Compliance Framework
What is Compliance Framework?
A structured set of guidelines, best practices, and standards that organisations follow to meet regulatory requirements, manage risks, and demonstrate compliance. Examples include ISO 27001, SOC 2, NIST CSF, and GDPR.
Terms that appear alongside compliance framework
Each of these is named in at least one of the same controls as compliance framework. The number is how many controls name both.
- compliance 5 shared controls
- industry self regulation 3 shared controls
- ccpa 3 shared controls
- state privacy laws 3 shared controls
- gdpr 3 shared controls
- privacy notice 3 shared controls
- privacy by design 2 shared controls
- glba 2 shared controls
Frameworks that govern compliance framework
What the standards actually require on compliance framework
Requirements naming compliance framework across 5 standards, quoted from the control text.
Coordination positions ICDPA within the broader US and international privacy regulatory landscape. (1) Utah UCPA Template Parent: Iowa CDPA most closely follows Utah CDPA (UCPA effective 31 December 2023) template - shared narrow Sale definition + opt-out (NOT...
ICDPA-Coord-USStatePrivacy-UCPA-Template-VCDPA-CPA-CTDPA-Federal-FTC-GDPR-International · Iowa CDPA Coordination - Utah CDPA Template Parent + US State Privacy Patchwork + Federal Sectoral (HIPAA/GLBA/FCRA/FERPA/COPPA) + FTC Section 5 + GDPR + India DPDP + International →Institute of Risk Management (IRM) Enterprise Risk Management (ERM) Framework principally embodied in A Risk Management Standard published 2002 + co-authored by AIRMIC (Association of Insurance and Risk Managers in Industry and Commerce) + ALARM (UK Public Ris...
IRM-Scope-ARM-Standard-2002-AIRMIC-ALARM-IRM-ISOGuide73-ISO31000-Definitions-Upside-Downside · IRM ERM Framework Scope + A Risk Management Standard (2002) + Co-Authored AIRMIC/ALARM/IRM + ISO Guide 73 Vocabulary + Upside/Downside Risk + CMIRM Qualification →Coordination positions INCDPA within the broader US and international privacy regulatory landscape. (1) US State Privacy Law Patchwork: 20+ comprehensive US state privacy laws as of 2026 (California CCPA/CPRA + Virginia VCDPA + Colorado CPA + Utah UCPA + Conne...
INCDPA-Coord-USStatePrivacy-VCDPA-CPA-CTDPA-CCPA-Federal-FTC-DPDP-GDPR-International · Indiana CDPA Coordination - US State Privacy Laws (Virginia/Colorado/Connecticut/Utah/Texas/Iowa+) + Federal Sectoral (HIPAA/GLBA/FCRA/FERPA/COPPA) + FTC Section 5 + GDPR + India DPDP + International Privacy Frameworks →Integrate ATT&CK with broader cybersecurity ecosystem and frameworks. MITRE Engenuity ATT&CK Evaluations - rigorous evaluations of cybersecurity vendor solutions against real adversary tradecraft (APT3 + APT29 + Carbanak/FIN7 + Wizard Spider + Sandworm + Turla...
MITRE-ATTACK-Integration-Engenuity-Evaluations-CALDERA-NIST-CSF-CIS-Lockheed-Kill-Chain-Diamond-Model-STIX-TAXII · MITRE ATT&CK Integration + MITRE Engenuity + ATT&CK Evaluations + CALDERA + NIST CSF + CIS + STIX + TAXII →Per OFAC Sanctions Compliance Framework: Senior Management Commitment to Sanctions Compliance + Board oversight + resources + clear accountability.
USOFAC-1 · Senior Management Commitment →Questions people ask about compliance framework
What is Compliance Framework?
Why is Compliance Framework important for compliance?
Which compliance frameworks address Compliance Framework?
Where can I learn more about Compliance Framework?
See how Compliance Framework applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.