We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Glossary

Cybersecurity & compliance glossary

123 frameworks, standards and regulations — what each one is, who it applies to, and a full guide behind every entry. Written by CERT-In empanelled auditors and PCI QSAs who assess against them.

ABCDEFGHIJKLMNOPQRSTUZ

A

ABDM / Health Data Security AuditNational Health Authority · India
Security and privacy audit for the Ayushman Bharat Digital Mission ecosystem.
APRA CPS 234 (Australia)APRA (Australia) · Australia
Information security prudential standard for APRA-regulated entities.
ASD Essential Eight (Australia)Australian Signals Directorate (ACSC) · Australia
Eight prioritised mitigation strategies against cyber threats.
Australia ISM & IRAPASD / ACSC (Australia) · Australia
Australian government security manual and assessor program.

B

Bharat Bill Payment System (BBPS) AuditNPCI Bharat BillPay (NBBL) · India
System audit requirements for BBPS operating units in the bill-payment ecosystem.
BSI C5 (Cloud Computing Compliance Criteria Catalogue)BSI (Germany) · Germany / EU
German catalogue of cloud security controls attested by auditors.

C

Canada OSFI B-13 (Technology & Cyber Risk)OSFI (Canada) · Canada
Canadian guideline on technology and cyber risk for FRFIs.
CCA / eSign / Digital Signature AuditCCA (MeitY) · India
Audit of Certifying Authorities, eSign and digital-signature ecosystems.
CCPA / CPRAState of California · United States
California’s consumer privacy law and its CPRA amendments.
CEA Power-Sector Cyber SecurityCentral Electricity Authority · India
Cybersecurity in the power/electricity sector under CEA regulations.
CERT-In Comprehensive Cyber Security AuditCERT-In, MeitY · India
Cybersecurity audit under CERT-In’s 2025 audit policy guidelines.
CERT-In Directions (Cyber Incident Reporting)CERT-In, MeitY · India
CERT-In’s directions on incident reporting, log retention and security practices.
China PIPL / Cybersecurity Law / MLPSPRC Government · China
China's data-protection, cybersecurity and grading regime.
CIS ControlsCenter for Internet Security · Global
A prioritised set of 18 safeguards that stop the most common attacks.
CMMCUS Department of Defense · United States
Cybersecurity Maturity Model Certification for the US defense supply chain.
CMMI V3.0ISACA / CMMI Institute · Global
Capability Maturity Model Integration — a model for building repeatable, measurable, continually improving organisational capability.
COBITISACA · Global
A governance and management framework for enterprise information and technology.
Common Criteria (ISO/IEC 15408) / IC3SCommon Criteria / STQC · Global / India
International product security evaluation and certification.
COSO Internal Control FrameworkCOSO · Global
The leading framework for internal control and enterprise risk management.
CryptoCurrency Security Standard (CCSS)C4 (CryptoCurrency Certification Consortium) · Global
Security standard for systems that use cryptocurrencies.
CSA AI Controls Matrix (AICM)Cloud Security Alliance · Global
CSA control matrix for securing and governing AI systems.
CSA CCM & STARCloud Security Alliance · Global
The Cloud Controls Matrix and STAR programme for cloud security assurance.
Cyber Essentials (UK)UK NCSC / IASME · United Kingdom
A UK government-backed certification for baseline cyber hygiene.
Cyber Risk Institute (CRI) ProfileCyber Risk Institute · Global (Finance)
Harmonised cybersecurity profile for the financial sector.
Cybersecurity Capability Maturity Model (C2M2)US DOE · Global
Maturity model to evaluate and improve cyber capabilities.

D

DORA (Digital Operational Resilience Act)European Union · EU
EU regulation on ICT and operational resilience for financial entities.
DPDP Act, 2023 (India)MeitY, Government of India · India
India’s data-protection law governing the personal data of data principals.

E

EU AI ActEuropean Union · EU
Risk-tiered EU regulation governing AI systems and models.
EU-US Data Privacy FrameworkUS Dept of Commerce / EC · EU / US
Transatlantic mechanism for lawful personal-data transfers.

F

FBI CJIS Security PolicyUS FBI · United States
Security policy protecting US criminal-justice information.
FedRAMPUS FedRAMP PMO / GSA · United States
The US government authorisation programme for cloud services.
FFIEC Cybersecurity AssessmentFFIEC · United States
US banking regulators' cyber maturity and IT examination framework.
FIPS 140-3 Cryptographic Module ValidationNIST / CMVP · Global
Validation of cryptographic modules to US federal standards.

G

GDPREuropean Union · EU / EEA
The EU regulation governing the processing of personal data.
GIGW & Web Accessibility (WCAG) AuditMeitY / W3C · India / Global
Government website guidelines and web accessibility compliance audit.
GLBA & FTC Safeguards RuleUS FTC · United States
US financial-privacy and information-safeguards requirements.

H

HIPAAUS Dept. of Health & Human Services · United States
US law protecting the privacy and security of protected health information (PHI).
HITRUST CSFHITRUST Alliance · Global / US
A certifiable security framework that harmonises HIPAA, ISO, NIST, PCI and more.

I

IEC 62443 (OT/ICS Security)IEC / ISA · Global
The standard for cybersecurity of industrial automation and control systems.
IFSCA Cyber Resilience AuditIFSCA · India (GIFT IFSC)
Cybersecurity and resilience audit for regulated entities in GIFT IFSC.
IRDAI Information & Cyber SecurityIRDAI · India
Information and cybersecurity guidelines for insurers and intermediaries.
ISO 22301ISO · Global
The international standard for business continuity management systems (BCMS).
ISO 27799 (Health Informatics Security)ISO · Global
Health-sector application of ISO 27002 controls.
ISO 28000 (Supply Chain Security)ISO · Global
Management system for security of the supply chain.
ISO 9001 (Quality)ISO · Global
The international standard for a quality management system (QMS).
ISO/IEC 20000-1ISO / IEC · Global
The international standard for an IT service management system (SMS).
ISO/IEC 27001ISO / IEC · Global
The international standard for an Information Security Management System (ISMS).
ISO/IEC 27005 (Information Security Risk Management)ISO / IEC · Global
Guidance for managing information security risk.
ISO/IEC 27017ISO / IEC · Global
Cloud-specific information security controls extending ISO 27002.
ISO/IEC 27018ISO / IEC · Global
Protection of personal data (PII) in public cloud services.
ISO/IEC 27031 (ICT Continuity)ISO / IEC · Global
ICT readiness for business continuity.
ISO/IEC 27035 (Incident Management)ISO / IEC · Global
The standard for information security incident management.
ISO/IEC 27701ISO / IEC · Global
A privacy extension (PIMS) to ISO 27001 for managing personal data.
ISO/IEC 29147 & 30111 (Vulnerability Disclosure)ISO / IEC · Global
Standards for vulnerability disclosure and handling.
ISO/IEC 42001 (AI Management)ISO / IEC · Global
The management-system standard for artificial intelligence (AIMS).
ISO/SAE 21434 & UNECE R155 (Automotive Cybersecurity)ISO / SAE / UNECE · Global
Cybersecurity engineering for road vehicles.

J

Japan ISMAPGovernment of Japan · Japan
Japanese assessment program for government cloud services.

K

Korea ISMS-PKISA (Korea) · South Korea
Korean certification for information security and privacy management.

L

LGPD (Brazil)Brazil (ANPD) · Brazil
Brazil’s General Data Protection Law for personal data.

M

MAS TRM (Singapore)Monetary Authority of Singapore · Singapore
Technology Risk Management guidelines for Singapore financial institutions.
Medical Device CybersecurityFDA / IEC · Global
Cybersecurity for medical devices across the product lifecycle.
MITRE ATLAS (AI/ML Threats)MITRE · Global
A knowledge base of adversarial threats to AI and machine-learning systems.
MITRE ATT&CKMITRE · Global
A knowledge base of real-world adversary tactics and techniques.
MITRE D3FENDMITRE · Global
A knowledge base of defensive countermeasures mapped to ATT&CK.

N

NCIIPC Critical Information Infrastructure AuditNCIIPC · India
Protection and audit of Critical Information Infrastructure in India.
NERC CIP (Critical Infrastructure Protection)NERC · North America
Mandatory cyber standards for the North American bulk power system.
NIS2 DirectiveEuropean Union · EU
EU directive raising cybersecurity for essential and important entities.
NIST AI Risk Management FrameworkNIST · Global
Voluntary framework to manage risks of AI systems.
NIST Cybersecurity Framework (CSF 2.0)NIST · Global
A voluntary, outcome-based framework for managing and reducing cybersecurity risk.
NIST Ransomware Risk Management ProfileNIST · Global
CSF profile to prevent, detect and recover from ransomware.
NIST Secure Software Development Framework (SSDF)NIST · Global
Secure software development practices (SP 800-218).
NIST SP 800-161 (C-SCRM)NIST · Global
Cyber supply-chain risk management practices for systems.
NIST SP 800-171NIST · Global / US
Protecting Controlled Unclassified Information (CUI) in non-federal systems.
NIST SP 800-53NIST · Global
A comprehensive catalog of security and privacy controls for information systems.
NIST SP 800-63 (Digital Identity)NIST · Global
Digital identity guidelines — identity proofing, authentication and federation.
NIST SP 800-82 (OT Security)NIST · Global
Guide to securing operational technology and control systems.
NPCI Product Security Audits (IMPS, RuPay, AePS, NACH, NFS, FASTag, CTS)NPCI · India
Security audits across NPCI’s payment products beyond UPI.
NPCI UPI / TPAP Security AuditNPCI · India
Security audit requirements for UPI Third-Party Application Providers and PSP banks.
NYDFS Part 500 Cybersecurity RegulationNY Dept of Financial Services · United States
New York cybersecurity rules for financial-services companies.

O

OWASP API Security Top 10OWASP · Global
The most critical security risks to APIs.
OWASP ASVSOWASP · Global
A detailed, testable standard for verifying application security.
OWASP Top 10OWASP · Global
The standard awareness document for the most critical web application risks.

P

PCI DSSPCI SSC · Global
The security standard for organisations that handle payment card data.
PCI PIN & P2PEPCI SSC · Global
Standards for secure PIN management and point-to-point encryption of card data.
PCI Software Security Framework & 3DSPCI SSC · Global
PCI standards for payment software security and 3-D Secure.
PDPA (Singapore)PDPC (Singapore) · Singapore
Singapore’s Personal Data Protection Act.
PFRDA Cyber Security & IS AuditPFRDA · India
Information and cybersecurity audit for the pension (NPS) ecosystem.
PIPEDA (Canada)Canada (OPC) · Canada
Canada’s federal private-sector privacy law.
POPIA (South Africa)South Africa (Information Regulator) · South Africa
South Africa’s Protection of Personal Information Act.

Q

Qatar National Information Assurance (NIA)Qatar (NCSA) · Qatar
Qatar’s National Information Assurance standard for information security.

R

RBI Account Aggregator FrameworkReserve Bank of India · India
The consent-based financial-data-sharing framework in India.
RBI Co-operative Bank Cyber Security FrameworkReserve Bank of India · India
Basic and Comprehensive (graded) cybersecurity framework audit for UCBs.
RBI Cyber Security Framework for BanksReserve Bank of India · India
Baseline cybersecurity and resilience controls mandated by RBI for banks.
RBI Digital Lending (DLA/LSP) AuditReserve Bank of India · India
Technical and privacy due-diligence audit of digital lending apps and service providers.
RBI Digital Payment Security ControlsReserve Bank of India · India
RBI’s master direction on securing internet, mobile and card digital payment channels.
RBI Fraud Risk Management AuditReserve Bank of India · India
Audit of fraud governance, monitoring and reporting technology for REs.
RBI FREE-AI & AI Model Risk ManagementReserve Bank of India · India
RBI’s AI governance regime for banks, NBFCs and regulated entities — the FREE-AI framework (Aug 2025) plus the draft Model Risk Management guidance (2026).
RBI Housing Finance Company (HFC) IS & Cyber AuditReserve Bank of India · India
Information systems and cybersecurity audit for housing finance companies.
RBI IT Framework for NBFCsReserve Bank of India · India
RBI’s IT governance, security and audit expectations for NBFCs.
RBI IT Governance, Risk, Controls & AssuranceReserve Bank of India · India
RBI’s master direction on IT governance, risk, controls and IS assurance practices.
RBI IT Outsourcing Directions AuditReserve Bank of India · India
Audit of IT outsourcing, cloud and supply-chain risk for RBI-regulated entities.
RBI KYC / V-CIP Technology AuditReserve Bank of India · India
Audit of KYC and Video-based Customer Identification Process technology controls.
RBI Payment Aggregators & Payment Gateways (PA-PG)Reserve Bank of India · India
Authorisation and security requirements for payment aggregators and payment gateways.
RBI Prepaid Payment Instruments (PPI)Reserve Bank of India · India
Rules for issuing and operating prepaid payment instruments (wallets, cards).
RBI System Audit Report (SAR) & Data LocalisationReserve Bank of India · India
Annual system audit and payment-data localisation assurance for payment system operators.

S

SABSA (Security Architecture)The SABSA Institute · Global
A business-driven framework and methodology for enterprise security architecture.
SAMA Cyber Security FrameworkSaudi Central Bank (SAMA) · Saudi Arabia
Mandatory cybersecurity framework for financial institutions in Saudi Arabia.
SANS / CWE Top 25MITRE / SANS · Global
The most dangerous and common software weaknesses developers must avoid.
Saudi NCA Essential Cybersecurity Controls (ECC)National Cybersecurity Authority (Saudi Arabia) · Saudi Arabia
Saudi Arabia’s mandatory Essential Cybersecurity Controls for national entities.
SEBI CSCRFSEBI · India
SEBI’s Cyber Security and Cyber Resilience Framework for regulated entities.
SEBI Stock Broker & MII System AuditSEBI · India
System audits for stock brokers, clearing members and market infrastructure institutions.
Secure Controls Framework (SCF)Secure Controls Framework Council · Global
Metaframework mapping controls across 100+ authorities.
SOC 2 (AICPA)AICPA · Global
An attestation report on controls relevant to security, availability and privacy.
SOX IT General Controls (ITGC)US SEC / PCAOB · United States
IT general controls supporting Sarbanes-Oxley financial-reporting compliance.
STQC IT Testing & CertificationSTQC, MeitY · India
Government testing and certification for IT products, e-governance and security.
SWIFT CSP / CSCFSWIFT · Global
SWIFT’s Customer Security Controls Framework for institutions on the SWIFT network.

T

TEC MTCTE (Telecom Equipment)TEC / DoT · India
Mandatory Testing and Certification of Telecom Equipment, including security.
TISAX (Automotive)ENX Association · Global / Europe
The information-security assessment standard for the automotive industry.
TOGAFThe Open Group · Global
The leading enterprise architecture framework and method (ADM).

U

UAE Information Assurance (NESA / SIA)UAE Cybersecurity Council / SIA · United Arab Emirates
The UAE’s Information Assurance standards for government and critical entities.
UIDAI / Aadhaar (AUA-KUA)UIDAI · India
Security and audit requirements for entities in the Aadhaar authentication ecosystem.
UK FCA Operational ResilienceFCA / PRA / Bank of England · UK
UK regulatory rules on operational resilience for financial firms.

Z

Zero Trust (NIST SP 800-207)NIST · Global
A security model of "never trust, always verify" for modern architectures.

Working out which apply to you

Most organisations are subject to more than one of these at once, and the overlap between them is substantial — testing once and reusing the evidence is usually the difference between one programme and four. If you are not sure where you stand, the free assessment maps your obligations in a few minutes, and the cost guide explains what each one typically involves.

Free compliance assessment →What it costsKnowledge Center
PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

Ready to discuss your Compliance frameworks requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →