Compliance Framework Content Registry
ZenGRC comes with the content you need to be compliant.
Our solutions can support any framework and provides content for over 30 various standard and regulations. Using our pre-loaded content not only saves you time but also helps you quickly identify gaps and overlaps of running multiple programs at the same time. If you need to comply with a standard or regulation that is not listed here, it can be easily loaded into ZenGRC and managed through the application like the frameworks below.
Note: For select frameworks and standards, Illustrative Control and Risk templates are available.
Framework
Use Case / Description
Useful Links
California Consumer Privacy Act (CCPA)
Common Control Mapping Available:
Use Case / Description:
The California Consumer Privacy Act (CCPA) is a state statute intended to enhance privacy rights and consumer protection for residents of California, United States.
Useful Links:
Official legislative information
Compliance Controls Catalogue (C5)
Common Control Mapping Available:
Use Case / Description:
The Cloud Computing Compliance Controls Catalogue (abbreviated “C5”) is intended primarily for professional cloud service providers, their auditors and customers of the cloud service providers. It is defined which requirements (also referred to as controls in this context) the cloud providers have to comply with or which minimum requirements the cloud providers should be obliged to meet.
Useful Links:
General information Official documentation
CJIS
Common Control Mapping Available:
Use Case / Description:
The Criminal Justice Information Services (CJIS) Security Policy provides requirements for criminal justice and associated agencies to use when accessing Criminal Justice Information (CJI). This Policy is also applicable to service providers who process CJI on behalf of criminal justice agencies. The policy prescribes safeguards that must be in place to secure CJI at rest and in transit.
Useful Links:
COBIT
Common Control Mapping Available:
Use Case / Description:
COBIT (Control Objectives for Information and Related Technologies) is a framework created by international professional association ISACA for IT management and governance. It is generic and useful for enterprises of all sizes and across sectors, including commercial, not-for-profit, and the public sector.
Useful Links:
COSO Internal Control–Integrated Framework
Common Control Mapping Available:
Use Case / Description:
The Committee of Sponsoring Organizations of the Treadway Commission (COSO) provides non-prescriptive guidance on internal controls, enterprise risk management, and fraud deterrence.
Useful Links:
CSA Cloud Controls Matrix
Common Control Mapping Available:
Use Case / Description:
The Cloud Security Alliance Cloud Controls Matrix (CCM) is specifically designed to provide fundamental security principles to guide cloud vendors and to assist prospective cloud customers in assessing the overall security risk of a cloud provider.
Useful Links:
CIS Controls
Common Control Mapping Available:
Use Case / Description:
Sponsored by the Center for Internet Security (CIS), the CIS Controls is a prioritized list of recommended controls for cyber defense based on collective best practices and real-world risks, threats, and responses.
Useful Links:
Cybersecurity Maturity Model Certification (CMMC)
Common Control Mapping Available:
Use Case / Description:
The Cybersecurity Maturity Model Certification (CMMC) framework consists of maturity processes and cybersecurity best practices from multiple cybersecurity standards, frameworks, and other references.
Useful Links:
EU/US Privacy Shield
Common Control Mapping Available:
Use Case / Description:
The EU-U.S. and Swiss-U.S. Privacy Shield Frameworks were designed by the U.S. Department of Commerce, and the European Commission and Swiss Administration, respectively, to provide companies on both sides of the Atlantic with a mechanism to comply with data protection requirements.
Useful Links:
FedRAMP Low / Moderate / High
Common Control Mapping Available:
Use Case / Description:
The Federal Risk and Authorization Management Program, or FedRAMP, is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services.
Useful Links:
General information Official templates Official documentation
General Data Protection Regulation (GDPR)
Common Control Mapping Available:
Use Case / Description:
The General Data Protection Regulation (EU) 2016/679 (GDPR) is a regulation in EU law on data protection and privacy in the European Union (EU) and the European Economic Area (EEA).
Useful Links:
HIPAA
Common Control Mapping Available:
Use Case / Description:
The Health Insurance Portability and Accountability act (HIPAA) defines rules for the security and privacy of healthcare information.
Useful Links:
ISO 27001/2, 27017, 27018, 27701
Common Control Mapping Available:
Use Case / Description:
The ISO/IEC 27000 family of standards helps organizations keep information assets secure.
Useful Links:
NIST CSF
Common Control Mapping Available:
Use Case / Description:
In response to Executive Order 13636, the National Institute of Standards and Technology (NIST) published the Framework for Improving Critical Infrastructure Cybersecurity.
Useful Links:
NIST SP 800-53
Common Control Mapping Available:
Use Case / Description:
The Federal Information Security Modernization Act (FISMA) requires civilian agencies of the US Federal Government to report on the security posture of their information systems.
Useful Links:
NIST SP 800-171
Common Control Mapping Available:
Use Case / Description:
The purpose of NIST 800-171 is to provide agencies with recommended requirements for protecting the confidentiality of CUI.
Useful Links:
NY DFS
Common Control Mapping Available:
Use Case / Description:
The New York Cybersecurity Regulation (NY DFS 23 NYCRR 500) mandates a set of cybersecurity requirements for financial services companies operating within the state.
Useful Links:
PCI-DSS
Common Control Mapping Available:
Use Case / Description:
The Payment Card Industry Data Security Standard (PCI-DSS) was created by the major credit card brands in 2004 to encourage and enhance the security of credit card data.
Useful Links:
Secure Controls Framework (SCF)
Common Control Mapping Available:
Not Available
Use Case / Description:
The Secure Controls Framework (SCF) is a comprehensive catalog of controls that is designed to enable companies to design, build and maintain secure processes, systems and applications.
Useful Links:
SOC 1
Common Control Mapping Available:
Not Available
Use Case / Description:
These reports, prepared in accordance with Statement on Standards for Attestation Engagements (SSAE) No. 18, are specifically intended to meet the needs of the managements of user entities.
Useful Links:
SOC 2
Common Control Mapping Available:
Use Case / Description:
SOC 2 is intended to meet the needs of a broad range of users that need information and assurance about the controls at a service organization.
Useful Links:
SOX
Common Control Mapping Available:
Not Available
Use Case / Description:
Publicly-traded U.S. corporations must maintain compliance with provisions of the Sarbanes-Oxley Act of 2002 (SOX).
Useful Links: