Current toolbox
- Cloud Controls Matrixv4 as CCM WG leader for the mapping to NIST SP 800-53 and new ISO/IEC FDIS 27002
- 21 CFR Part 11
- 21 CFR Part 820
- HIPAA-HITECH CFR 45
- Eudralex V4 Annex 11
- GAMP® 5*
- HITRUST 9.3* (you must have a valid client license with HITRUST)
- ISO 13485:2016
- ISO/IEC 30111:2019
- ISO/IEC 27001:2013 €
- ISO/IEC 27017:2015 € 27002 for cloud services
- ISO/IEC 27799:2016 €
- ISO/IEC 27002:2013 € New ISO/IEC FDIS 27002 and mapping to CCM V4 and NIST 171 Assessment
- ISO/IEC 27018:2019 €
- ISO/IEC 27701:2019 €
- ISO/IEC TR 3445:2022 € Information technology — Cloud computing — Audit of cloud services
- NIST SP 800-171r2, NIST SP 800-171A, NIST SP 800-172, NIST.HB.162
- NIST SP 800-53 r5 / NIST SP 800-53B rev 5 / NIST SP 800-53A rev 5
- NIST SP 800-37 RMF v2
- NIST Cybersecurity Framework CSF- we have V1.1 mapped to SOC2, NIST 800-53, CIS-CSC 8.1, ISO/IEC 27001 and 27017, NIST 800-171&172 for CMMC 2.0
- GDPR
- CCPA 1798
- SOC 2 AICPA
- CIS Benchmarks - OSCAL & SCAP integration, mapping to custom cybersecurity products
- CIS CSC v7.1-> 8.1 - the top 18 - mapped to CCM v4.5
- PCI DSS V3.2.1
- COSO 2013 as mapped to IT and Cybersecurity standards and ISMS
- FFIEC (with insights from the CRI, Cyber Risk Institute)
- National Cyber Security Center NCSC UK Announces Major Updates to Cyber Essentials
- UK Cyber Essential in Brief
- Criminal Justice Information Services (CJIS) Security Policy
- Compliance Controls Catalogue (C5)
- Cloudification and building to Zero Trust
- More upon request.
