CompliverseAI
Framework guides

Every framework, mapped and drawn.

Overview, scope, structure and the road to compliance for each one. Different frameworks, one connected data model underneath.

ISO 27001
Information security

The international standard for an Information Security Management System. The 2022 revision groups its 93 Annex A controls into four themes.

GlobalOpen guide
SOC 2
Trust services

An attestation report by a CPA firm on how well a service organisation's controls meet the AICPA Trust Services Criteria.

Global (US-origin)Open guide
SAMA CSF
Banking cyber

The Saudi Central Bank's mandatory cyber security framework for the financial sector, assessed on a maturity model from level 0 to 5.

Saudi ArabiaOpen guide
NCA ECC
National cyber

The National Cybersecurity Authority's baseline controls for protecting Saudi Arabia's information and technology assets, structured into five domains.

Saudi ArabiaOpen guide
PCI DSS
Payment security

The baseline of technical and operational requirements that protect payment account data, organised as twelve requirements under six goals.

GlobalOpen guide
NIST CSF
Cyber framework

A voluntary framework that organises cybersecurity outcomes into six functions, from governance through to recovery, for any organisation to profile against.

Global (US-origin)Open guide
GDPR
Data protection

The EU regulation governing how personal data is collected and used, built on seven principles and a set of enforceable data-subject rights.

European UnionOpen guide
CBUAE
Banking tech risk

The Central Bank of the UAE's expectations for how licensed financial institutions govern technology and cyber risk across their operations.

United Arab EmiratesOpen guide
SBP ETGRMF
Banking tech

The State Bank of Pakistan's framework for governing enterprise technology and technology risk across regulated financial institutions.

PakistanOpen guide
MAS TRM
Tech risk

The Monetary Authority of Singapore's guidelines on managing technology risk, from governance and development through to resilience and cyber operations.

SingaporeOpen guide
ISO 22301
Business continuity

The international standard for a Business Continuity Management System, a governed way to prepare for, respond to and recover from disruption.

GlobalOpen guide
DORA
Operational resilience

The EU regulation making financial entities operationally resilient to ICT disruption, built on five pillars from risk management to testing.

European UnionOpen guide
NIS2
Cyber directive

The EU directive raising the cybersecurity baseline across essential and important sectors, with management held accountable for compliance.

European UnionOpen guide
HIPAA
Health data

The US law protecting health information, with Security Rule safeguards, a Privacy Rule and a Breach Notification Rule.

United StatesOpen guide
COBIT 2019
IT governance

ISACA's framework for the governance and management of enterprise IT, organised into forty objectives across five domains.

GlobalOpen guide
SOX ITGC
Financial reporting

The IT general controls that underpin Sarbanes-Oxley, giving assurance over the systems behind financial reporting.

United StatesOpen guide
SWIFT CSCF
Payments network

The mandatory and advisory controls SWIFT users implement to secure their local payments environment, grouped under security principles.

GlobalOpen guide
ARAMCO CCC
Supplier cyber

Saudi Aramco's third-party cybersecurity standard, where suppliers earn a Cybersecurity Compliance Certificate before doing business.

Saudi ArabiaOpen guide
CIS Controls
Security baselines

A prioritised set of eighteen controls and their safeguards, ordered by the attacks they stop, with Implementation Groups for phasing.

GlobalOpen guide
HITRUST
Health trust

A certifiable framework that harmonises HIPAA, ISO, NIST, PCI and more into one set of prescriptive, scalable control domains.

Global (US-origin)Open guide
NIST 800-53
Federal controls

The US federal catalogue of security and privacy controls, organised into twenty families and applied through Low, Moderate and High baselines.

United StatesOpen guide
SBP Cloud Outsourcing
Banking cloud

The State Bank of Pakistan's conditions for banks adopting cloud services, from governance and due diligence to data residency and a workable exit.

PakistanOpen guide
SBP Internet Banking
Banking channels

The State Bank of Pakistan's security requirements for internet and mobile banking, from strong authentication to fraud monitoring.

PakistanOpen guide
SABIC CyberTrust
Supplier cyber

SABIC's cybersecurity requirements for the third parties in its supply chain, a supplier assurance standard in the spirit of Aramco's.

Saudi ArabiaOpen guide
Sri Lanka BSS
Banking cyber

The Central Bank of Sri Lanka's Baseline Security Standard for licensed banks, a mandatory floor of cybersecurity controls.

Sri LankaOpen guide