Compliance Framework Content Registry

ZenGRC comes with the content you need to be compliant.

Our solutions can support any framework and provides content for over 30 various standard and regulations. Using our pre-loaded content not only saves you time but also helps you quickly identify gaps and overlaps of running multiple programs at the same time. If you need to comply with a standard or regulation that is not listed here, it can be easily loaded into ZenGRC and managed through the application like the frameworks below.

Note: For select frameworks and standards, Illustrative Control and Risk templates are available.

Framework

Use Case / Description

Useful Links

California Consumer Privacy Act (CCPA)

Common Control Mapping Available:

Use Case / Description:

The California Consumer Privacy Act (CCPA) is a state statute intended to enhance privacy rights and consumer protection for residents of California, United States.

Useful Links:

Official legislative information

Compliance Controls Catalogue (C5)

Common Control Mapping Available:

Use Case / Description:

The Cloud Computing Compliance Controls Catalogue (abbreviated “C5”) is intended primarily for professional cloud service providers, their auditors and customers of the cloud service providers. It is defined which requirements (also referred to as controls in this context) the cloud providers have to comply with or which minimum requirements the cloud providers should be obliged to meet.

Useful Links:

General information Official documentation

CJIS

Common Control Mapping Available:

Use Case / Description:

The Criminal Justice Information Services (CJIS) Security Policy provides requirements for criminal justice and associated agencies to use when accessing Criminal Justice Information (CJI). This Policy is also applicable to service providers who process CJI on behalf of criminal justice agencies. The policy prescribes safeguards that must be in place to secure CJI at rest and in transit.

Useful Links:

Official Policy Page

COBIT

Common Control Mapping Available:

Use Case / Description:

COBIT (Control Objectives for Information and Related Technologies) is a framework created by international professional association ISACA for IT management and governance. It is generic and useful for enterprises of all sizes and across sectors, including commercial, not-for-profit, and the public sector.

Useful Links:

General information

COSO Internal Control–Integrated Framework

Common Control Mapping Available:

Use Case / Description:

The Committee of Sponsoring Organizations of the Treadway Commission (COSO) provides non-prescriptive guidance on internal controls, enterprise risk management, and fraud deterrence.

Useful Links:

General information

CSA Cloud Controls Matrix

Common Control Mapping Available:

Use Case / Description:

The Cloud Security Alliance Cloud Controls Matrix (CCM) is specifically designed to provide fundamental security principles to guide cloud vendors and to assist prospective cloud customers in assessing the overall security risk of a cloud provider.

Useful Links:

General information

CIS Controls

Common Control Mapping Available:

Use Case / Description:

Sponsored by the Center for Internet Security (CIS), the CIS Controls is a prioritized list of recommended controls for cyber defense based on collective best practices and real-world risks, threats, and responses.

Useful Links:

General information

Cybersecurity Maturity Model Certification (CMMC)

Common Control Mapping Available:

Use Case / Description:

The Cybersecurity Maturity Model Certification (CMMC) framework consists of maturity processes and cybersecurity best practices from multiple cybersecurity standards, frameworks, and other references.

Useful Links:

General information

EU/US Privacy Shield

Common Control Mapping Available:

Use Case / Description:

The EU-U.S. and Swiss-U.S. Privacy Shield Frameworks were designed by the U.S. Department of Commerce, and the European Commission and Swiss Administration, respectively, to provide companies on both sides of the Atlantic with a mechanism to comply with data protection requirements.

Useful Links:

General information

FedRAMP Low / Moderate / High

Common Control Mapping Available:

Use Case / Description:

The Federal Risk and Authorization Management Program, or FedRAMP, is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services.

Useful Links:

General information Official templates Official documentation

General Data Protection Regulation (GDPR)

Common Control Mapping Available:

Use Case / Description:

The General Data Protection Regulation (EU) 2016/679 (GDPR) is a regulation in EU law on data protection and privacy in the European Union (EU) and the European Economic Area (EEA).

Useful Links:

General information

HIPAA

Common Control Mapping Available:

Use Case / Description:

The Health Insurance Portability and Accountability act (HIPAA) defines rules for the security and privacy of healthcare information.

Useful Links:

General information

ISO 27001/2, 27017, 27018, 27701

Common Control Mapping Available:

Use Case / Description:

The ISO/IEC 27000 family of standards helps organizations keep information assets secure.

Useful Links:

General information

NIST CSF

Common Control Mapping Available:

Use Case / Description:

In response to Executive Order 13636, the National Institute of Standards and Technology (NIST) published the Framework for Improving Critical Infrastructure Cybersecurity.

Useful Links:

General information

NIST SP 800-53

Common Control Mapping Available:

Use Case / Description:

The Federal Information Security Modernization Act (FISMA) requires civilian agencies of the US Federal Government to report on the security posture of their information systems.

Useful Links:

General information

NIST SP 800-171

Common Control Mapping Available:

Use Case / Description:

The purpose of NIST 800-171 is to provide agencies with recommended requirements for protecting the confidentiality of CUI.

Useful Links:

General information

NY DFS

Common Control Mapping Available:

Use Case / Description:

The New York Cybersecurity Regulation (NY DFS 23 NYCRR 500) mandates a set of cybersecurity requirements for financial services companies operating within the state.

Useful Links:

General information

PCI-DSS

Common Control Mapping Available:

Use Case / Description:

The Payment Card Industry Data Security Standard (PCI-DSS) was created by the major credit card brands in 2004 to encourage and enhance the security of credit card data.

Useful Links:

General information

Secure Controls Framework (SCF)

Common Control Mapping Available:

Not Available

Use Case / Description:

The Secure Controls Framework (SCF) is a comprehensive catalog of controls that is designed to enable companies to design, build and maintain secure processes, systems and applications.

Useful Links:

SCF information

SOC 1

Common Control Mapping Available:

Not Available

Use Case / Description:

These reports, prepared in accordance with Statement on Standards for Attestation Engagements (SSAE) No. 18, are specifically intended to meet the needs of the managements of user entities.

Useful Links:

General information

SOC 2

Common Control Mapping Available:

Use Case / Description:

SOC 2 is intended to meet the needs of a broad range of users that need information and assurance about the controls at a service organization.

Useful Links:

General information

SOX

Common Control Mapping Available:

Not Available

Use Case / Description:

Publicly-traded U.S. corporations must maintain compliance with provisions of the Sarbanes-Oxley Act of 2002 (SOX).

Useful Links:

General Information SEC Small Business Page for SOX