MASTER

COMPLIANCE

With 33+ global compliances and comprehensive Compliance support, we enable our customers to operate with greater confidence in a complex threat landscape.

Security team evaluating CSPM solutions based on cloud visibility, compliance, risk detection, and remediation capabilities.
SOC2

System and Organization Controls 2 (SOC 2)

Trust and security framework for service organizations

SOC 2 provides a framework for evaluating how service organizations protect customer data and operate effective controls across security, availability, processing integrity, confidentiality, and privacy. It helps organizations demonstrate that their systems and processes are designed and operated with appropriate safeguards.

gdpr

HIPAA Compliance Framework

U.S. healthcare data protection framework

HIPAA establishes requirements for protecting protected health information (PHI) and maintaining the security and privacy of healthcare data. It focuses on safeguards for access control, data protection, audit controls, security management, and protection against unauthorized disclosure or access.

CCM

CSA Cloud Controls Matrix (CCM) v4.0.13

Cloud security control framework

The CSA Cloud Controls Matrix (CCM) provides a structured set of cloud-specific security controls for assessing and managing security risks across cloud environments. Version 4.0.13 covers areas including governance, risk management, identity and access management, data security, application security, infrastructure security, and operational resilience.

ISO27001

ISO/IEC 27001 Information Security Management Standard 2022

International standard for information security management

ISO/IEC 27001:2022 defines requirements for establishing, maintaining, and continually improving an Information Security Management System (ISMS). It uses a risk-based approach to protect information assets through organizational, people, physical, and technological security controls.

Fedramp

FedRAMP 20x Key Security Indicators (KSIs) – Low Impact Level v25.05C

Modernized U.S. federal cloud security assessment

FedRAMP 20x introduces a more automated and evidence-driven approach to assessing cloud service security. The Low Impact Level KSIs provide measurable security indicators for evaluating areas such as access control, asset management, vulnerability management, logging, incident response, and continuous monitoring.

Cloud Computing CCC

Cloud Computing Compliance Criteria Catalogue (C5) 2025

German cloud security and compliance framework

The C5 framework, developed by Germany’s Federal Office for Information Security (BSI), defines security requirements for cloud service providers and helps organizations assess the security of cloud services. It covers areas including information security, access control, operations, data protection, and organizational security.

NIS2

NIS2 – Network and Information Security Directive

EU cybersecurity and resilience directive

NIS2 establishes cybersecurity risk-management and incident-reporting requirements for organizations operating in critical and important sectors across the European Union. It strengthens requirements around risk management, supply-chain security, access control, incident handling, business continuity, and security governance.

MitreAttack

MITRE ATT&CK Compliance Framework

Threat-informed cybersecurity knowledge base

MITRE ATT&CK is a globally used knowledge base that maps real-world adversary tactics and techniques observed across cyber attacks. It helps organizations evaluate security capabilities against threats such as credential access, privilege escalation, persistence, lateral movement, discovery, and data exfiltration.

pci dss

Payment Card Industry Data Security Standard (PCI DSS) v4.0

Global standard for payment card data security

PCI DSS v4.0 defines security requirements for organizations that store, process, or transmit payment card data. It strengthens protection through requirements covering access control, secure configurations, vulnerability management, encryption, logging, monitoring, authentication, and regular security testing.

rbi scf

Reserve Bank of India (RBI) Cyber Security Framework

Indian cybersecurity framework for financial institutions

The RBI Cyber Security Framework establishes security and governance requirements for banks and regulated financial entities in India. It emphasizes cyber-risk management, access controls, vulnerability management, security monitoring, incident response, data protection, and resilience against cyber threats.

dora

Digital Operational Resilience Act (DORA)

EU framework for financial-sector digital resilience

DORA establishes requirements for managing information and communication technology (ICT) risks across the European financial sector. It focuses on ICT risk management, resilience testing, incident reporting, third-party risk, and continuous monitoring of critical technology services.

gdpr

ASD Essential Eight Maturity Model – Maturity Level One (AWS)

Foundational Australian cybersecurity baseline

Developed by the Australian Signals Directorate (ASD), the Essential Eight provides foundational security practices to mitigate common cyber threats. Maturity Level One focuses on application control, patching, secure configuration, restricted administrative privileges, and multi-factor authentication.

gdpr

AWS Account Security Onboarding

AWS account security baseline

A foundational security baseline for establishing secure AWS accounts before workloads are deployed. It focuses on essential account-level practices such as identity and access management, logging, monitoring, and secure configuration.

gdpr

AWS AI Security Framework 1

Security framework for AWS AI environments

A security framework focused on protecting AI workloads and supporting infrastructure on AWS, with emphasis on secure access, data protection, monitoring, and responsible configuration of AI resources.

AWS Control Center

AWS Audit Manager Control Tower Guardrails

AWS governance and compliance controls

AWS Control Tower guardrails establish preventive and detective controls for governing AWS environments, while AWS Audit Manager helps collect evidence against defined requirements. Together, they provide a structured approach to enforcing account-level governance, security configurations, and ongoing compliance across AWS workloads.

gdpr

AWS Foundational Security Best Practices

AWS security baseline for foundational protection

A set of AWS-recommended security controls designed to identify and reduce common security risks across AWS accounts and workloads. It focuses on establishing secure configurations across identity, permissions, logging, monitoring, network controls, and data protection.

 

gdpr

AWS Foundational Technical Review

AWS architecture and operational readiness assessment

The AWS Foundational Technical Review (FTR) evaluates solutions against key AWS best practices to identify security, reliability, operational, and architectural risks. It helps organizations establish a stronger technical foundation for running and scaling workloads on AWS.

gdpr

AWS Well-Architected Framework – Reliability Pillar

Building resilient and recoverable AWS workloads

The Reliability Pillar focuses on designing AWS workloads that can withstand failures, recover quickly, and continue operating as demand changes. It covers resilient architecture, automated recovery, change management, monitoring, backup and disaster recovery, and capacity management.

AWS FTR

AWS Well-Architected Framework – Security Pillar

Protecting AWS workloads through security-focused architecture

The Security Pillar provides guidance for protecting AWS workloads, systems, and data throughout their lifecycle. It focuses on identity and access management, detection, infrastructure protection, data security, incident response, and maintaining secure operations.

gdpr

CIS Amazon Web Services Foundations Benchmark

AWS security configuration benchmark

The CIS AWS Foundations Benchmark provides prescriptive recommendations for securely configuring AWS accounts and core services. It helps organizations identify configuration weaknesses across areas such as IAM, logging, monitoring, networking, and security settings.

gdpr

CISA Cyber Essentials Framework

Foundational cybersecurity practices for organizations

CISA Cyber Essentials provides a practical starting point for organizations to strengthen their cybersecurity and protect critical systems, data, and services. It emphasizes foundational practices such as asset management, identity and access control, secure configuration, vulnerability management, and incident preparedness.

Fedramp

FedRAMP Low Revision 4

U.S. federal cloud security baseline

FedRAMP Low Revision 4 defines security controls and assessment requirements for cloud services handling federal information at the Low impact level. It establishes a baseline for protecting the confidentiality, integrity, and availability of federal data in cloud environments.

Fedramp

FedRAMP Moderate Revision 4

U.S. federal cloud security baseline

FedRAMP Moderate Revision 4 defines a comprehensive set of security controls for cloud services handling federal information with moderate impact. It provides stronger security and assessment requirements for protecting sensitive federal data and supporting secure cloud operations.

FFIEC

FFIEC Cybersecurity Assessment Tool Framework

Cybersecurity assessment framework for financial institutions

The FFIEC Cybersecurity Assessment Tool helps financial institutions evaluate their cybersecurity preparedness against inherent risks and identify areas requiring stronger controls. It supports structured assessment of cybersecurity maturity across governance, threat intelligence, resilience, risk management, and security practices.

gdpr

GDPR Compliance Framework

European data protection and privacy framework

The General Data Protection Regulation (GDPR) establishes requirements for protecting personal data and privacy of individuals in the European Union. It emphasizes data protection, privacy by design, access controls, breach management, data retention, and accountability throughout the handling of personal information.

gdpr

GxP (Good Practices) 21 CFR Part 11

U.S. requirements for electronic records and signatures

21 CFR Part 11 establishes requirements for electronic records and electronic signatures used in FDA-regulated industries. It focuses on ensuring records are trustworthy, reliable, traceable, and protected through controls such as access management, audit trails, validation, and data integrity.

gdpr

GxP (Good Practices) EU Annex 11

European requirements for computerized systems

EU GMP Annex 11 defines requirements for computerized systems used in regulated pharmaceutical and life-sciences environments. It emphasizes data integrity, system validation, access control, audit trails, security, and controlled management of electronic records.

ISO27001

ISO/IEC 27001 Information Security Management Standard 2013

International information security management standard

ISO/IEC 27001:2013 provides requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It takes a risk-based approach to protecting information assets through security controls covering access, operations, asset management, communications, and business continuity.

gdpr

KISA ISMS Compliance Framework 2023

South Korean information security management framework

The KISA Information Security Management System (ISMS) framework provides requirements for organizations to establish and operate systematic information security management practices in South Korea. It covers areas such as security governance, access control, asset management, risk management, incident response, and continuous security management.

gdpr

NIST Security and Privacy Controls

NIST security control framework for protecting information systems

NIST security control publications provide structured requirements for protecting sensitive information and information systems through risk-based security and privacy practices. They address areas including access control, system security, incident response, configuration management, system integrity, and continuous monitoring.

NIST

NIST Cybersecurity Framework (CSF)

Risk-based cybersecurity framework

The NIST Cybersecurity Framework provides a flexible, risk-based approach for organizations to manage and strengthen cybersecurity. It helps organizations identify and prioritize cybersecurity risks across governance, protection, detection, response, and recovery activities.

 

pci dss

Payment Card Industry Data Security Standard (PCI DSS) v3.2.1

Global standard for payment card data security

PCI DSS v3.2.1 establishes security requirements for organizations that store, process, or transmit payment card data. It focuses on protecting cardholder data through secure configurations, access controls, vulnerability management, monitoring, encryption, and regular security testing.

SecNum

SecNumCloud Référentiel d'Exigences v3.2

French cloud security qualification framework

Developed by France’s National Cybersecurity Agency (ANSSI), SecNumCloud defines stringent security requirements for trusted cloud service providers handling sensitive information. Version 3.2 covers technical, operational, organizational, and legal security requirements for cloud services.

gdpr

CIS Microsoft Azure Foundations Benchmark

Azure security configuration benchmark

The CIS Microsoft Azure Foundations Benchmark provides prescriptive recommendations for securely configuring Azure environments and reducing common security risks. It focuses on foundational controls across identity and access management, logging, monitoring, networking, and secure Azure service configuration.

gdpr

CIS Google Cloud Platform Foundation Benchmark

Google Cloud security configuration benchmark

The CIS Google Cloud Platform Foundation Benchmark provides prescriptive recommendations for securely configuring GCP environments and reducing common security risks. It focuses on foundational controls across identity and access management, logging, monitoring, networking, and secure configuration of Google Cloud services.

ENS RD 311

ENS RD 311/2022 – Categoría Alta

Spanish national security framework for information systems

The Spanish National Security Framework (ENS), established under Royal Decree 311/2022, defines security principles and requirements for protecting information systems used by public-sector organizations and service providers. The High category applies to systems where a security incident could have significant consequences for the organization or the services it provides.

gdpr

Common Cloud Controls Catalog (CCC) v2025.10

Standardized cloud security control framework

The Common Cloud Controls Catalog (CCC) provides a common set of cloud security controls designed to create consistency across cloud security assessments. It helps organizations evaluate cloud environments against controls covering areas such as identity, data security, infrastructure protection, monitoring, and governance.

gdpr

CIS Controls v8.1

Prioritized cybersecurity safeguards

The CIS Controls provide a prioritized set of cybersecurity safeguards designed to help organizations defend against common and evolving cyber threats. Version 8.1 organizes these safeguards around areas such as asset management, secure configuration, account management, vulnerability management, audit logging, and incident response.

Scroll to top