Every framework, mapped and drawn.
Overview, scope, structure and the road to compliance for each one. Different frameworks, one connected data model underneath.

The international standard for an Information Security Management System. The 2022 revision groups its 93 Annex A controls into four themes.

An attestation report by a CPA firm on how well a service organisation's controls meet the AICPA Trust Services Criteria.

The Saudi Central Bank's mandatory cyber security framework for the financial sector, assessed on a maturity model from level 0 to 5.
The National Cybersecurity Authority's baseline controls for protecting Saudi Arabia's information and technology assets, structured into five domains.

The baseline of technical and operational requirements that protect payment account data, organised as twelve requirements under six goals.

A voluntary framework that organises cybersecurity outcomes into six functions, from governance through to recovery, for any organisation to profile against.

The EU regulation governing how personal data is collected and used, built on seven principles and a set of enforceable data-subject rights.
The Central Bank of the UAE's expectations for how licensed financial institutions govern technology and cyber risk across their operations.

The State Bank of Pakistan's framework for governing enterprise technology and technology risk across regulated financial institutions.
The Monetary Authority of Singapore's guidelines on managing technology risk, from governance and development through to resilience and cyber operations.

The international standard for a Business Continuity Management System, a governed way to prepare for, respond to and recover from disruption.

The EU regulation making financial entities operationally resilient to ICT disruption, built on five pillars from risk management to testing.

The EU directive raising the cybersecurity baseline across essential and important sectors, with management held accountable for compliance.

The US law protecting health information, with Security Rule safeguards, a Privacy Rule and a Breach Notification Rule.

ISACA's framework for the governance and management of enterprise IT, organised into forty objectives across five domains.

The IT general controls that underpin Sarbanes-Oxley, giving assurance over the systems behind financial reporting.
The mandatory and advisory controls SWIFT users implement to secure their local payments environment, grouped under security principles.
Saudi Aramco's third-party cybersecurity standard, where suppliers earn a Cybersecurity Compliance Certificate before doing business.

A prioritised set of eighteen controls and their safeguards, ordered by the attacks they stop, with Implementation Groups for phasing.

A certifiable framework that harmonises HIPAA, ISO, NIST, PCI and more into one set of prescriptive, scalable control domains.

The US federal catalogue of security and privacy controls, organised into twenty families and applied through Low, Moderate and High baselines.

The State Bank of Pakistan's conditions for banks adopting cloud services, from governance and due diligence to data residency and a workable exit.

The State Bank of Pakistan's security requirements for internet and mobile banking, from strong authentication to fraud monitoring.
SABIC's cybersecurity requirements for the third parties in its supply chain, a supplier assurance standard in the spirit of Aramco's.
The Central Bank of Sri Lanka's Baseline Security Standard for licensed banks, a mandatory floor of cybersecurity controls.