Framework Explorer
Frameworks
Every framework follows the same template so you can compare like for like: overview, core concepts, controls, cloud mapping, implementation guidance, labs, and interview questions.
GDPR
The EU General Data Protection Regulation; Article 32 defines the security-of-processing obligations.
ISO/IEC 27001
The international standard for information security management systems (ISMS), with Annex A controls.
NIST CSF 2.0
A voluntary framework of cybersecurity outcomes across six functions: Govern, Identify, Protect, Detect, Respond, and Recover.
SOC 2
AICPA Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy.
CIS Controls v8
A prioritized set of 18 safeguards, organized by Implementation Group, to mitigate the most common attacks.
DORA
The EU Digital Operational Resilience Act for ICT risk management in the financial sector.
ISO/IEC 42001
The management-system standard for responsible AI (AIMS).
NIS2
The EU directive raising the baseline for network and information system security across essential and important entities.