The List of Applicable Frameworks

The List of Applicable Frameworks provides an overview of the key cybersecurity, compliance, and industry-specific frameworks supported by CSFaaS. These frameworks are essential for aligning your organisation’s cybersecurity governance, risk management, and compliance activities with international standards and best practices.

Additionally, CSFaaS allows users to create and customise their own frameworks to address specific organisational needs and regulatory requirements.

CSFaaS supports frameworks spanning areas such as privacy, risk management, organisational management, healthcare, critical infrastructure, and emerging technologies. The platform ensures seamless integration and alignment with these frameworks, enabling organisations to meet regulatory obligations while enhancing their cybersecurity posture.


Framework and Translation Availability

Below is a categorised and structured list of available frameworks, including language availability (EN, FR, ES) and region of application.

This section provides a high-level overview of the frameworks supported by CSFaaS, including their geographical applicability and language availability. It helps users quickly understand which frameworks are relevant to their region and available in their preferred language.

Purpose

  • Identify framework coverage by region (e.g., US, EU, Global).
  • Check language support (EN, FR, ES) for each framework.
  • Serve as a quick reference guide for framework selection and implementation.

Framework Availability Matrix

Type Framework Region EN FR ES
Privacy NIST PF 1.0 US Yes No Yes
GDPR EU Yes No No
IAPP CIPM US-EU Yes No No
Risk Management NIST SP 800-37 US Yes No No
Organisational Management NIST SP 800-53 rev. 5 US Yes No No
NIST CSF 2.0 US Yes Yes Yes
NIST SP 1300 Small Business US Yes Yes Yes
ISO 9001:2015 ISO Yes Yes Yes
ISO 27001:2022 ISO Yes Yes No
NCA ECC SA Yes No No
AICPA SOC2 US Yes No No
CCCS - Baseline Controls for SME BE Yes Yes No
Cyberfondamentaux Basic BE Yes Yes No
Cyberfondamentaux Important BE Yes Yes No
Cyberfondamentaux Essentials BE Yes Yes No
Cyberfondamentaux Small BE Yes Yes No
Health HIPAA US Yes No No
Financial Sector DORA EU Yes Yes Yes
Critical Infrastructure NIS2 EU Yes