36 baseline controls across 6 frameworks
Browse the full controls library, grouped by framework. Each control links to mapped policies, expected evidence, and implementation guidance. Click any control to see the long-form explainer.
ISO/IEC 27001
Version 2022 · 6 controls
ISO27001-A5.1
Information Security Policy Framework
Documented and approved information security policies are established and maintained.
ISO27001-A5.15
Access Control
Access rights are provisioned based on business need and least privilege.
ISO27001-A5.24
Incident Management Planning
Security incidents are identified, escalated, and responded to through defined procedures.
ISO27001-A5.30
ICT Readiness for Business Continuity
Recovery and continuity planning ensure resilience during disruption.
ISO27001-A6.3
Security Awareness and Training
Personnel receive security awareness and role-based training.
ISO27001-A8.12
Data Leakage Prevention
Measures are defined to prevent unauthorized disclosure or loss of sensitive information.
SOC 2 Trust Services Criteria
Version 2017 · 6 controls
SOC2-CC1.1
Control Environment and Integrity
Leadership demonstrates commitment to integrity, ethics, and accountability.
SOC2-CC2.1
Information and Communication
Information required for control operation is communicated internally and externally.
SOC2-CC6.1
Logical Access Security
Logical access controls restrict unauthorized access to systems and data.
SOC2-CC7.2
Security Event Monitoring
Security events are detected, analyzed, and acted on in a timely manner.
SOC2-CC8.1
Change Management
Changes to infrastructure, systems, and applications are authorized, tested, and approved.
SOC2-CC9.2
Vendor and Third-Party Oversight
Third-party service providers are evaluated and monitored for risk.
General Data Protection Regulation
Version 2016/679 · 6 controls
GDPR-ART5
Data Processing Principles
Personal data is processed lawfully, fairly, transparently, and with minimization.
GDPR-ART6
Lawful Basis for Processing
A valid lawful basis is documented for each data processing activity.
GDPR-ART28
Processor Contracting
Processors are governed by contracts with mandatory privacy clauses.
GDPR-ART30
Records of Processing Activities
Controllers/processors maintain records of processing activities.
GDPR-ART32
Security of Processing
Technical and organizational controls are in place to secure personal data.
GDPR-ART33
Breach Notification
Personal data breaches are reported to authorities and affected persons as required.
NIST Cybersecurity Framework
Version 2.0 · 6 controls
NIST-GV.OC
Cybersecurity Governance Context
Organizational context, strategy, and risk priorities are documented.
NIST-ID.AM
Asset Management
Assets and data are inventoried, classified, and prioritized.
NIST-PR.AA
Identity and Access Control
Identities are managed and access is controlled with least privilege.
NIST-DE.CM
Continuous Monitoring
Anomalies and cybersecurity events are continuously monitored and analyzed.
NIST-RS.RP
Incident Response Plan
Incident response plans are documented, tested, and executed.
NIST-RC.RP
Recovery Planning
Recovery plans enable restoration of systems and services after incidents.
HIPAA Security and Privacy Rules
Version 45 CFR Parts 160, 164 · 6 controls
HIPAA-164.308(a)(1)
Security Management Process
Implement risk analysis and risk management for ePHI.
HIPAA-164.308(a)(3)
Workforce Security
Workforce access to ePHI is authorized and supervised.
HIPAA-164.308(a)(5)
Security Awareness and Training
Implement security awareness and training for workforce members.
HIPAA-164.312(a)
Access Control
Implement technical policies for access to electronic protected health information.
HIPAA-164.312(b)
Audit Controls
Record and examine activity in systems containing ePHI.
HIPAA-164.314(a)
Business Associate Contracts
Business associates are bound by contractual safeguards for PHI.
PCI DSS
Version 4.0 · 6 controls
PCI-REQ1
Network Security Controls
Install and maintain network security controls to protect cardholder data.
PCI-REQ3
Protect Stored Account Data
Stored account data is protected with strong cryptography and minimization.
PCI-REQ6
Secure Systems and Software
Develop and maintain secure systems and applications.
PCI-REQ7
Restrict Access by Need-to-Know
Access to system components and cardholder data is restricted by business need.
PCI-REQ10
Log and Monitor Access
Log and monitor all access to system components and cardholder data.
PCI-REQ12
Security Policy and Risk Management
Maintain an information security policy with risk management and incident response expectations.
