Cybersecurity & compliance glossary
123 frameworks, standards and regulations — what each one is, who it applies to, and a full guide behind every entry. Written by CERT-In empanelled auditors and PCI QSAs who assess against them.
A
- ABDM / Health Data Security AuditNational Health Authority · India
- Security and privacy audit for the Ayushman Bharat Digital Mission ecosystem.
- APRA CPS 234 (Australia)APRA (Australia) · Australia
- Information security prudential standard for APRA-regulated entities.
- ASD Essential Eight (Australia)Australian Signals Directorate (ACSC) · Australia
- Eight prioritised mitigation strategies against cyber threats.
- Australia ISM & IRAPASD / ACSC (Australia) · Australia
- Australian government security manual and assessor program.
B
- Bharat Bill Payment System (BBPS) AuditNPCI Bharat BillPay (NBBL) · India
- System audit requirements for BBPS operating units in the bill-payment ecosystem.
- BSI C5 (Cloud Computing Compliance Criteria Catalogue)BSI (Germany) · Germany / EU
- German catalogue of cloud security controls attested by auditors.
C
- Canada OSFI B-13 (Technology & Cyber Risk)OSFI (Canada) · Canada
- Canadian guideline on technology and cyber risk for FRFIs.
- CCA / eSign / Digital Signature AuditCCA (MeitY) · India
- Audit of Certifying Authorities, eSign and digital-signature ecosystems.
- CCPA / CPRAState of California · United States
- California’s consumer privacy law and its CPRA amendments.
- CEA Power-Sector Cyber SecurityCentral Electricity Authority · India
- Cybersecurity in the power/electricity sector under CEA regulations.
- CERT-In Comprehensive Cyber Security AuditCERT-In, MeitY · India
- Cybersecurity audit under CERT-In’s 2025 audit policy guidelines.
- CERT-In Directions (Cyber Incident Reporting)CERT-In, MeitY · India
- CERT-In’s directions on incident reporting, log retention and security practices.
- China PIPL / Cybersecurity Law / MLPSPRC Government · China
- China's data-protection, cybersecurity and grading regime.
- CIS ControlsCenter for Internet Security · Global
- A prioritised set of 18 safeguards that stop the most common attacks.
- CMMCUS Department of Defense · United States
- Cybersecurity Maturity Model Certification for the US defense supply chain.
- CMMI V3.0ISACA / CMMI Institute · Global
- Capability Maturity Model Integration — a model for building repeatable, measurable, continually improving organisational capability.
- COBITISACA · Global
- A governance and management framework for enterprise information and technology.
- Common Criteria (ISO/IEC 15408) / IC3SCommon Criteria / STQC · Global / India
- International product security evaluation and certification.
- COSO Internal Control FrameworkCOSO · Global
- The leading framework for internal control and enterprise risk management.
- CryptoCurrency Security Standard (CCSS)C4 (CryptoCurrency Certification Consortium) · Global
- Security standard for systems that use cryptocurrencies.
- CSA AI Controls Matrix (AICM)Cloud Security Alliance · Global
- CSA control matrix for securing and governing AI systems.
- CSA CCM & STARCloud Security Alliance · Global
- The Cloud Controls Matrix and STAR programme for cloud security assurance.
- Cyber Essentials (UK)UK NCSC / IASME · United Kingdom
- A UK government-backed certification for baseline cyber hygiene.
- Cyber Risk Institute (CRI) ProfileCyber Risk Institute · Global (Finance)
- Harmonised cybersecurity profile for the financial sector.
- Cybersecurity Capability Maturity Model (C2M2)US DOE · Global
- Maturity model to evaluate and improve cyber capabilities.
D
- DORA (Digital Operational Resilience Act)European Union · EU
- EU regulation on ICT and operational resilience for financial entities.
- DPDP Act, 2023 (India)MeitY, Government of India · India
- India’s data-protection law governing the personal data of data principals.
E
- EU AI ActEuropean Union · EU
- Risk-tiered EU regulation governing AI systems and models.
- EU-US Data Privacy FrameworkUS Dept of Commerce / EC · EU / US
- Transatlantic mechanism for lawful personal-data transfers.
F
- FBI CJIS Security PolicyUS FBI · United States
- Security policy protecting US criminal-justice information.
- FedRAMPUS FedRAMP PMO / GSA · United States
- The US government authorisation programme for cloud services.
- FFIEC Cybersecurity AssessmentFFIEC · United States
- US banking regulators' cyber maturity and IT examination framework.
- FIPS 140-3 Cryptographic Module ValidationNIST / CMVP · Global
- Validation of cryptographic modules to US federal standards.
G
- GDPREuropean Union · EU / EEA
- The EU regulation governing the processing of personal data.
- GIGW & Web Accessibility (WCAG) AuditMeitY / W3C · India / Global
- Government website guidelines and web accessibility compliance audit.
- GLBA & FTC Safeguards RuleUS FTC · United States
- US financial-privacy and information-safeguards requirements.
H
- HIPAAUS Dept. of Health & Human Services · United States
- US law protecting the privacy and security of protected health information (PHI).
- HITRUST CSFHITRUST Alliance · Global / US
- A certifiable security framework that harmonises HIPAA, ISO, NIST, PCI and more.
I
- IEC 62443 (OT/ICS Security)IEC / ISA · Global
- The standard for cybersecurity of industrial automation and control systems.
- IFSCA Cyber Resilience AuditIFSCA · India (GIFT IFSC)
- Cybersecurity and resilience audit for regulated entities in GIFT IFSC.
- IRDAI Information & Cyber SecurityIRDAI · India
- Information and cybersecurity guidelines for insurers and intermediaries.
- ISO 22301ISO · Global
- The international standard for business continuity management systems (BCMS).
- ISO 27799 (Health Informatics Security)ISO · Global
- Health-sector application of ISO 27002 controls.
- ISO 28000 (Supply Chain Security)ISO · Global
- Management system for security of the supply chain.
- ISO 9001 (Quality)ISO · Global
- The international standard for a quality management system (QMS).
- ISO/IEC 20000-1ISO / IEC · Global
- The international standard for an IT service management system (SMS).
- ISO/IEC 27001ISO / IEC · Global
- The international standard for an Information Security Management System (ISMS).
- ISO/IEC 27005 (Information Security Risk Management)ISO / IEC · Global
- Guidance for managing information security risk.
- ISO/IEC 27017ISO / IEC · Global
- Cloud-specific information security controls extending ISO 27002.
- ISO/IEC 27018ISO / IEC · Global
- Protection of personal data (PII) in public cloud services.
- ISO/IEC 27031 (ICT Continuity)ISO / IEC · Global
- ICT readiness for business continuity.
- ISO/IEC 27035 (Incident Management)ISO / IEC · Global
- The standard for information security incident management.
- ISO/IEC 27701ISO / IEC · Global
- A privacy extension (PIMS) to ISO 27001 for managing personal data.
- ISO/IEC 29147 & 30111 (Vulnerability Disclosure)ISO / IEC · Global
- Standards for vulnerability disclosure and handling.
- ISO/IEC 42001 (AI Management)ISO / IEC · Global
- The management-system standard for artificial intelligence (AIMS).
- ISO/SAE 21434 & UNECE R155 (Automotive Cybersecurity)ISO / SAE / UNECE · Global
- Cybersecurity engineering for road vehicles.
J
- Japan ISMAPGovernment of Japan · Japan
- Japanese assessment program for government cloud services.
K
- Korea ISMS-PKISA (Korea) · South Korea
- Korean certification for information security and privacy management.
L
- LGPD (Brazil)Brazil (ANPD) · Brazil
- Brazil’s General Data Protection Law for personal data.
M
- MAS TRM (Singapore)Monetary Authority of Singapore · Singapore
- Technology Risk Management guidelines for Singapore financial institutions.
- Medical Device CybersecurityFDA / IEC · Global
- Cybersecurity for medical devices across the product lifecycle.
- MITRE ATLAS (AI/ML Threats)MITRE · Global
- A knowledge base of adversarial threats to AI and machine-learning systems.
- MITRE ATT&CKMITRE · Global
- A knowledge base of real-world adversary tactics and techniques.
- MITRE D3FENDMITRE · Global
- A knowledge base of defensive countermeasures mapped to ATT&CK.
N
- NCIIPC Critical Information Infrastructure AuditNCIIPC · India
- Protection and audit of Critical Information Infrastructure in India.
- NERC CIP (Critical Infrastructure Protection)NERC · North America
- Mandatory cyber standards for the North American bulk power system.
- NIS2 DirectiveEuropean Union · EU
- EU directive raising cybersecurity for essential and important entities.
- NIST AI Risk Management FrameworkNIST · Global
- Voluntary framework to manage risks of AI systems.
- NIST Cybersecurity Framework (CSF 2.0)NIST · Global
- A voluntary, outcome-based framework for managing and reducing cybersecurity risk.
- NIST Ransomware Risk Management ProfileNIST · Global
- CSF profile to prevent, detect and recover from ransomware.
- NIST Secure Software Development Framework (SSDF)NIST · Global
- Secure software development practices (SP 800-218).
- NIST SP 800-161 (C-SCRM)NIST · Global
- Cyber supply-chain risk management practices for systems.
- NIST SP 800-171NIST · Global / US
- Protecting Controlled Unclassified Information (CUI) in non-federal systems.
- NIST SP 800-53NIST · Global
- A comprehensive catalog of security and privacy controls for information systems.
- NIST SP 800-63 (Digital Identity)NIST · Global
- Digital identity guidelines — identity proofing, authentication and federation.
- NIST SP 800-82 (OT Security)NIST · Global
- Guide to securing operational technology and control systems.
- NPCI Product Security Audits (IMPS, RuPay, AePS, NACH, NFS, FASTag, CTS)NPCI · India
- Security audits across NPCI’s payment products beyond UPI.
- NPCI UPI / TPAP Security AuditNPCI · India
- Security audit requirements for UPI Third-Party Application Providers and PSP banks.
- NYDFS Part 500 Cybersecurity RegulationNY Dept of Financial Services · United States
- New York cybersecurity rules for financial-services companies.
O
- OWASP API Security Top 10OWASP · Global
- The most critical security risks to APIs.
- OWASP ASVSOWASP · Global
- A detailed, testable standard for verifying application security.
- OWASP Top 10OWASP · Global
- The standard awareness document for the most critical web application risks.
P
- PCI DSSPCI SSC · Global
- The security standard for organisations that handle payment card data.
- PCI PIN & P2PEPCI SSC · Global
- Standards for secure PIN management and point-to-point encryption of card data.
- PCI Software Security Framework & 3DSPCI SSC · Global
- PCI standards for payment software security and 3-D Secure.
- PDPA (Singapore)PDPC (Singapore) · Singapore
- Singapore’s Personal Data Protection Act.
- PFRDA Cyber Security & IS AuditPFRDA · India
- Information and cybersecurity audit for the pension (NPS) ecosystem.
- PIPEDA (Canada)Canada (OPC) · Canada
- Canada’s federal private-sector privacy law.
- POPIA (South Africa)South Africa (Information Regulator) · South Africa
- South Africa’s Protection of Personal Information Act.
Q
- Qatar National Information Assurance (NIA)Qatar (NCSA) · Qatar
- Qatar’s National Information Assurance standard for information security.
R
- RBI Account Aggregator FrameworkReserve Bank of India · India
- The consent-based financial-data-sharing framework in India.
- RBI Co-operative Bank Cyber Security FrameworkReserve Bank of India · India
- Basic and Comprehensive (graded) cybersecurity framework audit for UCBs.
- RBI Cyber Security Framework for BanksReserve Bank of India · India
- Baseline cybersecurity and resilience controls mandated by RBI for banks.
- RBI Digital Lending (DLA/LSP) AuditReserve Bank of India · India
- Technical and privacy due-diligence audit of digital lending apps and service providers.
- RBI Digital Payment Security ControlsReserve Bank of India · India
- RBI’s master direction on securing internet, mobile and card digital payment channels.
- RBI Fraud Risk Management AuditReserve Bank of India · India
- Audit of fraud governance, monitoring and reporting technology for REs.
- RBI FREE-AI & AI Model Risk ManagementReserve Bank of India · India
- RBI’s AI governance regime for banks, NBFCs and regulated entities — the FREE-AI framework (Aug 2025) plus the draft Model Risk Management guidance (2026).
- RBI Housing Finance Company (HFC) IS & Cyber AuditReserve Bank of India · India
- Information systems and cybersecurity audit for housing finance companies.
- RBI IT Framework for NBFCsReserve Bank of India · India
- RBI’s IT governance, security and audit expectations for NBFCs.
- RBI IT Governance, Risk, Controls & AssuranceReserve Bank of India · India
- RBI’s master direction on IT governance, risk, controls and IS assurance practices.
- RBI IT Outsourcing Directions AuditReserve Bank of India · India
- Audit of IT outsourcing, cloud and supply-chain risk for RBI-regulated entities.
- RBI KYC / V-CIP Technology AuditReserve Bank of India · India
- Audit of KYC and Video-based Customer Identification Process technology controls.
- RBI Payment Aggregators & Payment Gateways (PA-PG)Reserve Bank of India · India
- Authorisation and security requirements for payment aggregators and payment gateways.
- RBI Prepaid Payment Instruments (PPI)Reserve Bank of India · India
- Rules for issuing and operating prepaid payment instruments (wallets, cards).
- RBI System Audit Report (SAR) & Data LocalisationReserve Bank of India · India
- Annual system audit and payment-data localisation assurance for payment system operators.
S
- SABSA (Security Architecture)The SABSA Institute · Global
- A business-driven framework and methodology for enterprise security architecture.
- SAMA Cyber Security FrameworkSaudi Central Bank (SAMA) · Saudi Arabia
- Mandatory cybersecurity framework for financial institutions in Saudi Arabia.
- SANS / CWE Top 25MITRE / SANS · Global
- The most dangerous and common software weaknesses developers must avoid.
- Saudi NCA Essential Cybersecurity Controls (ECC)National Cybersecurity Authority (Saudi Arabia) · Saudi Arabia
- Saudi Arabia’s mandatory Essential Cybersecurity Controls for national entities.
- SEBI CSCRFSEBI · India
- SEBI’s Cyber Security and Cyber Resilience Framework for regulated entities.
- SEBI Stock Broker & MII System AuditSEBI · India
- System audits for stock brokers, clearing members and market infrastructure institutions.
- Secure Controls Framework (SCF)Secure Controls Framework Council · Global
- Metaframework mapping controls across 100+ authorities.
- SOC 2 (AICPA)AICPA · Global
- An attestation report on controls relevant to security, availability and privacy.
- SOX IT General Controls (ITGC)US SEC / PCAOB · United States
- IT general controls supporting Sarbanes-Oxley financial-reporting compliance.
- STQC IT Testing & CertificationSTQC, MeitY · India
- Government testing and certification for IT products, e-governance and security.
- SWIFT CSP / CSCFSWIFT · Global
- SWIFT’s Customer Security Controls Framework for institutions on the SWIFT network.
T
- TEC MTCTE (Telecom Equipment)TEC / DoT · India
- Mandatory Testing and Certification of Telecom Equipment, including security.
- TISAX (Automotive)ENX Association · Global / Europe
- The information-security assessment standard for the automotive industry.
- TOGAFThe Open Group · Global
- The leading enterprise architecture framework and method (ADM).
U
- UAE Information Assurance (NESA / SIA)UAE Cybersecurity Council / SIA · United Arab Emirates
- The UAE’s Information Assurance standards for government and critical entities.
- UIDAI / Aadhaar (AUA-KUA)UIDAI · India
- Security and audit requirements for entities in the Aadhaar authentication ecosystem.
- UK FCA Operational ResilienceFCA / PRA / Bank of England · UK
- UK regulatory rules on operational resilience for financial firms.
Z
- Zero Trust (NIST SP 800-207)NIST · Global
- A security model of "never trust, always verify" for modern architectures.
Working out which apply to you
Most organisations are subject to more than one of these at once, and the overlap between them is substantial — testing once and reusing the evidence is usually the difference between one programme and four. If you are not sure where you stand, the free assessment maps your obligations in a few minutes, and the cost guide explains what each one typically involves.

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
