Fifteen frameworks, mapped to what your business actually needs.
Filter by domain, or scroll the full set — each can be implemented standalone or combined into a single security operating model.
ISO 27001GLOBAL
Info Sec & Risk Governance
Information Security Management System
The global benchmark for information security governance.
- Systematic, risk-based ISMS implementation
- Certifiable, independently audited controls
- Prerequisite for enterprise and government tenders
Discuss ISO 27001 →
NIST CSFUS / GLOBAL
Info Sec & Risk Governance
Cybersecurity Framework 2.0
Identify, protect, detect, respond, recover.
- Common risk language across the enterprise
- Govern function elevates security to the board
- Maps to HIPAA, PCI-DSS, and sector regulation
Discuss NIST CSF →
NIST SP 800-53US FEDERAL
Info Sec & Risk Governance
Security & Privacy Control Catalogue
1,000+ controls, tailored to risk impact.
- Low / Moderate / High baseline tailoring
- Foundational to FedRAMP and FISMA authorization
- Fully integrated security and privacy controls
Discuss SP 800-53 →
ISO 31000GLOBAL
Info Sec & Risk Governance
Risk Management Guidelines
Turn uncertainty into informed decisions.
- Principles-based — applies to any risk type
- Embeds risk into governance, planning, and culture
- Guidance framework, not a certification scheme
Discuss ISO 31000 →
ISO 27701GLOBAL
Privacy & Data Protection
Privacy Information Management System
Extend your ISMS into provable privacy governance.
- Built as a certifiable extension to ISO 27001
- Supports GDPR, CCPA, and PDPA accountability
- Makes privacy a board-level governance responsibility
Discuss ISO 27701 →
GDPREU / EEA
Privacy & Data Protection
General Data Protection Regulation
The world's toughest personal data law.
- Lawful basis and RoPA for every processing activity
- Data subject rights: access, erasure, portability
- Fines up to €20M or 4% of global turnover
Discuss GDPR →
HIPAAUS
Privacy & Data Protection
Health Insurance Portability & Accountability Act
Protecting PHI across the healthcare supply chain.
- Privacy, Security, and Breach Notification Rules
- Mandatory Business Associate Agreements with vendors
- Penalties up to $1.9M per violation category, per year
Discuss HIPAA →
ISO 42001GLOBAL
AI Governance
Artificial Intelligence Management System
Certifiable governance for trustworthy AI.
- Manages bias, transparency, and AI-specific risk
- Human oversight and accountability structures
- Increasingly required in AI procurement and partnerships
Discuss ISO 42001 →
NIST AI RMFUS / GLOBAL
AI Governance
AI Risk Management Framework 1.0
Govern. Map. Measure. Manage.
- Goes beyond conventional cybersecurity controls
- Supports alignment with the EU AI Act and sector AI rules
- Covers fairness, transparency, security, and privacy
Discuss NIST AI RMF →
SOC 2US / GLOBAL
Assurance & Service Management
Service Organization Controls (Type II)
Independent proof your controls work — not just exist.
- Trust Services Criteria: security, availability, PI, confidentiality, privacy
- Type II attests operating effectiveness over 6–12 months
- Standard prerequisite for enterprise SaaS sales
Discuss SOC 2 →
ISO 20000-1GLOBAL
Assurance & Service Management
IT Service Management System
Deliver IT services your customers can rely on.
- Structured incident, change, and release control
- Common requirement for MSP and outsourcing contracts
- Continual service improvement built into the standard
Discuss ISO 20000-1 →
ISO 9001GLOBAL
Assurance & Service Management
Quality Management System
Consistency your customers can measure.
- Customer-focused, measurable quality objectives
- Recognized supplier qualification standard
- Drives continuous process improvement
Discuss ISO 9001 →
CPS 234AUSTRALIA
Sector & Regulatory
APRA Information Security Standard
Mandatory security governance for regulated financial entities.
- Board-level accountability for information security
- Third-party and supply chain security obligations
- 72-hour APRA incident notification requirement
Discuss CPS 234 →
Cyber EssentialsUK
Foundational Controls
UK Government-Backed Certification
Five controls that stop most common attacks.
- Firewalls, secure config, access control, malware, patching
- Required for many UK government contracts
- Cyber Essentials Plus adds independent technical testing
Discuss Cyber Essentials →
Essential EightAUSTRALIA
Foundational Controls
ACSC Mitigation Strategies
Australia's baseline for ransomware and intrusion resilience.
- Eight prioritized strategies, including MFA and backups
- Maturity Levels 1–3 track implementation progress
- Mandated for non-corporate Commonwealth entities
Discuss Essential Eight →