Evidence request lists
For every control in a framework: what the control requires, the artefacts an auditor will ask you for, and where that control commonly fails. Assembled from each framework’s own control set, so a list stays current as the framework does. 614 frameworks, 18,832 controls. Free to read.
- Australian Information Security Manual · 1081 controls
- FedRAMP High · 410 controls
- FedRAMP Moderate · 323 controls
- NIST SP 800-53 Rev 5 · 320 controls
- NIST SP 800-53 Revision 5.1 HIGH · 317 controls
- NIST SP 800-53 Rev 5 MODERATE · 275 controls
- PCI DSS 4.0 · 249 controls
- Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 · 197 controls
- NIST SP 800-161 Rev 1 · 191 controls
- NIST SP 800-53 Rev 5 LOW · 173 controls
- CIS Controls v8 · 153 controls
- ISO 27701:2019 · 145 controls
- C5 (Germany) · 121 controls
- CMMC 2.0 · 110 controls
- NIST Cybersecurity Framework 2.0 · 106 controls
- ISO 27002:2022 · 104 controls
- ISO 27001:2022 · 100 controls
- NIST SP 800-171 Rev 3 · 97 controls
- NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) · 97 controls
- NIST SP 800-171 · 88 controls
- Azure Security Benchmark · 85 controls
- ISO/IEC 23894:2023 · 85 controls
- ISO/IEC 42001:2023 · 83 controls
- IEC 62443 · 81 controls
- 21 CFR Part 211 - Current Good Manufacturing Practice · 78 controls
- FFIEC IT Examination Handbook · 78 controls
- NIST AI Risk Management Framework (AI RMF 1.0) · 72 controls
- ISO 26262:2018 - Functional Safety for Road Vehicles · 69 controls
- SASB Standards · 69 controls
- COBIT 2019 · 68 controls
- HIPAA Security Rule · 67 controls
- SSAE 18 - Attestation Standards (SOC Reporting) · 67 controls
- Aged Care Quality Standards (Australia) · 66 controls
- NIS2 Directive · 66 controls
- NIST SP 800-66 Rev 2 · 65 controls
- EU AI Act · 64 controls
- AWS Well-Architected Security Pillar · 63 controls
- SOC 2 · 61 controls
- ISO 26000:2010 · 60 controls
- ISO 56002 · 60 controls
- APEC Cross-Border Privacy Rules (CBPR) System · 59 controls
- ISO 37000:2021 · 59 controls
- ISO 22301:2019 · 57 controls
- ISO 30414:2018 - Human Resource Management: Guidelines for Internal and External Human Capital Reporting · 56 controls
- Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) · 56 controls
- BSI IT-Grundschutz · 55 controls
- eIDAS 2.0 - EU Digital Identity Regulation · 55 controls
- ITIL 4 · 53 controls
- China Personal Information Protection Law (PIPL) · 52 controls
- ISO 27043 · 52 controls
- NIST SP 800-181 · 52 controls
- AASB S2 Climate-related Disclosures · 51 controls
- NIST SP 800-207 · 51 controls
- ISO/SAE 21434 · 50 controls
- Egypt Personal Data Protection Law (Law No. 151 of 2020) · 49 controls
- FFIEC Cybersecurity Assessment Tool (CAT) · 49 controls
- NIST SP 800-160 · 49 controls
- PCI SSF · 49 controls
- Senge Fifth Discipline - Learning Organization · 49 controls
- Administrative Measures for the Security Assessment of Generative AI Services (2023) and Algorithmic Recommendation Management Provisions (2022) · 48 controls
- ISO 41001:2018 - Facility Management Systems · 48 controls
- NIST SP 800-82 Rev 3 · 48 controls
- BREEAM - Building Research Establishment Environmental Assessment Method · 47 controls
- IAIS Insurance Core Principles (ICPs) · 47 controls
- ISO 22313:2020 - Guidance on Business Continuity Management Systems · 47 controls
- ISO 37002:2021 - Whistleblowing Management Systems · 47 controls
- South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics · 47 controls
- CISA Zero Trust Maturity Model · 46 controls
- COSO Internal Control - Integrated Framework (2013) · 46 controls
- DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition) · 46 controls
- ISO 27019 · 46 controls
- ISO 27799 · 46 controls
- ISO 39001:2012 - Road Traffic Safety Management · 46 controls
- DoD Zero Trust Reference Architecture · 45 controls
- ISO 27018 · 45 controls
- ISO/IEC 27003:2017 · 45 controls
- NIST SP 800-190 · 45 controls
- SQF Code Edition 9 - Safe Quality Food · 45 controls
- Act on the Implementation of the General Data Protection Regulation (OG 42/2018) · 44 controls
- Bank Secrecy Act / Anti-Money Laundering (BSA/AML) · 44 controls
- Belgium CyberFundamentals · 44 controls
- ISO 19650 - Organisation and Digitisation of Information about Buildings and Civil Engineering Works (BIM) · 44 controls
- ISO/IEC 27011:2024 · 44 controls
- NIST SP 1800-32 · 44 controls
- PCI P2PE · 44 controls
- Singapore Government Instruction Manual on ICT&SS Management (IM8) · 44 controls
- 3GPP 5G Security Architecture (TS 33.501) · 43 controls
- APRA CPS 230 Operational Risk Management · 43 controls
- ISO 31000 · 43 controls
- ISO 9001 · 43 controls
- ISO/IEC 29134:2023 · 43 controls
- PCI PIN Security · 43 controls
- ANSSI Guide d'hygiene informatique (42 mesures, v2.0) · 42 controls
- ASIS SPC.1-2009 - Organizational Resilience Standard · 42 controls
- Authorised Economic Operator (AEO) Programmes - Global Standards · 42 controls
- EN 301 549 - Accessibility requirements for ICT products and services · 42 controls
- ISO 14064 - Greenhouse Gas Accounting and Verification (Parts 1-3) · 42 controls
- ISO 30401 · 42 controls
- ISO 37001 · 42 controls
- ISO 37301 · 42 controls
- ISO/IEC 23837 - Security Requirements for Quantum Key Distribution · 42 controls
- ISO/IEC 38500:2024 - Governance of IT · 42 controls
- NIST SP 800-218 · 42 controls
- WHO Global Strategy on Digital Health 2020-2025 · 42 controls
- ISO/IEC 27557:2022 - Organisational Privacy Risk Management · 41 controls
- ISO/IEC 29115:2023 - Entity Authentication Assurance Framework · 41 controls
- APRA CPS 220 Risk Management · 40 controls
- Australia My Health Records Act 2012 · 40 controls
- GDPR · 40 controls
- ISO 20400:2017 - Sustainable Procurement · 40 controls
- ISO 55001 · 40 controls
- ISO/IEC 29100:2024 · 40 controls
- ISO/IEC 29147:2018 · 40 controls
- SANS Incident Handler's Handbook and PICERL Methodology · 40 controls
- Space ISAC (Information Sharing and Analysis Center) - Threat Framework · 40 controls
- AML/CTF Act 2006 (Australia) · 39 controls
- CFTC System Safeguards (17 CFR 37, 38, 39, 49) · 39 controls
- ISO 15189:2022 - Medical Laboratories Requirements for Quality and Competence · 39 controls
- ISO 22000 · 39 controls
- ISO 22739:2024 - Blockchain and Distributed Ledger Technologies Vocabulary · 39 controls
- ISO 45001 · 39 controls
- ISO/IEC 27014:2020 · 39 controls
- NIST SP 800-128 · 39 controls
- Texas Data Privacy Act · 39 controls
- Turkey KVKK · 39 controls
- IEC 60601-1 - Medical Electrical Equipment Safety · 38 controls
- PDPA Thailand · 38 controls
- UNESCO Recommendation on the Ethics of AI · 38 controls
- AS9100D - Aerospace Quality Management System · 37 controls
- ASD Strategies to Mitigate Cyber Security Incidents · 37 controls
- ASEAN Guide on AI Governance and Ethics · 37 controls
- AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) · 37 controls
- ISO 22320:2018 · 37 controls
- ISO 27017 · 37 controls
- Saudi Arabia PDPL · 37 controls
- BSIMM · 36 controls
- Digital Services Act (DSA) - Regulation (EU) 2022/2065 · 36 controls
- ISO 22317 · 36 controls
- ISO 22318 · 36 controls
- ISO 28001:2007 Supply Chain Security Management · 36 controls
- ISO/IEC 25012:2008 - Data Quality Model · 36 controls
- UK Cyber Essentials · 36 controls
- VUCA Leadership Framework · 36 controls
- CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 · 35 controls
- Digital Economy Partnership Agreement (DEPA) · 35 controls
- Israel Protection of Privacy Law (5741-1981) · 35 controls
- NFPA 1600 - Standard on Continuity, Emergency, and Crisis Management · 35 controls
- NIST SP 800-150 · 35 controls
- NIST SP 800-172 · 35 controls
- Security of Critical Infrastructure Act 2018 (SOCI) · 35 controls
- UK Product Security and Telecommunications Infrastructure Act (PSTI) · 35 controls
- Virginia CDPA · 35 controls
- Argentina Law 25.326 (Personal Data Protection Law) · 34 controls
- EASA Part-IS - Information Security in Aviation · 34 controls
- IEC 62351 - Power Systems Communication Security · 34 controls
- ISAE 3402 - Assurance Reports on Controls at a Service Organisation · 34 controls
- ISO/IEC 30111:2019 · 34 controls
- Illinois Biometric Information Privacy Act (BIPA) · 34 controls
- NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices · 34 controls
- NIST SP 800-161 · 34 controls
- SWIFT CSCF · 34 controls
- Solvency II · 34 controls
- US Foreign Corrupt Practices Act (FCPA) · 34 controls
- Aged Care Quality Standards 2019 (repealed edition) · 33 controls
- Consumer Data Right (CDR) Framework (Australia) · 33 controls
- FBI CJIS Security Policy · 33 controls
- IEC 62304:2015 Medical Device Software Lifecycle Processes · 33 controls
- ISO 22316 · 33 controls
- ISO/IEC 27006:2024 · 33 controls
- NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity · 33 controls
- US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements · 33 controls
- 21 CFR Part 58 - Good Laboratory Practice (GLP) · 32 controls
- Australian Energy Sector Cyber Security Framework (AESCSF) · 32 controls
- Botswana Data Protection Act (2024) · 32 controls
- CCPA/CPRA · 32 controls
- ISO/IEC 27400:2022 · 32 controls
- NIST SP 800-187 · 32 controls
- SOC 1 (SSAE 18 / ISAE 3402) · 32 controls
- W3C Verifiable Credentials (VC) Data Model 2.0 · 32 controls
- WHO Global Competency Model · 32 controls
- Automotive SPICE (ASPICE) v4.0 - Process Assessment Model · 31 controls
- Brazil Open Finance (Resolução Conjunta No. 1/2020) · 31 controls
- Brunei Personal Data Protection Order 2022 (PDPO) · 31 controls
- Canadian PIPEDA · 31 controls
- SIG (Shared Assessments) · 31 controls
- APPI · 30 controls
- Chile Personal Data Protection Law (Law No. 21.719) · 30 controls
- EU Audiovisual Media Services Directive (AVMSD, Directive 2010/13/EU as amended by Directive 2018/1808 and Directive (EU) 2023/2586) · 30 controls
- EU Clinical Trials Regulation (CTR 536/2014) · 30 controls
- ISO 19011 · 30 controls
- ISO/IEC 27004:2016 · 30 controls
- ISO/IEC 27018:2019 · 30 controls
- NIST SP 800-183 · 30 controls
- NIST SP 800-53A Rev. 5 · 30 controls
- SEC Cybersecurity Disclosure Rule · 30 controls
- Section 508 - ICT Accessibility (Revised) · 30 controls
- UAE Virtual Asset Regulatory Authority (VARA) Regulations · 30 controls
- UK Defence Standard 05-138 - Cyber Security for Defence Suppliers · 30 controls
- ASIC Cyber Resilience Good Practices · 29 controls
- Bahrain PDPL · 29 controls
- Brazil AI Framework · 29 controls
- ISO 8000 - Data Quality · 29 controls
- ISO/IEC 17025:2017 - General Requirements for Testing and Calibration Laboratories · 29 controls
- ISO/IEC 27050 - Electronic Discovery (Parts 1-4) · 29 controls
- NIST SP 800-88 Rev 1 · 29 controls
- NSA Guidance for Transition to Quantum-Resistant Cryptography · 29 controls
- PTES · 29 controls
- TEFCA - Trusted Exchange Framework and Common Agreement · 29 controls
- APRA SPS 220 Risk Management (Superannuation) · 28 controls
- African Union Malabo Convention · 28 controls
- Basel III International Banking Framework · 28 controls
- Colombia Data Protection Law (Law 1581 of 2012) · 28 controls
- Cyber Essentials Plus · 28 controls
- EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) · 28 controls
- ENISA Data Protection Engineering - From Theory to Practice · 28 controls
- ISO/IEC 27007:2020 · 28 controls
- ISO/IEC 27010:2015 · 28 controls
- PSD2 SCA · 28 controls
- Protective Security Policy Framework (PSPF) Release 2024 · 28 controls
- Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation) · 28 controls
- Russia Federal Law on Personal Data (152-FZ) · 28 controls
- Samoa Telecommunications Act (2005) - Privacy & Data Protection · 28 controls
- TISAX - Trusted Information Security Assessment Exchange · 28 controls
- TNFD Recommendations · 28 controls
- US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule · 28 controls
- WELL Building Standard v2 (International WELL Building Institute) · 28 controls
- AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence · 27 controls
- ASEAN Data Management Framework · 27 controls
- Argyris Double-Loop Learning · 27 controls
- Australia NHMRC National Statement on Ethical Conduct in Human Research · 27 controls
- Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct · 27 controls
- Connecticut Data Privacy Act (CTDPA) · 27 controls
- EDM Council DCAM - Data Management Capability Assessment Model · 27 controls
- EU Data Act · 27 controls
- ISO/IEC 27031:2011 · 27 controls
- ISO/IEC 27701:2019 · 27 controls
- Singapore Cybersecurity Act 2018 · 27 controls
- Utah Consumer Privacy Act · 27 controls
- AICPA Privacy Management Framework (PMF) · 26 controls
- BIMCO Cyber Security · 26 controls
- BS 65000:2014 - Guidance on Organizational Resilience · 26 controls
- Canada ITSG-33 - IT Security Risk Management · 26 controls
- DORA · 26 controls
- EU Chips Act (Regulation (EU) 2023/1781) · 26 controls
- EU Digital Markets Act · 26 controls
- EU In Vitro Diagnostic Medical Devices Regulation (IVDR) · 26 controls
- EU Medical Devices Regulation (MDR 2017/745) · 26 controls
- ISO 27005 · 26 controls
- Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) · 26 controls
- Secure by Design: A Guide for Manufacturers (CISA) · 26 controls
- Senegal Law on Personal Data Protection (Law No. 2008-12) · 26 controls
- Serbia Law on Personal Data Protection (2018) · 26 controls
- TSA Pipeline Cybersecurity Directives · 26 controls
- UK Building Safety Act 2022 · 26 controls
- UK Construction (Design and Management) Regulations 2015 (CDM 2015) · 26 controls
- UN Guiding Principles on Business and Human Rights (UNGPs) · 26 controls
- Vermont Artificial Intelligence and Consumer Data Act (AICDA) · 26 controls
- CWE Top 25 Most Dangerous Software Weaknesses (2024) · 25 controls
- EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) · 25 controls
- Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019) · 25 controls
- SEC Climate Disclosure Rule · 25 controls
- Science Based Targets Initiative (SBTi) - Net-Zero Standard · 25 controls
- South Korea Credit Information Act · 25 controls
- South Korea ISMS-P · 25 controls
- UK Open Banking Standard · 25 controls
- Union Customs Code (UCC) - Regulation (EU) No 952/2013 · 25 controls
- Zimbabwe Data Protection Act (2021) · 25 controls
- ACSC Essential Eight · 24 controls
- API 1164 · 24 controls
- APRA CPS 234 · 24 controls
- Australia Consumer Data Right - Banking (CDR) · 24 controls
- BRCGS Global Standard for Food Safety Issue 9 · 24 controls
- Bermuda Personal Information Protection Act 2016 (PIPA) · 24 controls
- Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011) · 24 controls
- CNCF Security Technical Advisory Group (TAG) · 24 controls
- CSA STAR (Security, Trust, Assurance, and Risk) · 24 controls
- Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP · 24 controls
- EAR - Export Administration Regulations · 24 controls
- EU Carbon Border Adjustment Mechanism (CBAM) · 24 controls
- EU Cyber Resilience Act · 24 controls
- Ethiopia Personal Data Protection Proclamation (No. 1321/2024) · 24 controls
- ISO 13485 · 24 controls
- NY DFS 23 NYCRR 500 · 24 controls
- SA8000:2014 - Social Accountability Standard · 24 controls
- SLSA · 24 controls
- Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) · 24 controls
- US OFAC Sanctions Compliance Framework · 24 controls
- USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement) · 24 controls
- Ukraine Law on Personal Data Protection (Law No. 2297-VI) · 24 controls
- Uzbekistan Law on Personal Data (No. ZRU-547) · 24 controls
- Voluntary Principles on Security and Human Rights (VPs) · 24 controls
- WCO SAFE Framework of Standards to Secure and Facilitate Global Trade (2021) · 24 controls
- Wisconsin Data Privacy Act (SB 670) · 24 controls
- Angola Personal Data Protection Law (Law No. 22/11) · 23 controls
- Barbados Data Protection Act 2019 · 23 controls
- South Africa Promotion of Access to Information Act (PAIA) · 23 controls
- South Korea Cloud Security Assurance Program (CSAP) · 23 controls
- Tanzania Personal Data Protection Act (Draft) · 23 controls
- Tunisia Organic Law on Personal Data Protection (Law No. 2004-63) · 23 controls
- UK Concordat on Open Research Data (UKRI) · 23 controls
- US Automated Commercial Environment (ACE) - CBP Trade Data Requirements · 23 controls
- US Consumer Product Safety Commission (CPSC) - Connected Product Safety · 23 controls
- AICPA SOC 3 · 22 controls
- C2M2 · 22 controls
- CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) · 22 controls
- CSRD · 22 controls
- Canada's Anti-Spam Legislation (CASL) · 22 controls
- Cayman Islands Data Protection Act 2017 (DPA) · 22 controls
- China Cybersecurity Law (CSL) · 22 controls
- Colorado Privacy Act · 22 controls
- Critical Raw Materials Act (Proposed Regulation COM(2023) 192) · 22 controls
- DISA Security Technical Implementation Guides (STIGs) · 22 controls
- Danish Data Protection Act (Databeskyttelsesloven) · 22 controls
- Data Protection Act 2017 · 22 controls
- Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law · 22 controls
- Directive (EU) 2023/970 on pay transparency · 22 controls
- EMV 3‑D Secure (3DS) - Payment Authentication Protocol · 22 controls
- EU General Product Safety Regulation (GPSR, Regulation 2023/988) · 22 controls
- EU Markets in Crypto-Assets Regulation (MiCA) · 22 controls
- ISO 20000-1 · 22 controls
- Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter · 22 controls
- SOC for Cybersecurity - Cybersecurity Risk Management Examination · 22 controls
- UNICEF Policy Guidance on AI for Children (2021) · 22 controls
- Belgium Data Protection Act (Wet van 30 juli 2018, Loi du 30 juillet 2018) · 21 controls
- COPPA · 21 controls
- China Data Security Law (DSL) · 21 controls
- Czech Republic Act on the Protection of Personal Data (Act No. 110/2019 Coll.) · 21 controls
- Defence Security Principles Framework (DSPF) · 21 controls
- EU Energy Performance of Buildings Directive (EPBD Recast) - Directive (EU) 2024/1275 · 21 controls
- EU European Media Freedom Act (EMFA) · 21 controls
- Singapore AI Governance Framework · 21 controls
- 6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673) - superseded by AMLD7 · 20 controls
- Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) · 20 controls
- COSO Enterprise Risk Management (ERM) Framework (2017) · 20 controls
- Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134) · 20 controls
- Canada Artificial Intelligence and Data Act (AIDA) · 20 controls
- Code of Conduct on Data Protection for Research (GDPR Article 40) · 20 controls
- ECB TIBER-EU Framework · 20 controls
- ESRB Privacy Certified · 20 controls
- EU Better Internet for Kids (BIK+) Strategy · 20 controls
- EU Machinery Regulation (Regulation (EU) 2023/1230) · 20 controls
- Science Based Targets initiative (SBTi) Corporate Standard · 20 controls
- TCFD Recommendations · 20 controls
- UK Age Appropriate Design Code (Children's Code) · 20 controls
- UK Bribery Act 2010 · 20 controls
- UK Security and Emergency Measures Direction (SEMD) - Water Industry · 20 controls
- US ITAR and EAR - Export Control and Data Security · 20 controls
- Colorado Artificial Intelligence Act (proposed SB 24-205) · 19 controls
- EU Data Governance Act (DGA) · 19 controls
- EU Payment Services Directive (PSD2) · 19 controls
- Florida Digital Bill of Rights (FDBR) · 19 controls
- IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems · 19 controls
- OSHA General Industry Standards (29 CFR Part 1910) · 19 controls
- SOX 404 / ICFR · 19 controls
- Singapore Protection from Online Falsehoods and Manipulation Act (POFMA, 2019) · 19 controls
- UK Online Safety Act 2023 · 19 controls
- Armenia Law on Protection of Personal Data (2015) · 18 controls
- Australia eSafety Commissioner - Online Safety Expectations for Industry · 18 controls
- Data (Use and Access) Act 2025 · 18 controls
- Defence Industry Security Program (DISP) · 18 controls
- EU AI Liability Directive · 18 controls
- EU Cyber Solidarity Act (Regulation (EU) 2025/38) · 18 controls
- EU Product Liability Directive (Directive (EU) 2024/2853) · 18 controls
- EU SFDR (Sustainable Finance Disclosure Regulation) · 18 controls
- Responsible Minerals Initiative (RMI) - Responsible Minerals Assurance Process · 18 controls
- Sweden Data Protection Act (Dataskyddslag, 2018:218) · 18 controls
- TSA Pipeline Security · 18 controls
- Tennessee Information Protection Act (TIPA) · 18 controls
- Washington My Health My Data Act (MHMD) · 18 controls
- Annex 11 to EU GMP - Computerised Systems · 17 controls
- CCSDS 350.0-G-3 - Space Communications Security (Consultative Committee for Space Data Systems) · 17 controls
- CMMC 2.0 Level 1 · 17 controls
- Cook Islands Electronic Transactions Act 2003 · 17 controls
- Cyber Security Act 2024 (Australia) · 17 controls
- EU Network Code on Cybersecurity for the Electricity Sector · 17 controls
- EU Seveso III Directive (Directive 2012/18/EU) · 17 controls
- Jamaica Data Protection Act 2020 · 17 controls
- Sigstore - Software Artifact Signing and Verification · 17 controls
- UNECE WP.29 R156 · 17 controls
- Uganda Data Protection and Privacy Act (2019) · 17 controls
- Australia IRAP - Information Security Registered Assessors Program · 16 controls
- CISA Industrial Control Systems (ICS) Security Guidance · 16 controls
- EU Taxonomy Regulation · 16 controls
- European Accessibility Act (Directive (EU) 2019/882) · 16 controls
- FATF 40 Recommendations · 16 controls
- FIDO2 / WebAuthn · 16 controls
- Australia Online Safety Act 2021 · 15 controls
- Azerbaijan Law on Personal Data (2010) · 15 controls
- ETSI EN 303 645 · 15 controls
- EU ePrivacy Directive (2002/58/EC) · 15 controls
- Extractive Industries Transparency Initiative (EITI) Standard (2023) · 15 controls
- FAA Cybersecurity Framework for Aviation · 15 controls
- Family Educational Rights and Privacy Act (FERPA) · 15 controls
- UNECE WP.29 R155 · 15 controls
- Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) · 14 controls
- BCBS 239 · 14 controls
- Commercial National Security Algorithm Suite (CNSA) 2.0 · 14 controls
- EDM Council CDMC - Cloud Data Management Capability Framework · 14 controls
- EU Web Accessibility Directive (Directive 2016/2102) · 14 controls
- French Sapin II Law (Law No. 2016-1691) · 14 controls
- ISO 14001 · 14 controls
- OWASP ASVS · 14 controls
- Australian Privacy Principles (APPs) · 13 controls
- CDP (formerly Carbon Disclosure Project) · 13 controls
- FATF Recommendation 16 - Virtual Asset Travel Rule · 13 controls
- FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) · 13 controls
- FDA 21 CFR Part 11 · 13 controls
- FDA Quality Management System Regulation (QMSR) · 13 controls
- Fair Labor Association (FLA) Workplace Code of Conduct · 13 controls
- GS1 Global Standards - Supply Chain Traceability and Data Security · 13 controls
- Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) · 13 controls
- ITU-T X.805 - Security Architecture for End-to-End Communications · 13 controls
- Japan AI Guidelines · 13 controls
- US Americans with Disabilities Act (ADA) - Title III Digital Accessibility · 13 controls
- Arizona Air Quality Regulations (ADEQ / ARS Title 49 / AAC Title 18 Chapter 2) · 12 controls
- C-TPAT - Customs-Trade Partnership Against Terrorism · 12 controls
- DFARS 252.204-7012 - Safeguarding Covered Defense Information · 12 controls
- FIRST CSIRT Services Framework and Standards · 12 controls
- FISMA · 12 controls
- FedRAMP Rev 5 · 12 controls
- Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) · 12 controls
- GHG Protocol · 12 controls
- GLBA · 12 controls
- GLI-33 - Gaming Laboratories International Event Wagering Systems · 12 controls
- GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6 · 12 controls
- GRI Standards · 12 controls
- Ghana Cybersecurity Act · 12 controls
- Ghana Data Protection Act 2012 (Act 843) · 12 controls
- Global Cross-Border Privacy Rules (Global CBPR) Forum · 12 controls
- Goleman Emotional Intelligence Leadership Framework · 12 controls
- Greece Law 4624/2019 - Hellenic Data Protection Authority (HDPA) Implementation Act · 12 controls
- Heifetz Adaptive Leadership Framework · 12 controls
- ICN Leadership for Change Programme · 12 controls
- Kuwait National Cybersecurity Framework · 12 controls
- Telecommunications Sector Security Reforms (TSSR) · 12 controls
- UK Data Protection Act 2018 · 12 controls
- Critical Infrastructure Risk Management Program (CIRMP) Rules 2023 · 11 controls
- EU NIS2 Directive - Transport Sector Requirements · 11 controls
- FSSC 22000 - Food Safety System Certification · 11 controls
- FTC GLBA Safeguards Rule (16 CFR Part 314) · 11 controls
- FTC Health Breach Notification Rule · 11 controls
- Finland Data Protection Act (Tietosuojalaki, 1050/2018) · 11 controls
- GAMP 5 - Good Automated Manufacturing Practice · 11 controls
- Georgia Law on Personal Data Protection (2012) · 11 controls
- German Supply Chain Due Diligence Act (LkSG) · 11 controls
- HITECH Act · 11 controls
- HKMA Cyber Resilience Assessment Framework (C-RAF) · 11 controls
- HKMA SPM · 11 controls
- Hersey & Blanchard Situational Leadership Model · 11 controls
- IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) · 11 controls
- Japan FSA Cybersecurity Guidelines for Financial Institutions · 11 controls
- NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements · 11 controls
- Regulation on the European Health Data Space (EHDS) · 11 controls
- ECSS-E-ST-40C: Space Engineering - Software · 10 controls
- EPA Risk Management Program (40 CFR Part 68) · 10 controls
- Equator Principles (EP4, 2020) · 10 controls
- Full Range Leadership Model (Bass & Avolio) · 10 controls
- Hungary Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act) · 10 controls
- IATF 16949:2016 - Quality Management System for Automotive Production · 10 controls
- ICAO Annex 17 - Aviation Security (AVSEC) · 10 controls
- Indonesia PDP Law · 10 controls
- OWASP Top 10:2025 · 10 controls
- RICS Professional Standards - Data and Technology in Property · 10 controls
- Singapore Payment Services Act (PSA) - Digital Payment Token Regulation · 10 controls
- UK Telecommunications (Security) Act 2021 · 10 controls
- Aged Care Adjacent Schemes (Australia) · 9 controls
- Consumer Data Right Rules 2020 (selected operational obligations) · 9 controls
- Ethical Trading Initiative (ETI) Base Code · 9 controls
- IATA Operational Safety Audit (IOSA) Standards Manual · 9 controls
- ICH E6(R3) - Good Clinical Practice · 9 controls
- IEEE 7000 · 9 controls
- ISSB Standards · 9 controls
- PIC/S Guide to Good Manufacturing Practice for Medicinal Products · 9 controls
- UK Gambling Commission - Cyber Resilience Requirements · 9 controls
- UK Modern Slavery Act 2015 · 9 controls
- Australia AI Ethics Framework · 8 controls
- Delaware Online Privacy and Protection Act (proposed) · 8 controls
- HKMA TM-G-1 · 8 controls
- ICC Incoterms 2020 - International Commercial Terms · 8 controls
- ICMM Mining Principles (2024 Update) · 8 controls
- IFRS 17 - Insurance Contracts · 8 controls
- ILO Declaration on Fundamental Principles and Rights at Work (Core Conventions) · 8 controls
- ILO Nursing Personnel Convention C149 (1977) · 8 controls
- ILO Tripartite Declaration of Principles concerning Multinational Enterprises (MNE Declaration) · 8 controls
- IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2) · 8 controls
- IRS Publication 1075 · 8 controls
- ISMAP (Japan) · 8 controls
- ITAR - International Traffic in Arms Regulations · 8 controls
- ITU Radio Regulations and Space Security Standards · 8 controls
- Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) · 8 controls
- India Account Aggregator Framework (RBI) · 8 controls
- India CERT-In Cyber Security Directions 2022 · 8 controls
- India DPDP Act · 8 controls
- Indiana Consumer Data Protection Act · 8 controls
- Iowa Consumer Data Protection Act · 8 controls
- Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) · 8 controls
- Japan Act on Specified Commercial Transactions (ASCT) - Digital Services · 8 controls
- Jordan Draft Personal Data Protection Law (2022) · 8 controls
- Kazakhstan Law on Personal Data and Their Protection (No. 94-V) · 8 controls
- Kentucky Consumer Data Protection Act · 8 controls
- Kenya Data Protection Act · 8 controls
- Kids Online Safety Act (KOSA) · 8 controls
- Kolb Experiential Learning Cycle · 8 controls
- Kotter 8-Step Change Model · 8 controls
- Kuwait Data Privacy Protection Regulation (KDPPR, 2021 - CMA Directive) · 8 controls
- LEED v4.1 - Green Building Rating System (US Green Building Council) · 8 controls
- LGPD · 8 controls
- Laos Law on Prevention and Combating Cybercrime (2015) · 8 controls
- Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018) · 8 controls
- Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data · 8 controls
- Law No. 172-13 on the Protection of Personal Data · 8 controls
- Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data · 8 controls
- Law on Personal Data Protection (Official Gazette No. 42/2020) · 8 controls
- Lebanon Electronic Transactions and Personal Data Protection Law (Law No. 81/2018) · 8 controls
- Ley Orgánica de Protección de Datos Personales (LOPDP) · 8 controls
- Liechtenstein DPA · 8 controls
- Lithuania Law on Legal Protection of Personal Data (2018) · 8 controls
- Lloyd's Minimum Standards - Cyber Security · 8 controls
- Lloyd's of London Cyber Insurance Requirements and Underwriting Standards · 8 controls
- Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation) · 8 controls
- MARS-E · 8 controls
- MDS2 (Medical Device) · 8 controls
- MITRE ATT&CK · 8 controls
- MITRE D3FEND · 8 controls
- MTCS (Singapore) · 8 controls
- Malaysia PDPA 2010 · 8 controls
- Malta Data Protection Act (Cap. 586, 2018) · 8 controls
- Maryland Online Data Privacy Act of 2024 · 8 controls
- Maslach Burnout Inventory (MBI) and Areas of Worklife Survey (AWS) Model · 8 controls
- Mauritius DPA · 8 controls
- Mexico LFPDPPP · 8 controls
- MiFID II / MiFIR · 8 controls
- Minnesota Consumer Data Privacy Act · 8 controls
- Modern Slavery Act 2018 (Australia) · 8 controls
- Monetary Authority of Singapore Technology Risk Management Guidelines · 8 controls
- Montana Consumer Data Privacy Act · 8 controls
- Montenegro Law on Personal Data Protection (2023) · 8 controls
- Myanmar Cybersecurity Law (2023) · 8 controls
- NABERS - National Australian Built Environment Rating System · 8 controls
- NAIC Insurance Data Security Model Law (MDL-668) · 8 controls
- NATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production · 8 controls
- NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) · 8 controls
- NATO STANAG 4774 (Confidentiality Metadata Labels) and STANAG 4778 (Metadata Binding) · 8 controls
- NERC CIP · 8 controls
- NHS Healthcare Leadership Model · 8 controls
- NIS2 Directive Implementing Acts · 8 controls
- NIST AI 600-1: Generative AI Profile · 8 controls
- NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) · 8 controls
- NIST Privacy Framework · 8 controls
- NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) · 8 controls
- NIST SP 800-122 · 8 controls
- NIST SP 800-123 · 8 controls
- NIST SP 800-137 · 8 controls
- NIST SP 800-144 · 8 controls
- NIST SP 800-145 · 8 controls
- NIST SP 800-146 · 8 controls
- NIST SP 800-30 · 8 controls
- NIST SP 800-37 · 8 controls
- NIST SP 800-39 · 8 controls
- NIST SP 800-61 · 8 controls
- NIST SP 800-63 Digital Identity Guidelines · 8 controls
- NIST SP 800-63-4 · 8 controls
- NIST SP 800-66 · 8 controls
- NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security · 8 controls
- NIST SP 800-88 · 8 controls
- NIST SP 800-92 · 8 controls
- NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems · 8 controls
- NRF Cybersecurity and Data Privacy Framework (National Retail Federation) · 8 controls
- Nebraska Data Privacy Act · 8 controls
- Netherlands GDPR Implementation Act (UAVG - Uitvoeringswet AVG, 2018) · 8 controls
- Nevada Gaming Control Board Cybersecurity Requirements · 8 controls
- New Hampshire Data Privacy Act · 8 controls
- New Jersey Data Privacy Act · 8 controls
- New Zealand Information Security Manual (NZISM) · 8 controls
- Nigeria Data Protection Act 2023 (NDPA) · 8 controls
- Nigeria Data Protection Regulation (NDPR) · 8 controls
- Nigeria Open Banking Regulatory Framework (CBN, 2023) · 8 controls
- Notifiable Data Breaches Scheme (Australia) · 8 controls
- O-RAN WG11 Security Specification · 8 controls
- OCC Heightened Standards (12 CFR Part 30, Appendix D) · 8 controls
- OECD AI Principles · 8 controls
- OECD Guidelines for Multinational Enterprises on Responsible Business Conduct (2023 Update) · 8 controls
- OECD Recommendation on Artificial Intelligence (2024 Update) · 8 controls
- OECD/G20 Principles of Corporate Governance · 8 controls
- OSFI B-13 · 8 controls
- OWASP API Security Top 10 - 2023 · 8 controls
- OWASP MASVS · 8 controls
- OWASP Top 10 for LLM Applications 2025 · 8 controls
- Oman National Cybersecurity Framework · 8 controls
- Oman Personal Data Protection Law (Royal Decree 6/2022) · 8 controls
- Ontario Accessibility for Ontarians with Disabilities Act (AODA) - IASR Web Standard · 8 controls
- Open Banking Security · 8 controls
- OpenSSF Scorecard · 8 controls
- Oregon Consumer Privacy Act · 8 controls
- PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR) · 8 controls
- PDPA Singapore · 8 controls
- POPIA · 8 controls
- Pakistan Personal Data Protection Bill 2023 · 8 controls
- Panama Law on Personal Data Protection (Law No. 81 of 2019) · 8 controls
- Paraguay Law on Protection of Personal Data (Law No. 6534/2020) · 8 controls
- Personal Data Act (personopplysningsloven) · 8 controls
- Peru DPL · 8 controls
- Philippines Data Privacy Act · 8 controls
- Poland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018) · 8 controls
- Portugal Law No. 58/2019 - Data Protection Implementation Act · 8 controls
- Privacy Act 1988 (Australia) · 8 controls
- Privacy Act 2020 · 8 controls
- Privacy and Other Legislation Amendment Act 2024 (Australia) · 8 controls
- Qatar DPL · 8 controls
- RBI Cybersecurity Framework for Banks · 8 controls
- Rwanda DPL · 8 controls
- South Korea PIPA · 8 controls
- Taiwan PDPA · 8 controls
- US SEC Digital Assets and Crypto Regulatory Framework · 8 controls