Compliance Resource Hub

COMPLIANCE RESOURCE HUB

Compliance, framework by framework

Short, practical summaries of the frameworks technology and security leaders are asked about most. Each section includes a downloadable checklist you can use to scope work or brief a steering committee.

ISO/IEC 27001

International standard for an Information Security Management System (ISMS).

A risk-based management system covering policy, people, processes and technology. Certification provides independent assurance that information security is governed, measured and continually improved.

Best for: Organisations that need a recognised certification for customers, regulators or tender requirements.

Quick-start controls

  • Define ISMS scope, context and interested parties (Clause 4)
  • Leadership commitment, information security policy and roles (Clause 5)
  • Risk assessment and risk treatment plan with Statement of Applicability (Clause 6)
  • Resources, competence, awareness and documented information (Clause 7)
  • Operational planning and control of risk treatment (Clause 8)
  • Performance evaluation, internal audit and management review (Clause 9)
  • Nonconformity, corrective action and continual improvement (Clause 10)
  • Annex A controls across organisational, people, physical and technological themes

NIST Cybersecurity Framework 2.0

Outcome-based framework organised around six functions.

A flexible, voluntary framework that helps organisations describe their current and target cyber posture. Useful as a common language between technical teams, executives and the board.

Best for: Organisations that want a non-prescriptive structure to assess, prioritise and communicate cyber risk.

Quick-start controls

  • Govern: establish cyber risk strategy, roles, policy and oversight
  • Identify: assets, business environment, risk assessment and supply chain
  • Protect: identity management, awareness, data security, platform security
  • Detect: continuous monitoring and adverse event analysis
  • Respond: incident management, analysis, mitigation and communications
  • Recover: recovery plan execution, improvements and communications
  • Define current and target Profiles and prioritise the gap
  • Track progress with Tiers and measurable outcomes

ACSC Essential Eight

Baseline mitigation strategies from the Australian Signals Directorate.

Eight prioritised technical controls designed to make it significantly harder for adversaries to compromise systems. Maturity Levels 0–3 set a clear target state.

Best for: Australian organisations, government agencies and any team needing a pragmatic technical baseline.

Quick-start controls

  • Application control on workstations and servers
  • Patch applications within risk-based timeframes
  • Configure Microsoft Office macro settings
  • User application hardening (browsers, PDF readers, Office)
  • Restrict administrative privileges with separate accounts
  • Patch operating systems within risk-based timeframes
  • Multi-factor authentication for users and privileged access
  • Regular backups, tested and protected from modification

SOC 2 (AICPA TSC)

Attestation report against the Trust Services Criteria.

An independent CPA-issued report covering Security and optionally Availability, Processing Integrity, Confidentiality and Privacy. Type I tests design at a point in time; Type II tests operating effectiveness over a period.

Best for: B2B SaaS and service providers responding to enterprise customer due diligence.

Quick-start controls

  • Scope the report: which Trust Services Criteria and which systems
  • Common Criteria (CC1–CC9): governance, communication, risk, monitoring, control activities, logical and physical access, system operations, change management, risk mitigation
  • Define and document control activities mapped to each criterion
  • Evidence retention plan for the audit window (typically 6–12 months for Type II)
  • Vendor and subservice organisation oversight
  • Incident response with notification commitments to customers
  • Change management with separation of duties
  • Annual readiness assessment ahead of the auditor field work

Need help choosing or sequencing a framework?

FORTE/CYBERx gives technology and security leaders defensible, board-ready options for compliance, vendor and risk decisions — in under 60 seconds.