Critical Infrastructure Type: law Issued by: Australian Government Jurisdiction: Australia Version: Compilation No. 7, 1 July 2016 Effective: 2006-12-11 Industries: Government Tags: Independent Contracting, Workplace Relations, Employment Law, Services Contracts, Contractor Rights Source: https://www.legislation.gov.au/Details/C2016C00818 Available in the 6clicks app: yes Summary: The Independent Contractors Act 2006 is Australian legislation that regulates independent contracting arrangements, protects the rights of independent contractors, and provides mechanisms for addressing unfair services contracts. Description: The Independent Contractors Act 2006 is an Australian Commonwealth law that establishes a national framework governing independent contracting arrangements. Administered by the Department of Employment and Workplace Relations, the Act promotes freedom of contract for independent contractors while providing protections against unfair or harsh contracting arrangements. It sets out rules relating to the recognition of independent contractor relationships, prevents discrimination against independent contractors, and enables courts to review and, where appropriate, set aside unfair services contracts. The legislation supports the operation of independent contracting while distinguishing such arrangements from traditional employer-employee relationships within Australia's workplace relations system. --- ## Ozone Protection and Synthetic Greenhouse Gas Management Act 1989 URL: https://marketplace.6clicks.com/c/ozone-protection-and-synthetic-greenhouse-gas-management-act-1989 Domain: Critical Infrastructure Type: law Issued by: Australian Government Jurisdiction: Australia Version: 7, 1989 Effective: 1989-03-16 Last updated: 2020-01-01 Industries: Environment, Legislation Tags: ozone, greenhouse gases, montreal protocol, environment, compliance, australia Source: https://www.legislation.gov.au/Details/C2020C00041 Document: https://www.legislation.gov.au/Details/C2020C00041 Available in the 6clicks app: yes Summary: The Ozone Protection and Synthetic Greenhouse Gas Management Act 1989 is Australian legislation designed to manage the use, import, and export of ozone-depleting substances (ODS) and synthetic greenhouse gases (SGGs). It aligns with Australia's obligations under the Montreal Protocol, emphasizing environmental protection through licensing, quotas, and controls on substances and equipment. Description: This Act provides a regulatory framework in Australia for the management of substances that deplete the ozone layer or contribute to synthetic greenhouse gas emissions. Key features include the implementation of a licensing system for controlled substances, restrictions on imports and exports, and obligations for the reporting and recordkeeping of manufacturers, importers, and exporters. The legislation includes mechanisms to limit quotas for substances such as hydrochlorofluorocarbons (HCFCs) and hydrofluorocarbons (HFCs) and establishes enforcement powers granted to inspectors. The Act also outlines requirements for the disposal and use of these substances and implements penalties for non-compliance. Through these measures, Australia meets its commitments under the Montreal Protocol. --- ## Renewable Energy (Electricity) Act 2000 URL: https://marketplace.6clicks.com/c/renewable-energy-electricity-act-2000 Domain: Critical Infrastructure Type: law Issued by: Australian Government Jurisdiction: Australia Last updated: 2016-03-10 Industries: Critical infrastructure, Environment Tags: renewable energy, electricity, certificates, energy regulation, compliance, large-scale generation, small-scale technology Source: https://www.legislation.gov.au/Details/C2016C00624 Document: https://www.legislation.gov.au/Details/C2016C00624 Available in the 6clicks app: yes Summary: The Renewable Energy (Electricity) Act 2000 establishes a legal framework to encourage the generation of electricity from renewable energy sources in Australia. It creates a system for renewable energy certificates and mandates a Renewable Power Percentage to ensure participation by electricity retailers. Description: The Renewable Energy (Electricity) Act 2000, administered by the Department of Climate Change, Energy, the Environment and Water, is designed to promote Australia’s transition to renewable energy. The Act mandates the use of renewable energy certificates and specifies procedures for their creation, registration, transfer, and retirement. It encompasses frameworks for large-scale generation, small-scale technology installations, and emerging renewable technologies. Additionally, the Act includes provisions for penalties, exemptions, audits, and reporting requirements for regulated entities. Renewable energy targets are set and enforced under the Act, ensuring structured compliance and progress tracking. --- ## ADHICS — Abu Dhabi Healthcare Information and Cyber Security Standard URL: https://marketplace.6clicks.com/c/aamen Domain: Cybersecurity Type: standard Issued by: Department of Health Abu Dhabi Jurisdiction: Abu Dhabi, United Arab Emirates Version: 2 Last updated: 2026-05-01 Industries: Cybersecurity Tags: cybersecurity, healthcare, data privacy, information security, risk management, compliance, infrastructure Source: https://www.doh.gov.ae/en/programs-initiatives/Aamen Document: https://www.doh.gov.ae/-/media/Project/DoH/Programs/AAMEN/ADHICS-Standard-V2.pdf Available in the 6clicks app: yes Summary: The AAMEN programme ensures that all healthcare facilities in Abu Dhabi comply with information security and data privacy standards to safeguard patient data. It incorporates the Abu Dhabi Healthcare Information and Cyber Security Standard (ADHICS) and aims to enhance cybersecurity governance, resilience, and innovation in the healthcare sector. Description: The Abu Dhabi Healthcare Information Security Programme (AAMEN) is an initiative by the Department of Health Abu Dhabi to ensure the emirate’s healthcare sector adheres to robust information security and data privacy standards. The programme includes the Abu Dhabi Healthcare Information and Cyber Security Strategy, which outlines the sector's approach to mitigating cyber threats, with areas of focus such as cybersecurity governance, resilience, capabilities, partnerships, maturity, and innovation. A key component of AAMEN is the ADHICS V2 standard, which establishes the minimum cybersecurity requirements for healthcare facilities. Other initiatives under AAMEN include awareness programs, partnerships with the Abu Dhabi Healthcare CERT team, and support for IoMT security and patient authentication. The programme aims to secure sensitive health data, foster digital transformation, and ensure business continuity. --- ## AESCSF v2 Core — Australian Energy Sector Cyber Security Framework URL: https://marketplace.6clicks.com/c/aescsf-v2-core Domain: Cybersecurity Type: framework Issued by: Australian Energy Market Operator (AEMO) Jurisdiction: Australia Version: 2.0 Last updated: 2023-01-01 Industries: Cybersecurity, Critical infrastructure Tags: cybersecurity, energy, risk-management, resilience, framework Source: https://www.aemo.com.au/-/media/files/initiatives/cyber-security/aescsf/2023/the-aescsf-v2-core.xlsx?rev=4375ddea4d394bee8b5c9bb7eb7fcbde&sc_lang=en Document: https://www.aemo.com.au/-/media/files/initiatives/cyber-security/aescsf/2023/the-aescsf-v2-core.xlsx?rev=4375ddea4d394bee8b5c9bb7eb7fcbde&sc_lang=en Available in the 6clicks app: yes Summary: The Australian Energy Sector Cyber Security Framework (AESCSF) provides a structured approach for managing cybersecurity risks specific to the energy sector. Version 2 introduces updates and refinements to address evolving threats and ensure resilience. Description: The Australian Energy Sector Cyber Security Framework (AESCSF) is designed to enhance the cybersecurity posture of organizations within the energy sector. It serves as a guideline to evaluate and improve cybersecurity capabilities, focusing on risk management and resilience. Version 2 (2023) provides core components, metrics, and practices tailored for energy systems to mitigate risks from cyber threats. It includes enhancements aligned with global best practices while addressing sector-specific challenges, enabling organizations to maintain secure and reliable operations. --- ## Alabama Data Breach Notification Act of 2018 — Chapter 38 Data Breach Notification Act of 2018 URL: https://marketplace.6clicks.com/c/chapter-38-data-breach-notification-act-of-2018 Domain: Cybersecurity Type: law Issued by: State of Alabama Jurisdiction: Alabama, USA Version: Policy 621-01 Effective: 2018-03-28 Last updated: 2019-08-01 Industries: Government Tags: Data Breach Notification, Personal Information Protection, Information Security, Privacy Compliance, Data Protection Source: https://alison.legislature.state.al.us/code-of-alabama?section=8-38-1 Available in the 6clicks app: yes Summary: The Alabama Data Breach Notification Act of 2018 is a state data protection law that requires organizations to safeguard sensitive personal information, investigate security breaches, and provide timely notification to affected individuals and regulatory authorities when personal data is compromised. Description: The Alabama Data Breach Notification Act of 2018 (Chapter 38, §§ 8-38-1 to 8-38-12) is Alabama's data security and breach notification law that establishes requirements for organizations that acquire, use, maintain, or process sensitive personally identifying information. The Act requires covered entities and third-party agents to implement and maintain reasonable security measures to protect personal information from unauthorized access, acquisition, disclosure, or misuse. It also establishes procedures for investigating security breaches and mandates notification to affected individuals, the Alabama Attorney General, and, in certain cases, consumer reporting agencies when qualifying data breaches occur. In addition, the law requires the secure disposal of records containing sensitive personal information and provides enforcement mechanisms and penalties for non-compliance. The Act is designed to protect Alabama residents from identity theft, fraud, and other harms resulting from data breaches and inadequate information security practices. --- ## ASD Essential 8 Maturity Model - 2023 — Australian Signals Directorate (ASD) Essential Eight Maturity Model 2023 URL: https://marketplace.6clicks.com/c/asd-essential-eight-maturity-model-2023 Domain: Cybersecurity Type: standard Issued by: Australian Signals Directorate (ASD) Jurisdiction: Australia Version: November 2023 Last updated: 2023-11-27 Industries: Critical infrastructure, Government Tags: ASDEssential8, maturity model, cybersecurity framework, risk management, mitigation strategies, information security, compliance, cyber resilience, data protect, governance, Australian Signals Directorate Source: https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-explained Available in the 6clicks app: yes Summary: The ASD Essential 8 Maturity Model is a framework developed by the Australian Signals Directorate (ASD) to guide organizations in implementing prioritized cyber security mitigation strategies. It provides structured maturity levels to help organizations progressively strengthen their defenses against common cyber threats. The model ensures consistency, accountability, and resilience by aligning practices across all eight strategies. Description: The Essential 8 Maturity Model was first published in 2017 and is regularly updated to reflect evolving cyber threats and best practices. It is based on ASD’s extensive experience in cyber threat intelligence, incident response, penetration testing, and assisting organizations with implementation. The model supports the adoption of the Essential Eight mitigation strategies, which are designed to protect internet-connected IT networks from a wide range of attacks. While the principles can be applied to other environments such as enterprise mobility or operational technology, the model is primarily intended for traditional IT systems. Organizations using the Essential 8 Maturity Model are encouraged to identify and plan for a target maturity level appropriate to their environment. Implementation should be progressive, with organizations achieving the same maturity level across all eight strategies before advancing further. The model emphasizes a risk-based approach, minimizing exceptions by applying compensating controls and documenting any deviations. Exceptions must be approved through appropriate governance processes and reviewed regularly to ensure they remain valid. This structured approach ensures that organizations build balanced defenses rather than unevenly applying controls. The Essential 8 Maturity Model outlines a minimum set of preventative measures but acknowledges that additional controls may be necessary depending on the organization’s risk profile. While it helps mitigate the majority of cyber threats, it does not eliminate all risks, so organizations are advised to consider complementary strategies from ASD’s broader Strategies to Mitigate Cyber Security Incidents and the Information Security Manual. Importantly, there is no requirement for independent certification of Essential Eight implementation, making the model flexible and adaptable. By adopting the maturity model, organizations enhance their resilience, reduce vulnerabilities, and build confidence in their ability to withstand cyber threats. --- ## BDSG — Germany Federal Data Protection Act URL: https://marketplace.6clicks.com/c/germany-federal-data-protection-act Domain: Cybersecurity Type: law Version: 23 June 2021 Effective: 2017-06-30 Last updated: 2021-06-23 Industries: Government Tags: Federal Data Protection Act, BDSG, Germany Privacy Law, GDPR Compliance, Data Protection, Personal Data Processing Source: https://www.gesetze-im-internet.de/englisch_bdsg/englisch_bdsg.html Available in the 6clicks app: yes Summary: The Federal Data Protection Act (BDSG) is Germany's national data protection law that complements the GDPR by establishing rules for personal data processing, privacy protection, regulatory oversight, and compliance obligations for public and private sector organizations. Description: The Federal Data Protection Act (Bundesdatenschutzgesetz - BDSG) is Germany’s primary data protection law that supplements and implements the European Union General Data Protection Regulation (GDPR) within Germany. The Act regulates the processing of personal data by public authorities and private organizations, establishes legal bases for data processing, and defines additional national requirements in areas such as employment-related data processing, video surveillance, and the appointment of data protection officers. It also sets out the roles and responsibilities of data controllers and processors, protects the rights of data subjects, and provides oversight through the Federal Commissioner for Data Protection and Freedom of Information (BfDI). The BDSG supports the lawful, transparent, and secure processing of personal data while safeguarding individuals' privacy rights. --- ## C2M2 — Cybersecurity Capability Maturity Model URL: https://marketplace.6clicks.com/c/c2m2 Domain: Cybersecurity Type: framework Issued by: U.S. Department of Energy Jurisdiction: United States Version: 2.1 Effective: 2022-06-01 Last updated: 2022-06-01 Industries: Critical infrastructure, Cybersecurity, Government Tags: cybersecurity, maturity model, critical infrastructure, energy, self evaluation, risk management Source: https://www.energy.gov/ceser/cybersecurity-capability-maturity-model-c2m2 Document: https://c2m2.doe.gov Available in the 6clicks app: yes Summary: The Cybersecurity Capability Maturity Model (C2M2) is a tool developed by the U.S. Department of Energy to help organizations evaluate and enhance their cybersecurity capabilities. It focuses on both IT and OT environments, offering a structured framework of over 350 practices organized into 10 domains. Description: The C2M2 was initiated by the U.S. Department of Energy in collaboration with energy and cybersecurity industry stakeholders to address cybersecurity risks in critical infrastructure, including the energy sector. The model offers a maturity-based approach, with practices organized into domains, objectives, and maturity indicator levels (MILs). Initially targeted at the energy sector, it has been adopted across industries worldwide. Version 2.1, released in June 2022, features improvements in technology alignment, threat relevance, and usability. Supplemental tools, such as self-evaluation platforms and mapping guides, enhance user accessibility and simplify adoption. The model is designed to measure and improve cybersecurity over time, aiding organizations in prioritizing security investments and achieving targeted maturity levels. --- ## CAIQ Lite v4.1.0 — Consensus Assessments Initiative Questionnaire Lite v4.1.0 URL: https://marketplace.6clicks.com/c/consensus-assessments-initiative-questionnaire-lite-v4-1-0 Domain: Cybersecurity Type: standard Issued by: Cloud Security Alliance (CSA) Version: 4.1.0 Industries: Critical infrastructure Tags: CAIQ Lite, cloud security, governance, compliance, Cloud Security Alliance, CSA Source: https://cloudsecurityalliance.org/artifacts/ccm-lite-and-caiq-lite-v4 Available in the 6clicks app: yes Summary: Consensus Assessments Initiative Questionnaire (CAIQ) Lite v4.1.0 is a streamlined cloud security assessment questionnaire developed by the Cloud Security Alliance (CSA) and aligned with the Cloud Controls Matrix (CCM) v4.1 to help organizations evaluate cloud service providers using a standardized approach. It includes 138 focused questions across 17 security domains, enabling efficient vendor due diligence, third-party risk management, and security posture assessments. Description: The Consensus Assessments Initiative Questionnaire (CAIQ) Lite v4.1.0 is a cloud security assessment framework published by the Cloud Security Alliance (CSA) to provide a simplified and standardized method for evaluating cloud service providers. Derived from the Cloud Controls Matrix (CCM) v4.1, it enables organizations to assess a vendor’s implementation of critical security, privacy, and compliance controls using a focused set of industry-aligned questions. CAIQ Lite v4.1.0 includes 138 assessment questions covering 17 cloud security domains, such as governance, risk management, identity and access management, data security, application security, infrastructure protection, incident response, and regulatory compliance. The questionnaire is intentionally condensed from the full CAIQ to reduce the time and effort required for vendor assessments while maintaining coverage of the most essential cloud security controls. Organizations use CAIQ Lite v4.1.0 to streamline third-party risk assessments, support vendor due diligence processes, and improve visibility into a provider’s security posture. By leveraging a common industry framework, security and compliance teams can perform consistent evaluations, identify control gaps, and make more informed decisions regarding cloud service adoption and risk management. --- ## CAIQ v4.1.0 — Consensus Assessment Initiative Questionnaire v4.1.0 URL: https://marketplace.6clicks.com/c/consensus-assessment-initiative-questionnaire-v4-1-0 Domain: Cybersecurity Type: standard Issued by: Cloud Security Alliance (CSA) Version: 4.1.0 Industries: Critical infrastructure Tags: cybersecurity, Cloud Security Alliance, CSA, CAIQ, cloud security, assessment, compliance Source: http://www.cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4-1 Available in the 6clicks app: yes Summary: The Consensus Assessments Initiative Questionnaire (CAIQ) v4.1.0 is a comprehensive cloud security assessment questionnaire developed by the Cloud Security Alliance (CSA) and aligned with the Cloud Controls Matrix (CCM) v4.1 to help organizations evaluate the security, privacy, and compliance practices of cloud service providers. It includes 261 assessment questions mapped to 207 controls across 17 security domains, supporting detailed vendor due diligence, third-party risk management, and cloud security assessments using a standardized industry framework. Description: The Consensus Assessments Initiative Questionnaire (CAIQ) v4.1.0 is a comprehensive cloud security assessment questionnaire developed by the Cloud Security Alliance (CSA) to help organizations evaluate the security, privacy, and compliance capabilities of cloud service providers. Aligned with the Cloud Controls Matrix (CCM) v4.1, it provides a standardized framework for documenting and assessing the implementation of cloud security controls across a wide range of operational and technical areas. CAIQ v4.1.0 contains 261 yes-or-no assessment questions mapped to 207 controls across 17 security domains, including governance, risk management, identity and access management, application security, data protection, infrastructure security, incident management, and compliance. The questionnaire enables cloud providers to demonstrate their security practices consistently while allowing customers to perform detailed evaluations using a recognized industry standard. The primary purpose of CAIQ v4.1.0 is to support vendor due diligence, third-party risk management, cloud security assessments, and regulatory compliance efforts. By providing a common set of assessment criteria, it improves transparency between organizations and cloud vendors, helps identify potential security gaps, and facilitates informed decision-making when selecting, onboarding, or monitoring cloud services. --- ## CCM v4.0 — Cloud Controls Matrix v4.0 URL: https://marketplace.6clicks.com/c/ccm-v4-0 Domain: Cybersecurity Type: standard Issued by: Cloud Security Alliance (CSA) Version: 4.0 Effective: 2021-06-07 Tags: cloud security, compliance, risk management, information security, control mappings Source: https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4 Document: https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4 Available in the 6clicks app: yes Summary: The Cloud Controls Matrix (CCM) v4 is a meta-framework of cloud-specific security controls designed to provide clarity and structure for information security in cloud computing environments. It includes mappings to leading standards, best practices, and regulations. Description: The Cloud Controls Matrix (CCM) v4.0 is widely regarded as a de-facto standard for cloud security assurance and compliance. It provides a detailed catalog of cloud-specific security controls that align with various industry standards and frameworks. This version includes implementation and auditing guidelines, mappings to global security standards, and continuous auditing metrics. It supports organizations in achieving and demonstrating cloud security compliance through structured tools like the Consensus Assessment Initiative Questionnaire (CAIQ). CCM is also integrated into the CSA STAR Program for organizational certification and registry submissions. --- ## CCM v4.1 — Cloud Controls Matrix v4.1 URL: https://marketplace.6clicks.com/c/ccm-v4-1 Domain: Cybersecurity Type: framework Issued by: Cloud Security Alliance (CSA) Version: 4.1 Effective: 2026-01-27 Industries: Critical infrastructure Tags: cloud security, cybersecurity controls, privacy, risk management, security assessment, compliance tools Source: https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4-1 Document: https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4-1 Available in the 6clicks app: yes Summary: The Cloud Controls Matrix (CCM) v4.1 is a cybersecurity control framework that consists of 207 controls across 17 security domains, specifically tailored for cloud security and privacy. The Consensus Assessment Initiative Questionnaire (CAIQ) accompanies the CCM, offering a set of assessment questions to evaluate security controls. Description: The Cloud Controls Matrix (CCM) v4.1 is designed to provide a systematic approach to ensuring security in cloud environments and aligning with industry best practices. It includes detailed mappings to other standards, auditing guidelines, and metrics for continuous monitoring. The accompanying CAIQ v4.1 offers a security questionnaire to assess controls and supports submission to the STAR Registry for certification or attestation. Resources include implementation guidelines, change analysis between versions, and machine-readable formats for automation. This latest version emphasizes enhancing cloud security measures, privacy, shared responsibility models, and metrics for ongoing security assessment. --- ## Cert NZ Top 10 Critical Controls — Cert New Zealand Top Ten Critical Controls URL: https://marketplace.6clicks.com/c/cert-new-zealand-top-ten-critical-controls Domain: Cybersecurity Type: standard Issued by: National Cyber Security Centre (NCSC) Jurisdiction: New Zealand Version: 2021 Industries: Critical infrastructure Tags: NCSC, Critical Controls, Cybersecurity Framework, Cyber Risk Management, Information Security, Cyber Resilience Source: https://www.ncsc.govt.nz/protect-your-organisation/summary/ Available in the 6clicks app: yes Summary: The CERT NZ Top Ten Critical Controls is a cybersecurity framework that outlines ten essential security controls organizations can implement to reduce cyber risk, improve resilience, and protect systems, data, and services from common cyber attacks. Description: The CERT NZ Top Ten Critical Controls is a cybersecurity best-practice framework developed by New Zealand's National Cyber Security Centre (NCSC) and CERT NZ to help organizations prioritize the security measures that are most effective at preventing, detecting, and containing cyber threats. The framework identifies ten critical controls, including patch management, multi-factor authentication, password management, logging and alerting, asset lifecycle management, backups, application control, least privilege, network segmentation, and secure macro configurations. Based on threat intelligence, incident reporting, and real-world cyber attack trends, the controls provide a practical, risk-based approach for strengthening organizational cyber resilience and protecting information systems, data, and business operations from common cyber threats. --- ## CISA ZTMM V2 — CISA Zero Trust Maturity Model V2 URL: https://marketplace.6clicks.com/c/cisa-ztmm-v2 Domain: Cybersecurity Type: guideline Issued by: US Department of Homeland Security (DHS) Jurisdiction: United States Version: 2 Effective: 2023-04-11 Last updated: 2023-04-11 Industries: Cybersecurity Tags: zero trust, cybersecurity, guidance, identity management, network security Source: https://cloudsecurityalliance.org/resources/cisa-zero-trust-maturity-model-v2 Available in the 6clicks app: yes Summary: The CISA Zero Trust Maturity Model V2 provides a structured roadmap for organizations implementing a zero trust architecture. It outlines five key pillars and associated maturity levels to guide strategies and execution. Description: The CISA Zero Trust Maturity Model V2 is a guidance framework designed to help organizations develop and implement zero trust strategies. The model features five pillars—Identity, Device, Network, Application Workload, and Data—and incorporates three cross-cutting capabilities: Visibility and Analytics, Automation and Orchestration, and Governance. Each pillar includes maturity examples ranging from traditional setups to advanced zero trust architectures. Released by the US Department of Homeland Security, it is considered a foundational document for building robust zero trust capabilities within organizations. The model emphasizes iterative improvement and provides actionable insights at different stages of maturity. --- ## CIS Controls v8.1 — CIS Critical Security Controls Version 8.1 URL: https://marketplace.6clicks.com/c/cis-controls-v8-1 Domain: Cybersecurity Type: control set Issued by: Center for Internet Security (CIS) Version: 8.1 Industries: Cybersecurity Tags: cybersecurity, controls, frameworks, best practices, implementation, cloud security, safeguards Source: https://www.cisecurity.org/controls/v8-1 Document: https://www.cisecurity.org/controls/v8-1 Available in the 6clicks app: yes Summary: The CIS Critical Security Controls Version 8.1 is a prioritized set of cybersecurity best practices designed to defend against common cyber threats to systems and networks. It includes updates to align with evolving industry standards and frameworks, such as NIST CSF 2.0. Description: CIS Controls v8.1 is an iterative update to Version 8, focusing on context, coexistence with other frameworks, and consistency for existing users. Key changes include updated mappings to the NIST CSF 2.0 security functions, revised glossary definitions, changes to asset classes, and improved safeguard descriptions. It emphasizes security in hybrid and cloud environments and includes resources like PDFs, Excel files, and a change log to aid implementation. This version aims to align with both industry and policy frameworks while preserving the unique focus of the CIS Controls. --- ## CMMC — Cybersecurity Maturity Model Certification URL: https://marketplace.6clicks.com/c/tas-pspf-information-security Domain: Cybersecurity Type: framework Issued by: US Government Jurisdiction: United States Version: 2.13 Industries: Defense Tags: information security, cybersecurity, governance, audit and assessment, maturity model, compliance Source: https://dodcio.defense.gov/CMMC/About/ Document: https://dowcio.war.gov/Portals/0/Documents/CMMC/AssessmentGuideL2v2.pdf Available in the 6clicks app: yes Summary: The Cybersecurity Maturity Model Certification (CMMC) Assessment Guide defines how organizations are evaluated for compliance with cybersecurity requirements when working with the U.S. Department of Defense. It outlines assessment methods, evidence expectations, and control validation aligned with standards like NIST SP 800-171. The guide ensures consistent and rigorous verification of an organization’s ability to protect sensitive information. Description: The Cybersecurity Maturity Model Certification (CMMC) Assessment Guide provides detailed criteria and methodologies used by assessors to evaluate whether defense contractors meet required cybersecurity controls for protecting Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). It supports a tiered assessment model aligned with three maturity levels, defining specific practices, objectives, and evidence needed to demonstrate compliance with standards such as NIST SP 800-171. The guide ensures consistency and rigor in assessments by outlining how controls are verified, including documentation review, interviews, and testing procedures. It is used to validate that organizations have effectively implemented required safeguards as a condition for participating in U.S. Department of Defense contracts. --- ## CPG 1.0 — Cross-Sector Cybersecurity Performance Goals URL: https://marketplace.6clicks.com/c/cpg-1-0 Domain: Cybersecurity Type: framework Issued by: Cybersecurity and Infrastructure Security Agency (CISA) Jurisdiction: United States Version: v1.0.1 Last updated: 2023-11-29 Industries: Critical infrastructure Tags: cybersecurity critical infrastructure nist voluntary best practices risk management benchmarks Source: https://www.cisa.gov/cross-sector-cybersecurity-performance-goals/cross-sector-cybersecurity-performance-goals Available in the 6clicks app: yes Summary: The Cross-Sector Cybersecurity Performance Goals (CPGs) are a set of baseline cybersecurity practices developed by CISA to help organizations of all sizes and sectors strengthen their resilience against common cyber threats. They provide prioritized, actionable measures that align with the NIST Cybersecurity Framework and are designed to be achievable, cost-effective, and impactful. Description: The Cross-Sector Cybersecurity Performance Goals (CPGs) are voluntary baseline practices developed by CISA to help organizations strengthen resilience against common cyber threats. They provide prioritized, actionable measures—such as multi-factor authentication, data encryption, and incident response planning—that align with the NIST Cybersecurity Framework. Designed to be achievable and cost-effective, the CPGs serve as a practical checklist for organizations across all sectors, especially critical infrastructure, to raise their cybersecurity posture. --- ## CPG 234 — CPG 234 Information Security URL: https://marketplace.6clicks.com/c/cpg-234 Domain: Cybersecurity Type: guideline Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Version: June 2019 Last updated: 2019-06-01 Industries: Finance Sector, Cybersecurity Tags: information security, cyber risk, financial regulation, APRA, Australian standards Source: https://www.apra.gov.au/sites/default/files/cpg_234_information_security_june_2019_1.pdf Document: https://www.apra.gov.au/sites/default/files/cpg_234_information_security_june_2019_1.pdf Available in the 6clicks app: yes Summary: This standard provides information security guidance for Australian financial institutions regulated by APRA. It aims to ensure operational resilience and protect against information security threats. Description: The CPG 234 standard, issued by the Australian Prudential Regulation Authority (APRA), sets out key principles and recommended practices for information security management for entities within the financial services sector. It focuses on governance, data protection, threat management, and monitoring. This guidance helps organisations manage information security risks effectively, ensuring compliance with regulatory obligations and promoting robustness against cyber threats. It aligns with broader global best practices while being tailored to the Australian regulatory context. --- ## CSA IoT Controls v1 — CSA IoT Security Controls Framework URL: https://marketplace.6clicks.com/c/csa-iot-controls Domain: Cybersecurity Type: framework Issued by: Cloud Security Alliance (CSA) Version: 1 Effective: 2019-03-05 Industries: Critical infrastructure Tags: iot, security, controls, framework, cloud, devices, risk Source: https://cloudsecurityalliance.org/artifacts/iot-security-controls-framework Document: https://cloudsecurityalliance.org/artifacts/iot-security-controls-framework Available in the 6clicks app: yes Summary: The CSA IoT Security Controls Framework provides essential security controls to mitigate risks in IoT systems that include various connected devices, cloud services, and networks. It is designed to apply to a range of IoT systems, from handling low-value data to supporting critical services. Description: The CSA IoT Security Controls Framework offers foundational guidance for securing Internet of Things (IoT) systems. It defines baseline security controls to address common risks associated with interconnected IoT environments that use diverse devices, cloud technologies, and networking infrastructure. This framework is adaptable to IoT systems of varying complexity and sensitivity, including systems with high-value data or critical functions. The framework also includes tools to identify and allocate controls to specific system components. It is available for free, along with a companion guide providing usage instructions. --- ## CSA IoT Controls v2 — CSA IoT Security Controls Framework v2 URL: https://marketplace.6clicks.com/c/csa-iot-controls-v2 Domain: Cybersecurity Type: framework Issued by: Cloud Security Alliance (CSA) Version: 2 Effective: 2021-01-28 Industries: Critical infrastructure Tags: iot, security, framework, controls, cloud, critical services Source: https://cloudsecurityalliance.org/artifacts/csa-iot-security-controls-framework-v2/ Document: https://cloudsecurityalliance.org/artifacts/csa-iot-security-controls-framework-v2/ Available in the 6clicks app: yes Summary: The CSA IoT Security Controls Framework v2 provides a structured approach to securing enterprise IoT systems, including connected devices, cloud services, and networking technologies. It is suitable for systems ranging from low-impact data processes to highly sensitive critical services. Description: The CSA IoT Security Controls Framework v2 is designed to help organizations evaluate and implement secure IoT systems. Version 2 introduces updated technical controls, a revised domain structure for better categorization, and new domains addressing legal requirements and security testing. Infrastructure allocations have been simplified to streamline architectural component mapping. The framework guides users through evaluating IoT systems by offering detailed descriptions and instructions, helping organizations prioritize security based on system impact and data sensitivity. --- ## Cyber Essentials Danzell Question Set — Cyber Essentials Question Set v3.3 (Danzell) April 2026 URL: https://marketplace.6clicks.com/c/cyber-essentials-question-set-v3-3-danzell-april-2026 Domain: Cybersecurity Type: standard Issued by: National Cyber Security Centre (NCSC) Version: v3.3 Effective: 2026-04-27 Last updated: 2026-04-01 Industries: Critical infrastructure, Government Tags: CyberEssentials, compliance, IASME, self-assessment, UK standards, risk management, certification, SME security, cyber hygiene, assurance framework Source: https://iasme.co.uk/cyber-essentials/preview-the-self-assessment-questions-for-cyber-essentials/ Available in the 6clicks app: yes Summary: Cyber Essentials: Requirements for IT Infrastructure v3.3 Question Set is a structured self-assessment designed to help organizations evaluate their cyber security practices. It focuses on five key technical control areas—firewalls, secure configuration, user access control, malware protection, and patch management. By completing the question set, organizations can demonstrate compliance with baseline security standards and strengthen resilience against common cyber threats. Description: The Cyber Essentials: Requirements for IT Infrastructure v3.3 Question Set is a structured self-assessment tool developed by the UK’s National Cyber Security Centre (NCSC). Its purpose is to help organizations evaluate their cyber security posture against the five core technical control areas of the Cyber Essentials framework: firewalls, secure configuration, user access control, malware protection, and patch management. By answering the question set, organizations can identify gaps, implement improvements, and prepare for certification. This question set is designed for organizations of all sizes and sectors, from small businesses to large enterprises and government agencies. It provides a practical, accessible way to demonstrate compliance with baseline cyber hygiene standards and reassure customers, partners, and regulators that essential protections are in place. The format ensures consistency across assessments, making it easier for organizations to benchmark their practices against recognized standards. Version 3.3 reflects updates to modern IT environments and evolving cyber threats, ensuring the framework remains relevant and effective. Completing the question set not only supports certification but also strengthens resilience against common attacks, reduces vulnerabilities, and builds trust with stakeholders. Ultimately, it serves as both a compliance requirement and a roadmap for improving everyday cyber security practices. --- ## Cyber Essentials Mark — CSA Cybersecurity Certification: Cyber Essentials Mark URL: https://marketplace.6clicks.com/c/cyber-essentials Domain: Cybersecurity Type: standard Issued by: Cyber Security Agency of Singapore (CSA) Jurisdiction: Singapore Version: 04-2025 (Second edition) Last updated: 2026-04-14 Industries: Cybersecurity Tags: cybersecurity, certification, funding-support, cloud-security, ai-security, smes Source: https://www.csa.gov.sg/our-programmes/support-for-enterprises/sg-cyber-safe-programme/cybersecurity-certification-for-organisations/cyber-essentials/certification-for-the-cyber-essentials-mark/ Document: https://isomer-user-content.by.gov.sg/36/47c6066b-71a7-449f-82e0-e8cf10ee126f/cyber-essentials-v202504.pdf Available in the 6clicks app: yes Summary: The Cyber Essentials (2025) certification is a cybersecurity certification scheme developed by the Cyber Security Agency (CSA) of Singapore. It provides a framework for organisations to enhance their cybersecurity posture, covering areas like classical cybersecurity, cloud security, OT security, and AI security. Description: Cyber Essentials (2025) offers a structured approach to improving cybersecurity for organisations in Singapore. It includes specific sub-schemes for ICT vendors, Health Information Act (HIA) entities, and Health Information Management System vendors. The certification is valid for two years and involves a self-assessment verified by certification bodies. SMEs and NPOs can access funding support to offset certification costs. Certified organisations can improve their reputation globally and benefit from discounted cyber insurance and scholarship opportunities. Updated tools and templates were last revised in April 2026 to assist in achieving certification. --- ## Cyber Essentials v3.2 — Cyber Essentials Requirements for IT Infrastructure URL: https://marketplace.6clicks.com/c/cyber-essentials-v3-2 Domain: Cybersecurity Type: standard Issued by: UK National Cyber Security Centre (NCSC) Jurisdiction: United Kingdom Version: 3.2 Tags: cybersecurity, IT infrastructure, security controls, NCSC, UK government Source: https://www.ncsc.gov.uk/files/cyber-essentials-requirements-for-it-infrastructure-v3-2.pdf Document: https://www.ncsc.gov.uk/files/cyber-essentials-requirements-for-it-infrastructure-v3-2.pdf Available in the 6clicks app: yes Summary: Cyber Essentials is a UK government-backed scheme focused on protecting IT infrastructure from common cyber threats. Version 3.2 outlines updated security controls and practices. Description: The Cyber Essentials program provides organizations with a clear framework to safeguard IT systems against prevalent cyber attacks. Version 3.2 incorporates the latest industry recommendations and expands on essential measures like firewall protection, access control, secure configuration, and patch management. It aims to improve baseline security practices for small to medium-sized enterprises and public entities, helping them prevent unauthorized access and reduce vulnerabilities. --- ## Cyber Essentials v3.3 — Cyber Essentials: Requirements for IT Infrastructure URL: https://marketplace.6clicks.com/c/cyber-essentials-3-3 Domain: Cybersecurity Type: standard Issued by: NCSC (National Cyber Security Centre) Jurisdiction: United Kingdom Version: 3.3 Effective: 2026-04-26 Industries: Critical infrastructure Tags: cybersecurity, compliance, mfa, cloud services, patch management Source: https://www.ncsc.gov.uk/files/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf Available in the 6clicks app: yes Summary: Cyber Essentials v3.3 is a UK government-backed cybersecurity scheme defining baseline security measures for businesses. The update, effective from 26th April 2026, refines requirements to close ambiguities and enforce stricter compliance on cloud services, MFA, and endpoint protection. Description: Cyber Essentials v3.3 is an updated version of the UK government-backed scheme aimed at improving organizational cybersecurity practices. It retains its five core controls—firewalls, secure configuration, patch management, user access control, and malware protection—while introducing significant refinements. From April 2026, the scheme mandates stricter scoping for cloud services, expanded MFA deployment, and precise documentation of firewall rules. The 14-day patching rule applies to not only software fixes but also configuration changes, strengthening vulnerability management. Organizations are encouraged to proactively prepare to meet these standards by updating their IT scope, enforcing security measures on all devices, and documenting all changes clearly. Cyber Essentials certification demonstrates compliance with recognized security standards and is often deemed critical for public sector contracts. --- ## DCC-1:2022 — Data Cybersecurity Controls URL: https://marketplace.6clicks.com/c/dcc-1-2022 Domain: Cybersecurity Type: control set Issued by: National Cybersecurity Authority (NCA) Jurisdiction: Kingdom of Saudi Arabia Version: 1:2022 Last updated: 2025-05-15 Industries: Cybersecurity, Government, Critical infrastructure Tags: cybersecurity, controls, data protection, national standards, saudi arabia Source: https://nca.gov.sa/en/regulatory-documents/controls-list/dcc/ Available in the 6clicks app: yes Summary: The Data Cybersecurity Controls (DCC-1:2022) establish minimum cybersecurity requirements to protect data throughout its lifecycle. Issued by the Saudi National Cybersecurity Authority, the controls build on existing cybersecurity frameworks to enhance the Kingdom's overall cybersecurity maturity. Description: The Data Cybersecurity Controls (DCC-1:2022) were developed by the Saudi National Cybersecurity Authority after analyzing national and international cybersecurity frameworks, related laws, and best practices. These controls aim to mitigate cybersecurity risks, threats, and incidents by setting baseline requirements for safeguarding data in every stage of its lifecycle. The DCC serves as an extension to the Essential Cybersecurity Controls (ECC), and includes objectives, scope, compliance and monitoring details. It is designed to raise cybersecurity maturity across organizations in Saudi Arabia. --- ## DESE ISMS Scheme — DESE Information Security Management Systems (ISMS) Scheme URL: https://marketplace.6clicks.com/c/dese-isms-scheme Domain: Cybersecurity Type: framework Issued by: Australian Department of Employment and Workplace Relations (DEWR) Jurisdiction: Australia Effective: 2021-02-10 Industries: Government Tags: DESE ISMS Scheme, Information Security Management System, ISO 27001, Information Security, Cyber Risk Management, Right Fit For Risk Show more lines Source: https://www.jas-anz.org/dese-information-security-systems-scheme Available in the 6clicks app: yes Summary: The DESE ISMS Scheme is an information security certification framework that combines ISO/IEC 27001, the Australian Government Information Security Manual (ISM), and the Right Fit For Risk (RFFR) framework to help service providers manage cyber risks and protect sensitive information. Description: The DESE Information Security Management Systems (ISMS) Scheme is an Australian Government information security framework developed by the former Department of Education, Skills and Employment (DESE) to help service providers protect sensitive information used in the delivery of employment, training, and related government services. The scheme combines the requirements of ISO/IEC 27001, additional controls from the Australian Government Information Security Manual (ISM), and the Right Fit For Risk (RFFR) framework to establish a comprehensive, risk-based approach to information security management. Organizations participating in the scheme are required to implement and maintain an Information Security Management System that safeguards the confidentiality, integrity, and availability of information through appropriate governance, security controls, risk management practices, and ongoing monitoring. The scheme helps service providers meet contractual obligations while demonstrating their commitment to protecting sensitive government and customer information. --- ## DISP 2020 — Defence Industry Security Program (DISP)– Suitability Assessment (2020) URL: https://marketplace.6clicks.com/c/disp-2020 Domain: Cybersecurity Type: standard Issued by: Australian Department of Defence Jurisdiction: Australia Version: 2020 Effective: 2020-07-31 Industries: Defense Tags: Defence Industry Security Program, DISP, Defence Security, Supply Chain Security, Security Accreditation, Australian Defence Source: https://www.defence.gov.au/security/industry Available in the 6clicks app: yes Summary: The Defence Industry Security Program (DISP) is an Australian Defence membership program that helps organizations implement and demonstrate appropriate security controls for participating in Defence projects and managing Defence-related information and assets. Description: The Defence Industry Security Program (DISP) is a security accreditation and membership program administered by the Australian Department of Defence to strengthen security across the Defence industry supply chain. The program assists Australian businesses in implementing security measures that protect Defence-related information, personnel, technology, and assets. Built on the principles of the Defence Security Principles Framework (DSPF), DISP provides a scalable security model that enables organizations to demonstrate their ability to manage security risks and meet Defence contractual requirements. Through its membership levels, the program helps organizations improve their security maturity, access Defence security resources and guidance, and establish trusted partnerships within the Australian Defence ecosystem. --- ## DISP 2022 — Defence Industry Security Program – Suitability Requirements (2022) URL: https://marketplace.6clicks.com/c/disp-2022 Domain: Cybersecurity Type: standard Issued by: Australian Government Jurisdiction: Australia Version: 2022 Effective: 2022-08-30 Industries: Defense Tags: DISP, Australian Defence, Security Assurance, Defence Supply Chain Security, Security Governance Source: https://www.defence.gov.au/business-industry/industry-governance/industry-regulators/defence-industry-security-program Available in the 6clicks app: yes Summary: The Defence Industry Security Program (DISP) is an Australian Defence security assurance program that helps organizations meet security requirements for Defence contracts and projects by implementing appropriate governance, personnel, physical, and information security controls. Description: The Defence Industry Security Program (DISP) is the Australian Department of Defence's security assurance program designed to help industry partners protect Defence personnel, information, and assets. DISP is a multi-level membership program that supports Australian organizations in understanding and meeting their security obligations when participating in Defence tenders, contracts, and projects. Underpinned by the Defence Security Principles Framework (DSPF), the program provides a structured approach to managing security risks across governance, personnel, physical, and information security domains. DISP membership gives organizations access to Defence security guidance, training, support services, and, where applicable, the ability to sponsor security clearances. The program provides assurance to Defence and other government entities that participating organizations have implemented appropriate security measures and can securely handle Defence-related work and sensitive information. --- ## DSPF — Defence Security Principles Framework URL: https://marketplace.6clicks.com/c/defence-security-principles-framework Domain: Cybersecurity Type: framework Issued by: Australian Government Jurisdiction: Australia Version: 2 July 2018 Effective: 2018-07-02 Industries: Defense, Government Tags: DSPF, Australian Defence, Protective Security, Risk Management, Security Governance Source: https://www.defence.gov.au/business-industry/industry-governance/defence-security-principles-framework Available in the 6clicks app: yes Summary: The Defence Security Principles Framework (DSPF) is the Australian Department of Defence's principles-based security framework that provides governance, security principles, and controls to help Defence personnel manage risks and protect Defence people, information, assets, and operations in alignment with the PSPF. Description: The Defence Security Principles Framework (DSPF) is the Australian Department of Defence's security framework that aligns with the Australian Government's Protective Security Policy Framework (PSPF). It provides a principles-based approach to managing protective security risks through governance, security principles, expected outcomes, and controls that help protect Defence personnel, information, assets, and operations. The framework promotes risk-informed decision-making, accountability, and a strong security culture across the Defence enterprise. --- ## Dubai ISR — Dubai Government Information Security Regulation URL: https://marketplace.6clicks.com/c/dubai-isr Domain: Cybersecurity Type: regulation Issued by: Dubai Government Jurisdiction: Dubai Version: v3 Effective: 2014-12-01 Industries: Government Tags: Dubai, information security, governance, continuity, controls, confidentiality Source: https://www.desc.gov.ae/regulations/standards-policies/ Available in the 6clicks app: yes Summary: The Dubai Government Information Security Regulation (ISR) provides standards to ensure the continuity of critical business processes and minimize information security risks for Dubai Government Entities. It defines minimum requirements for information security controls and aims to maintain confidentiality, integrity, and availability of government information. Description: The Information Security Regulation (ISR) is a comprehensive framework aimed at safeguarding government information by setting minimum requirements for information security controls. Applicable to all Dubai Government Entities, the ISR governs the handling of printed, electronic, and verbal information across all divisions and functions. It comprises thirteen domains categorized into Governance, Operation, and Assurance. Governance domains focus on structuring and managing information security, Operation domains cover technical and non-technical controls based on risk assessments, and Assurance domains provide quality checks for implemented solutions. The regulation also mandates the alignment of resources to achieve an optimal balance between risk management costs and protected information value. Introduced via Resolution No. 13 of 2012 and formalized under Dubai Law No. 11 of 2014, DESC is tasked with its continuous improvement to adapt to new security practices. --- ## ECC 2-2024 — Essential Cybersecurity Controls URL: https://marketplace.6clicks.com/c/ecc-2-2024 Domain: Cybersecurity Type: control set Issued by: National Cybersecurity Authority Jurisdiction: Kingdom of Saudi Arabia Version: 2-2024 Last updated: 2026-04-20 Industries: Cybersecurity, Government, Critical infrastructure Tags: cybersecurity, controls, national strategy, saudi arabia, information security Source: https://nca.gov.sa/en/regulatory-documents/controls-list/ecc/ Available in the 6clicks app: yes Summary: The Essential Cybersecurity Controls (ECC 2-2024) aim to enhance cybersecurity at the national level in Saudi Arabia. They provide policies and controls to protect the information and technological assets of national entities. Description: The Essential Cybersecurity Controls (ECC 2-2024), issued by the National Cybersecurity Authority (NCA) of Saudi Arabia, are part of a broader effort to bolster national cybersecurity. These controls establish a comprehensive framework for protecting critical information and technological infrastructure across government and other key sectors. The document provides updated policies and control sets designed to address evolving cybersecurity threats, aligning with national and international best practices. This update reflects the ongoing commitment to achieving the objectives laid out in Saudi Vision 2030. --- ## EU Data Act — Regulation (EU) 2023/2854 - EU Data Act URL: https://marketplace.6clicks.com/c/regulation-eu-2023-2854-eu-data-act Domain: Cybersecurity Type: regulation Issued by: European Union Jurisdiction: EU Effective: 2023-12-13 Tags: Data Governance, Data Sharing, Data Access Rights, Data Portability, Data Protection, Digital Policy Source: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32023R2854 Available in the 6clicks app: yes Summary: The EU Data Act (Regulation (EU) 2023/2854) establishes harmonized rules to make data generated by connected products and related digital services more accessible and usable across the European Union. It gives users of connected devices, such as IoT products, the right to access and share the data they generate with third parties, while requiring data holders to provide that data under fair, reasonable, and non-discriminatory conditions. The regulation aims to reduce barriers to data sharing, promote innovation and competition, enable easier switching between cloud and data-processing services, and support public-sector access to data in situations of exceptional need, while preserving data protection, privacy, intellectual property rights, and trade secret safeguards. Overall, the Data Act is designed to create a fairer and more competitive European data economy by empowering users and improving access to valuable data resources. Description: The Regulation (EU) 2023/2854 - EU Data Act, addresses the challenges and opportunities presented by data in the European Union (EU), emphasising fair access and user rights, while ensuring that personal data is protected. Its aims include: • guaranteeing a fair distribution of the benefits derived from data amongst stakeholders; • stimulating a competitive data market; • opening up opportunities for data-driven innovation; and • making data, in particular data generated by connected products, more accessible. --- ## EU Digital Services Act — Regulation (EU) 2022/2065 - EU Digital Services Act URL: https://marketplace.6clicks.com/c/regulation-eu-2022-2065-eu-digital-services-act Domain: Cybersecurity Type: regulation Issued by: European Union Jurisdiction: EU Effective: 2022-10-19 Tags: Content Moderation, Digital Regulation, Platform Accountability, Transparency Requirements, Very Large Online Platforms (VLOPs), Digital Markets, Internet Governance Source: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2065 Available in the 6clicks app: yes Summary: The Digital Services Act (DSA) (Regulation (EU) 2022/2065) establishes a comprehensive framework for regulating online intermediary services, platforms, and marketplaces across the European Union to create a safer and more transparent digital environment. The regulation introduces obligations for online platforms to address illegal content, improve transparency in content moderation and advertising, protect users' rights, and manage systemic risks such as disinformation and harmful content. It also imposes enhanced requirements on very large online platforms and search engines, while preserving fundamental rights, consumer protection, and innovation. Overall, the DSA aims to harmonize rules across the EU and increase accountability for digital service providers operating within the Single Market. Description: The Regulation (EU) 2022/2065 - EU Digital Services Act aims to create a safer online environment for consumers and companies in the European Union (EU), with a set of rules designed to: • protect consumers and their fundamental rights more effectively; • define clear responsibilities for online platforms and social media; • deal with illegal content and products, hate speech and disinformation; • achieve greater transparency with better reporting and oversight; and • encourage innovation, growth and competitiveness in the EU’s internal market. --- ## FedRAMP Controls — FedRAMP Security Controls Baseline rev 5 URL: https://marketplace.6clicks.com/c/fedramp-security-controls-baseline-rev-5 Domain: Cybersecurity Type: standard Issued by: US Government Jurisdiction: United States Version: rev 5 Last updated: 2023-05-30 Industries: Government Tags: FedRAMP, Security Controls Baseline, Cloud Security, NIST SP 800-53, Federal Compliance, Risk Management Source: https://www.fedramp.gov/legacy/#all-legacy-assets Available in the 6clicks app: yes Summary: The FedRAMP Security Controls Baseline is a standardized set of cloud security requirements based on NIST SP 800-53 that defines the minimum security controls cloud service providers must implement to protect federal data and achieve FedRAMP authorization. Description: The FedRAMP Security Controls Baseline is a standardized set of security requirements established by the Federal Risk and Authorization Management Program (FedRAMP) for cloud service providers that offer services to U.S. federal agencies. Based on the NIST Special Publication (SP) 800-53 security and privacy controls framework, the baseline defines the minimum safeguards required to protect federal information processed, stored, or transmitted in cloud environments. FedRAMP organizes these requirements into multiple impact levels, including Low, Moderate, and High, with each baseline containing security controls tailored to the potential impact that a loss of confidentiality, integrity, or availability could have on government operations, assets, or individuals. The FedRAMP Security Controls Baseline provides a consistent approach to security assessment, authorization, and continuous monitoring, helping federal agencies evaluate cloud services while ensuring compliance with federal cybersecurity requirements and risk management practices. --- ## FSSCP — The Financial Services Sector Cybersecurity Profile URL: https://marketplace.6clicks.com/c/the-financial-services-sector-cybersecurity-profile Domain: Cybersecurity Type: framework Issued by: Financial Services Sector Coordinating Council (FSSCC) Jurisdiction: Global Effective: 2018-10-25 Industries: Finance Sector, Cybersecurity Tags: cybersecurity, assessment, financial-services, resilience, compliance Source: https://fsscc.org/ Document: https://fsscc.org/Financial-Sector-Cybersecurity-Profile Available in the 6clicks app: yes Summary: The Financial Services Sector Cybersecurity Profile is a scalable and extensible assessment tool designed to help financial institutions manage cyber risks and demonstrate regulatory compliance. It is based on the NIST Cybersecurity Framework and offers a tailored approach to streamline cybersecurity assessments globally. Description: Launched on October 25, 2018, the Financial Services Sector Cybersecurity Profile is a collaborative effort among financial institutions, vendors, and trade groups. It provides diagnostic assessment statements tailored to institutions' risk profiles, reducing the time required for comprehensive cybersecurity assessments while aligning with various regulatory frameworks. Regulators have welcomed its potential to enhance transparency and reduce systemic risk. The Profile is updated every two to three years by a coalition of stakeholders, ensuring alignment with new supervisory requirements and global standards like those from NIST and ISO. --- ## IS18 — Information and Cyber Security Policy (IS18) URL: https://marketplace.6clicks.com/c/is18 Domain: Cybersecurity Type: guideline Issued by: Queensland Government Jurisdiction: Queensland, Australia Version: 9.0.0 Effective: 2025-02-04 Last updated: 2026-01-14 Industries: Government, Cybersecurity, Risk Management Tags: information security, iso 27001, essential eight, risk management, cyber resilience, government Source: https://www.forgov.qld.gov.au/information-technology/queensland-government-enterprise-architecture-qgea/qgea-directions-and-guidance/qgea-policies-standards-and-guidelines/information-security-policy-is18 Available in the 6clicks app: yes Summary: The Information and Cyber Security Policy (IS18) is a policy framework established by the Queensland Government to enhance information security and organizational resilience. It mandates the implementation of ISO 27001-based ISMS, systematic risk management, and compliance with the Australian Signals Directorate's Essential Eight Strategies for all Queensland Government agencies. Description: The IS18 is a mandatory policy for Queensland Government agencies aimed at ensuring a consistent, risk-based approach to information and cyber security. Agencies must implement an Information Security Management System (ISMS) aligned with ISO 27001, manage risks systematically, and meet defined minimum security requirements including compliance with the Essential Eight Strategies. The policy also requires annual security assurance attestations by accountable officers and incident reporting to the Queensland Government Cyber Security Unit. The scope covers all information systems, applications, technologies, and their associated risks, with guidance on operational technology and supply chain management. By adopting IS18, the government aims to align with international standards, reduce cybersecurity risks, and improve resilience. --- ## ISM — Information Security Manual URL: https://marketplace.6clicks.com/c/information-security-manual Domain: Cybersecurity Type: regulation Issued by: Australian Government Jurisdiction: Australia Version: June 2026 Last updated: 2026-06-01 Industries: Critical infrastructure, Government Tags: cybersecurity framework, information security, risk management, government standards, critical infrastructure, compliance, data protection, resilience, IT security, ASD guidelines Source: https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism Available in the 6clicks app: yes Summary: The Australian ISM is the nationally recognized cybersecurity framework developed by the Australian Signals Directorate. It provides organizations with structured guidance to safeguard information and operational technology systems against evolving cyber threats. Description: The Australian Information Security Manual (ISM) is the government’s principal cybersecurity framework developed by the Australian Signals Directorate (ASD). Its purpose is to provide organizations with a structured, risk-based approach to safeguarding information and technology systems against evolving cyber threats, ensuring resilience and compliance with national security standards. The ISM is designed for chief information security officers, IT managers, and cybersecurity professionals across government agencies, defense, and critical infrastructure sectors. It also serves as a reference for private sector organizations that handle sensitive or high-value data, offering practical guidance on implementing security controls, managing risks, and aligning with broader governance frameworks. Key elements of the ISM include detailed cyber security principles, recommended practices for securing both IT and operational technology environments, and guidance on incident response and system hardening. By following the ISM, organizations can strengthen their defenses, meet regulatory obligations, and contribute to Australia’s overall cyber resilience. --- ## ISM CCM — Information Security Manual Cloud Controls Matrix Template URL: https://marketplace.6clicks.com/c/information-security-manual-cloud-controls-matrix-template Domain: Cybersecurity Type: standard Issued by: Australian Government Jurisdiction: Australia Version: June 2026 Last updated: 2026-06-01 Industries: Government Tags: cloud controls, cloud security, compliance framework, risk management, accreditation process, government standards, information security, data protection, ICT services, cybersecurity framework, resilience, ISM alignment, cloud governance Source: https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ Available in the 6clicks app: yes Summary: The Cloud Controls Matrix (CCM) Template is a comprehensive framework for mapping cloud security controls to industry standards and compliance requirements. It helps organizations assess, implement, and demonstrate effective cloud security practices across diverse environments. Description: The Cloud Controls Matrix Template provides a structured approach to managing cloud-specific risks by aligning security controls with recognized frameworks such as ISO, NIST, and the Australian Information Security Manual (ISM). Its purpose is to support organizations in identifying applicable controls, documenting their implementation, and ensuring compliance with regulatory and accreditation requirements. The template is designed for cloud service providers, government agencies, and enterprises that rely on cloud infrastructure, offering a transparent way to evaluate and communicate their security posture. Applicable across sectors including government, defense, critical infrastructure, and private enterprises, the CCM Template enables organizations to strengthen accountability, streamline audits, and enhance resilience against cyber threats. By using this template, organizations can demonstrate adherence to best practices, reduce risk exposure, and build trust with stakeholders who depend on secure and compliant cloud services. --- ## ISM SSP — Information Security Manual System Security Plan Annex Template URL: https://marketplace.6clicks.com/c/information-security-manual-system-security-plan-annex-template Domain: Cybersecurity Type: regulation Issued by: Australian Government Jurisdiction: Australia Version: June 2026 Last updated: 2026-06-01 Industries: Critical infrastructure, Government Tags: system security plan, SSP annex, cybersecurity documentation, accreditation process, risk management, government standards, compliance, data protection, ICT services, critical infrastructure, ASD guidelines, information security, system controls, cyber resilience Source: www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism Available in the 6clicks app: yes Summary: The System Security Plan (SSP) Annex Template is a structured document used to capture detailed information about an organization’s cyber security controls and implementation. It supports accreditation processes by providing evidence of compliance, risk management, and system-specific security measures. Description: The SSP Annex Template is designed to complement a System Security Plan by documenting how security controls are applied to specific systems, environments, and operational contexts. Its purpose is to provide transparency and assurance to accrediting authorities, demonstrating that an organization has implemented appropriate safeguards aligned with government cyber security standards. The template is primarily intended for ICT service providers, government agencies, and organizations seeking accreditation under frameworks such as Right Fit for Risk (RFFR). This annex is applicable across sectors that manage sensitive or official information, including defense, critical infrastructure, and contracted service providers. It ensures that system-specific risks are identified, controls are mapped to the Australian Information Security Manual (ISM), and any deviations or compensating measures are clearly justified. By using the SSP Annex Template, organizations strengthen their accreditation submissions, improve accountability, and enhance confidence in their overall cyber security posture. --- ## ISO/IEC 27001:2013 — ISO/IEC 27001:2013 - Information technology — Security techniques — Information security management systems — Requirements URL: https://marketplace.6clicks.com/c/iso-iec-27001-2013 Domain: Cybersecurity Type: standard Issued by: ISO/IEC Jurisdiction: Global Version: 2013 Effective: 2013-10-25 Industries: Risk Management Tags: information security, ISMS, cybersecurity, risk management, data protection Source: https://www.iso.org/contents/data/standard/05/45/54534.html Document: https://www.iso.org/standard/54534.html Available in the 6clicks app: yes Summary: ISO/IEC 27001:2013 specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). It also includes guidelines for assessing and addressing information security risks in organizations. Description: ISO/IEC 27001:2013 provides a comprehensive framework for creating an ISMS, applicable to organizations of all sizes and types. The standard outlines specific requirements for information security risk assessment as well as methodologies for risk treatment and mitigation. It emphasizes a continual improvement cycle, encouraging organizations to evaluate and enhance their practices over time. This edition was published in 2013 and has since been withdrawn after being replaced by ISO/IEC 27001:2022. --- ## ISO/IEC 27001:2022 — ISO/IEC 27001:2022 - Information security, cybersecurity and privacy protection — Information security management systems — Requirements URL: https://marketplace.6clicks.com/c/iso-iec-27001-2022 Domain: Cybersecurity Type: standard Issued by: ISO/IEC Jurisdiction: Global Version: 2022 Effective: 2022-10-25 Industries: Cybersecurity Tags: information security, ISMS, cybersecurity, risk management, data protection Source: https://www.iso.org/standard/27001 Document: https://www.iso.org/standard/82875.html Available in the 6clicks app: yes Summary: ISO/IEC 27001:2022 is an international standard defining requirements for an information security management system (ISMS). It helps organizations establish, implement, maintain, and continually improve their information security processes to manage data-related risks. Description: ISO/IEC 27001:2022 is the third edition of the standard, published in October 2022, that outlines requirements for managing and protecting information. It enables organizations of any size and sector to develop a holistic approach to information security that addresses people, processes, and technology. The standard supports risk management, ensures data confidentiality, integrity, and availability, and promotes operational resilience to evolving cyber threats. It is widely adopted worldwide, with certification processes available for businesses seeking formal accreditation to demonstrate compliance. --- ## ISO/IEC 27018:2025 — ISO/IEC 27018:2025 Information security, cybersecurity and privacy protection — Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors URL: https://marketplace.6clicks.com/c/iso-iec-27018-2025-information-security-cybersecurity-and-privacy-protection-gui Domain: Cybersecurity Type: standard Issued by: International Organization for Standardization (ISO) Version: 2025 Industries: Critical infrastructure, Government Tags: ISO, 27018, cloud security, PII protection, data privacy, compliance framework, risk management, information security, cybersecurity standards, cloud governance, privacy, accountability, ISM alignment Source: https://www.iso.org/standard/27018 Available in the 6clicks app: yes Summary: ISO/IEC 27018:2025 is the global standard for managing personally identifiable information (PII) in public cloud services. It provides cloud providers with a framework to ensure privacy, security, and compliance when processing customer data. Description: ISO/IEC 27018:2025 extends the ISO/IEC 27002 controls to address the unique risks of cloud computing, focusing on protecting PII handled by cloud service providers acting as data processors. Its purpose is to establish clear guidelines for transparency, accountability, and privacy-by-design, ensuring organizations meet regulatory obligations and customer expectations. The standard helps providers document control objectives, justify exclusions, and demonstrate compliance with international privacy principles. This standard is relevant to public cloud providers, enterprises, and government agencies that rely on cloud infrastructure to process sensitive personal data. It applies across industries such as healthcare, finance, and critical infrastructure, where secure handling of PII is essential. The 2025 edition aligns with ISO/IEC 27002:2022 and introduces updated implementation guidance, including a new annex for extended best practices. By adopting ISO/IEC 27018:2025, organizations can strengthen trust, reduce risk exposure, and enhance resilience in cloud-based data processing. --- ## ITSG-33 — IT Security Risk Management: A Lifecycle Approach (ITSG-33) URL: https://marketplace.6clicks.com/c/itsg-33 Domain: Cybersecurity Type: control set Issued by: Canadian Centre for Cyber Security Jurisdiction: Canada Effective: 2012-11-01 Industries: Government Tags: it security, risk management, government, security controls, framework Source: https://www.cyber.gc.ca/en/guidance/it-security-risk-management-lifecycle-approach-itsg-33 Document: https://www.cyber.gc.ca/sites/default/files/publications/ITSG-33_english.pdf Available in the 6clicks app: yes Summary: ITSG-33 is a guideline developed by the Canadian Centre for Cyber Security to help government departments manage IT security risks effectively. It outlines activities at both departmental and project levels, providing a structured process for integrating security considerations into IT environments and maintaining authorization to operate. Description: ITSG-33 helps Canadian federal departments address IT security risks by integrating risk management practices into departmental security programs and IT project lifecycles. It provides a comprehensive framework for identifying, managing, and mitigating risks through the use of a security control catalogue structured into technical, operational, and management controls. Additionally, it includes control profiles tailored for specific confidentiality, integrity, and availability requirements. By following ITSG-33, organizations can ensure cost-effectiveness, compliance with risk management strategies, and continuous improvement in adapting to evolving threats. --- ## ITSP.10.171 — Protecting Specified Information in Non-Government of Canada Systems and Organizations URL: https://marketplace.6clicks.com/c/itsp-10-171 Domain: Cybersecurity Type: standard Issued by: Canadian Centre for Cyber Security Jurisdiction: Canada Version: First release Effective: 2025-04-02 Last updated: 2025-10-28 Tags: cybersecurity, confidentiality, government-contracting, risk-management, canada, standards, compliance Source: https://www.cyber.gc.ca/en/guidance/protecting-specified-information-non-government-canada-systems-and-organizations-itsp10171 Document: https://www.cyber.gc.ca/en/guidance/protecting-specified-information-non-government-canada-systems-and-organizations-itsp10171 Available in the 6clicks app: yes Summary: ITSP.10.171 sets out security requirements for protecting 'specified information' when it resides in non-Government of Canada systems or organizations. It aligns with NIST standards but adapts them to the Canadian regulatory environment. Description: ITSP.10.171 is a cybersecurity standard issued by the Canadian Centre for Cyber Security to ensure the confidentiality of specified information as it resides in non-Government of Canada (non-GC) systems. The publication is modeled after NIST SP 800-171 but tailored to reflect Canadian legal, regulatory, and operational contexts. It outlines 17 families of security requirements, such as access control, incident response, and supply chain risk management. Non-GC organizations working with GC bodies must comply with these standards to safeguard contractual information. The document also supports scoping methods to limit security requirements to designated system components, balancing security needs with practicality. It references ITSP.10.033 as its control baseline and introduces organization-defined parameters (ODPs) for scalability and flexibility. --- ## NDPR 2019 — Nigeria Data Protection Regulation URL: https://marketplace.6clicks.com/c/nigeria-data-protection-regulation Domain: Cybersecurity Type: law Issued by: Government of Nigeria Jurisdiction: Nigeria Version: 2019 Effective: 2019-01-25 Tags: Data Protection, Privacy Compliance, Personal Data Processing, Data Privacy Source: https://nitda.gov.ng/wp-content/uploads/2020/11/NigeriaDataProtectionRegulation11.pdf Available in the 6clicks app: yes Summary: The Nigeria Data Protection Regulation (NDPR) 2019 is Nigeria's data protection framework that establishes requirements for the lawful processing, protection, and transfer of personal data while safeguarding the privacy rights of individuals and promoting responsible data management practices. Description: The Nigeria Data Protection Regulation (NDPR) 2019 is Nigeria's foundational data protection regulation, issued by the National Information Technology Development Agency (NITDA) to regulate the processing of personal data and protect individuals' privacy rights. The regulation establishes principles for lawful data processing, consent management, data security, third-party processing, cross-border data transfers, and the rights of data subjects. Its objectives include safeguarding personal data, promoting secure data-driven transactions, preventing misuse of personal information, and supporting Nigeria's participation in the global digital economy through internationally aligned privacy standards. The NDPR applies to organizations that process the personal data of Nigerian citizens and residents and provides compliance, enforcement, and audit requirements designed to ensure accountability and responsible data handling practices. --- ## NIPG — National Identity Proofing Guidelines 2025 URL: https://marketplace.6clicks.com/c/national-identity-proofing-guidelines-2025 Domain: Cybersecurity Type: standard Issued by: Australian Government Jurisdiction: Australia Effective: 2023-08-10 Last updated: 2025-09-16 Tags: Identity Verification, Identity Proofing, Digital Identity, Fraud Prevention, Risk-Based Approach Source: https://www.ag.gov.au/national-security/publications/national-identity-proofing-guidelines Available in the 6clicks app: yes Summary: The National Identity Proofing Guidelines 2025 provide voluntary, risk-based best-practice guidance for verifying an individual's identity, aligned with Digital ID Accreditation Rules to promote consistency across physical and digital identity verification processes. The guidelines support organizations in strengthening identity-proofing practices, increasing trust through a standardized and transparent approach, and enabling more identity verification activities to be conducted online. By leveraging national identity verification services, organizations can reduce the need to store identity document copies, resulting in lower costs, improved privacy, reduced data breach risks, and stronger protection against identity fraud. Description: The National Identity Proofing Guidelines 2025 provide broad, best practice guidance for identity proofing – establishing a person is who they say they are. The Guidelines align, where possible, with Digital ID Accreditation Rules to increase consistency in identity proofing for both physical and digital ID. They strengthen identity-proofing processes and increase trust through a standardised, transparent, national principles and risk-based approach. The Guidelines are voluntary. Compliance is encouraged but not mandatory. Public and private sector organisations should apply the recommended identity proofing practices in line with their circumstances and specific risk profile. The Guidelines enable a greater range of identity verification processes to be conducted online, supporting systems such as the national identity verification services. These systems increase the confidence that organisations have in the validity of an identity document and reduces the need to keep copies of individual’s identity documents. This results in significant cost savings, promotes privacy, lessens the impact of data breaches and maintains strong controls against identity fraud. --- ## NIST CSF 2.0 — NIST Cybersecurity Framework 2.0 URL: https://marketplace.6clicks.com/c/nist-csf-2-0 Domain: Cybersecurity Type: framework Issued by: National Institute of Standards and Technology (NIST) Jurisdiction: United States Version: 2.0 Last updated: 2026-02-24 Industries: Cybersecurity Tags: cybersecurity, framework, risk management, guidelines, profiles, enterprise security Source: https://www.nist.gov/cyberframework Document: https://www.nist.gov/cyberframework Available in the 6clicks app: yes Summary: The NIST Cybersecurity Framework 2.0 is a comprehensive framework to help organizations manage and reduce cybersecurity risks. It provides guidelines, tools, and resources for improving cybersecurity practices across diverse sectors. Description: The NIST Cybersecurity Framework 2.0 (CSF 2.0) builds on version 1.1 and introduces updates to better align with modern cybersecurity practices. It is designed to be adaptable for organizations of all sizes and sectors, helping them manage cybersecurity risks through core functions such as identify, protect, detect, respond, and recover. Version 2.0 introduces enhanced guidance on enterprise risk management, workforce management, and informative references. The framework also supports the creation of custom profiles tailored to specific industry or organizational needs, varying from quick-start guides to detailed mappings with other standards. CSF 2.0 encourages collaboration between industry and government, promoting the sharing of best practices for holistic risk management. --- ## NIST SP 800-161 Rev. 1 — NIST Special Publication 800-161 Rev. 1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations URL: https://marketplace.6clicks.com/c/nist-sp-800-161-rev-1 Domain: Cybersecurity Type: guideline Issued by: National Institute of Standards and Technology (NIST) Jurisdiction: United States Version: Rev. 1, Update 1 Effective: 2024-11-01 Industries: Cybersecurity, Risk Management Tags: cybersecurity, supply chain, risk management, c-scrm, guidance, assessment, supply chain security Source: https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final Document: https://doi.org/10.6028/NIST.SP.800-161r1-upd1 Available in the 6clicks app: yes Summary: This publication provides guidance on identifying, assessing, and mitigating cybersecurity risks throughout the supply chain. It integrates Cybersecurity Supply Chain Risk Management (C-SCRM) practices into organizational risk management processes. Description: NIST SP 800-161 Rev. 1 offers a comprehensive approach for managing cybersecurity risks in supply chains, addressing concerns such as malicious functionality, counterfeit products, and vulnerabilities stemming from poor manufacturing or development practices. It emphasizes the need for a multilevel, C-SCRM-specific strategy, covering areas like implementing C-SCRM policies, plans, and risk assessments for products and services. Updates to the document reflect ongoing efforts to integrate supply chain security into broader organizational risk management. The latest version also includes additional tools like the SCRM Assessment Scoping Questionnaire to aid in practical implementation. --- ## NIST SP 800-171A Rev. 3 — NIST Special Publication 800-171A Rev. 3 - Assessing Security Requirements for Controlled Unclassified Information URL: https://marketplace.6clicks.com/c/nist-sp-800-171a-rev-3 Domain: Cybersecurity Type: guideline Issued by: National Institute of Standards and Technology (NIST) Jurisdiction: United States Version: Revision 3 Effective: 2024-05-14 Last updated: 2023-11-09 Industries: Cybersecurity Tags: cui, security requirements, assessment procedures, fisma, compliance, audit, security controls, nonfederal systems Source: https://csrc.nist.gov/pubs/sp/800/171/a/r3/final Document: https://doi.org/10.6028/NIST.SP.800-171Ar3 Available in the 6clicks app: yes Summary: This publication provides a methodology and assessment procedures for evaluating security requirements associated with the protection of Controlled Unclassified Information (CUI). It supports compliance with NIST SP 800-171 in nonfederal systems and organizations. Description: NIST Special Publication 800-171A Revision 3 offers organizations a framework to assess the security requirements detailed in NIST SP 800-171. It provides flexible procedures that can accommodate both independent and government-sponsored assessments, allowing for customization based on depth and coverage needs. These assessments are crucial for safeguarding CUI, which is essential to the functioning of federal agencies. The publication aims to provide practical tools to reinforce federal contractors' compliance, particularly in the context of the Federal Acquisition Regulation (FAR) and the Federal Information Security Modernization Act (FISMA). The document also includes various families of controls, giving users clarity on standards they must meet. --- ## NIST SP 800-172 — Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171 URL: https://marketplace.6clicks.com/c/nist-sp-800-172 Domain: Cybersecurity Type: guideline Issued by: National Institute of Standards and Technology (NIST) Jurisdiction: United States Effective: 2020-07-06 Last updated: 2021-02-02 Industries: Critical infrastructure, Defense, Finance Sector, Government Tags: controlled unclassified information, advanced persistent threats, security requirements, cyber resiliency, critical programs, damage limitation, nonfederal systems, cui protection Source: https://csrc.nist.gov/publications/detail/sp/800-172/archive/2020-07-06 Document: https://doi.org/10.6028/NIST.SP.800-172-draft Available in the 6clicks app: yes Summary: NIST SP 800-172 elaborates enhanced security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations. It aims to mitigate risks posed by Advanced Persistent Threats (APT) through a defense-in-depth approach, building on the foundational requirements in NIST SP 800-171. Description: This document serves as a supplement to NIST SP 800-171, providing federal agencies with a model to establish enhanced security measures specifically aimed at protecting the confidentiality, integrity, and availability of Controlled Unclassified Information (CUI) in critical programs and high-value assets within nonfederal systems. Its requirements are tailored to address sophisticated Advanced Persistent Threats (APT), which employ cyber and physical attack vectors to breach defenses. The publication incorporates penetration-resistant architecture, damage-limiting operations, and cyber resiliency strategies to safeguard federal missions effectively. Key updates include revised scoping guidance, requirements flexibility, customization options, and threat modeling for defensive measures. The enhanced security measures must be implemented in addition to SP 800-171 requirements when specific safeguarding mandates are absent. --- ## NIST SP 800-39 — NIST Special Publication 800-39 - Managing Information Security Risk: Organization, Mission, and Information System View URL: https://marketplace.6clicks.com/c/nist-sp-800-39 Domain: Cybersecurity Type: guideline Issued by: National Institute of Standards and Technology (NIST) Jurisdiction: United States Effective: 2011-03-01 Last updated: 2011-03-01 Industries: Risk Management Tags: risk management, information security, enterprise risk, guidance, continuous monitoring, federal systems Source: https://csrc.nist.gov/pubs/sp/800/39/final Document: https://doi.org/10.6028/NIST.SP.800-39 Available in the 6clicks app: yes Summary: NIST SP 800-39 provides guidance for developing an organization-wide program to manage information security risk. It introduces a structured yet flexible framework for assessing, responding to, and monitoring risks associated with federal information systems. Description: This document offers an integrated approach to managing information security risks across an organization, focusing on organizational operations, assets, individuals, and national interests. It provides a broad-based strategy for risk management, emphasizing its harmonization with existing enterprise risk management programs rather than substituting them. SP 800-39 serves as a foundational guideline, complementing other NIST security standards and methods by addressing the planning, assessment, and continuous monitoring of risks. The framework underscores roles, responsibilities, and strategies to implement an effective, enterprise-wide information security risk management program. --- ## NZISM — New Zealand Information Security Manual URL: https://marketplace.6clicks.com/c/new-zealand-information-security-manual Domain: Cybersecurity Type: standard Issued by: New Zealand Government Communications Security Bureau (GCSB) Jurisdiction: New Zealand Version: Version 3.9 Effective: 2025-04-01 Industries: Critical infrastructure Tags: NZISM, New Zealand Information Security Manual, Information Security, Cybersecurity Framework, Risk Management, Protective Security Requirements Source: https://nzism.gcsb.govt.nz/ism-document Available in the 6clicks app: yes Summary: The New Zealand Information Security Manual (NZISM) is the New Zealand Government’s information security framework that provides baseline security controls, processes, and guidance to help organizations protect information systems and manage cybersecurity risks effectively. Description: The New Zealand Information Security Manual (NZISM) is the New Zealand Government’s authoritative framework for information assurance and information systems security, developed and maintained by the Government Communications Security Bureau (GCSB). The NZISM provides a comprehensive set of mandatory baseline controls, security processes, and recommended practices designed to protect government information, systems, and services from security threats. It supports a risk-based approach to information security by establishing requirements for areas such as asset management, identity and access management, authentication, logging, incident management, supply chain security, and risk management. The NZISM forms an integral part of New Zealand’s Protective Security Requirements (PSR) framework and promotes a consistent approach to safeguarding the confidentiality, integrity, and availability of information across government agencies. While primarily intended for government organizations, it is also widely used by Crown entities, local government bodies, contractors, and private sector organizations seeking to align with New Zealand government security standards. --- ## OWASP ASVS — OWASP Application Security Verification Standard URL: https://marketplace.6clicks.com/c/owasp-asvs Domain: Cybersecurity Type: standard Issued by: OWASP Foundation Version: 4.0.2 Last updated: 2025-05-30 Industries: Cybersecurity Tags: application security, web security, technical controls, secure development, vulnerability testing Source: https://owasp.org/www-project-application-security-verification-standard/#:~:text=The%20OWASP%20Application%20Security%20Verification%20Standard%20%28ASVS%29%20Project,with%20a%20list%20of%20requirements%20for%20secure%20development. Document: https://github.com/OWASP/ASVS/raw/master/5.0.0/en/0x13-V5_Environmental%20Control%20Requirements.md Available in the 6clicks app: yes Summary: The OWASP Application Security Verification Standard (ASVS) is an open standard for testing and verifying the security of web applications. It provides developers with a comprehensive list of requirements for secure development and helps establish confidence in application security. Description: The OWASP ASVS aims to normalize the rigor and coverage of web application security verification through a commercially workable open standard. It specifies technical security controls to protect applications and their environments from vulnerabilities like Cross-Site Scripting (XSS) and SQL injection. ASVS requirements, categorized into chapters and sections, serve as a metric for assessing web application security, a guide for security control development, and a framework for specifying security requirements in procurement contracts. Version 5.0.0 includes updates to structure, requirements, and use cases, available in various formats such as CSV and JSON for easy reference. --- ## PCI DSS — PCI Data Security Standard (PCI DSS) URL: https://marketplace.6clicks.com/c/pci-dss Domain: Cybersecurity Type: standard Issued by: PCI Security Standards Council Version: 4.x Industries: Finance Sector, Cybersecurity Tags: payment security, data protection, compliance, security standard, cardholder data Source: https://www.pcisecuritystandards.org/standards/pci-dss/ Document: https://www.pcisecuritystandards.org/pci_security/maintaining_payment_security Available in the 6clicks app: yes Summary: The PCI Data Security Standard (PCI DSS) is a global security standard designed to protect payment card account data. It establishes technical and operational security requirements for organizations that handle cardholder data. Description: The PCI DSS was developed to enhance payment card account data security globally by promoting consistent data security measures. It provides a baseline of technical and operational requirements intended for entities that store, process, or transmit cardholder data, including merchants, processors, and service providers. The latest version, PCI DSS v4.x, introduces additional flexibility and updated requirements to address emerging threats and technologies. Compliance is typically mandated by card brands or acquirers. Resources include documentation, training, qualified assessors, and vulnerability scanning services to help organizations adhere to the standard. --- ## PPG 511 — Prudential Practice Guide 511 - Remuneration URL: https://marketplace.6clicks.com/c/prudential-practice-guide-511-remuneration Domain: Cybersecurity Type: guideline Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Version: 30 November 2009 Last updated: 2009-11-30 Industries: Finance Sector Tags: PPG 511, Remuneration, APRA, Governance, Risk Management, Compensation Practices Source: https://www.apra.gov.au/system/files/PPG%20511%20Remuneration.pdf Available in the 6clicks app: yes Summary: Prudential Practice Guide (PPG) 511 - Remuneration is APRA guidance that helps regulated institutions design and manage remuneration arrangements that support prudent risk management, strong governance, and sustainable organisational performance. Description: Prudential Practice Guide (PPG) 511 - Remuneration is guidance issued by the Australian Prudential Regulation Authority (APRA) to assist APRA-regulated institutions in identifying and prudently managing risks arising from remuneration arrangements. The guide supports compliance with APRA's governance standards by promoting remuneration practices that align with sound risk management, prudent governance, and long-term financial stability. PPG 511 emphasizes that remuneration frameworks should encourage appropriate risk-taking behaviour, strengthen accountability, and ensure that executives and staff are not rewarded for poor risk management outcomes. The guide is aligned with international principles for sound compensation practices and provides practical guidance on developing effective remuneration policies and governance arrangements. --- ## PSPF 2026 — Protective Security Policy Framework Release 2026 URL: https://marketplace.6clicks.com/c/protective-security-policy-framework-release-2026 Domain: Cybersecurity Type: framework Issued by: Australian Government Jurisdiction: Australia Version: 2026 Effective: 2026-07-01 Last updated: 2026-07-02 Industries: Critical infrastructure Tags: PSPF, Protective Security Framework, Australian Government Security, Information Security, Risk Management, Security Compliance Source: https://www.protectivesecurity.gov.au/about Available in the 6clicks app: yes Summary: Protective Security Policy Framework (PSPF) Release 2026 is the Australian Government's updated protective security framework that sets mandatory requirements across six security domains to help government entities protect their people, information, assets, and resources through effective risk management and security practices. Description: The Protective Security Policy Framework (PSPF) Release 2026 is the Australian Government's latest protective security policy framework, published by the Department of Home Affairs and effective from 1 July 2026. The framework establishes mandatory protective security requirements across six security domains: Governance, Risk Management, Information Security, Technology Security, Personnel Security, and Physical Security. It provides a comprehensive, risk-based approach to safeguarding government people, information, assets, and resources both within Australia and internationally. PSPF Release 2026 supports government entities in identifying, assessing, and mitigating security risks and vulnerabilities while maintaining responsible and effective protective security practices. The annual release reflects updates to security requirements, standards, and guidance in response to the evolving threat environment and emerging security challenges. --- ## QCF — Qatar Cybersecurity Framework URL: https://marketplace.6clicks.com/c/qcf Domain: Cybersecurity Type: framework Issued by: Qatar National Cyber Security Committee (NCSC) Jurisdiction: Qatar Industries: Cybersecurity Tags: cybersecurity, capabilities, prevention, detection, response Source: https://ncsa.gov.qa/en/ Available in the 6clicks app: yes Summary: The Qatar Cybersecurity Framework (QCF) provides structured guidelines to help organizations manage and strengthen their cybersecurity practices across governance, risk, protection, detection, response, and recovery. It promotes a proactive, coordinated approach to mitigating cyber threats while enhancing national and organizational resilience. Description: The Qatar Cybersecurity Framework (QCF) is a national set of guidelines developed by the Qatar National Cyber Security Committee to help organizations implement and maintain cybersecurity best practices across their operations. It is structured around six core domains—strategy and governance, risk management, protection, detection and response, recovery, and collaboration—covering the full cybersecurity lifecycle from prevention to resilience. The framework was initially introduced to secure major national initiatives such as the FIFA World Cup 2022 and continues to be applied to organizations working with the Qatari government, with flexibility to adapt across industries. It emphasizes proactive risk management, strong security controls, incident response readiness, and continuous improvement to enhance organizational and national cybersecurity posture. Overall, the QCF promotes a coordinated, resilient approach to managing cyber threats while supporting secure digital growth. --- ## RFFR ISM SoA — Right Fit for Risk Information Security Manual Statement of Applicability URL: https://marketplace.6clicks.com/c/right-fit-for-risk-information-security-manual-statement-of-applicability Domain: Cybersecurity Type: regulation Issued by: Australian Government Jurisdiction: Australia Version: June 2026 Last updated: 2026-06-01 Industries: Critical infrastructure, Government Tags: cybersecurity framework, information security, risk management, government standards, critical infrastructure, compliance, data protection, resilience, IT security, ASD guidelines Source: https://www.dewr.gov.au/right-fit-risk-cyber-security-accreditation/resources/rffr-statement-applicability-soa-template Available in the 6clicks app: yes Summary: The Right Fit for Risk (RFFR) Statement of Applicability (SoA) is a structured template used to document how organizations meet cyber security accreditation requirements. It outlines applicable controls, their implementation status, and provides assurance of compliance with the RFFR framework. Description: The RFFR Statement of Applicability (SoA) serves as a key governance document within the Australian Government’s Right Fit for Risk cyber security accreditation program. Its purpose is to demonstrate how an organization applies relevant security controls, identifies exclusions, and justifies risk-based decisions in alignment with accreditation standards. The SoA is primarily intended for service providers seeking accreditation to deliver ICT services to government agencies, ensuring transparency and accountability in their cyber security posture. This framework applies across sectors that interact with government systems, including ICT vendors, managed service providers, and organizations handling sensitive or official information. By requiring organizations to map controls against the Information Security Manual (ISM) and other ASD guidance, the SoA ensures consistency, comparability, and confidence in cyber risk management. Ultimately, it provides government agencies with assurance that accredited providers have implemented appropriate safeguards, while also enabling providers to clearly communicate their compliance and risk management approach. --- ## SACSF V2.0 — South Australian Cyber Security Framework V2.0 URL: https://marketplace.6clicks.com/c/south-australian-cyber-security-framework-v2-0 Domain: Cybersecurity Type: framework Issued by: Australian Government Jurisdiction: South Australia Version: V2.0 Last updated: 2025-06-01 Industries: Critical infrastructure Tags: cybersecurity, cyber risks, governance, information security, personnel security, physical security Source: https://www.security.sa.gov.au/cyber-security/tiles-for-cs/sacsf Available in the 6clicks app: yes Summary: The South Australian Cyber Security Framework (SACSF) is a cybersecurity governance framework developed by Security SA to help South Australian Government agencies manage cyber risks and protect information, systems, and digital services. It consists of 18 policy statements across four core principles—Governance, Information Security, Personnel Security, and Physical Security—and uses a four-tier risk-based approach to implement security controls proportionate to agency risk exposure. Description: The South Australian Cyber Security Framework (SACSF) is a government cybersecurity framework developed by Security SA to ensure cyber security is effectively managed across South Australian Government agencies. It provides a risk-based approach for protecting government infrastructure, digital assets, information, and services while allowing agencies flexibility in how they implement security controls to meet their specific operational needs. The SACSF applies to South Australian public sector agencies defined under the Public Sector Act 2009 and is built around 18 policy statements that support four core principles: Governance, Information Security, Personnel Security, and Physical Security. The framework uses a four-tier implementation model, with each tier introducing progressively stronger security requirements based on the agency's risk exposure, ensuring that controls are proportionate to the level of risk. The primary purpose of the SACSF is to help agencies identify, manage, and reduce cyber security risks while strengthening operational resilience and security governance. The framework is supported by standards, rulings, guidelines, templates, and implementation resources that address areas such as risk management, incident reporting, vulnerability management, awareness training, email security, and secure technology practices, enabling a consistent and scalable approach to cybersecurity across government. The following principles are contained in this download: 1 Leadership 2 Organisational Structure and Staff Responsibilities 3 Risk Management 4 Policies, Procedures and Compliance 5 Supplier Management and Acquisition of Technology 6 Audit and Assurance 7 Information Asset Identification and Classification 8 Incident Management 9 Resilience and Service Continuity 10 Access to Information 11 Administrative Access 12 Robust ICT Systems and Operations 13 Vulnerability Management 14 Network Communications 15 Secure Software Development 16 Mobile Device Management & Remote Working 17 Personnel Security Lifecycle 18 Physical Security --- ## Safe & Trusted Internet — Guidelines on Information Security Practices for Government Entities URL: https://marketplace.6clicks.com/c/safe-trusted-internet-guidelines-on-information-security-practices-for-government-entities Domain: Cybersecurity Type: guideline Issued by: Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Jurisdiction: India Effective: 2023-06-30 Industries: Government Tags: information security, CERT-In, Cyber Risk Management, IT Act 2000, data protection Source: https://www.cert-in.org.in/PDF/guidelinesgovtentities.pdf Available in the 6clicks app: yes Summary: The Safe & Trusted Internet Guidelines on Information Security Practices for Government Entities, issued by the Indian Computer Emergency Response Team (CERT-In), establish baseline cyber security controls and best practices to help government entities protect ICT infrastructure, systems, networks, and data against evolving cyber threats and strengthen India’s digital security posture. Description: The Safe & Trusted Internet Guidelines on Information Security Practices for Government Entities, issued by the Indian Computer Emergency Response Team (CERT-In), establish a baseline framework for strengthening cyber security across government organisations in India. The guidelines aim to protect government ICT infrastructure, systems, networks, and citizen data from evolving cyber threats such as malware, ransomware, phishing, and data breaches through standardized security controls and best practices. --- ## SCF — Secure Controls Framework URL: https://marketplace.6clicks.com/c/scf Domain: Cybersecurity Type: framework Issued by: Secure Controls Framework (SCF) Council Version: 2026.1.1 Tags: cybersecurity, compliance, data privacy, control set, framework, risk management, audit-ready Source: https://securecontrolsframework.com/ Document: https://securecontrolsframework.com/ Available in the 6clicks app: yes Summary: The Secure Controls Framework (SCF) is a comprehensive, free cybersecurity and data privacy metaframework designed to simplify compliance and build secure, resilient organizations. It unifies control sets to simultaneously meet compliance requirements across multiple laws, regulations, and frameworks. Description: The SCF, also known as the Common Controls Framework (CCF), provides a unified control catalog with over 1,400 controls across 33 domains. It maps to over 200 unique laws, regulations, and frameworks globally, such as GDPR, HIPAA, ISO 27001, and more. The framework is created and maintained by volunteers from the cybersecurity and GRC community, ensuring transparent and rigorous methodologies like the NIST IR 8477 Set Theory Relationship Mapping (STRM). As a living control set, SCF is updated quarterly to stay relevant with evolving laws and threat landscapes. It is openly available in machine-readable formats compatible with modern GRC platforms. --- ## SMB1001 — SMB1001 Cybersecurity Standard URL: https://marketplace.6clicks.com/c/smb1001 Domain: Cybersecurity Type: standard Issued by: Dynamic Standards International (DSI) Jurisdiction: Australia Version: 2026 Last updated: 2025-09-01 Industries: Cybersecurity Tags: cybersecurity, data protection, certification, cyber resilience Source: https://dsi.org/smb1001 Document: https://dsi.org/smb1001 Available in the 6clicks app: yes Summary: The SMB1001 Cybersecurity Standard provides small and medium-sized businesses, including law firms, with a clear and achievable framework to enhance their cybersecurity defenses and demonstrate due diligence. It aims to help practitioners protect client confidentiality, reduce cyber risks, and meet stakeholder requirements. Description: The SMB1001 Cybersecurity Standard, developed to assist small and medium businesses including law practices, offers a practical and scalable framework to address cybersecurity risks. It emphasizes protecting confidential client information, building trust, and ensuring readiness against cyberattacks. The standard includes multiple certification tiers, which firms can adopt progressively to enhance their security posture. By following SMB1001, businesses gain tools for efficient use of cybersecurity budgets, improved insurability, certification opportunities, and enhanced credibility with key stakeholders. While implementation doesn't guarantee immunity against cyber incidents, it provides a strong foundation for compliance and professional assurance. --- ## SOC2 — SOC2 Trusted Services Criteria URL: https://marketplace.6clicks.com/c/soc-2 Domain: Cybersecurity Type: framework Issued by: American Institute of Certified Public Accountants (AICPA) Jurisdiction: United States Last updated: 2022-09-30 Industries: Cybersecurity Tags: soc 2, security, availability, integrity, confidentiality, privacy, controls Source: https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2 Document: https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 Available in the 6clicks app: yes Summary: SOC 2 is a framework for managing and reporting on controls at service organizations relevant to security, availability, processing integrity, confidentiality, and privacy. It aims to provide detailed information and assurance to stakeholders about how these controls are implemented to protect user data. Description: SOC 2 is a widely adopted standard developed by the AICPA to provide organizations with a structured framework for managing controls related to security, availability, processing integrity, confidentiality, and privacy. This framework is particularly relevant for service organizations that require transparency about their systems and processes. It uses the 2017 Trust Services Criteria (updated with revised points of focus in 2022) as its foundation and includes guidance on effective implementation and reporting. SOC 2 reports are targeted at stakeholders who need assurance about a service provider's internal controls regarding handling sensitive data. The framework also serves as the basis for a consistent and standardized examination, including illustrative examples and criteria for system descriptions. --- ## SOC-CMM — SOC-CMM Assessment Tool URL: https://marketplace.6clicks.com/c/soc-cmm-assessment-tool Domain: Cybersecurity Type: standard Issued by: SOC-CMM Effective: 2026-04-16 Tags: Security Operations Center (SOC), Capability Maturity Model, SOC Assessment Tool, Cybersecurity Governance, NIST CSF Mapping Source: https://www.soc-cmm.com/products/soc-cmm Available in the 6clicks app: yes Summary: The SOC-CMM model is a capability maturity model that can be used to perform a self-assessment of your Security Operations Center (SOC). The model is based on review conducted on literature regarding SOC setup and existing SOC models as well as literature on specific elements within a SOC. The literature analysis was then validated by questioning several Security Operations Centers in different sectors and on different maturity levels to determine which elements were actually in place. The output from the survey, combined with the initial analysis is the basis for this self-assessment. For more information regarding the scientific background and the literature used to create the SOC-CMM self-assessment tool, please refer to the thesis document as available through: https://www.soc-cmm.com/ Description: The SOC-CMM model is a capability maturity model that can be used to perform a self-assessment of your Security Operations Center (SOC). The model is based on review conducted on literature regarding SOC setup and existing SOC models as well as literature on specific elements within a SOC. The literature analysis was then validated by questioning several Security Operations Centers in different sectors and on different maturity levels to determine which elements were actually in place. The output from the survey, combined with the initial analysis is the basis for this self-assessment. For more information regarding the scientific background and the literature used to create the SOC-CMM self-assessment tool, please refer to the thesis document as available through: https://www.soc-cmm.com/ The purpose of the SOC-CMM is to gain insight into the strengths and weaknesses of the SOC. This enables the SOC management to make informed decisions about which elements of the SOC require additional attention and/or budget. By regularly assessing the SOC for maturity and capability, progress can be monitored. Besides the primary purpose of performing an assessment of the SOC, the assessment can also be used for extensive discussions about the SOC and can thus provide valuable insights. This tool is intended for use by SOC and security managers, experts within the SOC and SOC consultants. --- ## Spain ENS — Spain - National Security Framework URL: https://marketplace.6clicks.com/c/spain-national-security-framework Domain: Cybersecurity Type: framework Issued by: Government of Spain Jurisdiction: Spain Version: 5 May 2022 Effective: 2010-01-30 Last updated: 2022-05-05 Industries: Government Tags: ENS, Spain, Cybersecurity, Information Security, Public Sector Security, Risk Management Source: https://ens.ccn.cni.es/en/what-is-the-ens Available in the 6clicks app: yes Summary: The National Security Framework (ENS) is Spain's national cybersecurity framework that defines security principles and controls for public sector organizations and their suppliers to protect information systems and ensure the confidentiality, integrity, availability, authenticity, and traceability of digital services. Description: The National Security Framework (Esquema Nacional de Seguridad - ENS) is Spain's national cybersecurity and information security framework that establishes the security principles, requirements, and measures for protecting information and digital services used by the public sector. Applicable to Spanish public administrations and organizations that provide services to them, the ENS provides a common framework to ensure the confidentiality, integrity, availability, authenticity, traceability, and preservation of information processed through electronic means. Established in 2010 and updated through Royal Decree 311/2022, the framework adopts a risk-based approach to cybersecurity and requires organizations to implement appropriate organizational, operational, and technical security controls. The ENS aims to strengthen trust in government digital services, improve cyber resilience, and ensure the secure management of public sector information systems. --- ## TGISF — Tasmanian Government Information Security Framework URL: https://marketplace.6clicks.com/c/tasmanian-government-information-security-framework Domain: Cybersecurity Type: framework Issued by: Tasmanian Government Jurisdiction: Tasmania Industries: Critical infrastructure Tags: information security, risk management, security controls, compliance Source: https://www.security.tas.gov.au/ Available in the 6clicks app: yes Summary: The Tasmanian Government Information Security Framework (TGISF) is a government-wide information security and risk management framework that provides principles, guidelines, and controls to help Tasmanian Government agencies protect information assets and manage security risks effectively. Description: The Tasmanian Government Information Security Framework (TGISF) is a whole-of-government framework developed by the Tasmanian Department of Premier and Cabinet to provide a structured approach for managing and protecting government information assets. First published in 2003, the framework establishes information security principles, guidelines, and risk management practices designed to help government agencies safeguard the confidentiality, integrity, and availability of information. It supports consistent security governance across Tasmanian Government entities by defining responsibilities, promoting risk-based decision-making, and encouraging the implementation of appropriate security controls. The framework serves as a foundation for managing information security risks, ensuring compliance with government requirements, and protecting sensitive information from unauthorized access, disclosure, alteration, or loss. --- ## UAE IA V2 — UAE Information Assurance Standard Version 2 URL: https://marketplace.6clicks.com/c/uae-ia-v2 Domain: Cybersecurity Type: standard Issued by: UAE Cyber Security Council Jurisdiction: United Arab Emirates Version: 2.0 Effective: 2025-10-22 Last updated: 2025-10-22 Industries: Cybersecurity Tags: cybersecurity, information assurance, critical infrastructure, risk management, AI security, IoT security, post-quantum cryptography Source: https://complyan.com/uae-information-assurance-standard-v2redefining-cyber-resilience-in-the-emirates/ Document: https://csc.gov.ae/documents/38662/1018122/UAE+INFORMATION+ASSURANCE+STANDARD.pdf/45890541-9f4f-574b-89a5-ab65213df8c0?t=1763982792107 Available in the 6clicks app: yes Summary: The UAE Information Assurance Standard Version 2 (UAE IA V2) is a national cybersecurity framework issued by the UAE Cyber Security Council in 2025. It builds upon the previous version with updated controls and integrations to address modern technologies, such as AI/ML, IoT, cloud, and post-quantum cryptography. Description: The UAE Information Assurance Standard V2 (UAE IA V2) represents a significant update to the country's cybersecurity standard, published by the UAE Cyber Security Council. It reduces previous control overlaps, reorganizes controls into 15 families and 134 controls with 449 sub-controls, and aligns with seven National Cybersecurity Policies. New areas, such as post-quantum cryptography, threat intelligence, secure software development, and AI/ML security, address emerging threats and technologies. Key enhancements include modular risk-driven control architecture, explicit accountability assignments, and a prioritization model of 'Always Applicable' and 'Based on Risk' controls. The guideline harmonizes national and international standards, fostering better governance, continuous improvement, and simplified compliance across both government and critical infrastructure entities. --- ## VPDSS 2.0 — Victorian Protective Data Security Standards V2.0 URL: https://marketplace.6clicks.com/c/vpdss-2-0 Domain: Cybersecurity Type: standard Issued by: Office of the Victorian Information Commissioner (OVIC) Jurisdiction: Victoria, Australia Version: 2.0 Effective: 2019-10-28 Last updated: 2019-10-28 Industries: Government, Risk Management Tags: data security, public sector, ict security, risk management, governance, information protection Source: https://ovic.vic.gov.au/information-security/standards/ Document: https://ovic.vic.gov.au/wp-content/uploads/2020/09/VPDSS-2.0-Implementation-Guidance-V2.4.pdf Available in the 6clicks app: yes Summary: The Victorian Protective Data Security Standards (VPDSS) establish 12 high-level mandatory requirements for the protection of public sector information in Victoria, Australia. These requirements cover governance, information, personnel, ICT, and physical security, focusing on a risk-managed approach tailored to the Victorian government context. Description: The VPDSS 2.0 provide a structured framework to secure public sector information. Issued in October 2019, the standards replaced the 2016 version and are consistent with national and international security frameworks. They aim to ensure effective and economic investment in security measures, supporting efficient governance, information lifecycle management, personnel security, ICT security, and physical protections. Contracted service providers with access to public sector information must also comply. The standards empower Victorian public sector organizations to manage risks, make informed decisions, and share information securely. --- ## VPDSS PDSP v3.7 — Victorian Protective Data Security Standards Protective Data Security Plan v3.7 URL: https://marketplace.6clicks.com/c/vpdss-pdsp-v3-7 Domain: Cybersecurity Type: guideline Issued by: Office of the Victorian Information Commissioner (OVIC) Jurisdiction: Victoria, Australia Version: 3.7 Last updated: 2026-01-07 Industries: Government Tags: information security, reporting requirements, incident notification, public sector, victoria Source: https://ovic.vic.gov.au/information-security/agency-reporting-obligations/ Document: https://ovic.vic.gov.au/information-security/agency-reporting-obligations/ Available in the 6clicks app: yes Summary: Victorian public sector bodies are required to report on their information security practices to the Office of the Victorian Information Commissioner (OVIC). This includes submitting Protective Data Security Plans (PDSPs), annual attestations, and notifying OVIC of security incidents as outlined under the Victorian Protective Data Security Framework and Standards (VPDSF, VPDSS). Description: A Protective Data Security Plan (PDSP) is a formal, risk-based information security plan required under the Victorian Protective Data Security Framework (VPDSF) and administered by the Office of the Victorian Information Commissioner (OVIC). The PDSP documents how a Victorian Public Sector (VPS) organisation protects public sector information, manages information security risks, and complies with the Victorian Protective Data Security Standards (VPDSS). It is developed following a Security Risk Profile Assessment (SRPA) and outlines the organisation’s current security posture, identified risks, implemented controls, risk treatment activities, third-party assurance measures, and planned security improvements. The plan must address governance, personnel, ICT, physical, and information security controls, including obligations relating to contracted service providers that handle government data on the organisation’s behalf. VPS organisations are also expected to regularly review and update the PDSP, particularly when significant operational, technological, legislative, or risk-related changes occur, and submit the plan to OVIC as part of ongoing compliance and assurance obligations. --- ## WA Cyber Security Policy — Western Australian Government Cyber Security Policy URL: https://marketplace.6clicks.com/c/wa-cyber-security-policy Domain: Cybersecurity Type: guideline Issued by: Department of the Premier and Cabinet - Office of Digital Government Jurisdiction: Western Australia Version: 2024 Industries: Government Tags: cybersecurity, government, policy, guidelines, digital infrastructure, western australia Source: https://www.wa.gov.au/government/publications/2024-wa-government-cyber-security-policy Document: https://www.wa.gov.au/government/publications/2024-wa-government-cyber-security-policy Available in the 6clicks app: yes Summary: The 2024 WA Government Cyber Security Policy outlines the baseline requirements for cyber security practices within Western Australian Government entities. It aims to reduce cyber security risks through a comprehensive and systematic approach to safeguarding digital information, information systems, and assets. Description: The WA Government Cyber Security Policy specifies mandatory measures for government entities in Western Australia to manage cyber security risks effectively. It focuses on ensuring the confidentiality, integrity, and availability of critical information systems while accepting that cyber security threats cannot be entirely eliminated. The policy includes specific implementation guidelines and directives, such as restrictions on the use of certain software products, governance for data offshoring, and self-assessment tools for risk evaluation. Published by the Department of the Premier and Cabinet's Office of Digital Government, the policy is a key component of the state's efforts to secure digital infrastructure. --- ## WA Digital Security Policy — Western Australia Digital Security Policy URL: https://marketplace.6clicks.com/c/western-australia-digital-security-policy Domain: Cybersecurity Type: guideline Issued by: Australian Government Jurisdiction: Australia Effective: 2016-05-26 Industries: Government Tags: https://www.wa.gov.au/system/files/2018-06/Digital%20Security%20Policy_0.pdf Source: https://digitalgov.online/2016/05/was-new-digital-security-policy/ Document: https://digitalgov.online/2016/05/was-new-digital-security-policy/ Available in the 6clicks app: yes Summary: The West Australian Whole of Government Digital Security Policy provides guidelines for adopting and maintaining security controls in digital information and systems. It addresses confidentiality, integrity, and availability, relying on both Australian and international standards. Description: Launched on May 25, 2016, by the Minister for Innovation, the WA Digital Security Policy aims to enhance security practices across government institutions by focusing on three key areas: confidentiality, integrity, and availability of digital information. These principles ensure sensitive information is accessed and disclosed with authorization, data remains authentic and protected from unauthorized alterations, and users can access systems and services reliably. The policy also emphasizes the importance of integrating governance, people, processes, and technology in digital security strategies. It aligns with Australian and international standards for managing digital security. --- ## WLA-SCS:2020 — World Lottery Association Security Control Standard 2020 URL: https://marketplace.6clicks.com/c/wla-scs-2020 Domain: Cybersecurity Type: standard Issued by: World Lottery Association Jurisdiction: Global Version: 2020 Tags: information security, risk management, audit, compliance, security policies, incident management, lottery industry Source: https://world-lotteries.org/volumes/downloads/Download_Center/Security/WLA_SCS_2020/202012_EN_WLA-SCS-2020_Standard_V1-2.pdf Available in the 6clicks app: yes Summary: The World Lottery Association Security Control Standard (WLA-SCS:2020) offers a framework specifically designed for the lottery and gaming industry to safeguard information security and ensure operational compliance. It includes guidelines for security management, risk assessments, and audit processes and provides a benchmark for organizations seeking WLA certification. Description: The World Lottery Association Security Control Standard (WLA-SCS:2020) is tailored for lottery and gaming organizations worldwide. It focuses on establishing a robust security framework to protect critical information assets, comply with industry norms, and prevent operational risks. The standard outlines requirements for risk management, security policies, auditing, and continuous improvement processes. This edition also emphasizes collaboration for internal and external compliance assessment, as well as reporting procedures to align organizations with the WLA Executive Committee's certification requirements. The guidelines aim to enhance trust and accountability while facilitating effective governance, incident management, and evidence collection. --- ## Baseline Cyber Security Controls for Small and Medium Organizations URL: https://marketplace.6clicks.com/c/baseline-cyber-security-controls-for-small-and-medium-organizations Domain: Cybersecurity Type: guideline Issued by: Canadian Centre for Cyber Security Jurisdiction: Canada Version: 1.2 Industries: Cybersecurity Tags: cybersecurity, small businesses, baseline controls, incident response, patch management Source: https://www.cyber.gc.ca/en/guidance/baseline-cyber-security-controls-small-and-medium-organizations Document: https://www.cyber.gc.ca/sites/default/files/2021-04/SMO_Baseline_Controls-1.2-e.pdf Available in the 6clicks app: yes Summary: The Baseline Cyber Security Controls for Small and Medium Organizations provides guidance from the Canadian Centre for Cyber Security to improve the resilience of smaller organizations through focused cybersecurity measures. It applies the 80/20 rule, aiming to achieve significant cybersecurity benefits with minimal effort. Description: This guidance document offers a set of recommended cybersecurity practices tailored for small and medium organizations in Canada, defined as having fewer than 500 employees. It addresses common cybersecurity threats, such as cybercrime, and presents an actionable list of controls aimed at mitigating these risks, including incident response planning, automatic patching, secure configurations, and employee awareness training. The document emphasizes cost-effective measures and acknowledges the practical limitations faced by smaller entities. It also provides insights into organizational controls, baseline controls, and threat levels specific to this sector. This publication is part of Canada's broader effort to improve national cybersecurity resilience. --- ## BSI IT-Grundschutz-Compendium Edition 2022 URL: https://marketplace.6clicks.com/c/bsi-it-grundschutz-compendium-edition-2022 Domain: Cybersecurity Type: guideline Issued by: Federal Office for Information Security (BSI) Jurisdiction: Germany Version: 2022 Last updated: 2023-01-05 Industries: Cybersecurity Tags: cybersecurity, guidelines, risk-management, bsi, it-grundschutz Source: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.html Document: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.html Available in the 6clicks app: yes Summary: The BSI IT-Grundschutz-Compendium Edition 2022 is a comprehensive cybersecurity guideline published by the German Federal Office for Information Security (BSI). It provides a structured methodology for implementing information security in organizations based on standardized modules and best practices. Description: The BSI IT-Grundschutz-Compendium Edition 2022 serves as a cornerstone for organizations aiming to ensure robust information security. It consists of modular components covering key areas like asset management, risk analysis, and critical system protection. The compendium is part of the broader IT-Grundschutz approach developed by the BSI, which harmonizes guidelines to improve cybersecurity resilience. This edition focuses on accessibility and clarity to accommodate organizations of varying sizes and complexities, while reflecting the latest advancements in cybersecurity and the evolving threat landscape. --- ## ESMA Minimum Standard IT Security Controls URL: https://marketplace.6clicks.com/c/esma-minimum-standard-it-security-controls Domain: Cybersecurity Type: standard Issued by: European Securities and Markets Authority (ESMA) Jurisdiction: EU Industries: Critical infrastructure Tags: ESMA Minimum Security Controls, Information Security, Cybersecurity Controls, Security Compliance, Secure Software Development, Risk Management Source: https://www.esma.europa.eu/ Available in the 6clicks app: yes Summary: The ESMA Minimum Standard IT Security Controls is a cybersecurity and compliance framework that defines the minimum security requirements service providers must implement to protect ESMA systems, applications, data, and information services. Description: The ESMA Minimum Standard IT Security Controls is a security requirements framework developed by the European Securities and Markets Authority (ESMA) to assess and ensure that service providers, platforms, applications, and third-party solutions meet minimum cybersecurity, operational security, and compliance expectations when handling ESMA information and services. The framework defines mandatory controls across key security domains including identity and access management, authentication, cryptographic protection, data-in-transit security, security operations, vulnerability management, business continuity, auditability, compliance, supply chain security, and secure software development. It also establishes requirements for certifications, penetration testing, incident reporting, logging, backup and recovery, encryption, and security governance to help protect ESMA information assets and support regulatory security assurance. --- ## Guidelines on ICT and Security Risk Management URL: https://marketplace.6clicks.com/c/guidelines-on-ict-and-security-risk-management Domain: Cybersecurity Type: guideline Issued by: European Banking Authority (EBA) Jurisdiction: EU Version: 2025 update Effective: 2025-05-20 Last updated: 2025-07-15 Industries: Finance Sector Tags: ict risk, security management, financial sector, operational resilience, compliance Source: https://www.eba.europa.eu/activities/single-rulebook/regulatory-activities/internal-governance/guidelines-ict-and-security-risk-management Document: https://www.eba.europa.eu/sites/default/documents/files/document_library/Publications/Guidelines/2025/Final%20report%20on%20amending%20Guidelines%20on%20ICT%20risk%20and%20security%20management.pdf Available in the 6clicks app: yes Summary: The EBA Guidelines establish requirements for credit institutions, investment firms, and payment service providers on mitigating and managing information and communication technology (ICT) risks. They aim to ensure a consistent and robust approach to ICT and security risk management across the EU financial sector. Description: These Guidelines were developed by the European Banking Authority (EBA) to standardize ICT and security risk management practices in the EU financial system. They apply to credit institutions, investment firms, and payment service providers and aim to mitigate operational and ICT risks effectively. The Guidelines will replace the EBA GL/2017/17 Guidelines on security measures for operational and security risks. They are aligned with the Digital Operational Resilience Act (DORA), which harmonizes ICT risk management practices in the financial sector. The Guidelines focus on a simplified framework for managing ICT risks, including operational resilience, and are set to take effect on May 20, 2025. --- ## NSW Cyber Security Policy URL: https://marketplace.6clicks.com/c/nsw-cyber-security-policy Domain: Cybersecurity Type: regulation Issued by: Cyber Security NSW Jurisdiction: New South Wales, Australia Industries: Cybersecurity Tags: cybersecurity, nsw, government, risk-management, mandatory-requirements Source: https://www.digital.nsw.gov.au/policy/cyber-security-policy Document: https://www.digital.nsw.gov.au/sites/default/files/2022-09/NSW%20Cyber%20Security%20Policy.pdf Available in the 6clicks app: yes Summary: The NSW Cyber Security Policy outlines mandatory requirements that all NSW Government agencies must follow to ensure the effective management of cyber security risks to government information and systems. It mandates annual reporting by agencies and includes policy directives related to incident management, risk assessment, and compliance. Description: The NSW Cyber Security Policy is a regulatory framework established by Cyber Security NSW to standardize cyber security practices across all NSW Government agencies. It includes mandatory reporting, requiring agencies to provide assurance assessments, details on high or extreme residual risks, and an attestation on cyber security measures. Cyber Security NSW also issues related circulars and directives on various topics, such as accessing systems while overseas, managing cyber security incident information, and restricting certain applications due to foreign risk concerns. The policy is enforced through mandatory annual submissions and includes additional guidance documents and tools to aid compliance. --- ## 3PS 221- Aggregate Risk Exposures — Banking, Insurance and Life Insurance (prudential standard) determination No. 2 of 2016 - Prudential Standard 3PS 221 Aggregate Risk Exposures URL: https://marketplace.6clicks.com/c/3ps-221 Domain: GRC Type: regulation Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Version: 13 September 2016 Effective: 2016-09-13 Industries: Finance Sector Tags: prudential standards, risk management, banking insurance, aggregate risk exposures, treasury compliance Source: https://www.legislation.gov.au/Details/F2016L01429 Document: https://www.legislation.gov.au/Details/F2016L01429 Available in the 6clicks app: yes Summary: This legislative determination establishes prudential requirements for managing and reporting aggregate risk exposures within banking, insurance, and life insurance sectors. It aims to ensure robust risk management practices across these industries. Description: The Banking, Insurance and Life Insurance (prudential standard) determination No. 2 of 2016, known as Prudential Standard 3PS 221 Aggregate Risk Exposures, sets out specific obligations for entities within the banking, insurance, and life insurance industries in Australia. Administered by the Department of the Treasury, this standard ensures that organizations accurately manage and report their aggregate risk exposures to maintain financial stability and safeguard the public interest. The determination is enacted as a legislative instrument under the authority of the Banking Act 1959, Insurance Act 1973, and Life Insurance Act 1995. It includes provisions for compliance with risk aggregation and reporting frameworks. --- ## 3PS 222 — Banking, Insurance and Life Insurance (Prudential Standard) Determination No. 3 of 2016 - Prudential Standard 3PS 222 Intra-group Transactions and Exposures URL: https://marketplace.6clicks.com/c/3ps-222 Domain: GRC Type: regulation Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Version: 14 September 2016 Effective: 2016-09-14 Industries: Finance Sector Tags: prudential, financial regulation, intra group, risk exposure Source: https://www.legislation.gov.au/F2016L01433/latest/text Document: https://www.legislation.gov.au/F2016L01433/latest/text Available in the 6clicks app: yes Summary: Prudential Standard 3PS 222 establishes requirements for managing intra-group transactions and exposures within banking, insurance, and life insurance entities in Australia. It aims to ensure financial stability and risk management in group entities regulated under relevant Australian financial laws. Description: This prudential standard is applicable to financial institutions operating under the Banking Act 1959, Insurance Act 1973, and Life Insurance Act 1995. It sets out requirements for managing intra-group transactions and exposures to ensure the safety and soundness of entities within a corporate group. The primary focus is on ensuring financial stability by mitigating risks such as contagion and conflicts of interest that could arise from intra-group activities. Administered by the Department of the Treasury, this legislative instrument is binding on the entities it applies to. The latest version was made effective on September 14, 2016, and forms part of Australia's financial regulatory framework. --- ## 3PS 310 — Banking, Insurance and Life Insurance (Prudential Standard) Determination No. 4 of 2016 - Prudential Standard 3PS 310 Audit and Related Matters URL: https://marketplace.6clicks.com/c/3ps-310 Domain: GRC Type: regulation Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Effective: 2016-09-14 Industries: Finance Sector Tags: prudential auditing compliance finance regulation Source: https://www.legislation.gov.au/F2016L01437/latest/text Available in the 6clicks app: yes Summary: This prudential standard sets out auditing and related responsibilities for entities operating within the banking, insurance, and life insurance sectors in Australia. It is part of the regulatory framework administered by the Department of Treasury under the Banking Act, Insurance Act, and Life Insurance Act. Description: Prudential Standard 3PS 310 addresses audit and compliance requirements for financial institutions in the banking, insurance, and life insurance sectors. It outlines the responsibilities of these entities to ensure the accuracy and reliability of financial reporting and compliance with prudential requirements. Issued as a legislative instrument under key financial legislation, it forms part of Australia's broader framework to maintain the integrity and stability of its financial systems. Administered by the Department of Treasury, the standard emphasizes external auditing, reporting obligations, and associated matters relevant to these industries. --- ## Aboriginal Heritage Protection Act 1984 — Aboriginal and Torres Strait Islander Heritage Protection Act 1984 URL: https://marketplace.6clicks.com/c/aboriginal-heritage-protection-act-1984 Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Version: Compilation No. 17, 21 October 2016 Effective: 1984-11-15 Last updated: 2016-10-21 Industries: Government Tags: cultural preservation, heritage protection, indigenous rights, environment, legal, regulations Source: https://www.legislation.gov.au/Details/C2016C00937 Document: https://www.legislation.gov.au/Details/C2016C00937 Available in the 6clicks app: yes Summary: The Aboriginal and Torres Strait Islander Heritage Protection Act 1984 provides measures to preserve and protect significant Aboriginal areas and objects with cultural, historical, and spiritual importance. It includes provisions for declarations by the minister or authorized officers, penalties for violations, and procedures for legal assistance and compensation. Description: Enacted in 1984, this Act aims to uphold the rights and cultural heritage of Aboriginal and Torres Strait Islander communities in Australia. The legislation is structured into several parts, including preliminary definitions, provisions for protecting significant areas and objects, procedures for emergency declarations, discovery and disposal of Aboriginal remains, and legal processes concerning offences and penalties. The Act allows for emergency declarations to protect areas of significance and outlines processes for notifying such declarations and addressing legal claims. It binds individuals and bodies corporate, specifies the roles of authorized officers, and details penalties, legal assistance, and compensation for the acquisition of properties. The Attorney-General's Department and the Department of Climate Change, Energy, the Environment, and Water administer the Act. --- ## AML/CTF Act — Anti-Money Laundering and Counter-Terrorism Financing Act 2006 URL: https://marketplace.6clicks.com/c/anti-money-laundering-and-counter-terrorism-financing-act-2006 Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Version: Compilation No. 60, 31 March 2026 Industries: Finance Sector Tags: money laundering, terrorism financing, risk assessment, compliance, reporting, identity verification Source: https://www.legislation.gov.au/C2006A00169/latest/text Document: https://www.legislation.gov.au/C2006A00169/latest/text Available in the 6clicks app: yes Summary: This is an Australian law established to prevent money laundering and financing of terrorism. It imposes obligations on certain entities to implement anti-money laundering and counter-terrorism financing measures, including customer due diligence, reporting, and record-keeping. Description: The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act) is a comprehensive framework for addressing money laundering and terrorism financing in Australia. Administered by AUSTRAC, the Act delineates requirements for financial institutions and specific businesses, including risk assessments, customer identification (KYC), compliance reports, and measures to monitor and report suspicious transactions. The Act regulates sectors such as banking, gambling, and remittance services, introduces reporting obligations for threshold transactions and international fund transfers, and mandates the registration of remittance providers and virtual asset service providers. It also includes provisions for protecting information, external audits, and enforceable countermeasures. --- ## AML/CTF Rules — Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 URL: https://marketplace.6clicks.com/c/anti-money-laundering-and-counter-terrorism-financing-rules-2025 Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Version: Compilation No. 1, 31 March 2026 Industries: Finance Sector Tags: money laundering, terrorism financing, customer due diligence, compliance, reporting obligations Source: https://www.legislation.gov.au/F2025L01026/latest/text Document: https://www.legislation.gov.au/F2025L01026/latest/text Available in the 6clicks app: yes Summary: The Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 provide detailed obligations on reporting entities in Australia to prevent financial crimes, including money laundering and terrorism financing. Administered by the Department of Home Affairs, it supports compliance with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. Description: This regulation establishes comprehensive requirements for financial and designated service providers to detect and deter money laundering and terrorism financing activities. Key areas include customer due diligence, reporting obligations, risk management, and compliance officer requirements. Specific rules cover measures for high-risk scenarios like correspondent banking, real estate transactions, and virtual asset services. Compliance is monitored by AUSTRAC, which has the authority to impose penalties or corrective actions for non-compliance. --- ## APG 223 — Prudential Practice Guide APG 223 Residential Mortgage Lending URL: https://marketplace.6clicks.com/c/apg-223 Domain: GRC Type: guideline Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Effective: 2019-07-01 Last updated: 2019-07-05 Industries: Finance Sector Tags: residential mortgage lending, risk management, prudential regulation, financial services, guidance, buffer rates, serviceability assessments Source: https://www.apra.gov.au/consultations/prudential-practice-guide-apg-223-residential-mortgage-lending Document: https://www.apra.gov.au/sites/default/files/APG%20223%20Residential%20Mortgage%20Lending%20July%202019.pdf Available in the 6clicks app: yes Summary: APG 223 is a detailed guidance document issued by the Australian Prudential Regulation Authority (APRA) to assist authorized deposit-taking institutions (ADIs) in managing risks associated with residential mortgage lending. It provides recommendations on best practices for loan serviceability assessments and setting buffer and floor rates. Description: Prudential Practice Guide APG 223 provides practical guidance for authorized deposit-taking institutions (ADIs) on sound risk management practices related to residential mortgage lending. The guide emphasizes the importance of prudent decision-making in areas such as borrower serviceability assessments and the application of buffer and floor rates. It also includes updates to reflect changes in market conditions and regulatory requirements. APRA's revisions to APG 223 have been made over multiple rounds of industry consultations, with the final version released in July 2019. The latest revisions focus on improving the robustness of credit risk assessment to mitigate potential risks arising from economic fluctuations and unsound lending practices. --- ## APS 210 — Prudential Standard APS 210 Liquidity URL: https://marketplace.6clicks.com/c/aps-210 Domain: GRC Type: regulation Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Effective: 2018-01-01 Industries: Finance Sector Tags: prudential, liquidity risk, funding, APRA, standards Source: https://www.apra.gov.au/standards/aps-210 Available in the 6clicks app: yes Summary: APS 210 Liquidity is a prudential standard issued by APRA requiring authorised deposit-taking institutions (ADIs) to adopt prudent practices in managing liquidity risks. It mandates maintaining adequate liquidity to meet obligations under various operating scenarios, including severe stress situations. Description: APS 210 Liquidity establishes requirements for Australian ADIs to ensure the stability of funding and management of liquidity risks. Institutions must develop a risk management framework proportionate to their complexity, maintain a sufficient portfolio of liquid assets, and adopt robust funding structures. Key provisions include applying liquidity rules to Level 1 and Level 2 entities within corporate groups and offering operational requirements for securitization where applicable. The standard allows exclusions for certain assets and liabilities in regulatory measures while mandating inclusion of cash flows for securitized assets and liabilities during liquidity coverage calculations. This standard reinforces APRA’s Financial Resilience Pillar within its prudential framework. --- ## APS 220 — Prudential Standard APS 220 Credit Risk Management URL: https://marketplace.6clicks.com/c/aps-220 Domain: GRC Type: regulation Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Version: September 2020 Effective: 2006-01-01 Industries: Finance Sector Tags: credit risk, risk management, prudential standards, finance, apra, banking Source: https://www.apra.gov.au/standards/aps-220 Available in the 6clicks app: yes Summary: APS 220 sets requirements for authorised deposit-taking institutions (ADIs) to establish a comprehensive credit risk management framework. The standard includes strategies, policies, and procedures for identifying, assessing, and mitigating credit risks. Description: APS 220 Credit Risk Management is issued by the Australian Prudential Regulation Authority (APRA) under section 11AF of the Banking Act 1959. It revokes and replaces the previous 2022 version, taking effect from January 1, 2023. The standard applies to all ADIs, excluding purchased payment facility providers, and covers areas such as credit risk appetite, assessment and approval criteria, lifecycle management, problem exposure identification, and compliance with the Australian Accounting Standards. The guidance ensures institutions implement prudent risk management measures proportional to their size and complexity. Foreign ADIs are subject to specific obligations within their Australian businesses. --- ## APS 221 Large Exposures — Banking (prudential standard) determination No. 4 of 2019 URL: https://marketplace.6clicks.com/c/aps-221 Domain: GRC Type: regulation Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Version: 09 December 2019 Effective: 2019-12-09 Last updated: 2022-12-31 Industries: Finance Sector Tags: banking, prudential, risk management, exposures, legislation, finance sector Source: https://www.legislation.gov.au/F2019L01599/latest/text Document: https://www.legislation.gov.au/F2019L01599/latest/text Available in the 6clicks app: yes Summary: This is a prudential regulatory instrument issued under the Banking Act 1959 in Australia, focusing on controlling large exposures and risk concentrations within the banking sector. It includes provisions for boards, measurement, limits, and notification requirements related to large exposures. Description: Banking (prudential standard) determination No. 4 of 2019, administered by the Australian Department of the Treasury, establishes requirements under the Banking Act 1959 for managing large exposures in the banking industry. The document provides detailed guidance for boards and institutions, including methods for identifying, measuring, and setting limits on significant risk concentrations and large exposures. It outlines mandatory notification and approval procedures for any deviations from specified limits, along with adjustments and exclusions. The standard applied from December 9, 2019, until it ceased to be in force on December 31, 2022. --- ## APS 222 — Prudential Standard APS 222: Associations with Related Entities URL: https://marketplace.6clicks.com/c/aps-222 Domain: GRC Type: standard Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Version: January 2015 Effective: 2015-01-01 Industries: Finance Sector Tags: risk management, prudential standards, contagion risk, adi, step in risk, related entities, aps regulations Source: https://www.apra.gov.au/standards/aps-222-final-not-force Available in the 6clicks app: yes Summary: APS 222 is a prudential standard issued by the Australian Prudential Regulation Authority (APRA) aimed at ensuring that authorised deposit-taking institutions (ADIs) identify, monitor, and control risks related to their associations and dealings with related entities. It mandates policies and limits on exposures to mitigate contagion and step-in risks. Description: APS 222 sets out requirements for ADIs to manage the contagion risks that arise from relationships with related entities and entities creating step-in risks. It applies to all ADIs on a Level 1 basis, except purchased payment facility providers, with limited requirements for foreign ADIs. The standard mandates ADIs to have a board-approved policy, identify and control potential risks arising from associations with related entities, and maintain defined limits on exposures. Related entities include those controlled by the ADI or entities with significant influence over the ADI. APS 222 supports CPS 220. --- ## ASIC Act — Australian Securities and Investments Commission Act 2001 URL: https://marketplace.6clicks.com/c/asic-act Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Version: No. 91, 1 July 2023 Effective: 2023-07-01 Industries: Finance Sector, Government Tags: consumer protection, financial services, corporate regulation, asic, unfair contracts, compliance Source: https://www.legislation.gov.au/Details/C2023C00131 Document: https://www.legislation.gov.au/Details/C2023C00131 Available in the 6clicks app: yes Summary: This Act establishes the legal framework for the operation of the Australian Securities and Investments Commission (ASIC), which is responsible for regulating company, financial services, and consumer protection laws in Australia. It outlines ASIC's powers, functions, and responsibilities while detailing provisions for consumer protection and fair competition in financial services industries. Description: The Australian Securities and Investments Commission Act 2001 provides the statutory basis for ASIC, defining its roles to enforce laws and protect consumers in financial services. It encompasses regulations against unconscionable conduct, misleading representations, and unfair contract terms related to financial products and services. The Act details mechanisms for investigations, enforcement actions, pecuniary penalties, and remedies. It also specifies powers for inspections and hearings, the establishment of enforceable undertakings, and criminal penalties for violations. With provisions for cooperation with other regulators such as APRA, the Act serves as a cornerstone of financial services regulation in Australia, ensuring fair practices and the integrity of the financial market. --- ## BCI Act — Building and Construction Industry (Improving Productivity) Act 2016 URL: https://marketplace.6clicks.com/c/building-and-construction-industry-improving-productivity-act-2016 Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Version: No. 2, 17 February 2017 Effective: 2017-02-17 Industries: Government Tags: building industry, construction, productivity, compliance, workplace safety, industrial action Source: https://www.legislation.gov.au/Details/C2017C00042 Document: https://www.legislation.gov.au/Details/C2017C00042 Available in the 6clicks app: yes Summary: The Building and Construction Industry (Improving Productivity) Act 2016 establishes a regulatory framework aimed at improving productivity and accountability within the building and construction sector in Australia. It provides for the creation of the Australian Building and Construction Commission and outlines rules governing industrial actions, security of payments, and compliance with workplace safety regulations. Description: This Act focuses on enhancing productivity and compliance within the building and construction industry in Australia. Key provisions include the establishment of the Australian Building and Construction Commissioner to oversee industry conduct, the Federal Safety Commissioner to manage workplace health and safety accreditation, and frameworks to address unlawful industrial action and coercion. It also incorporates measures for obtaining information, enforcing compliance, and ensuring transparency through reporting obligations. Additionally, the Act extends its applicability to external territories, ensuring comprehensive coverage across Australia. --- ## CBK Law — Law No. (32) of 1968 Concerning Currency, The Central Bank of Kuwait and The Regulation of Banking URL: https://marketplace.6clicks.com/c/cbk-law Domain: GRC Type: law Issued by: Central Bank of Kuwait Jurisdiction: Kuwait Version: 2021 Last updated: 1977-10-25 Industries: Finance Sector, Government Tags: banking, currency, financial regulation, central bank, monetary policy Source: https://www.cbk.gov.kw/en/legislation-and-regulation/cbk-law Document: https://www.cbk.gov.kw/en/legislation-and-regulation/cbk-law Available in the 6clicks app: yes Summary: Law No. (32) of 1968 establishes the legal framework for the establishment and operation of the Central Bank of Kuwait (CBK) and governs currency issuance, banking regulations, and financial supervision within Kuwait. It includes amendments to address evolving economic and regulatory needs. Description: This law provides the foundation for the State of Kuwait's financial and banking systems. It outlines the regulatory authority and responsibilities of the Central Bank of Kuwait, including currency issuance, supervision of banking institutions, and regulation of financial entities like finance companies, investment companies, and e-payment providers. Key provisions were later amended, such as those introduced under Decree Law No. (130) of 1977. The law aims to maintain monetary stability and support economic development in Kuwait. The official text is only available in Arabic, with an English translation provided for reference by CBK. --- ## CCA 2010 — Competition and Consumer Act 2010 URL: https://marketplace.6clicks.com/c/cca-2010 Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Version: Compilation No. 129 Effective: 1974-10-01 Last updated: 2020-08-25 Industries: Critical infrastructure Tags: consumer protection, competition law, antitrust practices, misleading conduct, unconscionable conduct, fair trading, accc Source: https://www.legislation.gov.au/C2004A00109/2020-08-25/text Available in the 6clicks app: yes Summary: The Competition and Consumer Act 2010 is a legislative act of the Australian Parliament that governs competition law and consumer protection in Australia. It is administered by the Australian Competition & Consumer Commission (ACCC) and aims to promote fair trading and prevent anti-competitive practices, while providing protections for consumers. Description: The Competition and Consumer Act 2010, formerly known as the Trade Practices Act 1974, serves as a key framework for regulating fair competition and safeguarding consumer rights in Australia. Administered by the ACCC, the Act addresses critical issues such as restrictive trade practices, misleading and deceptive conduct, unconscionable conduct, and consumer guarantees under its Australian Consumer Law (ACL) provisions. It also establishes industry codes, regulates telecommunications, and provides mechanisms for price surveillance and dispute resolution in various industries, including access to nationally significant infrastructure like electricity grids and telecommunications networks. The Act is backed by enforcement mechanisms that allow the ACCC and individuals to pursue legal actions for contraventions. It also includes unique features such as granting exemptions via authorizations and notifications under specific conditions. --- ## COBIT 2019 — COBIT 2019 Framework URL: https://marketplace.6clicks.com/c/cobit-2019 Domain: GRC Type: framework Issued by: ISACA Version: 2019 Industries: Legal, Risk and Compliance, Complex Enterprise Tags: it governance, framework, enterprise it, risk management, it strategy, cybersecurity Source: https://www.isaca.org/resources/cobit Document: https://www.isaca.org/resources/cobit Available in the 6clicks app: yes Summary: The COBIT 2019 Framework, developed by ISACA, is a globally recognized standard for optimizing enterprise IT governance and management. It provides flexible, detailed guidance for organizations aiming to achieve effective governance over information and technology. Description: COBIT 2019 is designed to help organizations align IT governance with business goals, offering comprehensive resources such as governance and management objectives, implementation guides, and case studies. This version emphasizes flexibility, offering detailed guidance on integrating industry standards, frameworks, and regulations, including applications in areas like cybersecurity, IT risk, DevOps, and information security. COBIT 2019 supports organizations of all sizes and provides training, certifications, and practical templates for implementation. Key publications include the COBIT 2019 Governance and Management Objectives and the COBIT 2019 Implementation Guide, aimed at tailoring governance solutions to enterprise needs. --- ## COBIT 5 — COBIT 5 URL: https://marketplace.6clicks.com/c/cobit-5 Domain: GRC Type: framework Issued by: ISACA Jurisdiction: Global Version: 5 Effective: 2012-04-10 Industries: Critical infrastructure Tags: it governance, enterprise it, business value, risk management, framework, information systems Source: https://www.isaca.org/store2/product/WCB5 Document: https://www.isaca.org/store2/product/WCB5 Available in the 6clicks app: yes Summary: COBIT 5 is a comprehensive framework for the governance and management of enterprise IT, designed to maximize the value organizations derive from their information systems. It incorporates principles, practices, and tools to align IT with business strategies and goals. Description: COBIT 5 provides an end-to-end perspective on the governance of enterprise IT, ensuring that IT delivers value to the business and supports its objectives. Building on its predecessor, COBIT 4.1, this framework integrates other ISACA frameworks such as Val IT, Risk IT, and BMIS, and aligns with leading guidance and standards, including ITIL and ISO. It helps organizations increase trust in their information systems through globally recognized practices, analytical tools, and models. COBIT 5 addresses IT governance holistically, considering new challenges faced by businesses, and is available in multiple languages for global accessibility. --- ## Corporations Act 2001 — Corporations Act 2001 URL: https://marketplace.6clicks.com/c/corporations-act-2001 Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Version: 28 September 2017 Last updated: 2024-11-03 Industries: Legislation Tags: corporate governance, fiduciary duties, company law, australia, board members Source: https://www.legislation.gov.au/Details/C2017C00328 Document: https://www.legislation.gov.au/Details/C2017C00328 Available in the 6clicks app: yes Summary: The Corporations Act 2001 is Australia’s primary legislation regulating companies and other business entities. It outlines fiduciary duties for directors, including acting in good faith, exercising care and diligence, avoiding improper use of information or position, and disclosing certain interests. Description: The Corporations Act 2001 establishes a comprehensive legal framework for corporate governance in Australia. Enforced at a federal level, the Act imposes specific legal obligations on directors, secretaries, and officers of entities incorporated under this legislation. Key duties include acting in good faith for the best interests of the corporation, avoiding conflicts of interest, and adhering to standards of care and diligence. Criminal penalties and civil liabilities apply for breaches, including fines, disqualification from office, and potential compensation orders. Directors must also actively engage in corporate matters, avoid improper uses of their position or information, and disclose material personal interests related to their role. These duties align with common law obligations for board members of government entities. --- ## Corporations Regulations 2001 — Corporations Regulations 2001 URL: https://marketplace.6clicks.com/c/corporations-regulations-2001 Domain: GRC Type: regulation Issued by: Australian Government Jurisdiction: Australia Version: 01 January 2022 Effective: 2001-07-01 Last updated: 2022-01-01 Industries: Legislation Tags: corporate-governance, legislation, financial-reporting, australia, insolvency, compliance Source: https://www.legislation.gov.au/F2001B00274/2022-01-01/text Document: https://www.legislation.gov.au/F2001B00274/2022-01-01/text Available in the 6clicks app: yes Summary: The Corporations Regulations 2001 is a set of legislative rules in Australia that provide detailed regulations supporting the Corporations Act 2001. It governs key aspects of corporate governance, financial reporting, and administration within Australian companies. Description: The Corporations Regulations 2001 serves as a legislative instrument under the Corporations Act 2001 and encompasses a wide range of corporate regulatory requirements in Australia. It includes provisions on financial disclosure, corporate governance, restructuring, external administration, and liquidation processes. The regulations also specify compliance requirements for both local and foreign entities operating in Australia, particularly for lodging forms with the Australian Securities and Investments Commission (ASIC), conducting meetings, and managing corporate insolvency. These regulations are critical for maintaining corporate transparency, stakeholder protections, and regulatory compliance under Australian corporate law. --- ## CPG 235 — Prudential Practice Guide CPG 235 - Managing Data Risk URL: https://marketplace.6clicks.com/c/cpg-235 Domain: GRC Type: guideline Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Industries: Finance Sector Tags: data risk, prudential guidance, data management, risk mitigation, financial institutions Source: https://www.apra.gov.au/sites/default/files/Prudential-Practice-Guide-CPG-235-Managing-Data-Risk_1.pdf Document: https://www.apra.gov.au/sites/default/files/Prudential-Practice-Guide-CPG-235-Managing-Data-Risk_1.pdf Available in the 6clicks app: yes Summary: The Prudential Practice Guide CPG 235 provides guidance for Australian financial institutions on how to effectively manage data risk. It focuses on identifying, assessing, and mitigating risks associated with data to ensure its integrity, availability, and confidentiality. Description: The Prudential Practice Guide CPG 235, published by the Australian Prudential Regulation Authority (APRA), aims to help regulated financial institutions develop robust strategies for managing risks tied to their data assets. The guide emphasizes the importance of data management frameworks, risk assessments, and operational controls in safeguarding data integrity, availability, and confidentiality. While not a prescriptive standard, it serves as an advisory guide to align data risk management practices with prudential standards and regulatory expectations. Key themes include governance, accountability, and embedding effective controls. Institutions are encouraged to consider their size, complexity, and risk profile when implementing recommendations from this guide. --- ## CPS 220 — Prudential Standard CPS 220 Risk Management URL: https://marketplace.6clicks.com/c/cps-220 Domain: GRC Type: standard Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Last updated: 2017-07-01 Industries: Risk Management, Finance Sector Tags: risk management, governance, financial stability, board oversight, regulations Source: https://www.apra.gov.au/sites/default/files/Prudential-Standard-CPS-220-Risk-Management-%28July-2017%29.pdf Document: https://www.apra.gov.au/sites/default/files/Prudential-Standard-CPS-220-Risk-Management-%28July-2017%29.pdf Available in the 6clicks app: yes Summary: CPS 220 is a prudential standard issued by the Australian Prudential Regulation Authority (APRA) outlining risk management requirements for regulated entities. It establishes standards for institutions to identify, assess, and manage risks effectively to ensure financial stability and compliance. Description: Prudential Standard CPS 220 issued by APRA provides a comprehensive framework for regulated institutions in Australia to manage their risks. It outlines the obligations of boards and senior management in setting up a robust risk management framework and maintaining an independent risk management function. Key requirements include governance, board oversight, risk appetite settings, and periodic reviews of risk management processes. The standard aims to enhance the stability and soundness of financial entities under APRA's jurisdiction. --- ## CPS 226 — Prudential Standard CPS 226: Margining and Risk Mitigation for Non-centrally Cleared Derivatives URL: https://marketplace.6clicks.com/c/cps-226 Domain: GRC Type: standard Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Industries: Finance Sector Tags: derivatives, risk mitigation, financial institutions, margining, non-centrally cleared, Australia, APRA Source: https://www.apra.gov.au/sites/default/files/prudential_standard_cps_226_margining_and_risk_mitigation_for_non-centrally_cleared_derivatives.pdf Document: https://www.apra.gov.au/sites/default/files/prudential_standard_cps_226_margining_and_risk_mitigation_for_non-centrally_cleared_derivatives.pdf Available in the 6clicks app: yes Summary: This is an Australian standard issued by APRA outlining the requirements for margining and risk mitigation of non-centrally cleared derivatives. It ensures financial institutions operate with adequate practices to manage counterparty risk. Description: CPS 226 establishes principles for financial institutions in Australia to manage risk exposure related to non-centrally cleared derivatives. The standard requires institutions to exchange variation margin and initial margin, maintain documented policies, and implement operational processes to assess and mitigate risks. Additionally, it aligns with international frameworks promulgated by global regulatory bodies. By ensuring consistent risk mitigation practices, CPS 226 aims to reduce systemic risks arising from derivative transactions. --- ## CPS 230 — Prudential Standard CPS 230 Operational Risk Management URL: https://marketplace.6clicks.com/c/cps-230 Domain: GRC Type: standard Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Last updated: 2023-07-01 Industries: Finance Sector Tags: operational risk, risk management, APRA, governance, resilience, compliance Source: https://www.apra.gov.au/sites/default/files/2023-07/Prudential%20Standard%20CPS%20230%20Operational%20Risk%20Management%20-%20clean.pdf Document: https://www.apra.gov.au/sites/default/files/2023-07/Prudential%20Standard%20CPS%20230%20Operational%20Risk%20Management%20-%20clean.pdf Available in the 6clicks app: yes Summary: CPS 230 sets out requirements for APRA-regulated entities to effectively manage operational risks. It covers obligations on governance, risk frameworks, and risk controls to ensure resilience against operational disruptions. Description: The Prudential Standard CPS 230 enforces a structured approach to operational risk management for entities regulated by the Australian Prudential Regulation Authority (APRA). It mandates robust governance arrangements, comprehensive operational risk management frameworks, and appropriate risk controls. This standard aims to reduce the impact of operational disruptions on these entities and the broader financial system. CPS 230 incorporates expectations for incident response, business continuity, and operational resilience, alongside periodic risk assessments and reporting obligations. --- ## CPS 231 — Prudential Standard CPS 231 Outsourcing URL: https://marketplace.6clicks.com/c/cps-231 Domain: GRC Type: standard Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Effective: 2017-07-01 Last updated: 2017-07-01 Industries: Finance Sector Tags: outsourcing, risk management, prudential compliance, financial institutions, apra, contract management, business continuity Source: https://www.apra.gov.au/sites/default/files/Prudential-Standard-CPS-231-Outsourcing-%28July-2017%29.pdf Document: https://www.apra.gov.au/sites/default/files/Prudential-Standard-CPS-231-Outsourcing-%28July-2017%29.pdf Available in the 6clicks app: yes Summary: The Prudential Standard CPS 231 establishes requirements for outsourcing arrangements by financial institutions regulated by the Australian Prudential Regulation Authority (APRA). It aims to ensure that risks associated with outsourcing are effectively managed. Description: Prudential Standard CPS 231 provides a robust framework for APRA-regulated entities to manage the risks arising from outsourcing arrangements. It includes guidance on assessing service providers, ensuring sufficient contractual protections, and maintaining the ability to meet APRA's requirements. Key requirements include detailed documentation of outsourcing arrangements, monitoring of outsourced service providers, and ensuring business continuity. CPS 231 applies to material outsourcing arrangements, which are defined as those that have the potential to impact an institution's prudential obligations or business operations significantly. --- ## CPS 232 — Prudential Standard CPS 232 Business Continuity Management URL: https://marketplace.6clicks.com/c/cps-232 Domain: GRC Type: standard Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Last updated: 2017-07-01 Industries: Finance Sector Tags: business continuity, resilience, financial services, operational risk, australia Source: https://www.apra.gov.au/sites/default/files/Prudential-Standard-CPS-232-Business-Continuity-Management-%28July-2017%29.pdf Document: https://www.apra.gov.au/sites/default/files/Prudential-Standard-CPS-232-Business-Continuity-Management-%28July-2017%29.pdf Available in the 6clicks app: yes Summary: CPS 232 is an Australian Prudential Standard that outlines the requirements for regulated entities to maintain and manage effective business continuity plans. It ensures that entities are prepared to address and recover from disruptions to their operations. Description: The standard is issued by the Australian Prudential Regulation Authority (APRA) and emphasizes the need for financial institutions to establish a framework for business continuity management. This includes identifying critical business operations, assessing risks, and implementing mitigation strategies to ensure resilience during adverse events. Updated as of July 2017, it provides detailed requirements for governance, testing, and review mechanisms to maintain operational continuity. --- ## CPS 510 — Prudential Standard CPS 510 Governance URL: https://marketplace.6clicks.com/c/apra-cps-510 Domain: GRC Type: standard Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Industries: Finance Sector Tags: governance, board, risk, audit, prudential, compliance, regulation Source: https://www.apra.gov.au/sites/default/files/prudential_standard_cps_510_governance.pdf Document: https://www.apra.gov.au/sites/default/files/prudential_standard_cps_510_governance.pdf Available in the 6clicks app: yes Summary: This is a prudential standard issued by the Australian Prudential Regulation Authority (APRA) to provide requirements for governance of regulated entities. It focuses on promoting sound corporate governance practices. Description: The Prudential Standard CPS 510 Governance establishes the roles and responsibilities of boards of APRA-regulated entities in overseeing the management of prudential risks. It outlines specific governance requirements, including board composition, independence, audit committee responsibilities, and risk management oversight. The standard aims to ensure that sound governance supports the financial safety and stability of regulated entities and their stakeholders. Key elements include setting expectations for the structure and functioning of boards, the role of the board in risk culture, and the engagement with external auditors. --- ## CPS 520 — Prudential Standard CPS 520 Fit and Proper URL: https://marketplace.6clicks.com/c/cps-520 Domain: GRC Type: standard Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Last updated: 2019-07-01 Industries: Finance Sector Tags: prudential, fit and proper, responsible persons, governance, banking, insurance Source: https://www.apra.gov.au/fit-and-proper Document: https://www.apra.gov.au/sites/default/files/2020-02/PPG%20520%20Fit%20and%20Proper%20Final%20February%202020.pdf Available in the 6clicks app: yes Summary: The Prudential Standard CPS 520 sets out the requirements for assessing the fitness and propriety of responsible persons in APRA-regulated institutions, including banks, insurers, and private health insurers. It ensures that key positions are held by individuals who meet high standards of integrity and competence. Description: Prudential Standard CPS 520, issued by the Australian Prudential Regulation Authority (APRA), outlines requirements for assessing the suitability of individuals holding key responsible positions in authorised deposit-taking institutions, general insurers, life companies, and private health insurers. The standard ensures that these individuals demonstrate the requisite capabilities, integrity, fitness, and propriety for their roles. The standard applies to positions such as CEOs, directors, senior managers, Appointed Actuaries, and Appointed Auditors. It is aimed at fostering prudent management and oversight in APRA-regulated institutions. Supporting guidance (e.g., HPG 520) assists institutions in compliance and outlines prudent practices. --- ## EU 2016/1675 — Commission Delegated Regulation (EU) 2016.1675 on High Risk Third Countries URL: https://marketplace.6clicks.com/c/eu-2016-1675 Domain: GRC Type: regulation Issued by: European Commission Jurisdiction: EU Version: 14 July 2016 Effective: 2016-09-20 Last updated: 2023-06-26 Industries: Finance Sector Tags: aml, cft, high-risk countries, eu regulation, financial compliance Source: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R1675&qid=1777620648868 Document: https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R1675 Available in the 6clicks app: yes Summary: This regulation identifies high-risk third countries with strategic deficiencies in the area of anti-money laundering (AML) and countering the financing of terrorism (CFT). It supplements Directive (EU) 2015/849, providing a legal framework for such identifications. Description: Commission Delegated Regulation (EU) 2016/1675, adopted on 14 July 2016, supplements Directive (EU) 2015/849 by establishing a framework for identifying high-risk third countries with strategic deficiencies in their anti-money laundering and counter-terrorism financing regimes. The regulation includes amendments approved through subsequent updates. It aims to ensure financial systems within the EU are not misused by entities operating from jurisdictions with inadequate controls. This regulation has EEA relevance and is referenced in updates regarding specific countries added to or removed from the high-risk list over time. --- ## EU Data Act — Regulation on harmonised rules on fair access to and use of data (Data Act) URL: https://marketplace.6clicks.com/c/data-act Domain: GRC Type: regulation Issued by: European Commission Jurisdiction: EU Version: (EU) 2023/2854 Effective: 2024-01-11 Last updated: 2025-12-15 Tags: data sharing, iot, cloud, fair access, legal terms, data economy, european union Source: https://digital-strategy.ec.europa.eu/en/policies/data-act Document: https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng Available in the 6clicks app: yes Summary: The Data Act is an EU regulation that aims to establish fair rules for access to and use of data generated by connected devices. It promotes data sharing, safeguards user rights, and prevents unfair practices while supporting innovation and the data economy. Description: The Data Act sets out harmonised rules for fair access to and use of data generated by Internet-of-Things (IoT) devices. It ensures that consumers and businesses can access and transfer data while maintaining confidentiality. The regulation introduces measures for improving legal certainty in data-sharing contracts, enabling users to switch between cloud providers, and prohibits unfair contractual terms. It also grants public sector bodies access to certain private sector data in public interest cases like emergencies. The act is cross-sectoral, applying broadly to foster innovation, competition, and sustainability while aligning related legislation with its principles. It comes into force on 11 January 2024 and will be applicable from 12 September 2025. --- ## ISO 14001 — ISO 14001:2026 - Environmental management systems URL: https://marketplace.6clicks.com/c/iso-14001 Domain: GRC Type: standard Issued by: International Organization for Standardization (ISO) Version: 2026 Effective: 2026-04-15 Last updated: 2026-04-15 Industries: Critical infrastructure Tags: environmental management, sustainability, resource optimization, waste reduction, regulatory compliance Source: https://www.iso.org/standard/14001 Document: https://www.iso.org/standard/14001 Available in the 6clicks app: yes Summary: ISO 14001:2026 is the internationally recognized standard for environmental management systems (EMS). It offers a framework for organizations to improve environmental performance through methods including resource optimization, waste management, and stakeholder engagement. Description: ISO 14001:2026 provides a structured framework for organizations to design, implement, and continually improve their environmental management systems. The 2026 edition builds on the established methodology of ISO 14001 with updated guidance, a clearer structure, and alignment with modern environmental priorities. The standard emphasizes achieving better environmental performance, regulatory compliance, cost-efficiency, and stakeholder credibility. It is applicable across all industries and organization sizes, encouraging global adoption and adaptability to meet pressing environmental challenges. Organizations can certify to ISO 14001 to validate their commitment to sustainability and adherence to environmental requirements. --- ## ISO 31000 — ISO 31000:2018 Risk management — Guidelines URL: https://marketplace.6clicks.com/c/iso-31000 Domain: GRC Type: standard Issued by: International Organization for Standardization (ISO) Version: 2018 Effective: 2018-02-14 Last updated: 2023-10-05 Industries: Critical infrastructure Tags: risk management, guidelines, governance, efficiency, proactive, stakeholders Source: https://www.iso.org/standard/65694.html Available in the 6clicks app: yes Summary: ISO 31000:2018 is an international standard providing principles and guidelines for risk management across organizations. It outlines processes for identifying, analyzing, evaluating, monitoring, and communicating risks, helping entities manage uncertainty proactively. Description: ISO 31000:2018 serves as a comprehensive framework for risk management, applicable to any organization regardless of size or sector. The standard emphasizes embedding risk management into governance, strategy, and operations, fostering proactive identification and mitigation of risks. While it is not a certifiable standard, ISO 31000 provides valuable tools for benchmarking an organization's risk management practices, enhancing decision-making and stakeholder confidence. Key elements include guidance on the principles of risk management, criteria for monitoring and improvement, and frameworks for integrating risk management into organizational processes. --- ## ISO 45001 — ISO 45001:2018 - Occupational Health and Safety Management Systems — Requirements with Guidance for Use URL: https://marketplace.6clicks.com/c/iso-45001 Domain: GRC Type: standard Issued by: International Organization for Standardization (ISO) Version: 2018 Effective: 2018-03-12 Last updated: 2024-05-31 Industries: Workplace Health & Safety, Risk Management, Quality Tags: occupational health, safety management, risk management, iso standards, workplace compliance Source: https://www.iso.org/standard/63787.html Available in the 6clicks app: yes Summary: ISO 45001:2018 is an international standard that specifies requirements for an occupational health and safety (OH&S) management system. It helps organizations improve workplace safety, reduce risks, and enhance overall OH&S performance. Description: ISO 45001:2018 provides a structured framework for managing occupational health and safety risks. Key components include leadership commitment, worker participation, hazard identification, risk assessment, regulatory compliance, emergency planning, and a focus on continual improvement via the Plan-Do-Check-Act methodology. The standard enables organizations of any size or sector to systematically manage OH&S risks, meet legal obligations, and demonstrate a commitment to worker safety. It aligns with other ISO management standards, facilitating certification and integration within broader management systems. Originally replacing OHSAS 18001, ISO 45001 has become the globally recognized benchmark for OH&S systems. --- ## ISO 9001 — ISO 9001:2015 Quality Management Systems — Requirements URL: https://marketplace.6clicks.com/c/iso-9001 Domain: GRC Type: standard Issued by: International Organization for Standardization (ISO) Version: 2015 (Edition 5) Effective: 2015-09-22 Last updated: 2021-05-20 Industries: Quality, Project Management, Legal, Risk and Compliance, Risk Management Tags: quality management, process improvement, customer satisfaction, standards Source: https://www.iso.org/standard/62085.html Document: https://www.iso.org/standard/62085.html Available in the 6clicks app: yes Summary: ISO 9001:2015 is an international standard for quality management systems. It provides requirements for organizations to establish, implement, maintain, and continually improve a quality management system to enhance customer satisfaction and operational efficiency. Description: ISO 9001:2015 specifies a framework for maintaining effective quality management systems. It promotes practices such as strong customer focus, improved process efficiency, continuous improvement, and meeting both statutory and regulatory requirements. The standard is widely used across diverse industries and includes requirements for organizational context, leadership, planning, support, operational control, performance evaluation, and continuous improvement. Certified organizations benefit from enhanced customer trust, cost savings, and a competitive edge. The standard is part of the ISO 9000 family and is regularly updated to ensure relevance, with a new revision expected in 2026. Certification is optional but widely pursued for stakeholder confidence. --- ## NCCP Regulations — National Consumer Credit Protection Regulations 2010 URL: https://marketplace.6clicks.com/c/nccp-regulations Domain: GRC Type: regulation Issued by: Australian Government Jurisdiction: Australia Version: 2021-12 Effective: 2021-12-21 Industries: Finance Sector, Government Tags: credit, licensing, consumer protection, responsible lending, regulation Source: https://www.legislation.gov.au/F2010L00631/2021-12-21/text Document: https://www.legislation.gov.au/F2010L00631/2021-12-21/text Available in the 6clicks app: yes Summary: This regulation provides detailed requirements under the National Consumer Credit Protection Act 2009 to govern the licensing, responsible lending, credit contracts, and compliance monitoring for entities providing credit services in Australia. It aims to ensure transparency and protection for consumers in financial and credit transactions. Description: The National Consumer Credit Protection Regulations 2010 establish a framework to regulate credit-related activities in Australia, authorized under the National Consumer Credit Protection Act 2009. It covers licensing procedures for credit entities, exemptions from licensing, rules for responsible lending conduct, compliance obligations, enforcement mechanisms, and specific guidelines on credit contracts, including reverse mortgages and small amount credit contracts. It also includes provisions related to consumer protection such as comparison rates, disclosures, and prohibitions on conflicted remuneration. Additional rules are applied to safeguard borrowers and ensure entities meet prescribed standards, including collaboration with the Australian Financial Complaints Authority (AFCA). --- ## RG 1 — Regulatory Guide 1: Applying for and varying an AFS licence URL: https://marketplace.6clicks.com/c/rg-1 Domain: GRC Type: guideline Issued by: Australian Securities and Investments Commission (ASIC) Jurisdiction: Australia Effective: 2025-06-16 Industries: Finance Sector Tags: afs licence, licensing process, financial regulation, documentation, compliance Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-1-applying-for-and-varying-an-afs-licence/ Document: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-1-applying-for-and-varying-an-afs-licence/ Available in the 6clicks app: yes Summary: This regulatory guide provides details on the process for applying for and varying an Australian Financial Services (AFS) licence. It outlines ASIC’s approach to assessing applications and the required documentation for submission. Description: RG 1 outlines the steps and requirements for obtaining or modifying an Australian Financial Services (AFS) licence. It helps applicants understand the criteria and processes ASIC uses for assessment, as well as the type of information and documentation needed during the application process. The guide serves as an essential reference for businesses and individuals aiming to comply with financial regulatory obligations in Australia. Issued on June 16, 2025, this guide reflects ASIC’s ongoing commitment to transparent licensing processes in financial services. --- ## RG 104 — Regulatory Guide 104: AFS Licensing: Meeting the General Obligations URL: https://marketplace.6clicks.com/c/rg-104 Domain: GRC Type: guideline Issued by: Australian Securities and Investments Commission (ASIC) Jurisdiction: Australia Effective: 2022-06-23 Industries: Finance Sector Tags: afs, licensing, compliance, corporations act, australia, asic Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-104-afs-licensing-meeting-the-general-obligations/ Document: https://download.asic.gov.au/media/av3fovx5/rg104-published-23-june-2022-20260310.pdf Available in the 6clicks app: yes Summary: This regulatory guide provides information for Australian Financial Services (AFS) licensees and applicants about compliance with general obligations under section 912A(1) of the Corporations Act. It outlines what ASIC looks for during assessments of compliance. Description: Issued by ASIC, RG 104 outlines the general obligations that Australian Financial Services (AFS) licensees and applicants must comply with under section 912A(1) of the Corporations Act. This guide aims to clarify the compliance expectations and assessment criteria used by ASIC. While focusing on most general obligations, it refers to separate guides for obligations not covered within its content. It serves as a foundational resource for AFS licensees and provides references for further details. --- ## RG 105 — RG 105 AFS Licensing: Organisational Competence URL: https://marketplace.6clicks.com/c/rg-105 Domain: GRC Type: guideline Issued by: Australian Securities and Investments Commission (ASIC) Jurisdiction: Australia Effective: 2022-06-23 Industries: Finance Sector Tags: afs licensing, organisational competence, compliance, corporations act, financial services, asic Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-105-afs-licensing-organisational-competence/ Document: https://download.asic.gov.au/media/cndf2udp/rg105-published-23-june-2022-20250616.pdf Available in the 6clicks app: yes Summary: This guide outlines the requirements for Australian financial services (AFS) licensees and applicants to meet the 'organisational competence obligation' under the Corporations Act. It provides clarity on compliance expectations relating to the qualifications, experience, and capability of key individuals within the licensee's organization. Description: RG 105 is a regulatory guide issued by the Australian Securities and Investments Commission (ASIC) to aid AFS licensees and applicants in understanding and meeting the 'organisational competence obligation'. This obligation, as specified under section 912A(1) of the Corporations Act, mandates that licensees ensure their organization has the necessary competence to provide financial services efficiently, honestly, and fairly. The guide discusses factors such as the qualifications, experience, and ongoing development of responsible managers, as well as the systems and processes that support organisational competence. By adhering to this guide, licensees can ensure they meet regulatory expectations and maintain the integrity of their financial services. --- ## RG 132 — Regulatory Guide 132: Funds management: Compliance and oversight URL: https://marketplace.6clicks.com/c/rg-132 Domain: GRC Type: guideline Issued by: Australian Securities & Investments Commission (ASIC) Jurisdiction: Australia Effective: 2025-06-30 Tags: funds management, compliance, oversight, investment schemes, corporate governance, australian law Source: https://asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-132-funds-management-compliance-and-oversight/ Document: https://asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-132-funds-management-compliance-and-oversight/ Available in the 6clicks app: yes Summary: This regulatory guide outlines compliance and oversight obligations for managed investment schemes, retail and wholesale corporate collective investment vehicles, and other related entities. It helps responsible entities understand their obligations under the Corporations Act and other relevant laws. Description: RG 132 provides detailed guidance for responsible entities of registered managed investment schemes, corporate directors of retail corporate collective investment vehicles (CCIVs), and Australian passport fund operators. It also includes aspects relevant to wholesale scheme operators, IDPS operators, and MDA providers. The guide addresses oversight responsibilities involving compliance committees, compliance plan auditors, independent oversight entities, and annual implementation reviewers. It focuses on ensuring compliance with the Corporations Act and lays out expectations for legal and procedural integrity. --- ## RG 133 — RG 133 Funds Management and Custodial Services: Holding Assets URL: https://marketplace.6clicks.com/c/rg-133 Domain: GRC Type: guideline Issued by: Australian Securities and Investments Commission (ASIC) Jurisdiction: Australia Last updated: 2024-12-10 Industries: Finance Sector Tags: funds management, custodial services, afs licence, asset protection, compliance Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-133-funds-management-and-custodial-services-holding-assets/ Document: https://download.asic.gov.au/media/rg133.pdf Available in the 6clicks app: yes Summary: RG 133 outlines the Australian financial services (AFS) licence obligations for entities involved in managing and holding client assets. It sets minimum standards that apply to responsible entities of registered managed investment schemes, licensed custody providers, MDA providers, and IDPS operators. Description: This regulatory guide issued by ASIC focuses on the proper management and custodial services related to holding assets. It targets entities such as responsible entities of registered managed investment schemes, licensed providers of custodial services, Managed Discretionary Account (MDA) providers, and Investor Directed Portfolio Service (IDPS) operators. The guide explains in detail the obligations under the Australian financial services (AFS) licence regime, establishes minimum standards for handling client assets, and aims to ensure higher levels of asset protection and compliance in the financial sector. The standards include operational controls, compliance requirements, and reporting obligations. --- ## RG 166 — RG 166 AFS Licensing: Financial Requirements URL: https://marketplace.6clicks.com/c/rg-166 Domain: GRC Type: guideline Issued by: Australian Securities and Investments Commission (ASIC) Jurisdiction: Australia Last updated: 2023-09-07 Industries: Finance Sector Tags: afs licensing, financial requirements, corporations act, asic, australian regulations Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-166-afs-licensing-financial-requirements/ Document: https://download.asic.gov.au/media/refhaghu/rg166-published-7-september-2023-20260305.pdf Available in the 6clicks app: yes Summary: RG 166 provides financial requirements for holders of an Australian Financial Services (AFS) licence, which vary based on the financial products and services offered. It excludes entities regulated by the Australian Prudential Regulation Authority (APRA) that are not required to comply with specific provisions of the Corporations Act 2001. Description: This regulatory guide, issued by the Australian Securities & Investments Commission (ASIC), outlines financial requirements for entities holding an Australian Financial Services (AFS) licence. The guide addresses conditions based on the types of financial products and services provided, ensuring adequate financial capacity is maintained. It is not applicable to entities regulated by the Australian Prudential Regulation Authority (APRA) and exempt from compliance with section 912A(1)(d) of the Corporations Act 2001. The document also includes information on relevant legal instruments, such as the Deed of Subordination and the Deed of Mutual Release, with downloadable templates provided. --- ## RG 175 — RG 175 AFS licensing: Financial product advisers—Conduct and disclosure URL: https://marketplace.6clicks.com/c/rg-175 Domain: GRC Type: guideline Issued by: Australian Securities and Investments Commission (ASIC) Jurisdiction: Australia Last updated: 2024-11-21 Industries: Finance Sector Tags: financial services, corporations act, conduct, disclosure, retail clients, advisers Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-175-afs-licensing-financial-product-advisers-conduct-and-disclosure/ Document: https://download.asic.gov.au/media/iiwmzurz/rg175-published-2024.pdf Available in the 6clicks app: yes Summary: This regulatory guide outlines the conduct and disclosure obligations of financial product advisers who provide advice to retail clients in Australia. It focuses on requirements under Part 7.7 and Division 2 of Part 7.7A of the Corporations Act. Description: RG 175 is a regulatory guide issued by the Australian Securities and Investments Commission (ASIC) to assist persons providing financial product advice to retail clients. It details obligations relating to conduct and disclosure, which are governed by Part 7.7 and Division 2 of Part 7.7A of the Corporations Act. Key components include the framework for providing advice, disclosure requirements for advisers, and principles to ensure transparency and compliance. The guide serves as a reference for financial advisers and their legal representatives to meet Australian financial services licensing conditions. --- ## RG 181 — RG 181 AFS licensing: Managing conflicts of interest URL: https://marketplace.6clicks.com/c/rg-181 Domain: GRC Type: guideline Issued by: Australian Securities and Investments Commission (ASIC) Jurisdiction: Australia Last updated: 2025-12-16 Industries: Finance Sector Tags: conflicts of interest, afs licensing, corporations act, financial services, legal obligations Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-181-afs-licensing-managing-conflicts-of-interest/ Document: https://download.asic.gov.au/media/6784527/rg181-published-16-december-2025.pdf Available in the 6clicks app: yes Summary: This regulatory guide outlines the legal obligations under the Corporations Act for Australian financial services (AFS) licensees to have adequate arrangements to manage conflicts of interest. It provides specific guidance on identifying conflicts, implementing effective arrangements, and managing conflicts using appropriate tools. Description: RG 181 is a regulatory guide issued by the Australian Securities & Investments Commission (ASIC) to assist AFS licensees, their representatives, and licence applicants in understanding their legal responsibilities under the Corporations Act. It focuses on ensuring that conflicts of interest are adequately managed, offering detailed advice on identifying conflicts, what constitutes adequate arrangements, and strategies for effective conflict management. The guide aims to support compliance while promoting fair and transparent practices within the financial services industry. --- ## RG 205 — Regulatory Guide 205: Credit Licensing: General Conduct Obligations URL: https://marketplace.6clicks.com/c/rg-205 Domain: GRC Type: guideline Issued by: Australian Securities & Investments Commission (ASIC) Jurisdiction: Australia Effective: 2020-04-01 Industries: Finance Sector Tags: credit licensing, conduct obligations, compliance, asic, finance sector, regulatory guide Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-205-credit-licensing-general-conduct-obligations/ Document: https://asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-205-credit-licensing-general-conduct-obligations/ Available in the 6clicks app: yes Summary: RG 205 is a regulatory guide issued by ASIC detailing the general conduct obligations for credit licensees, license applicants, and unlicensed carried-over instrument lenders. It helps entities comply with the National Credit Act and outlines specific areas of focus during compliance assessments. Description: RG 205 provides detailed guidance to credit licensees, applicants, and unlicensed COI lenders on meeting their general conduct obligations under Section 47(1) of the National Credit Act. It explains how ASIC assesses compliance and highlights obligations such as engaging in honest and fair practices, maintaining adequate resources, and ensuring responsible lending practices. Some obligations are covered in separate regulatory guides, referenced in the document. This guide helps entities understand compliance requirements and navigate regulatory oversight more effectively. --- ## RG 206 — Regulatory Guide 206: Credit licensing: Competence and training URL: https://marketplace.6clicks.com/c/rg-206 Domain: GRC Type: guideline Issued by: Australian Securities and Investments Commission (ASIC) Jurisdiction: Australia Effective: 2020-04-01 Industries: Finance Sector Tags: credit compliance, training requirements, competence obligations, financial regulation, licensing Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-206-credit-licensing-competence-and-training/ Document: https://download.asic.gov.au/media/5815811/rg206-published-1-april-2020.pdf Available in the 6clicks app: yes Summary: Regulatory Guide 206 outlines the minimum expectations for credit licensees in demonstrating organisational competence as required by the National Credit Act. It covers compliance obligations related to qualifications, experience, training, and competence for individuals involved in credit activities. Description: RG 206 sets out the Australian Securities and Investments Commission's (ASIC) expectations regarding the organisational competence requirements under section 47(1)(f) and training obligations under section 47(1)(g) of the National Credit Act. It explains how licensees must demonstrate competence through qualifications and experience of 'fit and proper' persons conducting credit activities. Additionally, credit licensees must ensure their representatives are adequately trained and capable of carrying out the activities authorized by their licenses. The guide highlights that the compliance measures depend on the business's nature, scale, and complexity and emphasizes embedding appropriate training and recruitment systems for representatives. --- ## RG 207 — Regulatory Guide 207: Credit licensing: Financial requirements URL: https://marketplace.6clicks.com/c/rg-207 Domain: GRC Type: guideline Issued by: Australian Securities & Investments Commission (ASIC) Jurisdiction: Australia Effective: 2020-04-01 Industries: Finance Sector Tags: credit licensing, financial requirements, regulatory compliance, asic, consumer credit, apra exclusion, afsl Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-207-credit-licensing-financial-requirements/ Available in the 6clicks app: yes Summary: RG 207 outlines the minimum expectations for Australian credit licensees to comply with the financial resource requirements under the National Consumer Credit Protection Act 2009. It provides guidance on how licensees should demonstrate adequate financial resources to ASIC during license application and annual compliance certification. Description: Regulatory Guide 207 Credit licensing: Financial requirements (RG 207) is issued by ASIC to set minimum requirements for Australian credit licensees to demonstrate adequate financial resources as stipulated under s47(1)(l) of the National Consumer Credit Protection Act 2009. The guide explains expectations for both initial compliance during the credit licence application process and ongoing compliance via annual certifications. Bodies regulated by APRA, as defined in s3(2) of the Australian Prudential Regulation Authority Act 1998, are excluded from these requirements, as APRA sets independent standards for its own regulated entities. --- ## RG 209 — Regulatory Guide 209 Credit licensing: Responsible lending conduct URL: https://marketplace.6clicks.com/c/rg-209 Domain: GRC Type: guideline Issued by: Australian Securities & Investments Commission (ASIC) Jurisdiction: Australia Version: 2019 Effective: 2019-12-09 Industries: Finance Sector Tags: responsible lending, credit licensing, financial compliance, consumer protection, regulatory guide Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-209-credit-licensing-responsible-lending-conduct/ Document: https://download.asic.gov.au/media/5526900/rg209-published-9-december-2019.pdf Available in the 6clicks app: yes Summary: RG 209 is a regulatory guide issued by the Australian Securities & Investments Commission (ASIC). It outlines responsible lending obligations for credit licensees and applicants under Chapter 3 of the National Consumer Credit Protection Act 2009, providing steps to ensure compliance and reduce risks. Description: This regulatory guide specifies ASIC’s interpretation of responsible lending obligations as stipulated in the National Credit Act. It is designed to assist credit licensees and credit applicants in understanding their duties to avoid lending irresponsibly. The guide provides detailed steps for assessing and verifying a borrower’s financial situation before offering credit. It includes comparisons between the 2014 and 2019 versions, highlighting updates that reflect evolving consumer protection measures. RG 209 aims to help industry participants align with legal standards and minimize compliance risks. It also includes supplementary documents such as responses to submissions and the navigation guide. --- ## RG 210 — Regulatory Guide 210: Compensation and Insurance Arrangements for Credit Licensees URL: https://marketplace.6clicks.com/c/rg-210 Domain: GRC Type: guideline Issued by: Australian Securities and Investments Commission (ASIC) Jurisdiction: Australia Version: March 2010 Last updated: 2020-07-27 Industries: Finance Sector Tags: credit licensees, insurance, compensation, asic, regulatory requirements, professional indemnity Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-210-compensation-and-insurance-arrangements-for-credit-licensees/ Available in the 6clicks app: yes Summary: ASIC Regulatory Guide 210 outlines the compensation and insurance arrangements required for credit licensees in Australia. It primarily mandates professional indemnity insurance to ensure financial resources are available for consumer compensation claims. Description: Regulatory Guide 210 (RG 210) by the Australian Securities and Investments Commission (ASIC) sets the requirements for credit licensees to maintain adequate arrangements for consumer compensation. The primary method to comply is through professional indemnity insurance, ensuring coverage is sufficient in scope, amount, and policy conditions to meet potential claims. Alternative arrangements may be approved by ASIC if necessary. The guide aims to mitigate risks of financial inability among licensees to address compensation claims. Applications for relief under RG 210 must be submitted through the ASIC Regulatory Portal starting 27 July 2020. --- ## RG 259 — Regulatory Guide 259: Risk management systems of fund operators URL: https://marketplace.6clicks.com/c/rg-259 Domain: GRC Type: guideline Issued by: Australian Securities and Investments Commission (ASIC) Jurisdiction: Australia Effective: 2022-10-06 Industries: Finance Sector Tags: risk management, fund operators, AFS licensees, corporate governance, compliance Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-259-risk-management-systems-of-fund-operators/ Document: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-259-risk-management-systems-of-fund-operators/ Available in the 6clicks app: yes Summary: This regulatory guide provides specific guidance for Australian financial services (AFS) licensees that are responsible entities or corporate directors (fund operators) on how to comply with their obligation under s912A(1)(h) of the Corporations Act 2001 to maintain adequate risk management systems. Description: RG 259 outlines the expectations for AFS licensees, particularly fund operators, to establish and maintain effective risk management systems. It provides detailed steps and considerations to comply with section 912A(1)(h) of the Corporations Act 2001, which mandates adequate risk management systems. Issued by the Australian Securities and Investments Commission (ASIC), the guide is designed to promote consistency across the industry and ensure that operators adequately identify, assess, and mitigate risks. The guide was issued on October 6, 2022, and includes supplementary materials like a regulation impact statement. --- ## RG 270 — Regulatory Guide 270: Whistleblower Policies URL: https://marketplace.6clicks.com/c/rg-270 Domain: GRC Type: guideline Issued by: Australian Securities and Investments Commission (ASIC) Jurisdiction: Australia Effective: 2019-11-13 Industries: Finance Sector Tags: whistleblowing, corporate governance, compliance, corporations act, public companies, ASIC, legal obligations Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-270-whistleblower-policies/ Document: https://download.asic.gov.au/media/5702691/rg270-published-13-november-2019-20200727.pdf Available in the 6clicks app: yes Summary: This guide provides entities with information on establishing whistleblower policies that comply with legal obligations under the Corporations Act. It includes guidance for both entities required to have such policies and those managing whistleblowing under legal frameworks. Description: Regulatory Guide 270 (RG 270) is designed for public companies, large proprietary companies, and proprietary companies that are trustees of registrable superannuation entities. It outlines the requirements for developing a whistleblower policy that adheres to the Corporations Act, offering practical advice on implementation and ongoing maintenance. Additionally, it provides guidance for entities not formally required to adopt a whistleblower policy but obligated to manage whistleblowing under the law. The guide emphasizes legal compliance and the adoption of good practices. --- ## RG 271 — Regulatory Guide: 271 Internal Dispute Resolution URL: https://marketplace.6clicks.com/c/rg-271 Domain: GRC Type: guideline Issued by: Australian Securities and Investments Commission (ASIC) Jurisdiction: Australia Effective: 2021-09-02 Last updated: 2021-09-02 Industries: Finance Sector Tags: internal dispute resolution, complaint management, financial services, asic, compliance, dispute resolution Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-271-internal-dispute-resolution/ Document: https://download.asic.gov.au/media/5929217/rg271-published-2-september-2021.pdf Available in the 6clicks app: yes Summary: This regulatory guide outlines enforceable standards and requirements for internal dispute resolution (IDR) systems for financial firms in Australia. It specifies the obligations these firms must meet to comply with ASIC's IDR standards. Description: RG 271 establishes mandatory guidelines for Australian financial services (AFS) licensees, trustees of regulated superannuation funds, credit licensees, and other financial institutions to operate effective internal dispute resolution systems. It aims to ensure complaints are handled fairly and transparently, aligning with ASIC's oversight. The guide references both AS/NZS 10002:2014 and AS 10002:2022 standards for complaint management and is intended to work alongside RG 267, which covers the Australian Financial Complaints Authority (AFCA). Many firms subject to RG 271 are also required to report IDR data to ASIC for compliance monitoring. --- ## RG 273 — Regulatory Guide 273: Mortgage brokers: Best interests duty URL: https://marketplace.6clicks.com/c/rg-273 Domain: GRC Type: guideline Issued by: Australian Securities & Investments Commission (ASIC) Jurisdiction: Australia Version: 2020 Effective: 2020-06-24 Industries: Finance Sector Tags: mortgage brokers, consumer protection, credit regulation, best interests, compliance guidance Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-273-mortgage-brokers-best-interests-duty/ Document: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-273-mortgage-brokers-best-interests-duty/ Available in the 6clicks app: yes Summary: RG 273 is a regulatory guide issued by ASIC that provides guidance for mortgage brokers and Australian credit licensees on complying with best interests obligations outlined in Part 3-5A of the National Consumer Credit Protection Act 2009. It includes steps to minimize the risk of non-compliance. Description: Issued by the Australian Securities & Investments Commission (ASIC), RG 273 outlines the best interest duties for mortgage brokers and relevant Australian credit licensees under the National Consumer Credit Protection Act 2009. The guide explains what ASIC looks for when assessing compliance with these obligations, providing actionable steps and guidelines to ensure adherence to regulations. The document serves as a resource for understanding legal expectations and practical strategies to fulfill the best interests duty, minimizing the risk of non-compliance. This guide is part of broader efforts related to implementing consumer protection measures in the mortgage brokerage industry as recommended by the Royal Commission. --- ## RG 274 — Regulatory Guide 274: Product Design and Distribution Obligations URL: https://marketplace.6clicks.com/c/rg-274 Domain: GRC Type: guideline Issued by: Australian Securities and Investments Commission (ASIC) Jurisdiction: Australia Effective: 2024-09-10 Industries: Finance Sector Tags: financial products, compliance, design obligations, distribution obligations, corporations act, asic Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-274-product-design-and-distribution-obligations/ Document: https://asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-274-product-design-and-distribution-obligations/download-rg-274.pdf Available in the 6clicks app: yes Summary: This guide, issued by ASIC, outlines obligations for issuers and distributors of financial products under Part 7.8A of the Corporations Act. It provides ASIC's interpretation, expectations for compliance, and approach for administering these obligations. Description: RG 274 is targeted at financial product issuers and distributors who must comply with design and distribution obligations as set out in Part 7.8A of the Corporations Act. These obligations aim to ensure financial products are designed to meet the needs of consumers and are distributed appropriately. The guide explains ASIC's interpretation of these obligations, compliance expectations, and how ASIC oversees their administration. The document also includes insights into significant dealing notification requirements and responses to prior consultations on the subject. --- ## RG 78 — Regulatory Guide 78: Breach Reporting by AFS Licensees and Credit Licensees URL: https://marketplace.6clicks.com/c/rg-78 Domain: GRC Type: guideline Issued by: Australian Securities and Investments Commission (ASIC) Jurisdiction: Australia Effective: 2023-12-19 Industries: Finance Sector Tags: breach reporting, financial services, credit licensees, compliance, asic, regulatory, corporations act Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-78-breach-reporting-by-afs-licensees-and-credit-licensees/ Document: https://download.asic.gov.au/media/132456/RG78.pdf Available in the 6clicks app: yes Summary: This guide provides Australian Financial Services (AFS) licensees and credit licensees with instructions on reporting certain legal breaches to ASIC, as required under the Corporations Act 2001 and the National Consumer Credit Protection Act 2009. Description: Regulatory Guide 78 outlines obligations for AFS and credit licensees to report breaches of the law to the Australian Securities and Investments Commission (ASIC). Specifically, it refers to Division 3 of Part 7.6 under the Corporations Act 2001 and Division 5 of Part 2-2 under the National Consumer Credit Protection Act 2009. The guide clarifies circumstances under which reporting is mandatory and provides detailed regulatory procedures. It aims to enhance transparency and ensure compliance within the financial services and credit sectors. RG 78 was officially issued on December 19, 2023. --- ## RG 96 — Regulatory Guide 96: Debt Collection Guideline: For Collectors and Creditors URL: https://marketplace.6clicks.com/c/rg-96 Domain: GRC Type: guideline Issued by: Australian Securities and Investments Commission (ASIC) Jurisdiction: Australia Version: 13 April 2021 Effective: 2021-04-13 Industries: Finance Sector Tags: debt collection, consumer protection, creditors, debtors, guideline, compliance Source: https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-96-debt-collection-guideline-for-collectors-and-creditors/ Document: https://download.asic.gov.au/media/5811283/rg96-published-13-april-2021.pdf Available in the 6clicks app: yes Summary: This guideline was jointly produced by the Australian Competition and Consumer Commission (ACCC) and the Australian Securities and Investments Commission (ASIC) to outline how Commonwealth consumer protection laws apply to debt collection. It applies to creditors and external agencies involved in debt collection, and provides guidance to debtors. Description: RG 96 is a regulatory guide issued by the ACCC and ASIC to provide clarity on the application of Commonwealth consumer protection laws to debt collection practices. It highlights the responsibilities of both creditors who directly engage in debt collection and external debt collection agencies. It aims to ensure fair treatment of debtors while promoting best practices among collectors. Additionally, the guideline offers practical advice for debtors to understand their rights and responsibilities when dealing with debt collectors. The guide emphasizes transparency, fairness, and compliance with legal obligations. --- ## SIS Act — Superannuation Industry (Supervision) Act 1993 URL: https://marketplace.6clicks.com/c/superannuation-industry-supervision-act-1993 Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Version: No. 78, 1993 Last updated: 2017-03-01 Industries: Finance Sector, Government Tags: superannuation funds, trustees, compliance, prudential standards, licensing Source: https://www.legislation.gov.au/Details/C2017C00052 Document: https://www.legislation.gov.au/Details/C2017C00052 Available in the 6clicks app: yes Summary: The Superannuation Industry (Supervision) Act 1993 establishes the regulatory framework for superannuation funds in Australia. It defines compliance standards for trustees, funds, and associated entities, aiming to ensure proper administration and protection of member benefits. Description: The Superannuation Industry (Supervision) Act 1993 provides detailed requirements for the structure, operation, and regulation of superannuation funds. Administered by the Department of the Treasury, it outlines licensing conditions for trustees, establishes prudential and operating standards, and details obligations regarding accounting, auditing, and reporting. The Act includes provisions for compliance with MySuper standards, in-house asset rules, managing fund membership, and ensuring proper governance. It also empowers the Australian Prudential Regulation Authority (APRA) with the authority to monitor compliance and issue notices. Overall, the Act aims to safeguard superannuation assets and promote transparency and fairness in fund operations. --- ## SOX — Sarbanes-Oxley Act of 2002 URL: https://marketplace.6clicks.com/c/sox Domain: GRC Type: law Issued by: US Government Jurisdiction: United States Effective: 2002-07-30 Industries: Finance Sector Tags: corporate accountability, financial reporting, internal controls, audit regulations, pcaob Source: https://www.sarbanes-oxley-act.com/ Available in the 6clicks app: yes Summary: The Sarbanes-Oxley Act (SOX) is a U.S. federal law enacted in 2002 to enhance corporate accountability and financial transparency in response to major corporate scandals. It applies to publicly traded companies, mandating stricter financial reporting, internal controls, and governance standards. Description: The Sarbanes-Oxley Act of 2002 was introduced following significant corporate scandals such as Enron and WorldCom, which undermined public confidence in U.S. capital markets. The law focuses on enforcing transparency and integrity in public company financial reporting through various provisions, including enhanced responsibilities for corporate executives, independent audit committees, and stronger internal controls over financial reporting. Key sections include Section 302, requiring executive certification of financial reports, and Section 404, mandating management assessments of internal control effectiveness. The Act also established the Public Company Accounting Oversight Board (PCAOB) to regulate audit practices. SOX has become fundamental for U.S.-listed companies and indirectly influences global corporate governance. --- ## SPS 310 — Prudential Standard SPS 310 Audit and Related Matters URL: https://marketplace.6clicks.com/c/sps-310 Domain: GRC Type: standard Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Effective: 2024-06-30 Last updated: 2024-06-18 Industries: Finance Sector, Legal, Risk and Compliance Tags: audit, superannuation, financial reporting, governance, compliance Source: https://www.apra.gov.au/amendments-to-prudential-standard-sps-310-audit-and-related-matters Document: https://www.apra.gov.au/sites/default/files/2024-06/Prudential%20Standard%20SPS%20310%20Audit%20and%20Related%20Matters%20-%20clean.pdf Available in the 6clicks app: yes Summary: Prudential Standard SPS 310 establishes requirements for conducting audits and related matters for the superannuation industry in Australia. It ensures compliance with financial reporting and auditing practices in accordance with regulatory standards. Description: The Prudential Standard SPS 310 Audit and Related Matters is issued by the Australian Prudential Regulation Authority (APRA) and focuses on audit standards and practices for superannuation entities. The standard seeks to ensure consistent and high-quality auditing processes, financial reporting, and effective governance within the superannuation system. Minor and consequential amendments were made in line with changes to the Treasury Laws Amendment (2022 Measures No. 4) Act 2023. These updates align with contemporary best practices and are applicable starting 30 June 2024. Additional changes were made to related standards such as SPS 510 Governance and SPS 520 Fit and Proper, as well as the corresponding Prudential Practice Guide SPG 520. --- ## SPS 521 — Prudential Standard SPS 521 - Conflicts of Interest URL: https://marketplace.6clicks.com/c/sps-521 Domain: GRC Type: standard Issued by: Australian Prudential Regulation Authority (APRA) Jurisdiction: Australia Effective: 2012-11-23 Industries: Finance Sector Tags: superannuation, conflicts of interest, prudential standard, compliance, australia Source: https://www.legislation.gov.au/Details/F2012L02230 Document: https://www.legislation.gov.au/Details/F2012L02230 Available in the 6clicks app: yes Summary: Prudential Standard SPS 521 is a legislative instrument under the Superannuation Industry (Supervision) Act 1993. It sets requirements for superannuation entities in Australia to appropriately manage conflicts of interest to ensure compliance and trust in their operations. Description: Prudential Standard SPS 521, issued under the Superannuation Industry (Supervision) Act 1993, focuses on managing conflicts of interest within superannuation entities in Australia. The standard outlines specific obligations for responsible entities to identify, manage, and mitigate conflicts to protect member interests and maintain public confidence in the superannuation system. Released as Legislative Instrument F2012L02230 on November 23, 2012, this standard reinforces the importance of governance in the superannuation industry and is monitored by the Department of the Treasury. --- ## Age Discrimination Act 2004 URL: https://marketplace.6clicks.com/c/age-discrimination-act-2004 Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Version: Compilation No. 35, 12 October 2017 Effective: 2004-06-23 Last updated: 2017-10-12 Industries: Government Tags: age discrimination, human rights, employment, exemptions, australia Source: https://www.legislation.gov.au/C2004A01302/2017-10-12/text Available in the 6clicks app: yes Summary: The Age Discrimination Act 2004 is an Australian law that aims to eliminate age discrimination across various areas, including employment, education, and access to goods and services. It outlines unlawful discriminatory practices and establishes protections against victimization and related offenses. Description: Enacted in Australia, the Age Discrimination Act 2004 aims to prevent discrimination based on age in numerous domains like employment, partnerships, access to goods and services, and education. It delineates both direct and indirect forms of age discrimination, establishes general and specific exemptions, and provides for the appointment of an Age Discrimination Commissioner to oversee its implementation. The Act also outlines the procedures for addressing grievances through the Australian Human Rights Commission and includes provisions for positive discrimination and exemptions for certain bodies such as charities, religious organizations, and superannuation schemes. --- ## Autonomous Sanctions Act 2011 URL: https://marketplace.6clicks.com/c/autonomous-sanctions-act-2011 Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Version: Compilation No. 4, 9 April 2024 Effective: 2011-09-09 Last updated: 2014-06-30 Industries: Government, Defense Tags: sanctions, foreign policy, law enforcement, australia, penalties, regulations Source: https://www.legislation.gov.au/C2011A00038/latest/text Document: https://www.legislation.gov.au/C2011A00038/latest/text Available in the 6clicks app: yes Summary: The Autonomous Sanctions Act 2011 establishes the legal framework for imposing sanctions by the Australian Government as part of its foreign policy objectives. It includes provisions for sanction regulations, offences, and enforcement mechanisms. Description: The Autonomous Sanctions Act 2011 sets out the framework for the Australian Government's autonomous sanctions regime. It enables the government to impose targeted financial measures, travel bans, and other forms of penal actions on persons or entities, for reasons relating to Australia's foreign policy interests, including human rights, threats to international peace, and security. The Act includes provisions on the making and enforcement of regulations, penalties for breaches including contravening a sanction law or providing false information, and powers to request, retain, and use documents and information related to sanctions. It also explicitly allows regulations to have extraterritorial effects and ensures they take precedence over other laws. --- ## Criminal Code Act 1995 URL: https://marketplace.6clicks.com/c/criminal-code-act-1995 Domain: GRC Type: law Issued by: Attorney-General's Department Jurisdiction: Australia Version: No. 137, 17 February 2021 Effective: 1995-03-01 Last updated: 2021-02-17 Industries: Government Tags: criminal law, australian federal law, espionage, national security, terrorism Source: https://www.legislation.gov.au/C2004A04868/2021-02-17/text Document: https://www.legislation.gov.au/C2004A04868/2021-02-17/text Available in the 6clicks app: yes Summary: The Criminal Code Act 1995 is an Australian federal law that establishes the legal framework for addressing criminal offenses. It outlines principles of criminal responsibility, specific offenses such as terrorism and espionage, and provisions for external and corporate liabilities. Description: The Criminal Code Act 1995 provides a comprehensive structure for dealing with criminal responsibility in Australia. It includes chapters on general principles, extensions of criminal responsibility, geographical jurisdiction, and a detailed codification of offenses. Key sections address crimes such as treason, espionage, foreign interference, sabotage, terrorism, and bribery of foreign officials. It also includes specific provisions for offenses related to United Nations personnel, explosives, people smuggling, corporate criminal liability, and the security of the Commonwealth. The Act is designed to support national security while ensuring proper procedural justice through requirements such as Attorney-General consent for certain prosecutions. --- ## Disability Discrimination Act 1992 URL: https://marketplace.6clicks.com/c/disability-discrimination-act-1992 Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Version: No. 31, 1 July 2016 Last updated: 2017-10-11 Industries: Government Tags: disability rights, discrimination, legal protections, inclusive practices, human rights, australia Source: https://www.legislation.gov.au/C2004A04426/2016-07-01/text Document: https://www.legislation.gov.au/C2004A04426/2016-07-01/text Available in the 6clicks app: yes Summary: The Disability Discrimination Act 1992 is an Australian law prohibiting discrimination based on disability across various areas, including employment, education, access to services, and public spaces. It aims to promote equal opportunity and eliminate unjustifiable hardship for individuals with disabilities. Description: The Disability Discrimination Act 1992 establishes a legal framework to protect individuals with disabilities from discrimination. It covers direct and indirect discrimination, as well as discrimination relating to carers, assistants, assistance animals, and disability aids. The Act applies to employment, education, access to premises, goods and services, accommodation, and more. It includes provisions for the development of disability action plans, the Australian Human Rights Commission’s role in addressing violations, and standards and exemptions for certain activities. The Act also defines offenses and penalties related to victimization, harassment, and incitement of unlawful acts. The legislation emphasizes removing barriers and ensuring just treatment for individuals with disabilities across different sectors. --- ## Environment Protection and Biodiversity Conservation Act 1999 URL: https://marketplace.6clicks.com/c/environment-protection-and-biodiversity-conservation-act-1999 Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Version: No. 55, 16 December 2020 Effective: 1999-07-16 Last updated: 2020-12-16 Tags: environment, biodiversity, heritage, conservation, sustainability, marine Source: https://www.legislation.gov.au/C2004A00485/2020-12-16/text Document: https://www.legislation.gov.au/C2004A00485/2020-12-16/text Available in the 6clicks app: yes Summary: The Environment Protection and Biodiversity Conservation Act 1999 (EPBC Act) is Australia's key environmental legislation. It provides a legal framework to protect and manage nationally and internationally significant flora, fauna, ecological communities, and heritage places. Description: The EPBC Act establishes processes for assessing and approving actions that may have a significant impact on the environment, including World Heritage properties, Ramsar wetlands, threatened species, and communities. It also outlines requirements for environmental impact assessments, approvals for specific actions, protecting Commonwealth land as well as managing bilateral agreements with other jurisdictions like state governments. Revised in 2020 to include updates impacting environmental approvals, heritage sites, and nuclear actions, it is administered by the Department of Climate Change, Energy, the Environment and Water. The Act is integral to the conservation of Australia’s biodiversity and management of sustainable development practices. --- ## Fair Work Regulations 2009 URL: https://marketplace.6clicks.com/c/fair-work-regulations-2009 Domain: GRC Type: regulation Issued by: Department of Employment and Workplace Relations (DEWR) Jurisdiction: Australia Effective: 2009-07-01 Last updated: 2018-05-01 Industries: Government, Legal, Risk and Compliance, Workplace Health & Safety Tags: employment, workplace, labor, compliance, regulation Source: https://www.legislation.gov.au/F2009L02356/2018-05-01/text Document: https://www.legislation.gov.au/F2009L02356/2018-05-01/text Available in the 6clicks app: yes Summary: The Fair Work Regulations 2009 provide detailed legislative backing to the Fair Work Act 2009, outlining the operational rules and requirements for employment relationships, industrial agreements, and workplace standards in Australia. It includes rules on employer obligations, employee protections, and compliance mechanisms. Description: The Fair Work Regulations 2009 are part of Australia's legislative framework for workplace relations, designed to support the Fair Work Act 2009. It sets down specific provisions for employee rights, employer responsibilities, and interactions between the two under national workplace laws. The document covers topics such as the National Employment Standards, enterprise agreements, industrial action, unfair dismissal, workplace rights, and compliance mechanisms. It also prescribes the processes for handling disputes, inspections, and regulatory oversight by the Fair Work Ombudsman. The regulations have been periodically updated, reflecting amendments tied to evolving workplace policies and norms. --- ## Migration Act 1958 URL: https://marketplace.6clicks.com/c/migration-act-1958 Domain: GRC Type: law Issued by: Parliament of Australia Jurisdiction: Australia Version: Compilation No. 150, 22 March 2021 Effective: 1958-10-01 Last updated: 2021-03-22 Industries: Government Tags: immigration, visas, entry, deportation, detention, non citizens Source: https://www.legislation.gov.au/C1958A00062/2021-03-22/text Document: https://www.legislation.gov.au/C1958A00062/2021-03-22/text Available in the 6clicks app: yes Summary: The Migration Act 1958 is an Australian legislative framework governing the entry, presence, and departure of non-citizens in Australia. It includes provisions for visas, immigration status, detention, deportation, and migration-related rights and obligations. Description: The Migration Act 1958 establishes the rules for dealing with non-citizens in Australia, including processing visa applications, determining immigration status, and addressing issues like detention and deportation. Key provisions include the categorization of visas, conditions for granting visas, procedures for cancellations or revocations, and obligations of sponsors. It also contains safeguards for minors, protection visa criteria, and processes for handling unlawful non-citizens. The Act is administered by the Department of Home Affairs. --- ## National Greenhouse and Energy Reporting Act 2007 URL: https://marketplace.6clicks.com/c/national-greenhouse-and-energy-reporting-act-2007 Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Effective: 2007-07-01 Last updated: 2021-09-01 Industries: Environment, Government Tags: greenhouse gas, energy reporting, climate change, corporate compliance, australia Source: https://www.legislation.gov.au/C2007A00175/2021-09-01/text Document: https://www.legislation.gov.au/C2007A00175/2021-09-01/text Available in the 6clicks app: yes Summary: The National Greenhouse and Energy Reporting Act 2007 establishes a national framework for corporations to report their greenhouse gas emissions, energy production, and energy consumption. It aims to improve data transparency and inform government policy on climate change. Description: The National Greenhouse and Energy Reporting Act 2007 is an Australian law designed to create a unified system for the reporting of greenhouse gas emissions, energy production, and energy consumption by registered corporations. This Act requires corporations exceeding defined thresholds to register and report their data annually to the Regulator. Key components include detailed rules on operational control, auditing, reporting for large facilities, and the emissions reduction safeguard mechanism. The law also enforces compliance through provisions for civil penalties, enforceable undertakings, and audits. It supports climate policy by providing robust data on emissions and energy use, while ensuring transparency in corporate environmental impacts. --- ## Patents Act 1990 URL: https://marketplace.6clicks.com/c/patents-act-1990 Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Version: Compilation No. 41, 24 February 2017 Effective: 1990-01-01 Last updated: 2018-08-24 Industries: Government Tags: patents, intellectual property, legal framework, australia, innovation Source: https://www.legislation.gov.au/C2004A04014/2017-02-24/text Document: https://www.legislation.gov.au/C2004A04014/2017-02-24/text Available in the 6clicks app: yes Summary: The Patents Act 1990 establishes the legal framework for patent rights in Australia. It outlines the processes for applying for and granting patents, the exclusive rights conferred by patents, and provisions for examining, opposing, amending, and invalidating patents. Description: The Patents Act 1990 is an Australian legislative act that governs the registration, protection, and exploitation of patents in the country. It details procedures for patent applications, validity requirements, the terms and extensions of patents, and provisions for addressing disputes, oppositions, and infringements. It also includes special provisions for compulsory licenses, international agreements, and pharmaceutical substance patents. Key components involve the responsibilities of the Commissioner of Patents, administration of the Patent Office, and the establishment of the Register of Patents. --- ## Protection of Movable Cultural Heritage Act 1986 URL: https://marketplace.6clicks.com/c/protection-of-movable-cultural-heritage-act-1986 Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Version: Compilation No. 18, 21 October 2016 Effective: 1986-04-01 Last updated: 2023-08-21 Industries: Government Tags: cultural heritage, export control, import control, heritage protection, law, compliance Source: https://www.legislation.gov.au/C2004A03252/2016-10-21/text Document: https://www.legislation.gov.au/C2004A03252/2016-10-21/text Available in the 6clicks app: yes Summary: The Protection of Movable Cultural Heritage Act 1986 establishes a framework for safeguarding movable cultural heritage in Australia. It provides regulations concerning the export, import, administration, and enforcement related to cultural heritage objects. Description: The Protection of Movable Cultural Heritage Act 1986 governs the control and protection of Australia's cultural heritage objects that are movable, preventing unlawful export and ensuring compliance with established guidelines. The Act defines cultural heritage items, provides mechanisms to grant permits or certificates of exemption for export, establishes the National Cultural Heritage Committee with defined duties, and creates a National Cultural Heritage Account for funding related activities. It also outlines enforcement measures, including powers for inspectors, the issuance of search warrants, and procedures regarding seizure of protected objects. Furthermore, it includes provisions for international cooperation regarding the return of objects. --- ## Racial Discrimination Act 1975 URL: https://marketplace.6clicks.com/c/racial-discrimination-act-1975 Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Version: Compilation No. 17, 10 December 2015 Effective: 1975-06-11 Last updated: 2015-12-10 Industries: Government Tags: racial discrimination, rights, equality, law, human rights, employment Source: https://www.legislation.gov.au/Details/C2016C00089 Document: https://www.legislation.gov.au/Details/C2016C00089 Available in the 6clicks app: yes Summary: The Racial Discrimination Act 1975 establishes legal protections against racial discrimination in Australia, implementing the International Convention on the Elimination of All Forms of Racial Discrimination. It prohibits racial hatred and discrimination in areas including employment, housing, and public services. Description: The Racial Discrimination Act 1975 is a key piece of legislation in Australia designed to protect individuals from racial discrimination and promote equality. It makes racial discrimination unlawful in several areas such as employment, housing, goods and services, and public access. Additionally, it prohibits offensive behavior based on racial hatred and has provisions for exceptions and exemptions where applicable. The Act also provides for the appointment of a Race Discrimination Commissioner responsible for monitoring and enforcing its provisions. The legislation is administered by the Attorney-General's Department and aligns with Australia's obligations under the International Convention on the Elimination of All Forms of Racial Discrimination. --- ## Sex Discrimination Act 1984 URL: https://marketplace.6clicks.com/c/sex-discrimination-act-1984 Domain: GRC Type: law Issued by: Attorney-General's Department Jurisdiction: Australia Version: 1 January 2014 Effective: 1984-12-01 Last updated: 2014-01-01 Industries: Government Tags: gender equality, discrimination, workplace protections, sexual harassment, human rights Source: https://www.legislation.gov.au/Details/C2014C00002 Available in the 6clicks app: yes Summary: A federal law enacted by the Australian Government to eliminate discrimination on the basis of sex, gender identity, sexual orientation, marital status, pregnancy, or family responsibilities. It also addresses sexual harassment and outlines protections in employment, education, goods and services, and public programs. Description: The Sex Discrimination Act 1984 is a comprehensive law aimed at promoting gender equality and protecting against discrimination in various areas including workplace, education, accommodation, and goods and services. It provides definitions for terms such as sexual harassment, intersex status, and indirect discrimination while stipulating exemptions for certain practices such as religious freedoms and charities. The Act also establishes the role of the Sex Discrimination Commissioner and outlines functions of the Australian Human Rights Commission in handling complaints and monitoring compliance. The legislation incorporates international conventions like the Convention on the Elimination of All Forms of Discrimination Against Women to further its objectives. --- ## South Africa Electronic Communications and Transactions Act 25 of 2002 URL: https://marketplace.6clicks.com/c/south-africa-electronic-communications-and-transactions-act-25-of-2002 Domain: GRC Type: law Issued by: Government of South Africa Jurisdiction: South Africa Effective: 2002-08-30 Last updated: 2021-12-01 Tags: electronic transactions, cybersecurity, internet, e commerce, digital communications, legal framework Source: https://www.gov.za/documents/electronic-communications-and-transactions-act Document: https://www.saflii.org/za/legis/consol_act/ecata2002427/ Available in the 6clicks app: yes Summary: The Electronic Communications and Transactions Act 25 of 2002 establishes legal and policy frameworks for regulating electronic communications and transactions in South Africa. It aims to facilitate universal access to electronic services, prevent abuse of information systems, and promote the use of e-government services and small business technology adoption. Description: Enacted on August 30, 2002, the Electronic Communications and Transactions Act provides comprehensive guidelines to facilitate and regulate electronic communications and transactions within South Africa. The Act mandates the development of a national e-strategy, encourages the use of electronic transactions by small, micro, and medium enterprises (SMMEs), promotes human resource development and universal access to digital services, and seeks to protect against abuse in electronic systems. Additionally, it supports efforts to increase usage of e-government services and addresses related matters. The Act has been amended to integrate provisions from the Cybercrimes Act 19 of 2020 and the Consumer Protection Act 68 of 2008. It is pivotal for shaping South Africa’s approach to digital communication and its adoption across industries. --- ## Superannuation Guarantee (Administration) Act 1992 URL: https://marketplace.6clicks.com/c/superannuation-guarantee-administration-act-1992 Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Version: Compilation No. 67, 1 July 2017 Effective: 1992-07-01 Last updated: 2017-07-01 Tags: superannuation, compliance, employer obligations, employee benefits, australia, record keeping Source: https://www.legislation.gov.au/C2004A04402/2017-07-01/text Document: https://www.legislation.gov.au/C2004A04402/2017-07-01/text Available in the 6clicks app: yes Summary: The Superannuation Guarantee (Administration) Act 1992 is an Australian law that mandates employers to provide a prescribed level of superannuation contributions to eligible employees. It outlines rules for calculating contributions, penalties for non-compliance, and record-keeping requirements. Description: The Superannuation Guarantee (Administration) Act 1992 establishes the legal framework for compulsory employer superannuation contributions in Australia. It defines key terms such as employee, employer, and salary or wages, sets out the liability to pay superannuation guarantee charges, and provides details on the administration, collection, and recovery of these charges. The Act includes provisions for compliance with choice of fund requirements, the creation of standard choice forms, and guidelines for payments of shortfall components to employees. Employers who fail to meet the requirements listed in the Act may incur penalties, including additional superannuation charges. Administered by the Department of the Treasury, the Act applies to a wide range of employers and contains detailed instructions for assessment and reporting. --- ## Trade Marks Act 1995 URL: https://marketplace.6clicks.com/c/trade-marks-act-1995 Domain: GRC Type: law Issued by: Department of Industry, Science and Resources Jurisdiction: Australia Version: Compilation No. 38, 24 February 2019 Effective: 1995-12-15 Last updated: 2019-02-24 Industries: Government Tags: trade marks, intellectual property, registration, legal protection, infringement, administration Source: https://www.legislation.gov.au/C2004A04969/2019-02-24/text Document: https://www.legislation.gov.au/C2004A04969/2019-02-24/text Available in the 6clicks app: yes Summary: The Trade Marks Act 1995 is an Australian legislation that governs the registration, use, protection, and enforcement of trade marks within the country. It provides rules for registering trade marks, handling disputes, managing trade mark rights, and addressing infringements. Description: The Trade Marks Act 1995 outlines the legal framework for protecting trade marks in Australia. Its purpose is to ensure that trade marks can be registered and protected as a form of intellectual property. The act defines trade marks, specifies conditions for their registration, explains rights conferred by registration, and outlines the process for handling opposition, infringement, amendments, cancellation, and assignment of trade marks. It also includes provisions for special types of trade marks such as collective trade marks and certification trade marks. The law contains measures related to the importation of goods infringing Australian trade marks and sets penalties for violations such as falsification and unauthorized use of registered trade marks. The act supports administration through the Trade Marks Office and establishes guidelines for court proceedings relating to trade mark conflicts. --- ## Work Health and Safety Act 2011 URL: https://marketplace.6clicks.com/c/work-health-and-safety-act-2011 Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Version: No. 9, 1 July 2018 Effective: 2011-09-16 Last updated: 2018-07-01 Industries: Government Tags: workplace safety, regulation, health and safety, compliance, australia, law Source: https://www.legislation.gov.au/Details/C2018C00293 Document: https://www.legislation.gov.au/Details/C2018C00293 Available in the 6clicks app: yes Summary: The Work Health and Safety Act 2011 is Australian legislation that establishes a framework to ensure workplace safety and health across various industries and occupations. It defines responsibilities for employers, workers, and other parties in maintaining safe conditions and managing risks related to work-related activities. Description: The Work Health and Safety Act 2011 is a federal legal framework in Australia aimed at protecting workers from physical harm and ensuring safe workplace environments. The Act outlines the primary duty of care, sets out obligations for businesses and individuals, and describes procedures for risk management, incident notification, consultation, and participation. It also includes provisions regarding discriminatory practices, workplace entry permits, enforcement actions, and legal proceedings. The Act emphasizes collaboration and co-operation between employers and workers and introduces responsibilities for conducting risk assessments, incident reporting, and compliance with safety notices. Specific duties are imposed on employers, workers, officers, manufacturers, designers, and persons in control of workplaces, all aimed at minimizing workplace hazards and ensuring a standard of safety. --- ## Work Health and Safety Regulations 2011 URL: https://marketplace.6clicks.com/c/work-health-and-safety-regulations-2011 Domain: GRC Type: regulation Issued by: Australian Government Jurisdiction: Australia Version: No. 15, 1 July 2020 Effective: 2011-01-01 Last updated: 2020-07-01 Industries: Government Tags: workplace safety, risk management, hazardous work, compliance, australia Source: https://www.legislation.gov.au/F2011L02664/2020-07-01/text Document: https://www.legislation.gov.au/F2011L02664/2020-07-01/text Available in the 6clicks app: yes Summary: The Work Health and Safety Regulations 2011 establish detailed requirements for workplace health and safety in compliance with the Work Health and Safety Act 2011. They cover topics such as risk management, workplace conditions, hazardous materials, emergency plans, and licensing for high-risk activities. Description: The Work Health and Safety Regulations 2011 are a comprehensive legislative instrument issued by the Australian Government to ensure the safety and health of workers across various industries. Administered by the Department of Employment and Workplace Relations, the regulations provide detailed guidelines on managing risks, workplace conditions, and procedures related to hazardous work, among many other provisions. Key areas covered include risk management strategies, information and training requirements, emergency planning, management of hazardous materials, licensing for high-risk activities such as electrical and demolition work, and detailed standards for plant and workplace structures. Notable updates include the revocation of several earlier codes of practice in 2012. These regulations are designed to work alongside the Work Health and Safety Act 2011 and other related legislative acts. --- ## Workplace Relations Act 1996 URL: https://marketplace.6clicks.com/c/workplace-relations-act-1996 Domain: GRC Type: law Issued by: Australian Government Jurisdiction: Australia Effective: 2006-03-31 Last updated: 2006-12-10 Industries: Workplace Health & Safety, Legislation Tags: workplace relations, labor law, wage-setting, employment conditions, anti-discrimination Source: https://www.legislation.gov.au/Details/C2006C00104 Document: https://www.legislation.gov.au/Details/C2006C00104 Available in the 6clicks app: yes Summary: The Workplace Relations Act 1996 was an Australian federal law governing employment relations, setting frameworks for workplace agreements, wage-setting, and employee entitlements. It covered topics such as the Australian Fair Pay Commission, industrial relations, and minimum workplace standards. Description: The Workplace Relations Act 1996 provided a comprehensive legal structure for workplace relations in Australia. It established the Australian Fair Pay Commission to oversee wage-setting functions and included regulations for workplace agreements, industrial relations, and employment conditions. The Act aimed to create a balance between employers' and employees' rights while ensuring compliance with minimum workplace standards, such as wages, leave, and hours of work. It also incorporated anti-discrimination considerations and provisions for parental, personal, and annual leave. The Act outlined roles for industrial institutions like the Australian Industrial Relations Commission and the Australian Industrial Registry, emphasizing fair treatment, efficiency, and flexibility in workplace relations across Australia. --- ## 201 CMR 17.00 — Massachusetts: Standards for the protection of personal information of residents of the Commonwealth URL: https://marketplace.6clicks.com/c/massachusetts-standards-for-the-protection-of-personal-information-of-residents-of-the-commonwealth Domain: Privacy Type: regulation Issued by: Office of Consumer Affairs and Business Regulation Jurisdiction: Massachusetts, USA Effective: 2009-11-13 Tags: Massachusetts, Data Security, Personal Information Protection, Information Security, Privacy Compliance, Data Protection Source: https://www.mass.gov/regulations/201-CMR-1700-standards-for-the-protection-of-personal-information-of-residents-of-the-commonwealth Available in the 6clicks app: yes Summary: 201 CMR 17.00 is a Massachusetts information security regulation that establishes minimum requirements for protecting the personal information of Massachusetts residents through administrative, technical, and physical security safeguards. Description: 201 CMR 17.00: Standards for the Protection of Personal Information of Residents of the Commonwealth is a Massachusetts data security regulation issued by the Office of Consumer Affairs and Business Regulation (OCABR) that establishes minimum standards for safeguarding the personal information of Massachusetts residents. The regulation applies to any organization or individual that owns, licenses, stores, or processes personal information relating to Massachusetts residents, regardless of where the organization is located. It requires the implementation of a comprehensive, risk-based information security program, including administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, use, disclosure, alteration, or destruction. The regulation also includes requirements for computer system security, employee access controls, encryption, vendor oversight, and ongoing monitoring to help ensure the confidentiality and integrity of personal information. --- ## Anti-Discrimination Act 1991 (Qld) — Queensland Anti-Discrimination Act 1991 URL: https://marketplace.6clicks.com/c/queensland-anti-discrimination-act-1991 Domain: Privacy Type: law Issued by: Queensland Government Jurisdiction: Queensland, Australia Industries: Government Tags: anti discrimination, equality, queensland, law, justice, rights Source: https://www.legislation.qld.gov.au/view/html/inforce/current/act-1991-085 Document: https://www.legislation.qld.gov.au/view/html/inforce/current/act-1991-085 Available in the 6clicks app: yes Summary: The Anti-Discrimination Act 1991 is legislation enacted by the Queensland Government to promote equality of opportunity, prohibit discrimination, and encourage tolerance in the state of Queensland, Australia. It covers areas such as work, education, and the provision of goods and services. Description: The Anti-Discrimination Act 1991 is a state law aimed at eliminating discrimination and promoting equal opportunities in Queensland. It specifies protected attributes, including gender, race, disability, age, and religion, and applies to sectors such as employment, education, accommodation, and the delivery of goods and services. The Act also provides mechanisms for complaints and resolutions through the Anti-Discrimination Commission Queensland. Its provisions underscore the state’s commitment to fostering an inclusive and equitable society, ensuring that individuals are not unfairly disadvantaged based on inherent characteristics. --- ## APPs — Australian Privacy Principles URL: https://marketplace.6clicks.com/c/apps Domain: Privacy Type: law Issued by: Office of the Australian Information Commissioner (OAIC) Jurisdiction: Australia Industries: Privacy Tags: privacy, data protection, personal information, compliance, privacy act 1988 Source: https://www.oaic.gov.au/privacy/australian-privacy-principles Document: https://www.oaic.gov.au/privacy/australian-privacy-principles/read-the-australian-privacy-principles Available in the 6clicks app: yes Summary: The Australian Privacy Principles (APPs) are a set of 13 principles that form the privacy protection framework under the Privacy Act 1988. They govern how personal information is collected, used, disclosed, and managed by organizations and agencies subject to the Act. Description: The Australian Privacy Principles (APPs) are core to Australia's Privacy Act 1988 and consist of 13 principles providing standards for handling personal information. They address various areas, including collection, use, and disclosure of personal data; integrity and correction of information; and an individual's right to access their information. The principles are principles-based, enabling flexibility for implementation according to organizational needs, and technology-neutral, allowing adaptation to evolving technologies. Failure to comply with an APP constitutes an 'interference with the privacy of an individual' and can result in penalties or regulatory actions. --- ## Arkansas PIPA — Arkansas Personal Information Protection Act URL: https://marketplace.6clicks.com/c/arkansas-personal-information-protection-act Domain: Privacy Type: law Issued by: State of Arkansas Jurisdiction: Arkansas, USA Effective: 2005-04-05 Industries: Government Tags: PIPA, Data Breach Notification, Personal Information Protection, Information Security, Privacy Compliance Source: https://law.justia.com/codes/arkansas/2010/title-4/subtitle-7/chapter-110 Available in the 6clicks app: yes Summary: The Arkansas Personal Information Protection Act (PIPA) is a data privacy and security law that requires organizations to protect personal information, implement reasonable security measures, and notify affected individuals in the event of a qualifying data breach. Description: The Arkansas Personal Information Protection Act (PIPA), codified under Arkansas Code Title 4, Subtitle 7, Chapter 110, is a state privacy and data security law that establishes requirements for the protection of personal information maintained by businesses, individuals, and government entities. The Act requires organizations that own, license, or maintain personal information to implement and maintain reasonable security procedures and practices to safeguard sensitive data from unauthorized access, destruction, use, modification, or disclosure. It also establishes data breach notification obligations, requiring affected individuals to be notified when a security breach compromises personal information. In addition, the law includes provisions relating to the proper disposal of personal records and the protection of consumer information throughout its lifecycle. The Act aims to reduce the risk of identity theft, fraud, and other harms resulting from unauthorized access to personal information. --- ## Brazilian LGPD — Brazilian General Data Protection Law URL: https://marketplace.6clicks.com/c/brazilian-lgpd Domain: Privacy Type: law Issued by: Brazilian government Jurisdiction: Brazil Effective: 2020-09-18 Industries: Government Tags: data protection, personal data, gdpr alignment, brazil, anpd, privacy rights, security Source: https://www.dlapiperdataprotection.com/index.html?t=about&c=BR Available in the 6clicks app: yes Summary: The LGPD is Brazil’s first comprehensive data protection regulation, aligned with principles of the EU GDPR. It governs the processing, storage, and sharing of personal data of individuals within Brazil, including data security and breach notifications. Description: Effective since September 18, 2020, the LGPD is Brazil's cornerstone law for personal data protection. It applies to organizations processing data in Brazil or targeting Brazilian residents, regardless of where the organization is headquartered. Key provisions include the appointment of a Data Protection Officer (DPO), rules for data transfers, and penalties for noncompliance. The National Data Protection Authority (ANPD) oversees enforcement, offering autonomy in governance since 2022. Amendments in 2022 to Brazil's Federal Constitution have enshrined the protection of personal data as a fundamental right. While the LGPD is largely modeled after the GDPR, specific provisions related to small businesses, startups, and innovative companies reflect local considerations. Further regulations are expected from the ANPD for full implementation. --- ## CDR Designation 2019 — Consumer Data Right (Authorised Deposit Taking Institutions) Designation 2019 URL: https://marketplace.6clicks.com/c/cdr-designation-2019 Domain: Privacy Type: regulation Issued by: Australian Government Jurisdiction: Australia Version: 14 July 2023 Last updated: 2023-07-14 Industries: Privacy, Finance Sector Tags: consumer data, banking sector, open banking, data sharing, data access Source: https://www.legislation.gov.au/Details/F2019L01153 Document: https://www.legislation.gov.au/Details/F2019L01153 Available in the 6clicks app: yes Summary: This legislative instrument designates the banking sector in Australia as subject to the Consumer Data Right (CDR). It specifies which classes of information are included or excluded under the CDR framework. Description: The Consumer Data Right (Authorised Deposit-Taking Institutions) Designation 2019 is a legislative instrument under the Competition and Consumer Act 2010, administered by the Department of the Treasury. It formally identifies the banking sector as designated under the Consumer Data Right (CDR) framework, enabling consumers to access and control their data. The instrument specifies various classes of information, including product usage data and product details, that are covered under the CDR, while explicitly excluding certain types of information, such as credit information and materially enhanced data. This lays the groundwork for open banking initiatives in Australia and aims to promote competition and consumer empowerment. --- ## CDR Energy Sector Designation 2020 — Consumer Data Right (Energy Sector) Designation 2020 URL: https://marketplace.6clicks.com/c/cdr-energy-sector-designation-2020 Domain: Privacy Type: regulation Issued by: Australian Government Jurisdiction: Australia Version: 26 June 2020 Effective: 2020-06-29 Last updated: 2020-06-29 Industries: Environment, Critical infrastructure Tags: consumer data, energy, privacy, data sharing, australia Source: https://www.legislation.gov.au/F2020L00833/latest/text Document: https://www.legislation.gov.au/F2020L00833/latest/text Available in the 6clicks app: yes Summary: This legislative instrument designates the Australian energy sector under the Consumer Data Right (CDR) framework. It specifies the types of data, entities, and arrangements covered by CDR for energy consumers. Description: The Consumer Data Right (Energy Sector) Designation 2020 is a regulatory instrument made under the Competition and Consumer Act 2010, administered by the Department of the Treasury. It outlines provisions for the designation of Australia’s energy sector under the Consumer Data Right. The regulation specifies classes of information related to customers, electricity and natural gas transactions, retail arrangements, and defines data holders. The aim is to enhance consumer control over their data to promote competition and innovation within the energy market. Certain data categories deemed materially enhanced are excluded from this designation. --- ## Consumer Data Right — Competition and Consumer (Consumer Data Right) Rules 2021 URL: https://marketplace.6clicks.com/c/competition-and-consumer-consumer-data-right-rules-2020 Domain: Privacy Type: regulation Issued by: Department of the Treasury Jurisdiction: Australia Industries: Legislation, Privacy Tags: consumer data right, data sharing, privacy, accreditation, data security, dispute resolution Source: https://www.legislation.gov.au/F2020L00094/latest/text Document: https://www.legislation.gov.au/F2020L00094/latest/text Available in the 6clicks app: yes Summary: The Competition and Consumer (Consumer Data Right) Rules 2021 outline regulations for implementing Australia's Consumer Data Right (CDR) framework. They establish rules for data sharing, privacy safeguards, accreditation of data recipients, and dispute resolution processes. Description: The Consumer Data Right Rules 2021 provide a detailed regulatory framework to operationalize the consumer data-sharing provisions detailed under the Consumer Data Right framework in Australia. They set requirements for accredited data holders and recipients, including processes for data requests, privacy safeguards, joint account permissions, consumer consent management, and data standards development. Notably, the rules also specify obligations for data de-identification and deletion, measures for data integrity and security, and internal and external dispute resolution mechanisms. Additionally, the rules include provisions for accrediting participants and ensuring compliance with privacy obligations. --- ## CR code v2.1 — Privacy (Credit Reporting) Code 2014 (Version 2.1) URL: https://marketplace.6clicks.com/c/cr-code-v2-1 Domain: Privacy Type: regulation Issued by: Australian Government Jurisdiction: Australia Version: 2.1 Effective: 2020-02-14 Last updated: 2022-04-21 Industries: Finance Sector Tags: credit reporting, privacy act, data protection, consumer credit, compliance Source: https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/privacy-credit-reporting-code-2014-version-2.1 Available in the 6clicks app: yes Summary: The Privacy (Credit Reporting) Code 2014 (Version 2.1) provides a framework for credit reporting practices under Australia's Privacy Act. It outlines obligations for Credit Reporting Bodies (CRBs), Credit Providers (CPs), and other affected entities to ensure compliance with privacy regulations. Description: The Privacy (Credit Reporting) Code 2014 (Version 2.1), effective from February 14, 2020 to April 21, 2022, forms a crucial part of Australia's regulatory framework for credit reporting. As mandated by the Privacy Act 1988, its provisions aim to enhance privacy protection amid comprehensive credit reporting. The code defines obligations for CRBs, CPs, and information recipients regarding the handling, accuracy, and security of credit-related personal information. It complements existing requirements in the Privacy Act, including Part IIIA, and requires adherence to additional data management and notification procedures. The Information Commissioner oversees compliance and enforcement of this registered code. --- ## Cyprus - Law 125(I)2018 — Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data of 2018 URL: https://marketplace.6clicks.com/c/cyprus-law-125-i-2018 Domain: Privacy Type: law Issued by: Government of Cyprus Jurisdiction: Cyprus Effective: 2018-07-31 Last updated: 2026-10-16 Industries: Government Tags: Law 125(I)/2018, Cyprus Privacy Law, GDPR Compliance, Data Protection, Personal Data Processing, Privacy Rights Source: https://www.dataprotection.gov.cy/dataprotection/dataprotection.nsf/All/2B53605103DCE4A4C225826300362211 Available in the 6clicks app: yes Summary: Law 125(I)/2018 is Cyprus's data protection legislation that implements and supplements the GDPR, establishing requirements for personal data processing, privacy protection, regulatory oversight, and the protection of individuals' data rights. Description: The Law 125(I)/2018 on the Protection of Natural Persons with Regard to the Processing of Personal Data and the Free Movement of Such Data is Cyprus's national data protection law that supplements and implements the European Union General Data Protection Regulation (GDPR). Enacted in 2018, the law establishes the legal framework for the lawful processing of personal data, the protection of individuals' privacy rights, and the free movement of personal data within the European Union. It defines the responsibilities of data controllers and processors, provides rules for the processing of personal and sensitive data, establishes supervisory and enforcement powers for the Commissioner for Personal Data Protection, and sets national provisions in areas where the GDPR permits member-state legislation. The law aims to ensure transparent, secure, and accountable handling of personal data while safeguarding the fundamental rights and freedoms of individuals. --- ## Dubai HDPR — Dubai Health Data Protection Regulation - DHCC Regulation No. 7 of 2013 URL: https://marketplace.6clicks.com/c/dubai-health-data-protection-regulation-dhcc-regulation-no-7-of-2013 Domain: Privacy Type: law Issued by: Dubai Healthcare City Authority (DHCA) Jurisdiction: Dubai Version: 21 October 2013 Effective: 2013-10-21 Industries: Government Tags: Health Data Protection, Dubai Healthcare City, Patient Health Information, Healthcare Privacy, Data Protection, Health Information Security Source: https://www.dhcc.ae/frontend/images/docs/10-Health%20Data%20Protection%20Regulation.pdf Available in the 6clicks app: yes Summary: The Dubai Health Data Protection Regulation is a healthcare privacy regulation that governs the protection, use, disclosure, and management of patient health information within Dubai Healthcare City, ensuring the confidentiality and security of health data. Description: The Dubai Health Data Protection Regulation (DHCC Regulation No. 7 of 2013) is a health information privacy and protection regulation issued by the Dubai Healthcare City Authority (DHCA). The regulation establishes requirements for the collection, use, disclosure, storage, and protection of Patient Health Information (PHI) within Dubai Healthcare City (DHCC). It aims to safeguard the confidentiality, integrity, and security of health data while supporting effective healthcare delivery and evidence-based decision-making. The regulation applies to entities licensed within DHCC and sets out obligations for consent management, data security, access controls, data retention, breach handling, and compliance monitoring. It also provides a framework for protecting patient privacy and ensuring responsible management of health information in accordance with healthcare regulatory requirements --- ## Estonia PDPA — Estonia - Personal Data Protection Act URL: https://marketplace.6clicks.com/c/estonia-personal-data-protection-act Domain: Privacy Type: law Issued by: Government of Estonia Jurisdiction: Estonia Version: 15 January 2019 Effective: 2018-12-12 Last updated: 2019-01-23 Tags: Personal Data Protection Act, Estonia Privacy Law, GDPR Compliance, Data Protection, Privacy Rights, Personal Data Processing Source: https://www.riigiteataja.ee/en/akt/523012019001 Available in the 6clicks app: yes Summary: The Estonia Personal Data Protection Act (IKS) is Estonia's data protection law that implements and supplements the GDPR, establishing requirements for personal data processing, privacy protection, and regulatory oversight. Description: The Estonia Personal Data Protection Act (Isikuandmete kaitse seadus - IKS) is Estonia's national data protection legislation that supplements and implements the European Union General Data Protection Regulation (GDPR) and the EU Law Enforcement Directive. The Act establishes rules for the processing and protection of personal data, defines individuals' privacy rights, provides requirements for data controllers and processors, and sets out procedures for supervisory oversight and enforcement. It also includes specific provisions for areas such as journalism, scientific research, public archives, children's data, deceased persons' data, and processing by law enforcement authorities. The Act aims to safeguard the rights and freedoms of individuals while enabling the lawful and transparent use of personal data across public and private sectors. --- ## FCA BCOBS — Banking: Conduct of Business Sourcebook (BCOBS) URL: https://marketplace.6clicks.com/c/fca-bcobs Domain: Privacy Type: regulation Issued by: Financial Conduct Authority (FCA) Jurisdiction: United Kingdom Version: February 2026 Industries: Finance Sector Tags: banking, retail customers, recordkeeping, payment services, consumer protection, fca Source: https://handbook.fca.org.uk/handbook?entityId=bcobs Document: https://www.handbook.fca.org.uk/handbook/BCOBS/ Available in the 6clicks app: yes Summary: The FCA's Banking: Conduct of Business Sourcebook (BCOBS) applies to firms accepting deposits from banking customers, focusing on protecting retail customers in banking and payment services. It includes key recordkeeping requirements, such as notifications of cancellation rights. Description: The FCA's Banking: Conduct of Business Sourcebook (BCOBS) sets out requirements for firms accepting deposits. Its primary goal is the protection of retail consumers in relation to banking and payment services. It outlines specific obligations for cancellation rights notifications and provides firms with a structured approach to recordkeeping. The sourcebook ensures transparency and compliance with consumer banking practices. Detailed guidelines are present in the directive table accessible via the FCA handbook. --- ## Finland Data Protection Act — Data Protection Act (1050/2018) - Finland URL: https://marketplace.6clicks.com/c/data-protection-act-1050-2018-finland Domain: Privacy Type: law Issued by: Government of Finland Jurisdiction: Finland Version: 1050/2018 Effective: 2018-01-01 Industries: Government Tags: data protection, gdpr, personal data, privacy law, finland Source: https://tietosuoja.fi/en/legislation Document: https://tietosuoja.fi/en/legislation Available in the 6clicks app: yes Summary: The Data Protection Act (1050/2018) provides national specifications and supplements the EU GDPR in Finland. It governs the roles and powers of the data protection authority, sets age limits for services to children, and includes rules for special categories of personal data and data processing in public interest contexts. Description: The Finnish Data Protection Act (1050/2018) is designed to complement the EU General Data Protection Regulation (GDPR) while applying specific provisions tailored to Finland. Its key components include regulations on appointing and organizing the operations of the Finnish supervisory authority, setting the age limit for offering information society services to minors, and governing the processing of special categories of personal data. The Act also addresses personal data processing for journalistic, academic, artistic, or literary purposes, regulations for public interest scenarios, and provides exceptions for particular domains like working life and credit information. Additionally, it discusses the Population Register's role and ensures accountability in data protection with provisions on rectification, anonymization, and archiving. --- ## France Act no. 78-17 of 6 January 1978 — Act no. 78-17 of 6 January 1978 on Data Processing, Data Files and Individual Liberties URL: https://marketplace.6clicks.com/c/france-act-no-78-17-of-6-january-1978 Domain: Privacy Type: law Issued by: Government of France Jurisdiction: France Effective: 1978-01-06 Tags: data protection, privacy, personal data, human rights, information technology Source: https://fra.europa.eu/en/law-reference/act-ndeg78-17-6-january-1978-data-processing-data-files-and-individual-liberties Available in the 6clicks app: yes Summary: This French law governs the protection of personal data and the rights of individuals in relation to data processing. It sets principles for the use of information technology to ensure it serves citizens without violating human rights, privacy, or individual liberties. Description: The Act no. 78-17 of 6 January 1978, also known as the Data Protection Act, applies to both automatic and non-automatic processing of personal data within filing systems. It establishes that data processing must comply with principles of human dignity, protecting privacy and restricting unauthorized liberties infringements. It exempts data processing activities carried out exclusively for private purposes. This law is considered foundational for data protection in France, embodying the right to personal data protection and imposing conditions for data controllers to follow. --- ## GDPR — General Data Protection Regulation URL: https://marketplace.6clicks.com/c/gdpr Domain: Privacy Type: regulation Issued by: European Parliament and Council of the European Union Jurisdiction: EU Effective: 2018-05-25 Last updated: 2018-05-25 Tags: data protection, privacy, eu regulation, personal data, gdpr compliance, data rights, security, breach notification Source: https://gdpr-info.eu/ Document: https://gdpr-info.eu/ Available in the 6clicks app: yes Summary: The General Data Protection Regulation (GDPR) is a comprehensive data protection law enacted by the European Union to harmonize privacy regulations across member states. It governs the processing of personal data by organizations operating within the EU and those outside the EU that target EU residents. Description: The GDPR, formally known as Regulation (EU) 2016/679, establishes strict guidelines for the collection, processing, storage, and transfer of personal data. It emphasizes transparency, accountability, and the rights of data subjects, including rights to access, rectification, and erasure of data ('right to be forgotten'). Key principles include data protection by design, explicit consent for data processing, and mandatory reporting of data breaches. The regulation also introduces significant penalties for non-compliance and applies to organizations globally that process data of EU residents. The GDPR became effective on May 25, 2018, replacing Directive 95/46/EC. --- ## Ghana Data Protection Act — Ghana Data Protection Act, 2012 (Act 843) URL: https://marketplace.6clicks.com/c/ghana-data-protection-act-2012-act-843 Domain: Privacy Type: law Issued by: Government of Ghana Jurisdiction: Ghana Effective: 2012-10-16 Industries: Government Tags: Ghana Privacy Law, Data Protection, Personal Data Processing, Privacy Rights, Data Protection Commission Source: https://nca.org.gh/wp-content/uploads/2020/09/Data-Protection-Act-2012.pdf Available in the 6clicks app: yes Summary: The Data Protection Act, 2012 (Act 843) is Ghana’s data protection law that regulates the processing of personal data, establishes privacy rights for individuals, and sets requirements for organizations to protect and manage personal information responsibly. Description: The Data Protection Act, 2012 (Act 843) is Ghana’s primary data protection legislation, enacted to protect the privacy of individuals and regulate the processing of personal information. The Act establishes the Data Protection Commission (DPC) as the national supervisory authority responsible for monitoring compliance, investigating complaints, and maintaining the Data Protection Register. It sets out key data protection principles governing the collection, use, storage, disclosure, and security of personal data, and defines the rights of data subjects, including rights of access, correction, and objection to certain forms of processing. The Act also requires data controllers to register with the Commission and implement appropriate safeguards to protect personal information. By providing a comprehensive framework for responsible data handling, the legislation promotes privacy, accountability, and trust in Ghana’s digital and business environments. --- ## Greece Law 2472/1997 — Greece Law 2472/1997 on the Protection of Individuals with regard to the Processing of Personal Data URL: https://marketplace.6clicks.com/c/greece-law-2472-1997 Domain: Privacy Type: law Issued by: Government of Greece Jurisdiction: Greece Effective: 1997-04-10 Industries: Government Tags: data protection, privacy, personal data, law, eu charter Source: https://fra.europa.eu/en/law-reference/law-24721997-protection-individuals-regard-processing-personal-data# Available in the 6clicks app: yes Summary: Law 2472/1997 is a legal framework from Greece designed to safeguard individual privacy rights in relation to the processing of personal data. It aligns with principles outlined in the EU Charter of Fundamental Rights, specifically addressing data protection and privacy issues. Description: Enacted in Greece, Law 2472/1997 sets forth provisions to ensure the protection of individuals' personal data during processing activities. It establishes key obligations for entities handling personal information, including obtaining consent, maintaining transparency, and safeguarding data against unauthorized access or misuse. This law forms a foundational basis for data protection legislation within Greece and integrates principles from the EU Charter of Fundamental Rights, notably Article 8 focused on the protection of personal data. The legislation promotes alignment with broader EU data protection standards aimed at guaranteeing individual privacy and rights in the digital age. --- ## India - DPDP Act — India - Digital Personal Data Protection (DPDP) Act (Act No. 22 of 2023) URL: https://marketplace.6clicks.com/c/india-digital-personal-data-protection-act Domain: Privacy Type: law Issued by: Government of India Jurisdiction: India Version: 2023 Last updated: 2023-08-11 Industries: Government Tags: privacy, cybersecurity, India, data protection, compliance, governance, digital regulation, privacy law, data security, DPDP Act, personal data, risk management Source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf Available in the 6clicks app: yes Summary: The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) establishes India’s legal framework for processing digital personal data while balancing individuals’ privacy rights with lawful data use. The Act defines obligations for organizations handling personal data, grants rights and duties to individuals, and introduces requirements for consent, data protection, and breach accountability. It also establishes the Data Protection Board of India to oversee compliance, adjudication, and enforcement of penalties for violations. Description: The Digital Personal Data Protection Act, 2023 is India’s primary data protection legislation governing the collection, storage, use, sharing, and processing of digital personal data. The Act applies to personal data collected in digital form or offline data subsequently digitized, and seeks to protect privacy while enabling lawful processing for legitimate purposes. The Act establishes obligations for Data Fiduciaries (organizations or entities processing personal data), including obtaining valid consent, ensuring data accuracy where necessary, implementing reasonable security safeguards, deleting data when no longer required, and notifying authorities and affected individuals in the event of breaches. Additional obligations apply to entities classified as Significant Data Fiduciaries, which may be subject to stricter governance and audit requirements. Individuals (Data Principals) are granted rights relating to access to information about processing, correction and erasure of personal data, grievance redressal, and nomination rights. The Act also includes provisions for children’s data protection, government exemptions in specified circumstances, cross-border data transfer controls, and duties for individuals when exercising their rights. To enforce compliance, the Act establishes the Data Protection Board of India, empowered to investigate non-compliance, adjudicate matters, and impose significant financial penalties for violations. Overall, the legislation creates a comprehensive privacy and accountability framework intended to strengthen trust in India’s digital economy and regulate responsible use of personal data. --- ## India - DPDP Rules — India - Digital Personal Data Protection (DPDP) Rules URL: https://marketplace.6clicks.com/c/india-digital-personal-data-protection-dpdp-rules Domain: Privacy Type: regulation Issued by: Government of India Jurisdiction: India Version: 2025 Last updated: 2025-01-03 Industries: Government Tags: privacy, cybersecurity, India, data protection, compliance, governance, digital regulation, privacy law, data security, DPDP Act, personal data, risk management Source: https://www.meity.gov.in/static/uploads/2025/02/f8a8e97a91091543fe19139cac7514a1.pdf Available in the 6clicks app: yes Summary: The Digital Personal Data Protection Rules, 2025 operationalize India’s Digital Personal Data Protection Act, 2023 by establishing detailed requirements for the collection, processing, storage, and protection of digital personal data. The Rules define obligations for organizations handling personal data, including consent management, breach notifications, data retention, and protections for children and vulnerable individuals. They also establish governance mechanisms such as the Data Protection Board and provide a phased implementation timeline for compliance. Description: The Digital Personal Data Protection Rules, 2025 create the practical framework for implementing India’s data privacy regime under the DPDP Act, 2023. The Rules require organizations (“data fiduciaries”) to obtain clear and informed consent, provide transparent privacy notices, limit data use to specified purposes, implement security safeguards, and enable individuals to exercise rights over their personal data. The Rules introduce requirements for reporting personal data breaches, managing consent withdrawal, retaining and deleting data appropriately, and protecting children’s data through verifiable parental or guardian consent. They also regulate cross-border transfers of personal data and establish operational procedures for the Data Protection Board of India to oversee compliance, investigate violations, and address grievances. Implementation is phased over multiple years, allowing organizations time to adapt compliance programs, governance processes, and technical controls. Overall, the Rules aim to strengthen privacy protection, accountability, and responsible digital data use while balancing individual rights with legitimate data processing needs in India’s digital economy. --- ## Kenya DPA — Kenya Data Protection Act No. 24 OF 2019 URL: https://marketplace.6clicks.com/c/kenya-data-protection-act-no-24-of-2019 Domain: Privacy Type: law Issued by: Government of Kenya Jurisdiction: Kenya Effective: 2019-11-25 Industries: Government Tags: Kenya Privacy Law, Data Protection, Personal Data Processing, Privacy Rights, Data Protection Commissioner Source: https://www.kentrade.go.ke/wp-content/uploads/2022/09/Data-Protection-Act-1.pdf Available in the 6clicks app: yes Summary: The Data Protection Act, 2019 is Kenya’s national data protection law that regulates the processing of personal data, establishes privacy rights for individuals, and sets obligations for organizations to protect personal information through secure and lawful data handling practices. Description: The Data Protection Act, 2019 (Kenya) is Kenya’s primary data protection legislation, enacted to protect individuals' privacy rights and regulate the processing of personal data. The Act establishes the Office of the Data Protection Commissioner (ODPC) as the national supervisory authority responsible for overseeing compliance, investigating complaints, and enforcing data protection requirements. It sets out the rights of data subjects, the obligations of data controllers and processors, principles for lawful data processing, requirements for breach notification, protections for sensitive personal data, and conditions for cross-border data transfers. The Act also promotes accountability, transparency, and security in the handling of personal information, ensuring that personal data is processed fairly and in accordance with established privacy standards. --- ## Korea PIPA — Korea Personal Information Protection Act URL: https://marketplace.6clicks.com/c/korea-personal-information-protection-act Domain: Privacy Type: law Issued by: South Korean Government Jurisdiction: South Korea Effective: 2011-09-30 Industries: Government Tags: privacy, data protection, personal information, south korea, legal framework Source: https://elaw.klri.re.kr/eng_service/lawView.do?hseq=53044&lang=ENG Available in the 6clicks app: yes Summary: The Personal Information Protection Act establishes legal principles and requirements for protecting personal information within South Korea. It defines the rights of individuals regarding their data and sets obligations for organizations handling personal information. Description: The Personal Information Protection Act (PIPA) is South Korea's comprehensive data protection legislation. It outlines the legal framework for the collection, use, storage, and processing of personal information, ensuring privacy rights are protected. The law specifies individual rights, including the right to access, rectify, and delete personal data, and mandates organizations to implement security measures to prevent data breaches. PIPA also includes provisions for penalties and enforcement by regulatory authorities. It serves as a cornerstone of privacy regulation in South Korea, reflecting a strong commitment to data protection and privacy. --- ## Law No.59 — Vietnam - Law on Protection of Consumers' Rights URL: https://marketplace.6clicks.com/c/vietnam-law-on-protection-of-consumers-rights Domain: Privacy Type: law Issued by: Government of Vietnam Jurisdiction: Vietnam Version: Law No.59/2010/QH12 Effective: 2010-11-17 Industries: Government Tags: Consumer Rights, Consumer Information Protection, Privacy Protection, Consumer Data, Consumer Protection Source: https://aseanconsumer.org/file/pdf_file/Vietnam%20Legislation%20-%20Law%20on%20Protection%20of%20Consumer%20(english).pdf Available in the 6clicks app: yes Summary: The Vietnam Law on Protection of Consumers' Rights is a consumer protection framework that establishes consumer rights, business obligations, consumer information protection requirements, and mechanisms for resolving disputes between consumers and traders. Description: The Vietnam Law on Protection of Consumers' Rights is a consumer protection law that establishes the rights and obligations of consumers, the responsibilities of traders, and the mechanisms for consumer protection and dispute resolution in Vietnam. The law provides a comprehensive framework governing consumer transactions, product and service safety, consumer information, and unfair business practices. It requires businesses to protect consumers' legitimate interests, provide accurate and transparent information, safeguard consumer information, and address complaints and disputes fairly. The law also defines the responsibilities of government agencies and social organizations in supporting consumer protection efforts. In its updated form, the legislation places stronger emphasis on the protection of consumer information and personal data, e-commerce transactions, vulnerable consumers, and the accountability of businesses operating in digital environments. --- ## LGOIMA — Local Government Official Information and Meetings Act 1987 - New Zealand URL: https://marketplace.6clicks.com/c/lgoima Domain: Privacy Type: law Issued by: New Zealand Government Jurisdiction: New Zealand Version: 23 December 2023 Effective: 1988-03-01 Last updated: 2024-03-05 Industries: Government Tags: freedom of information, local government, transparency, meeting standards, public access, new zealand, privacy Source: https://www.legislation.govt.nz/act/public/1987/0174/latest/whole.html#DLM123045 Document: https://www.legislation.govt.nz/act/public/1987/0174/latest/DLM122242.html Available in the 6clicks app: yes Summary: The Local Government Official Information and Meetings Act 1987 (LGOIMA) is a New Zealand law that provides public access to information held by local authorities and council-controlled organizations. It also sets transparency standards for local government meetings, ensuring public notification and accessibility. Description: The Local Government Official Information and Meetings Act 1987 establishes the framework for public access to information held by New Zealand's local authorities and council-controlled entities. Inspired by the Official Information Act 1982 (OIA), it allows all persons—not just citizens or residents—to request information, with protections for good faith decisions to release information. The Act mandates that local government meetings be publicly notified, open to the public, and that agendas, reports, and minutes be accessible. Exemptions to public accessibility require resolutions stating specific reasons. The Act also provides legal protections, such as privilege against defamation for meeting records. A review conducted by the New Zealand Law Commission in 2012 recommended its integration into a broader freedom of information law, a recommendation that has yet to be fully enacted. In 2022, new legislation was introduced to include national security grounds in withholding information under this Act. --- ## Maine Notice of Risk to Personal Data — Title 10, Chapter 210-B: Notice of Risk to Personal Data URL: https://marketplace.6clicks.com/c/title-10-chapter-210-b-notice-of-risk-to-personal-data Domain: Privacy Type: law Issued by: State of Maine Jurisdiction: Maine, USA Effective: 2006-01-01 Last updated: 2025-10-20 Tags: data protection, personal information, security breach, enforcement, identity theft Source: https://www.mainelegislature.org/LEGIS/STATUTES/10/title10ch210-Bsec0.html Available in the 6clicks app: yes Summary: Maine's Title 10, Chapter 210-B establishes regulations around personal data protection and security breach notifications. It includes provisions on prohibited use of personal data, mandatory breach notification, enforcement mechanisms, and rules for reporting identity theft. Description: Title 10, Chapter 210-B, enacted by the Maine Legislature, outlines several key provisions aimed at protecting personal data. The chapter prohibits the unauthorized release or use of personal information, mandates reporting requirements in the event of a security breach, and defines penalties for non-compliance. It also includes rules for education and compliance, as well as mandatory reporting mechanisms for identity theft along with potential investigations. These measures are designed to enhance accountability in data management practices. The statute includes specific definitions, details on enforcement, and outlines procedures for affected parties to report incidents. The rules help ensure organizations operating in Maine adhere to data protection standards. --- ## Mauritius DPA — Mauritius Data Protection Act 2017 URL: https://marketplace.6clicks.com/c/mauritius-dpa Domain: Privacy Type: law Issued by: Government of Mauritius Jurisdiction: Mauritius Effective: 2018-01-15 Tags: privacy, data protection, personal information, mauritius, regulation, rights Source: https://dataprotection.govmu.org/Pages/The%20Law/Data-Protection-Act-2017.aspx Document: https://dataprotection.govmu.org/Pages/The%20Law/Data-Protection-Act-2017.aspx Available in the 6clicks app: yes Summary: The Data Protection Act 2017 establishes legal protections for privacy rights in Mauritius, regulating the collection, processing, storage, and use of personal information. It aims to safeguard privacy amid technical advancements while balancing the needs of government, businesses, and individuals. Description: The Data Protection Act 2017 is legislation enacted in Mauritius, focused on ensuring the privacy rights of individuals are protected in light of advancements in data capture, transmission, storage, and processing technologies. It mandates compliance with data protection principles for organizations holding personal data, defining roles for data controllers and data subjects. The Act came into force on January 15, 2018, and seeks to balance privacy concerns with the demands of public security, administration efficiency, and economic development. It underlines transparency and individual rights around the use of personal information. --- ## NCCP Act 2009 — National Consumer Credit Protection Act 2009 URL: https://marketplace.6clicks.com/c/national-consumer-credit-protection-act-2009 Domain: Privacy Type: law Issued by: Australian Government Jurisdiction: Australia Version: No. 134 Effective: 2009-07-01 Last updated: 2022-07-01 Industries: Finance Sector, Government Tags: consumer credit, finance, regulations, compliance, licensing, responsible lending, consumer protection Source: https://www.legislation.gov.au/C2009A00134/2022-07-01/text Document: https://www.legislation.gov.au/C2009A00134/2022-07-01/text Available in the 6clicks app: yes Summary: The National Consumer Credit Protection Act 2009 is an Australian law that regulates the provision of consumer credit and financial services in the country. It outlines licensing requirements for entities engaged in credit activities and includes protections for consumers against unsuitable credit agreements. Description: This Act establishes a framework for consumer credit regulation across Australia, requiring individuals and entities that provide credit services to be licensed and comply with responsible lending obligations. It includes provisions for licensee conduct, credit reporting, consumer notification responsibilities, and penalties for non-compliance. The Act also introduces key measures to prevent consumers from being offered unsuitable credit contracts. The legislation is administered by the Australian Securities and Investments Commission (ASIC), which oversees licensing, compliance, and enforcement activities. The Act ensures the uniform application of credit regulations across the states and territories while harmonizing Commonwealth legislation with local laws. --- ## Netherlands WBP — Netherlands Personal Data Protection Act URL: https://marketplace.6clicks.com/c/netherlands-personal-data-protection-act Domain: Privacy Type: law Issued by: Government of Netherlands Jurisdiction: Netherlands Effective: 2001-01-01 Last updated: 2018-05-25 Industries: Government Tags: WBP, Netherlands Privacy Law, Data Protection, Personal Data Processing, Privacy Rights Available in the 6clicks app: yes Summary: The Personal Data Protection Act (WBP) was the Netherlands' data protection law that governed the processing of personal data and established privacy rights, data protection obligations, and regulatory oversight for organizations handling personal information. Description: The Personal Data Protection Act (Wet bescherming persoonsgegevens - WBP) was the Netherlands' primary data protection law, enacted to implement the European Union Data Protection Directive 95/46/EC and establish a legal framework for the protection of personal data. The Act regulated the collection, processing, use, storage, and disclosure of personal information by public and private organizations, while safeguarding the privacy rights of individuals. It defined the responsibilities of data controllers and processors, established requirements for lawful data processing, and provided individuals with rights related to access, correction, and protection of their personal data. The WBP formed the foundation of Dutch privacy regulation and was overseen by the Dutch Data Protection Authority. --- ## Nevada Chapter 603A — Security and Privacy of Personal Information URL: https://marketplace.6clicks.com/c/security-and-privacy-of-personal-information Domain: Privacy Type: regulation Issued by: State of Nevada Jurisdiction: Nevada, USA Industries: Government Tags: Nevada Chapter 603A, Data Privacy Law, Personal Information Protection, Data Breach Notification, Information Security, Privacy Compliance Source: https://www.leg.state.nv.us/nrs/nrs-603a.html Available in the 6clicks app: yes Summary: Nevada Chapter 603A - Security and Privacy of Personal Information is a Nevada privacy and data security law that requires organizations to safeguard personal information, notify individuals of certain data breaches, and comply with consumer privacy requirements relating to the collection, use, and protection of personal data. Description: Nevada Chapter 603A - Security and Privacy of Personal Information is a Nevada state law that establishes requirements for the protection of personal information maintained by businesses, data collectors, and other organizations. The law requires entities that collect or maintain personal information to implement and maintain reasonable security measures to protect data from unauthorized access, acquisition, destruction, use, modification, or disclosure. Chapter 603A also includes provisions for the secure disposal of records, data breach notification obligations, encryption requirements for certain payment card data, consumer privacy notices for information collected online, and consumer rights regarding the sale of covered information. In addition, the chapter contains provisions governing consumer health data and grants enforcement authority to the Nevada Attorney General. The law is designed to promote data security, privacy protection, and responsible handling of personal information by organizations operating in or serving Nevada residents. --- ## NIST Privacy Framework v 1.0 — NIST Privacy Framework: A Tool for Improving Privacy Through Enterprise Risk Management URL: https://marketplace.6clicks.com/c/nist-privacy-framework-a-tool-for-improving-privacy-through-enterprise-risk-management Domain: Privacy Type: framework Issued by: National Institute of Standards and Technology (NIST) Jurisdiction: Global Version: Version 1.0 Effective: 2020-01-16 Industries: Critical infrastructure Tags: NIST, Privacy Risk Management, Enterprise Risk Management, Privacy Governance, Data Privacy, NIST Framework Source: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.01162020.pdf Available in the 6clicks app: yes Summary: The NIST Privacy Framework Version 1.0 is a voluntary framework that helps organizations integrate privacy risk management into enterprise risk management by providing a structured approach for managing privacy risks, protecting personal data, and improving privacy governance. Description: The NIST Privacy Framework: A Tool for Improving Privacy Through Enterprise Risk Management, Version 1.0 is a voluntary privacy risk management framework developed by the National Institute of Standards and Technology (NIST) to help organizations identify, assess, manage, and communicate privacy risks arising from the processing of personal data. Published in January 2020, the framework provides a flexible and scalable approach to integrating privacy into enterprise risk management and organizational decision-making. It is structured around three components: the Core, which outlines privacy protection activities and outcomes; Profiles, which help organizations align privacy activities with business objectives and risk tolerance; and Implementation Tiers, which support the assessment of privacy risk management maturity. Designed to be used alongside the NIST Cybersecurity Framework, Version 1.0 helps organizations strengthen privacy governance, support regulatory compliance efforts, build customer trust, and manage the privacy impacts of products, services, and data processing activities. --- ## NIST SP 800-53 Rev. 5.2 — Security and Privacy Controls for Information Systems and Organizations URL: https://marketplace.6clicks.com/c/nist-sp-800-53-rev-5 Domain: Privacy Type: control set Issued by: NIST (National Institute of Standards and Technology) Jurisdiction: United States Version: 5.2.0 Effective: 2020-12-10 Last updated: 2025-08-27 Tags: security controls, privacy controls, risk management, fisma, cybersecurity, confidentiality, integrity, availability Source: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final Document: https://doi.org/10.6028/NIST.SP.800-53r5 Available in the 6clicks app: yes Summary: NIST Special Publication 800-53 Rev. 5 provides a comprehensive catalog of security and privacy controls designed to safeguard organizational operations, assets, and individuals from a broad spectrum of risks including cyberattacks, human mistakes, and natural disasters. It is widely used for implementing security measures as part of risk management frameworks. Description: NIST SP 800-53 Rev. 5 delivers a consolidated and flexible set of security and privacy controls aimed at protecting information systems and organizations against threats such as hostile attacks, structural failures, and foreign intelligence activities. This publication is a crucial resource for federal agencies and other organizations that need to comply with various security requirements derived from laws, regulations, and policies. Notable updates in Rev. 5 include integration and expansion of privacy controls, increased emphasis on trustworthiness and assurance, and mappings to other frameworks like the NIST Cybersecurity Framework and ISO/IEC 27001:2022. It targets both functionality and confidence in security and privacy capabilities to ensure trustworthy systems. --- ## Pakistan EDPA 2005 — Pakistan The Electronic Data Protection Act, 2005 URL: https://marketplace.6clicks.com/c/pakistan-edpa-2005 Domain: Privacy Type: law Issued by: Government of Pakistan Jurisdiction: Pakistan Effective: 2005-01-01 Last updated: 2014-02-19 Industries: Government Tags: electronic data, privacy, data security, pakistan, data protection, sensitive data Source: http://media.mofo.com/docs/mofoprivacy/PAKISTAN%20Draft%20Law%202nd%20Revision%20.pdf Available in the 6clicks app: yes Summary: The Electronic Data Protection Act, 2005 is a law enacted in Pakistan to address the processing and protection of electronic data. It aims to ensure the privacy, security, and rights of data subjects, with provisions for data processing, security measures, and penalties for violations. Description: The Electronic Data Protection Act, 2005 provides comprehensive guidelines for the processing of electronic data within Pakistan and addresses issues related to privacy, security, and personal identity. It applies not only to local data but also to foreign data processed in Pakistan. The Act defines key roles and responsibilities, including those of data controllers, data processors, and data operators. It mandates transparent data collection, strict security measures to prevent unauthorized access, and ensures the rights of data subjects. Specific provisions allow exemptions for government activities, regulate the transfer of local data abroad, and establish penalties for unlawful data processing, dissemination, or disclosure. It also empowers the Sessions Judge to handle complaints and enforce compliance. Sensitive data is addressed under heightened security requirements. --- ## PIPEDA — Personal Information Protection and Electronic Documents Act URL: https://marketplace.6clicks.com/c/pipeda Domain: Privacy Type: law Issued by: Government of Canada Jurisdiction: Canada Effective: 2001-01-01 Last updated: 2025-03-04 Industries: Privacy, Legal, Risk and Compliance Tags: privacy, personal-information, canada, electronic-commerce, data-protection, law Source: https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html Document: https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html Available in the 6clicks app: yes Summary: The Personal Information Protection and Electronic Documents Act (PIPEDA) is a Canadian federal law that sets rules for the collection, use, and disclosure of personal information in the course of commercial activities. It aims to balance individuals' privacy rights with industry needs for personal data use. Description: PIPEDA was enacted in 2000 to promote privacy and support electronic commerce in Canada. It applies to private-sector organizations across Canada that handle personal information in the course of commercial activities, with some exemptions for organizations operating within provinces with comparable privacy laws. The law establishes core privacy principles based on a National Standard of Canada for protecting personal information. Key areas include obligations for valid consent, breach notification requirements, and accountability through audits and compliance agreements. The law also sets specific provisions for electronic documents and amendments to other federal acts. PIPEDA is enforced by the Privacy Commissioner of Canada, who has investigative and reporting powers. --- ## POPIA — Protection of Personal Information Act URL: https://marketplace.6clicks.com/c/popia Domain: Privacy Type: law Issued by: Government of South Africa Jurisdiction: South Africa Effective: 2020-07-01 Tags: personal data, data protection, information regulator, consent, lawful processing, security, rights Source: https://popia.co.za/ Available in the 6clicks app: yes Summary: The Protection of Personal Information Act (POPIA) is South African legislation that governs the lawful processing of personal information. It establishes principles and rights for data subjects, conditions for processing, obligations for responsible parties, and enforcement mechanisms. Description: POPIA, enacted by the South African Parliament, aims to protect personal data by setting conditions for its lawful processing, including accountability, security safeguards, openness, and data subject participation. It also addresses special categories of personal data, processing of children's data, and transborder information flows. The Act establishes an Information Regulator with supervisory and enforcement powers and outlines rights for individuals, including those related to access, correction, and objection. Effective as of July 2020, POPIA includes provisions for administrative fines, civil remedies, and penalties for non-compliance. --- ## PP 82/2012 — Indonesia - Peraturan Pemerintah No.82 Tahun 2012 - Government Regulation - Data Protection Regulation URL: https://marketplace.6clicks.com/c/pp-82-2012 Domain: Privacy Type: regulation Issued by: Government of the Republic of Indonesia Jurisdiction: Indonesia Effective: 2012-10-15 Industries: Government Tags: electronic systems, data protection, transactions, electronic signatures, certification Source: https://www.flevin.com/id/lgso/translations/JICA%20Mirror/english/4902_PP_82_2012_e.html Available in the 6clicks app: yes Summary: This regulation specifies the requirements for electronic system and transaction operations in Indonesia, including provisions for electronic agents, signatures, certification, and data management. It aims to ensure security, transparency, and accountability in the use and management of electronic systems and information. Description: Regulation PP 82/2012 provides a comprehensive framework for the operation of electronic systems and transactions in Indonesia, addressing key areas such as hardware and software requirements, expert competencies, risk management, personal data protection, and electronic signature operations. It mandates registration for electronic systems operators involved in public services and outlines certification processes for system capability. Key provisions include obligations for data center localization within Indonesia to ensure sovereignty, detailed security requirements such as audit trails and disaster recovery protocols, and guidance for the protection and correct handling of personal data. Ministerial regulations will further define specific standards and implementation processes. --- ## PRIS Act — Privacy and Responsible Information Sharing Act 2024 URL: https://marketplace.6clicks.com/c/pris-act Domain: Privacy Type: law Issued by: Government of Western Australia Jurisdiction: Western Australia Effective: 2024-12-06 Last updated: 2026-06-11 Industries: Government Tags: privacy principles, information sharing, personal data, public sector, compliance, data breaches, information commissioner Source: https://www.wa.gov.au/organisation/office-of-the-information-commissioner/privacy-western-australia Available in the 6clicks app: yes Summary: The Privacy and Responsible Information Sharing Act 2024 (PRIS Act) establishes a privacy framework for the Western Australian public sector. It introduces Information Privacy Principles (IPPs) and provisions for privacy complaints, privacy impact assessments, and a notifiable information breach scheme. Description: The PRIS Act is a landmark legislation aimed at protecting personal information handled by Western Australian government agencies, departments, and other public sector entities. It introduces 11 Information Privacy Principles (IPPs) dealing with the handling, security, and disposal of personal information. Starting from 1 July 2026, public entities will need to comply with these principles, designate privacy officers, and publish privacy policies. A notifiable information breach scheme requiring public entities to notify affected individuals and the Information Commissioner about breaches will commence on 1 January 2027. The Act empowers the Information Commissioner and a Deputy Commissioner to investigate and enforce compliance. --- ## Privacy Act 1988 — Privacy Act 1988 URL: https://marketplace.6clicks.com/c/privacy-act-1988 Domain: Privacy Type: law Issued by: Australian Government Jurisdiction: Australia Version: No. 119, 1988 Industries: Privacy Tags: privacy, data protection, personal information, australian law, data breaches Source: https://www.legislation.gov.au/C2004A03712/latest/text Document: https://www.legislation.gov.au/C2004A03712/latest/text Available in the 6clicks app: yes Summary: The Privacy Act 1988 is an Australian law that regulates the handling of personal information by businesses, government agencies, and other entities. It includes provisions for the Australian Privacy Principles, credit reporting, and notification of data breaches. Description: The Privacy Act 1988 establishes a comprehensive framework for managing personal information to protect individuals' privacy in Australia. It outlines the Australian Privacy Principles (APPs), which provide guidelines for handling personal information, including collection, use, storage, and disclosure. The Act also includes specific provisions for credit reporting, mandates for the notification of eligible data breaches, and mechanisms for individuals to lodge complaints about privacy breaches. Administered by the Attorney-General's Department and the Department of the Treasury, the Act applies to organisations, agencies, and entities operating in Australia with specific provisions extending to certain overseas entities. --- ## Privacy and Data Protection Act 2014 — Privacy and Data Protection Act 2014 Version No. 032 URL: https://marketplace.6clicks.com/c/privacy-and-data-protection-act-2014 Domain: Privacy Type: law Issued by: Victorian Government Jurisdiction: Victoria, Australia Version: Version No. 032 Effective: 2026-05-01 Last updated: 2026-05-01 Industries: Privacy, Government Tags: privacy, data protection, public sector, victoria, information security Source: https://www.legislation.vic.gov.au/in-force/acts/privacy-and-data-protection-act-2014/033 Document: https://www.legislation.vic.gov.au/sites/default/files/2026-05/14-60aa033%20authorised.pdf Available in the 6clicks app: yes Summary: The Privacy and Data Protection Act 2014 establishes a framework for protecting personal information and ensuring data security within the State of Victoria, Australia. It sets out responsibilities for Victorian public sector agencies regarding personal data handling and protections. Description: The Privacy and Data Protection Act 2014 is a regulatory framework enacted to safeguard the privacy of individuals and ensure robust data protection practices throughout the Victorian public sector. The Act governs how personal information is collected, stored, used, and disclosed by public bodies. It also includes a compliance and enforcement mechanism to ensure agencies adhere to established privacy principles. Over time, multiple versions and amendments have been made, with the latest authorized version effective from 1 May 2026. --- ## Qatar PDPPL — Qatar Personal Data Privacy Protection Law (Law No. (13) of 2016) URL: https://marketplace.6clicks.com/c/qatar-pdppl Domain: Privacy Type: law Issued by: Qatar National Cyber Security Agency (NCSA) Jurisdiction: Qatar Effective: 2016-11-03 Industries: Privacy, Legislation Tags: data protection, consent management, cross-border transfers, cybersecurity controls, personal data Source: https://www.centraleyes.com/qatar-personal-data-privacy-protection-law/ Document: https://ncsa.gov.qa/en Available in the 6clicks app: yes Summary: The Qatar Personal Data Privacy Protection Law (PDPPL), formally Law No. 13 of 2016, is the primary data protection framework in Qatar. It governs how organizations collect, process, store, transfer, and secure personal data belonging to individuals in the country. Description: The Qatar Personal Data Privacy Protection Law (PDPPL) was issued by the Ministry of Transport and Communications and is enforced through regulatory bodies like the Compliance and Data Protection Department (now under the Ministry of Communications and Information Technology). Covering both public and private sectors, the law aligns with international standards such as the EU GDPR and includes provisions for consent, breach notifications, cross-border data transfers, and cybersecurity controls. Subsequent guidelines have further clarified implementation requirements. Compliance is vital for legal assurance, trust-building, and operational efficiency, with non-compliance attracting penalties and reputational risks. --- ## Royal Decree 69/2008 — Electronic Transactions Law in Oman URL: https://marketplace.6clicks.com/c/royal-decree-69-2008 Domain: Privacy Type: law Issued by: Government of Oman Jurisdiction: Oman Effective: 2008-01-01 Industries: Critical infrastructure, Government Tags: electronic transactions, e signatures, cybersecurity, authentication, regulation, data protection Source: https://mtcit.gov.om/library-3/legislations-policies-8/laws-75/electronic-transactions-law-1031 Available in the 6clicks app: yes Summary: The Electronic Transactions Law in Oman, enacted in 2008 through Royal Decree 69/2008, aims to streamline electronic transactions and ensure their security. It establishes provisions for authentication service providers, e-signature confidentiality, and data integrity. Description: The Electronic Transactions Law in Oman was introduced to provide a controlled medium for conducting electronic transactions securely. It includes measures such as coding, firewalls, information filters, and other methods to safeguard company databases against data breaches and integrity violations. The law also specifies procedural safeguards, such as the requirement for authentication service providers to comply with certain protocols. Additionally, it introduces conditions to ensure the validity of electronic transactions, including controls on e-signature creation and verification. Enforcement mechanisms include oversight and judicial seizure authority granted to the Competent Authority. Non-compliance may result in the revocation of licenses for service providers. --- ## Switzerland FADP — Switzerland Federal Act on Data Protection URL: https://marketplace.6clicks.com/c/switzerland-fadp Domain: Privacy Type: law Issued by: The Federal Assembly of the Swiss Confederation Jurisdiction: Switzerland Version: 3 January 2019 Effective: 1992-06-19 Last updated: 2019-01-03 Industries: Government Tags: Switzerland Privacy Law, Data Protection, Personal Data Processing, Privacy Rights, Regulatory Compliance Source: https://www.fedlex.admin.ch/eli/cc/1993/1945_1945_1945/en Available in the 6clicks app: yes Summary: The Federal Act on Data Protection (FADP) is Switzerland's data protection law that regulates the processing of personal data and protects the privacy rights of individuals by establishing requirements for lawful, transparent, and secure data handling. Description: The Federal Act on Data Protection (FADP) is Switzerland’s primary data protection law governing the processing of personal data by private organizations and federal government bodies. The Act aims to protect the privacy and fundamental rights of individuals whose personal data is processed, while promoting transparency, accountability, and lawful data handling practices. It establishes requirements for the collection, use, disclosure, storage, and transfer of personal data, outlines the rights of data subjects, and defines the responsibilities of data controllers and processors. The FADP also provides oversight and enforcement mechanisms through Switzerland’s data protection regulatory framework, helping ensure that personal data is processed securely, fairly, and in accordance with Swiss law. --- ## Taiwan PDPA — Taiwan Personal Data Protection Act URL: https://marketplace.6clicks.com/c/taiwan-pdpa Domain: Privacy Type: law Issued by: Personal Data Protection Commission Jurisdiction: Taiwan Last updated: 2025-11-11 Industries: Government Tags: personal data, privacy rights, data protection, government entities, non government entities, cross border transfer Source: https://law.moj.gov.tw/ENG/LawClass/LawAll.aspx?pcode=I0050021 Available in the 6clicks app: yes Summary: The Personal Data Protection Act (PDPA) of Taiwan establishes legal requirements for the collection, processing, and utilization of personal data in order to protect personality rights while enabling appropriate use of such data. It applies to both government and non-government entities, ensuring compliance and safeguarding individuals' privacy and rights. Description: Taiwan's Personal Data Protection Act (PDPA) provides a comprehensive framework for the protection and lawful use of personal data. It is structured into multiple chapters that outline general provisions, government and non-government agency roles, definitions, and specific statutory protections for sensitive personal data. Key principles include the rights of individuals to access, correct, and erase their data, requirements for consent, and limitations on cross-border transfers. Government and organizational accountability mechanisms are emphasized, alongside mandates for reporting data breaches. The PDPA is overseen by the Personal Data Protection Commission, which coordinates policy promotion and compliance. Regular updates ensure alignment with current socio-economic conditions and technological developments. --- ## Thailand PDPA — Thailand Personal Data Protection Act B.E. 2562 (2019) URL: https://marketplace.6clicks.com/c/thailand-personal-data-protection-act Domain: Privacy Type: law Issued by: Government of Thailand Jurisdiction: Thailand Version: 27 May 2019 Effective: 2019-05-27 Last updated: 2021-09-03 Industries: Government Tags: personal data, privacy, data protection, law, thailand, rights Source: https://data.thailand.opendevelopmentmekong.net/en/laws_record/2562/resource/ec616be5-9fbf-4071-b4b5-cb1f3e46e826 Document: https://data.opendevelopmentmekong.net/dataset/78c90118-6671-4c19-afe1-7bfbace4d46a/resource/ec616be5-9fbf-4071-b4b5-cb1f3e46e826/download/entranslation_of_the_personal_data_protection_act_0.pdf Available in the 6clicks app: yes Summary: The Personal Data Protection Act B.E. 2562 (2019) is Thailand's primary law for personal data protection. It establishes rules for data collection, use, and disclosure, and aims to protect individuals' personal information and ensure effective remedies for violations. Description: Enacted in 2019, Thailand's Personal Data Protection Act B.E. 2562 provides a framework for the protection of personal data rights. Modeled in part on the GDPR, it lays down principles for lawful processing, requiring consent for data collection and implementing safeguards against unauthorized access or disclosure. The law aligns with Section 26 of the Constitution of the Kingdom of Thailand and grants individuals the right to remedies for violations of their data rights. Businesses operating in Thailand are obligated to ensure compliance, including appointing data protection officers where necessary and adhering to conditions for cross-border data transfers. --- ## UAE Personal Data Protection Law — Federal Decree Law No. 45 of 2021 Regarding the Protection of Personal Data URL: https://marketplace.6clicks.com/c/uae-personal-data-protection-law Domain: Privacy Type: law Issued by: UAE Data Office Jurisdiction: United Arab Emirates Version: 20 Sep 2021 Effective: 2022-01-02 Industries: Privacy, Legal, Risk and Compliance, Government, Legislation Tags: data protection, privacy, personal data, compliance, uae data office, consent, cross-border data Source: https://uaelegislation.gov.ae/en/legislations/1972 Document: https://u.ae/en/about-the-uae/digital-uae/data/data-protection-laws Available in the 6clicks app: yes Summary: The UAE Personal Data Protection Law establishes an integrated framework to ensure the confidentiality of information and protect individual privacy in the UAE. It governs the processing of personal data, defines the rights of data owners, sets requirements for cross-border data transfer, and outlines obligations for businesses handling personal data. Description: The UAE Personal Data Protection Law (Federal Decree Law No. 45 of 2021) applies to the processing of personal data within and outside the UAE via electronic systems. Key provisions include requiring consent for data processing, outlining obligations for data controllers to secure and maintain confidentiality, and granting individuals the right to correct, restrict, or stop the processing of their data. The law establishes controls for cross-border data sharing and applies exceptions to processing for public interest or legal procedures. It came into force on January 2, 2022, and was developed in collaboration with private sector technology companies. The UAE Data Office is tasked with overseeing its implementation, issuing guidance, and handling complaints. --- ## Charter of the United Nations Act 1945 URL: https://marketplace.6clicks.com/c/charter-of-the-united-nations-act-1945 Domain: Privacy Type: law Issued by: Australian Government Jurisdiction: Australia Version: No. 14, 1 July 2016 Effective: 2016-07-01 Last updated: 2021-09-13 Industries: Government Tags: united nations, sanctions, terrorism, legislation, assets, australian law Source: https://www.legislation.gov.au/C1945A00032/2016-07-01/text Document: https://www.legislation.gov.au/C1945A00032/2016-07-01/text Available in the 6clicks app: yes Summary: The Charter of the United Nations Act 1945 provides a legal framework for implementing United Nations Security Council Resolutions in Australia. It regulates the application of sanctions, the listing and proscription of individuals or entities, and addresses offenses related to UN sanctions. Description: The Charter of the United Nations Act 1945 establishes Australia's commitment to implementing UN Security Council Resolutions, particularly sanctions and measures dealing with terrorism and asset control. The Act specifies regulations to apply sanctions, enforce compliance, and manage freezable assets. It includes provisions for offenses such as contravening sanction enforcement laws or providing false information. Relevant entities are empowered to impose and revoke listings, require documentation, and ensure compliance. Additional mechanisms include indemnity and compensation for persons wrongly affected and delegations of authority to specific officials. This Act ensures Australia's alignment with UN decisions under international law. --- ## Child Support (Registration and Collection) Act 1988 URL: https://marketplace.6clicks.com/c/child-support-registration-and-collection-act-1988 Domain: Privacy Type: law Issued by: Australian Government Jurisdiction: Australia Version: No. 61, 17 November 2016 Last updated: 2016-11-17 Industries: Government Tags: child support, registration, collection, maintenance, legal framework Source: https://www.legislation.gov.au/Details/C2016C01102 Document: https://www.legislation.gov.au/Details/C2016C01102 Available in the 6clicks app: yes Summary: The Child Support (Registration and Collection) Act 1988 sets the legal framework for registering and collecting child maintenance liabilities in Australia. It outlines processes for enforcing payments, managing registrable liabilities, and utilizing computer programs for certain decisions. Description: This Australian law provides detailed procedures for the registration and collection of maintenance liabilities related to child support. Administered by the Department of Social Services, the Act ensures mechanisms for calculation, enforcement, and collection of child support payments. Key features include provisions for employer withholding, penalties for late payment, and use of computer programs for administrative decision-making. The law also covers international enforcement of child support obligations and allows for review and objection processes via the Administrative Appeals Tribunal (AAT) or courts for affected parties. --- ## Copyright Act 1968 URL: https://marketplace.6clicks.com/c/copyright-act-1968 Domain: Privacy Type: law Issued by: Australian Government Jurisdiction: Australia Version: No. 59, 18 December 2020 Last updated: 2020-12-18 Industries: Government Tags: copyright, intellectual property, fair dealing, education, library rights, legal protections Source: https://www.legislation.gov.au/Details/C2021C00044 Document: https://www.legislation.gov.au/Details/C2021C00044 Available in the 6clicks app: yes Summary: The Copyright Act 1968 is a foundational law in Australia governing copyrights and intellectual property rights in literary, artistic, dramatic, and musical works, as well as sound recordings, broadcasts, and published editions. It defines the rights and protections for creators and sets out provisions for infringement, fair dealing, and public access in specific scenarios such as education and disabilities. Description: The Copyright Act 1968 establishes the framework for copyright law in Australia, outlining the scope and duration of rights for various types of works, including literary, artistic, dramatic, and musical pieces, as well as related subject matter such as sound recordings and broadcasts. The Act specifies how copyrights are acquired, how they can be infringed, and what actions can be taken in case of violations. It includes provisions for fair dealing under conditions like research, criticism, parody, and reporting. Further, it addresses library and archive reproduction rights, protections for technological measures, and limitations on remedies for service providers. The Act has been updated several times to keep pace with technological developments. --- ## Croatia - Personal Data Protection Act URL: https://marketplace.6clicks.com/c/croatia-personal-data-protection-act Domain: Privacy Type: law Issued by: Government of Croatia Jurisdiction: Croatia Effective: 2018-05-09 Industries: Government Tags: gdpr, data protection, privacy, biometric, genetic data, croatia Source: https://narodne-novine.nn.hr/clanci/sluzbeni/2018_05_42_805.html Available in the 6clicks app: yes Summary: The Act governs the implementation of the EU General Data Protection Regulation (GDPR) in Croatia. It outlines specific roles such as the responsibilities of the supervisory authority, the Croatian Data Protection Agency (AZOP), and sets additional national measures related to GDPR compliance. Description: The 'Zakon o provedbi Opće uredbe o zaštiti podataka' lays down national regulations to implement the EU General Data Protection Regulation (GDPR) within Croatia. It specifies organizational roles, including the Croatian Data Protection Agency's independence, its powers to issue fines and recommendations, and oversee GDPR compliance. Additional provisions restrict the processing of genetic and biometric data and set the age of consent for processing children's data at 16 years. The law also establishes rules for collaboration with other national and international supervisory bodies, regulates cross-border operations, and stipulates transparency and accountability measures, including mandatory annual reporting to the Croatian Parliament. --- ## Do Not Call Register Act 2006 URL: https://marketplace.6clicks.com/c/do-not-call-register-act-2006 Domain: Privacy Type: law Issued by: Australian Government Jurisdiction: Australia Version: No. 15, 12 December 2019 Effective: 2006-06-30 Last updated: 2021-08-31 Industries: Government Tags: privacy, telemarketing, civil penalties, communication, marketing faxes, do not call register Source: https://www.legislation.gov.au/Details/C2020C00017 Document: https://www.legislation.gov.au/Details/C2020C00017 Available in the 6clicks app: yes Summary: The Do Not Call Register Act 2006 establishes a framework to prevent unsolicited telemarketing calls and faxes to individuals and organizations who register their numbers on the Do Not Call Register. It includes rules for telemarketers and penalties for violations. Description: The Do Not Call Register Act 2006, introduced in Australia, aims to reduce unsolicited telemarketing calls and marketing faxes to numbers on the national Do Not Call Register. The Act defines rules for the operation of telemarketing and faxing, including eligibility criteria for numbers to be registered, requirements for telemarketers and fax marketers to comply, civil penalties for breaches, and provisions for administration of the register. Government bodies, charities, educational institutions, and certain political communications are exceptions under the Act. It also ties into the Privacy Act 1988 for handling registered data and specifies procedures for enforcement, including civil penalties and injunctions. --- ## Hawaii - Security Breach of Personal Information Chapter 487N URL: https://marketplace.6clicks.com/c/hawaii-security-breach-of-personal-information-chapter-487n Domain: Privacy Type: law Issued by: State of Hawaii Jurisdiction: Hawaii Effective: 2002-06-30 Industries: Government Tags: Data Breach Notification, Personal Information Protection, Privacy Law, Information Security, Data Protection Source: https://ipsc.hawaii.gov/wp-content/uploads/2013/10/Chapter-487N.pdf Available in the 6clicks app: yes Summary: Hawaii Security Breach of Personal Information (Chapter 487N) is a Hawaii state law that requires businesses and government agencies to notify affected individuals of data breaches involving personal information and establishes requirements for protecting and managing sensitive personal data. Description: Hawaii Security Breach of Personal Information (Hawaii Revised Statutes Chapter 487N) is a state privacy and data breach notification law that establishes requirements for businesses and government agencies that collect, own, license, maintain, or process personal information of Hawaii residents. The law requires organizations to provide notice to affected individuals without unreasonable delay following the discovery of a security breach involving personal information where misuse has occurred or is reasonably likely to occur. Chapter 487N defines personal information, outlines breach notification obligations, establishes reporting requirements, and provides penalties for non-compliance. The legislation also promotes information security best practices and supports the protection of individuals from risks associated with unauthorized access, disclosure, or acquisition of personal data. --- ## Israel - Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001 URL: https://marketplace.6clicks.com/c/israel-privacy-protection-transfer-of-data-to-databases-abroad-regulations-5761-2001 Domain: Privacy Type: regulation Issued by: Government of Israel Jurisdiction: Israel Effective: 2001-05-08 Industries: Government Tags: Privacy Protection Regulations, Cross-Border Data Transfer, Israel Privacy Law, Data Protection, Personal Data Transfer, Privacy Compliance Source: https://www.gov.il/BlobFolder/legalinfo/legislation/en/Privacy-ProtectionTransferofDataabroadRegulationsun.pdf Available in the 6clicks app: yes Summary: The Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001 establish Israel's requirements for cross-border transfers of personal data, ensuring that personal information transferred outside Israel remains subject to adequate privacy and data protection safeguards. Description: The Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001 are Israeli privacy regulations that govern the transfer of personal data from databases located in Israel to databases or entities outside the country. Issued under the Protection of Privacy Law, 5741-1981, the regulations require that personal data may only be transferred to countries that provide an adequate level of privacy protection comparable to Israeli law, or where specific legal conditions are met. These conditions include obtaining the data subject's consent, transferring data under contractual safeguards, transferring data within a controlled corporate group, or transferring data to jurisdictions recognized as providing adequate privacy protections. The regulations also require organizations to implement measures that protect the privacy of data subjects and ensure that foreign recipients handle personal data securely and in accordance with applicable privacy requirements. The framework is designed to facilitate cross-border data flows while maintaining strong protections for personal information. --- ## Maine - An Act To Protect the Privacy of Online Customer Information URL: https://marketplace.6clicks.com/c/maine-an-act-to-protect-the-privacy-of-online-customer-information Domain: Privacy Type: law Issued by: Maine Legislature Jurisdiction: Maine, USA Effective: 2020-07-01 Tags: privacy, broadband, customer information, maine, data protection Source: https://www.mainelegislature.org/legis/bills/bills_129th/billtexts/SP027501.asp Available in the 6clicks app: yes Summary: This law establishes privacy protections for broadband Internet access service customers in Maine. Providers are prohibited from using, disclosing, selling or allowing access to customer personal information unless explicit consent is given, with certain exceptions for service provision, emergency scenarios, and lawful orders. The law also mandates providers to adopt reasonable security measures for customer data and gives customers rights regarding consent and notification requirements. Description: An Act To Protect the Privacy of Online Customer Information was enacted by the Maine Legislature to protect broadband Internet access service customers in the state. The act requires providers to obtain express, affirmative customer consent before using, disclosing, selling or granting access to customer personal information, such as browsing history, billing information, or geolocation data. It prohibits providers from refusing service or penalizing customers based on their consent decisions. The law lays out certain exceptions for lawful uses, including compliance with court orders, emergency services, and billing purposes. Providers must implement reasonable security measures tailored to the sensitivity and scope of the data they handle, and clear notices must be provided at the point of sale and on websites regarding customer rights and provider obligations. The act is applicable to broadband providers operating in Maine and serving customers physically located and billed within the state. --- ## New York Privacy Act URL: https://marketplace.6clicks.com/c/new-york-privacy-act Domain: Privacy Type: law Issued by: New York State Legislature Jurisdiction: New York, United States Last updated: 2022-02-01 Tags: consumer rights, privacy protections, automated decision making, data security, legislation Source: https://www.consumerprivacyact.com/new-york-privacy-act/ Document: https://www.nysenate.gov/legislation/bills/2022/s6701 Available in the 6clicks app: yes Summary: The New York Privacy Act aims to provide state-level consumer privacy protections similar to California’s CCPA. It introduces rights like access, correction, and challenging automated decision-making, while requiring businesses to implement security measures and obtain consent for specific practices. Description: The New York Privacy Act, reintroduced in the State Senate and Assembly in February 2022, proposes comprehensive consumer privacy rights. These include rights of access, correction, and the ability to challenge automated decision-making. The Assembly version differs by requiring reasonable security measures and specific consumer notifications and consent. Although prior versions failed, the reintroduction indicates growing legislative momentum. If enacted, New York would join states like California and Virginia in advancing privacy protections at the state level. --- ## Privacy Act URL: https://marketplace.6clicks.com/c/privacy-act Domain: Privacy Type: law Issued by: Government of Canada Jurisdiction: Canada Last updated: 2025-06-02 Industries: Privacy, Government, Legal, Risk and Compliance, Regulators Tags: personal information, government, privacy rights Source: https://laws-lois.justice.gc.ca/eng/acts/p-21/index.html Document: https://laws-lois.justice.gc.ca/PDF/P-21.pdf Available in the 6clicks app: yes Summary: The Privacy Act of Canada governs the collection, use, retention, and disclosure of personal information by federal government institutions. It ensures that individuals have the right to access and correct their personal information held by the government. Description: The Privacy Act, codified as R.S.C., 1985, c. P-21, establishes rules for federal government institutions regarding the handling of personal data. Key provisions include the collection, protection, and disposal of personal information, the creation and management of personal information banks, access and correction rights for individuals, and exemptions for certain situations. The Act also outlines the responsibilities of the Office of the Privacy Commissioner, procedures for investigations, and reporting requirements to ensure compliance. Amendments and regulations under this Act provide further specificity on its application and updates to maintain relevance. --- ## Spam Act 2003 URL: https://marketplace.6clicks.com/c/spam-act-2003 Domain: Privacy Type: law Issued by: Australian Government Jurisdiction: Australia Version: No. 10, 10 March 2016 Effective: 2003-04-10 Last updated: 2016-03-10 Industries: Government Tags: spam regulation, email consent, unsubscribe, address harvesting, civil penalties Source: https://www.legislation.gov.au/Details/C2016C00614 Document: https://www.legislation.gov.au/Details/C2016C00614 Available in the 6clicks app: yes Summary: The Spam Act 2003 is an Australian law designed to regulate the sending of commercial electronic messages to ensure compliance with consent, sender identification, and unsubscribe requirements. It aims to prevent unsolicited messages and address harvesting practices. Description: The Spam Act 2003 provides legal rules for sending commercial electronic messages in Australia. It prohibits unsolicited commercial electronic messages, requires accurate sender information in such messages, and mandates the inclusion of a functional unsubscribe facility. The Act also regulates the use and distribution of address-harvesting software and harvested-address lists. It outlines civil penalties for violations, including pecuniary penalties, injunctions, and enforceable undertakings, and provides a framework for enforcement through entities like the Australian Communications and Media Authority (ACMA). The Act includes exemptions for certain types of messages, such as those sent by government bodies, educational institutions, political parties, and charities. --- ## The Privacy and Electronic Communications (EC Directive) Regulations 2003 URL: https://marketplace.6clicks.com/c/the-privacy-and-electronic-communications-ec-directive-regulations-2003 Domain: Privacy Type: regulation Issued by: UK Parliament Jurisdiction: United Kingdom Version: 18th September 2003 Effective: 2003-12-11 Tags: privacy, communications, data protection, marketing, uk regulation, electronic Source: https://www.legislation.gov.uk/uksi/2003/2426/contents/made Available in the 6clicks app: yes Summary: This UK regulation implements the EU Directive on privacy and electronic communications. It sets rules for the confidentiality of communications, restrictions on processing of traffic and location data, and regulates direct marketing via electronic channels. Description: The Privacy and Electronic Communications (EC Directive) Regulations 2003 establish data protection and privacy standards specific to electronic communications in the UK. Key provisions include requirements for the security and confidentiality of public electronic communication services, rules on itemized billing, protections against unsolicited communication for direct marketing, and conditions for processing traffic and location data. The regulation also outlines compliance and enforcement mechanisms, including modifications to the Data Protection Act 1998, and specifics for collaboration with the Information Commissioner’s Office. It replaces earlier legislation and incorporates transitional provisions for smooth implementation. --- 6clicks operationalizes these regulations against your control set, evidence and risks. Learn more at https://www.6clicks.com. Generated by Orbit for 6clicks.