- All country
- Australia
- Brazil
- Ecuador
- European Union
- Germany
- Global
- India
- Netherlands
- Qatar
- Saudi Arabia
- Spain
- UAE
- UK
- United States
- All Industries
- Automotive
- Aviation
- Critical
- Energy
- Finance / Banking
- Government / Defense
- Healthcare
- IT / SaaS / Cloud
- Manufacturing
HIPAA
The Standards for Privacy of Individually Identifiable Health Information, commonly known as the HIPAA Privacy Rule.
PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards developed to ensure the protection.
GDPR
GDPR sets several principles that controllers and processors must follow when handling personal data.
BACEN
The BACEN cybersecurity regulations guide financial institutions in Brazil on managing cyber risks and protecting digital banking operations.
PNCiber
PNCiber, Brazil's national cybersecurity policy, establishes strategic guidelines to strengthen cyber resilience across organizations.
ANAC
ANAC cybersecurity guidance helps aviation organizations in Brazil strengthen information security and maintain regulatory readiness.
NIS2
The NIS2 Directive expands cybersecurity requirements for essential and important entities across the European Union.
EU CRA
The EU Cyber Resilience Act introduces cybersecurity requirements for digital products and connected software placed on the EU market.
SEBI CSCRF
SEBI CSCRF helps financial entities in India align cybersecurity practices with risk management, resilience, and reporting expectations.
ISO 27001
ISO/IEC 27001 is the leading global standard focused on information security management systems (ISMS). It provides a framework that helps companies efficiently protect their data through the implementation of an ISMS.
Cyber essentials
Cyber Essentials is a UK cybersecurity certification scheme that helps organizations protect against common online threats.
SOX
The SOX Act also sets rules for the accounting firms that audit public companies and the analysts who publish research on securities.
PDPL
The Personal Data Protection Law (PDPL) regulates the collection, processing, and storage of personal data within Saudi Arabia.
NIST CSF
The NIST CSF provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks.
NIST SP 800-171
NIST SP 800-171 outlines security requirements for protecting controlled unclassified information (CUI) in non-federal systems and organizations.
UAE-NESA
The UAE NESA Information Assurance Standards define cybersecurity controls to strengthen the protection of the nation’s critical information infrastructure.
SAMA CSF
The SAMA cybersecurity framework helps financial institutions manage cyber risks and ensure compliance with Saudi Arabia’s regulatory requirements.
QCF
The Qatar Cybersecurity Framework (QCF) sets security guidelines to protect national information assets and ensure operational resilience.
TISAX
The Trusted Information Security Assessment Exchange (TISAX) ensures consistent information security standards within the automotive industry.
LGPD
The Lei Geral de Proteção de Dados (LGPD) governs how organizations in Brazil collect, process, and protect personal data.
SOC 2
SOC 2 compliance evaluates how service providers manage customer data across security, availability, integrity, confidentiality, and privacy principles.
ECC
The Essential Cybersecurity Controls (ECC) framework defines baseline cybersecurity standards for government entities and critical sectors in Saudi Arabia.
NCA
The National Cybersecurity Authority (NCA) establishes policies and frameworks to enhance cybersecurity governance and safeguard national digital infrastructure.
GAMP 5
GAMP 5 sets out a risk-based approach to specifying, validating, and maintaining GxP computerized systems so they stay fit for intended use and data integrity is preserved.
DPDP
The DPDP Act governs the collection, processing, storage, and transfer of digital personal data, setting consent, security safeguard, and breach-notification duties for Data Fiduciaries.
SUSEP
SUSEP Circular No. 638 establishes cybersecurity requirements for insurance companies, open private pension entities, capitalization companies, and local reinsurers.
ENS
The ENS is Spain's mandatory information security framework for public sector bodies and the private organisations that provide electronic services on their behalf.
SEPS
SEPS norms set minimum information security and electronic-channel controls for savings and credit cooperatives, mutual associations, and central funds.
LOPGDD
The LOPDGDD adapts the EU GDPR into Spanish law and adds a national catalogue of digital rights.
German NIS2
The NIS2UmsuCG transposes the EU NIS2 Directive into German law by replacing the BSI-Gesetz, imposing registration, risk management, and incident-reporting duties on essential and important entities.
INCIBE
INCIBE is Spain's national cybersecurity institute and operates INCIBE-CERT, the incident response centre for citizens and private-sector entities.
21 CFR Part 11
FDA rule setting the conditions under which electronic records and electronic signatures are considered trustworthy and equivalent to paper, requiring system validation, secure audit trails, and access controls.
DORA
Regulation (EU) 2022/2554 imposing uniform ICT risk management, incident reporting, resilience testing, and third-party provider oversight on financial entities, applicable since 17 January 2025.
BIO2
The Baseline Informatiebeveiliging Overheid 2.0 is the ISO 27001/27002-based information security baseline for Dutch government bodies, and serves as the route by which the government sector meets its Cyberbeveiligingswet duty of care.
NEN 7510
Dutch sector standard for information security management in healthcare, building on ISO 27001/27002 with additional controls for patient data; current version is NEN 7510-1:2024.
Cyberbeveiligingswet (Cbw)
The Cyberbeveiligingswet transposes the EU NIS2 Directive into Dutch law and replaces the Wbni, imposing registration, duty of care, incident reporting, and management accountability on essential and important entities across 18 sectors; in force since 15 August 2026. Rijksoverheid Nctv
KRITIS-Dachgesetz (KRITISDachG)
Transposes the EU CER Directive (2022/2557) and establishes Germany's first cross-sector federal framework for the physical resilience of critical installations across ten sectors, in force since 17 March 2026.
IT-Sicherheitskatalog
Bundesnetzagentur catalogues issued under §11(1a) and §11(1b) EnWG, requiring electricity and gas network operators and energy installation operators to run a certified ISO 27001/27019-based ISMS.
Essential Eight
ASD/ACSC baseline of eight prioritised mitigation strategies scored across Maturity Levels 0–3, mandatory for non-corporate Commonwealth entities and widely adopted as a general Australian security benchmark.
Ready to simplify compliance and stay audit-ready with Log360?
Automate compliance checks, streamline audit reporting, and ensure continuous visibility across your IT environment.
