Our GRC library is public to the GRC community and published under Creative Commons CC-BY 4.0.
Import any of these frameworks directly into INSπRE as a Compliance Package. Each requirement maps to your controls, policies, and exceptions.
Reserve Bank of India Cybersecurity Framework
33 controls · Banks, UCBs, NBFCs
Securities & Exchange Board of India Cybersecurity Framework
30 controls · Brokers, AMCs, Depositories
Computer Emergency Response Team India Directions
20 directions · All entities in India
Insurance Regulatory & Development Authority of India
29 controls · All insurers
Digital Personal Data Protection Act
9 key obligations · All data fiduciaries
Information Security Management System
93 Annex A controls · Global certification
General Data Protection Regulation
11 key articles · EU/Global
Cybersecurity Framework Version 2.0
6 functions · US Federal/Global
Security & Privacy Controls
20 control families · US Federal
Payment Card Industry Data Security Standard
8 key requirements · Global
Service Organisation Control 2
5 trust service criteria · SaaS/Cloud
Health Insurance Portability & Accountability Act
Safeguards · US healthcare
Digital Operational Resilience Act
5 pillars · EU financial entities
AI Management System Standard
AI governance · Global
Customer Security Programme
Mandatory · SWIFT network participants
Center for Internet Security Controls
18 controls · Global
Sarbanes-Oxley IT General Controls
Financial controls · US listed
Privacy Information Management
Extension to ISO 27001 · Global
26 ready-to-use security and privacy policy templates with full HTML content, version control, and employee acknowledgement tracking — each mapped to the real ISO 27001 Annex A controls it satisfies, 93 control-links in total.
| Policy ▾ | Category | ISO 27001 mapping | Version | Internal controls |
|---|---|---|---|---|
|
Supplier Management Policy
This document outlines the Supplier Management Policy for the organization. This policy aims to ensure that the organization's information security is maintained when working with suppliers…
|
Vendor | ISO 27001 A.5.19-5.22 | v1.4 | 4 controls |
|
Risk Management Policy
This document delineates the approaches and standards applied in Risk Management. It ensures alignment with the established information security framework for risk management and aids in…
|
Information Security | ISO 27001 6.1.2-6.1.3 | v1.6 | Clause-level |
|
Logging and Monitoring Policy
This policy defines the principles and procedures that guide our robust Logging and Monitoring program, focusing on enhancing our security framework through vigilant supervision.
|
Information Security | ISO 27001 A.8.15-8.16 | v1.4 | 2 controls |
|
IT Security Policy
The IT Security Policy dictates the organization's standards for using endpoint devices and IT resources. Its primary goal is ensuring their safe and efficient use, preventing potential…
|
Information Security | ISO 27001 A.8.1 / A.6.7 | v1.4 | 14 controls |
|
Information Security Policy
The Information Security Policy defines the security standards of the organization as approved by the management. The document describes the core foundations for this entity's Information…
|
Information Security | ISO 27001 A.5.1-5.2 | v1.5 | 6 controls |
|
Incident Management Policy
This document outlines the standards and procedures governing our Incident Management program in alignment with the requirements of the Information Security Management System. An incident…
|
Incident Response | ISO 27001 A.5.24-5.28 / CERT-In | v1.5 | 7 controls |
|
Hardening Policy
This document outlines the technical standards and procedures applied to the cloud and on-premise environments. The policies aim to uphold information security, adhering to organizational…
|
Information Security | ISO 27001 A.8.9 / CIS Controls | v1.5 | Clause-level |
|
Documents and Records Policy
This policy outlines the organization's classification, handling, and records management of information. It is essential to properly classify and handle information and records to maintain…
|
Information Security | ISO 27001 A.5.33 | v1.4 | 2 controls |
|
Compliance Management Policy
The purpose of this document is to describe the standards and procedures of the Compliance Management program implemented by the organization. The program aims to ensure that the…
|
Information Security | ISO 27001 A.5.31 | v1.5 | 4 controls |
|
Communication Security Policy
This policy details the methods and procedures essential for securing information during its communication and transfer, both within and outside the organization.
|
Information Security | ISO 27001 A.8.20-8.24 | v1.4 | 5 controls |
|
Cloud Services Policy
The purpose of this document is to define the policies and procedures for the use of cloud services within the organization's environment. The policies and procedures outlined in this…
|
Information Security | ISO 27001 A.5.23 | v1.3 | 1 controls |
|
Change and Configuration Management Policy
Introduction This document outlines the policy and procedures for the Change and Configuration Management program within the organization. The program aims to ensure that changes and…
|
Change Mgmt | ISO 27001 A.8.32 | v1.4 | 4 controls |
|
Business Continuity Policy
This document outlines the policy and procedures for Business Continuity within the organization. The Business Continuity Policy ensures the continuity of critical business functions during…
|
Bcp | ISO 27001:2022 | v1.4 | 4 controls |
|
Backup Policy
This document outlines the Backup and Recovery Management Policy for the organization. The primary objective of this policy is to ensure that the organization's data, systems, and software…
|
Information Security | ISO 27001 A.8.13 | v1.5 | 1 controls |
|
Awareness Management Policy
The Awareness Management Policy establishes the guidelines and procedures for our comprehensive awareness program. Its essence lies in imparting knowledge to all employees about the…
|
Training | ISO 27001 A.6.3 | v1.5 | 2 controls |
|
Asset Management Policy
This Asset Management Policy provides a framework for the management and protection of organizational assets, ensuring efficiency, security, and compliance with relevant regulations and…
|
Information Security | ISO 27001 A.5.9-5.14 | v1.4 | 6 controls |
|
Access Management Policy
The Access Management Policy defines the organization's approach to ensuring appropriate access controls on all systems, including the full lifecycle management of identities and secure…
|
Access Control | ISO 27001 A.5.15-5.18 | v1.4 | 7 controls |
|
Physical Security Policy
Purpose This policy establishes the guidelines and procedures to protect the organisation's facilities, assets, and proprietary information from theft, tampering, unauthorized access…
|
Information Security | ISO 27001 A.7.1-7.14 | v1.4 | 8 controls |
|
Secure Development Policy
Purpose This policy lays down guidelines for secure software and web application development practices across the organization. Designed to weave security integrally from design to…
|
Information Security | ISO 27001 A.8.25-8.34 | v1.4 | 10 controls |
|
Privacy Policy
This Privacy Policy outlines our commitment to protect personal data and describes the practices surrounding its collection, processing, and storage. For queries regarding this policy…
|
Dpdp | ISO 27001 A.5.34 / DPDP Act 2023 | v1.5 | 1 controls |
|
Human Resources Security Policy
This policy establishes standards for managing human resources security and reducing security risks related to employees, contractors, and third parties. An effective HR security program is…
|
Information Security | ISO 27001 A.6.1-6.8 | v1.5 | 5 controls |
|
ICS/OT Security Policy
The ICS/OT Security Policy establishes the standards and practices for securing our Industrial Control Systems and Operational Technology. This policy aligns with the commitment to defend…
|
Information Security | ISO 27001 / IEC 62443 | v1.0 | Clause-level |
|
Business Continuity Plan
The Business Continuity Management System (BCMS) Plan provides a framework for decision-making and business continuity procedures in case of a disruptive incident that could impact…
|
Bcp | ISO 27001:2022 | v1 | Clause-level |
|
Business Impact Analysis Procedure
This procedure aims to assist organizations in conducting a Business Impact Analysis (BIA) to determine the critical processes to be recovered during a disruption. It helps in understanding…
|
Information Security | ISO 22301 | v1 | Clause-level |
|
Communication Procedure and Plan
Communication Procedure and Plan Purpose The purpose of this procedure is to establish a communication process, both internal and external, that aligns with our organization's policies…
|
Information Security | ISO 27001:2022 | v1 | Clause-level |
|
Crisis Management Policy
This document outlines the standards and procedures governing our Crisis Communication program in alignment with the requirements of the Information Security Management System. A crisis is…
|
Information Security | ISO 22301 | v1 | Clause-level |
All 93 ISO 27001:2022 Annex A controls with Objective, Testing Methodology, and Success Criteria — ready to import, test, and track.
37 controls
Policies, roles, responsibilities, supplier security, incident management, business continuity
8 controls
Screening, terms of employment, awareness, disciplinary process, remote working
14 controls
Physical security perimeters, equipment, clear desk, secure disposal
34 controls
Access control, cryptography, malware, logging, patch management, SSDLC
| ID ▾ | Control | Theme | Linked policy | Test frequency |
|---|---|---|---|---|
| A.5.1 |
Policies for information security
Ensure the organisation's information security policy and topic-specific policies are current, reflect organisational needs, and are endorsed by management.
|
Organisational | Information Security Policy | Annual |
| A.5.2 |
Information security roles and responsibilities
Ensure information security roles and responsibilities are properly defined, allocated, and communicated across the organisation.
|
Organisational | Information Security Policy | Annual |
| A.5.3 |
Segregation of duties
Ensure management supports and demonstrates commitment to information security through clear communication and active participation.
|
Organisational | Information Security Policy | Annual |
| A.5.4 |
Management responsibilities
Ensure all personnel and contractors are aware of and adhere to the organisation's information security policies.
|
Organisational | Awareness Management Policy | Annual |
| A.5.5 |
Contact with authorities
Ensure timely and appropriate contact with relevant authorities and adherence to regulatory requirements regarding information security incidents.
|
Organisational | Incident Management Policy | Annual |
| A.5.6 |
Contact with special interest groups
Ensure the organisation maintains contact with special interest groups, security forums, and professional associations relevant to information security.
|
Organisational | Information Security Policy | Annual |
| A.5.7 |
Threat intelligence
Collect and analyse information about information security threats to produce actionable threat intelligence.
|
Organisational | Information Security Policy | Annual |
| A.5.8 |
Information security in project management
Ensure information security is integrated into project management across all project types.
|
Organisational | Change and Configuration Management Policy | Annual |
| A.5.9 |
Inventory of information and other associated assets
Maintain an accurate, up-to-date inventory of information assets and associated assets with designated owners.
|
Organisational | Asset Management Policy | Annual |
| A.5.10 |
Acceptable use of information and other assets
Ensure information and other assets are used only for approved purposes as specified by the organisation's acceptable use policies.
|
Organisational | IT Security Policy | Annual |
| A.5.11 |
Return of assets
Ensure assets are returned by employees and contractors upon termination of employment or contract.
|
Organisational | Asset Management Policy | Semi-annual |
| A.5.12 |
Classification of information
Ensure information is classified according to the organisation's information classification scheme based on sensitivity and criticality.
|
Organisational | Asset Management Policy | Annual |
| A.5.13 |
Labelling of information
Ensure information is labelled in accordance with the organisation's information classification scheme.
|
Organisational | Asset Management Policy | Annual |
| A.5.14 |
Information transfer
Ensure information transfer is conducted securely in accordance with the organisation's classification requirements.
|
Organisational | Communication Security Policy | Annual |
| A.5.15 |
Access control
Ensure access to information and systems is controlled based on business and security requirements using a formal access control policy.
|
Organisational | Access Management Policy | Semi-annual |
| A.5.16 |
Identity management
Ensure the full lifecycle of identity management — creation, maintenance, and deletion — is controlled and auditable.
|
Organisational | Access Management Policy | Quarterly |
| A.5.17 |
Authentication information
Ensure authentication information is managed securely and in accordance with the organisation's password and authentication policy.
|
Organisational | Access Management Policy | Semi-annual |
| A.5.18 |
Access rights
Ensure access rights are provisioned, reviewed, modified, and revoked based on business need and the principle of least privilege.
|
Organisational | Access Management Policy | Quarterly |
| A.5.19 |
Information security in supplier relationships
Ensure information security risks associated with suppliers are identified, assessed, and mitigated through contractual controls.
|
Organisational | Supplier Management Policy | Annual |
| A.5.20 |
Addressing information security within supplier agreements
Ensure information security requirements are addressed in agreements with suppliers.
|
Organisational | Supplier Management Policy | Annual |
| A.5.21 |
Managing information security in the ICT supply chain
Manage information security risks in the ICT supply chain to protect software and hardware components acquired from suppliers.
|
Organisational | Supplier Management Policy | Annual |
| A.5.22 |
Monitoring, review and change management of supplier services
Maintain and improve the information security level through regular monitoring and review of supplier service delivery.
|
Organisational | Supplier Management Policy | Annual |
| A.5.23 |
Information security for use of cloud services
Ensure information security is appropriately managed when using cloud services, with clear shared responsibility boundaries.
|
Organisational | Cloud Services Policy | Annual |
| A.5.24 |
Information security incident management planning and preparation
Ensure information security is planned and prepared through a defined incident management process covering all stages of the incident lifecycle.
|
Organisational | Incident Management Policy | Annual |
| A.5.25 |
Assessment and decision on information security events
Ensure information security events are assessed and classified to determine if they constitute incidents requiring response.
|
Organisational | Incident Management Policy | Semi-annual |
| A.5.26 |
Response to information security incidents
Ensure information security incidents are responded to in accordance with the documented incident response procedures.
|
Organisational | Incident Management Policy | Semi-annual |
| A.5.27 |
Learning from information security incidents
Apply knowledge gained from information security incidents to strengthen controls and reduce recurrence.
|
Organisational | Incident Management Policy | Annual |
| A.5.28 |
Collection of evidence
Enable collection, preservation, and presentation of evidence related to information security incidents in a legally admissible manner.
|
Organisational | Incident Management Policy | Annual |
| A.5.29 |
Information security during disruption
Ensure information security is planned and implemented during disruptions to maintain the required level of information security.
|
Organisational | Business Continuity Policy | Annual |
| A.5.30 |
ICT readiness for business continuity
Ensure ICT is ready to support business continuity when disruptions occur, with defined RTO and RPO for critical systems.
|
Organisational | Business Continuity Policy | Annual |
| A.5.31 |
Legal, statutory, regulatory and contractual requirements
Identify and document all legal, statutory, regulatory, and contractual requirements relevant to information security.
|
Organisational | Compliance Management Policy | Annual |
| A.5.32 |
Intellectual property rights
Implement appropriate procedures to ensure compliance with legal, regulatory, and contractual requirements related to intellectual property rights.
|
Organisational | Compliance Management Policy | Annual |
| A.5.33 |
Protection of records
Ensure records are protected from loss, destruction, falsification, unauthorised access, and unauthorised release.
|
Organisational | Documents and Records Policy | Annual |
| A.5.34 |
Privacy and protection of PII
Ensure privacy and protection of PII in accordance with applicable legislation and regulation.
|
Organisational | Privacy Policy | Annual |
| A.5.35 |
Independent review of information security
Ensure independent review of the ISMS is conducted to verify it is being implemented effectively and in accordance with organisational policies.
|
Organisational | Compliance Management Policy | Annual |
| A.5.36 |
Compliance with policies, rules and standards for information security
Ensure compliance with information security policies, rules, and standards is regularly reviewed by management.
|
Organisational | Information Security Policy | Annual |
| A.5.37 |
Documented operating procedures
Ensure documented operating procedures for information processing facilities are maintained and available to authorised personnel.
|
Organisational | IT Security Policy | Annual |
| A.6.1 |
Screening
Ensure background verification checks are conducted for all candidates prior to employment, proportionate to the role's risk.
|
People | Human Resources Security Policy | Annual |
| A.6.2 |
Terms and conditions of employment
Ensure employment contracts state personnel's and the organisation's responsibilities for information security.
|
People | Human Resources Security Policy | Annual |
| A.6.3 |
Information security awareness, education and training
Ensure all personnel receive appropriate information security awareness, education, and training relevant to their role.
|
People | Awareness Management Policy | Annual |
| A.6.4 |
Disciplinary process
Ensure a formal disciplinary process exists for personnel who commit information security policy violations.
|
People | Human Resources Security Policy | Annual |
| A.6.5 |
Responsibilities after termination or change of employment
Ensure that information security responsibilities remain in force after termination or change of employment.
|
People | Human Resources Security Policy | Annual |
| A.6.6 |
Confidentiality or non-disclosure agreements
Ensure confidentiality and non-disclosure agreements are identified, documented, and signed by relevant personnel and third parties.
|
People | Human Resources Security Policy | Annual |
| A.6.7 |
Remote working
Ensure remote workers comply with security measures to protect information processed outside the organisation's premises.
|
People | IT Security Policy | Semi-annual |
| A.6.8 |
Information security event reporting
Ensure personnel can report suspected information security events through accessible, confidential reporting channels.
|
People | Incident Management Policy | Annual |
| A.7.1 |
Physical security perimeters
Ensure physical security perimeters are defined and implemented to protect areas containing information and associated assets.
|
Physical | Physical Security Policy | Annual |
| A.7.2 |
Physical entry
Ensure secure areas are protected by appropriate entry controls to allow only authorised personnel to access.
|
Physical | Physical Security Policy | Quarterly |
| A.7.3 |
Securing offices, rooms and facilities
Ensure offices, rooms, and facilities are designed and secured to protect information and associated assets.
|
Physical | Physical Security Policy | Annual |
| A.7.4 |
Physical security monitoring
Detect and prevent unauthorised physical access through continuous monitoring of premises.
|
Physical | Physical Security Policy | Quarterly |
| A.7.5 |
Protecting against physical and environmental threats
Protect physical premises and equipment from damage by natural disasters, accidents, or deliberate attacks.
|
Physical | Physical Security Policy | Annual |
| A.7.6 |
Working in secure areas
Ensure personnel are aware of procedures for working in secure areas and that access to these areas is controlled.
|
Physical | Physical Security Policy | Annual |
| A.7.7 |
Clear desk and clear screen
Prevent unauthorised access, loss, or compromise through clear desk and clear screen practices.
|
Physical | IT Security Policy | Quarterly |
| A.7.8 |
Equipment siting and protection
Ensure equipment is sited and protected to reduce risks from environmental threats and opportunities for unauthorised access.
|
Physical | Physical Security Policy | Annual |
| A.7.9 |
Security of assets off-premises
Ensure assets taken off-site are protected appropriately against loss, theft, or compromise.
|
Physical | IT Security Policy | Annual |
| A.7.10 |
Storage media
Ensure storage media is managed throughout its lifecycle — acquisition, use, transportation, and disposal.
|
Physical | Asset Management Policy | Annual |
| A.7.11 |
Supporting utilities
Ensure information processing facilities are protected from power failures and other disruptions caused by utility failures.
|
Physical | Business Continuity Policy | Annual |
| A.7.12 |
Cabling security
Ensure cabling carrying power and data is protected from interception, interference, or damage.
|
Physical | Physical Security Policy | Annual |
| A.7.13 |
Equipment maintenance
Ensure equipment is maintained correctly to ensure its continued availability and integrity.
|
Physical | IT Security Policy | Annual |
| A.7.14 |
Secure disposal or re-use of equipment
Ensure information is not compromised when equipment containing storage media is disposed of or repurposed.
|
Physical | Asset Management Policy | Annual |
| A.8.1 |
User endpoint devices
Ensure user endpoint devices are appropriately secured to protect organisational information.
|
Technological | IT Security Policy | Quarterly |
| A.8.2 |
Privileged access rights
Ensure only authorised users, software, and systems have access to information assets through formal privileged access management.
|
Technological | Access Management Policy | Quarterly |
| A.8.3 |
Information access restriction
Restrict access to information and system functions based on access control policy.
|
Technological | Access Management Policy | Semi-annual |
| A.8.4 |
Access to source code
Ensure source code is protected from unauthorised access and modification.
|
Technological | Secure Development Policy | Semi-annual |
| A.8.5 |
Secure authentication
Ensure secure authentication mechanisms are implemented and enforced on all systems.
|
Technological | Access Management Policy | Semi-annual |
| A.8.6 |
Capacity management
Monitor and manage the use of resources to ensure required system performance and detect capacity issues before they become incidents.
|
Technological | IT Security Policy | Semi-annual |
| A.8.7 |
Protection against malware
Ensure detection and recovery controls against malware are implemented and user awareness is maintained.
|
Technological | IT Security Policy | Quarterly |
| A.8.8 |
Management of technical vulnerabilities
Ensure technical vulnerabilities are identified and managed to reduce the risk of exploitation.
|
Technological | IT Security Policy | Quarterly |
| A.8.9 |
Configuration management
Ensure configurations of hardware, software, and services are established, documented, implemented, and monitored.
|
Technological | Change and Configuration Management Policy | Quarterly |
| A.8.10 |
Information deletion
Ensure information is securely deleted when no longer required, in accordance with retention policy.
|
Technological | Documents and Records Policy | Annual |
| A.8.11 |
Data masking
Ensure data masking is used to protect sensitive information in non-production environments and high-risk processing.
|
Technological | Secure Development Policy | Annual |
| A.8.12 |
Data leakage prevention
Prevent unauthorised exfiltration of information through data leakage prevention controls.
|
Technological | IT Security Policy | Quarterly |
| A.8.13 |
Information backup
Ensure information backup copies are maintained and can be used to restore systems and data following incidents.
|
Technological | Backup Policy | Quarterly |
| A.8.14 |
Redundancy of information processing facilities
Ensure information processing facilities are implemented with sufficient redundancy to meet availability requirements.
|
Technological | Business Continuity Policy | Annual |
| A.8.15 |
Logging
Ensure logs recording activities, exceptions, and events are produced, stored, protected, and analysed.
|
Technological | Logging and Monitoring Policy | Quarterly |
| A.8.16 |
Monitoring activities
Ensure networks, systems, and applications are monitored and anomalous behaviour is detected and responded to.
|
Technological | Logging and Monitoring Policy | Quarterly |
| A.8.17 |
Clock synchronisation
Ensure clocks of information processing systems are synchronised with approved time sources to support incident investigation.
|
Technological | IT Security Policy | Annual |
| A.8.18 |
Use of privileged utility programs
Restrict use of utility programs that could override system and application security controls.
|
Technological | IT Security Policy | Semi-annual |
| A.8.19 |
Installation of software on operational systems
Ensure software installation on operational systems is controlled to maintain system integrity.
|
Technological | Change and Configuration Management Policy | Quarterly |
| A.8.20 |
Networks security
Manage and control networks to protect information in systems and applications.
|
Technological | Communication Security Policy | Annual |
| A.8.21 |
Security of network services
Ensure security mechanisms and service levels of network services are identified and incorporated into service agreements.
|
Technological | Communication Security Policy | Annual |
| A.8.22 |
Segregation of networks
Separate networks to protect information systems and applications from unauthorised access through network segmentation.
|
Technological | Communication Security Policy | Annual |
| A.8.23 |
Web filtering
Manage access to external websites to reduce the risk of malicious content.
|
Technological | IT Security Policy | Quarterly |
| A.8.24 |
Use of cryptography
Ensure cryptographic controls are used effectively and appropriately to protect the confidentiality, integrity, and authenticity of information.
|
Technological | Communication Security Policy | Annual |
| A.8.25 |
Secure development life cycle
Ensure secure software development principles are established and applied throughout the development lifecycle.
|
Technological | Secure Development Policy | Annual |
| A.8.26 |
Application security requirements
Ensure application security requirements are identified, specified, and approved during development and acquisition.
|
Technological | Secure Development Policy | Annual |
| A.8.27 |
Secure system architecture and engineering principles
Establish, maintain, and apply secure engineering principles for all system engineering activities.
|
Technological | Secure Development Policy | Annual |
| A.8.28 |
Secure coding
Ensure secure coding techniques are applied to reduce vulnerabilities in developed software.
|
Technological | Secure Development Policy | Annual |
| A.8.29 |
Security testing in development and acceptance
Ensure security testing is defined and implemented in the development and acceptance lifecycle.
|
Technological | Secure Development Policy | Annual |
| A.8.30 |
Outsourced development
Ensure outsourced development meets the organisation's information security requirements.
|
Technological | Secure Development Policy | Annual |
| A.8.31 |
Separation of development, test and production environments
Separate development, testing, and production environments to reduce the risk of unauthorised access or changes to the operational environment.
|
Technological | Secure Development Policy | Annual |
| A.8.32 |
Change management
Ensure changes to information processing facilities and systems are controlled through formal change management.
|
Technological | Change and Configuration Management Policy | Quarterly |
| A.8.33 |
Test information
Ensure test information is appropriately selected, protected, and managed to avoid exposure of sensitive data.
|
Technological | Secure Development Policy | Annual |
| A.8.34 |
Protection of information systems during audit testing
Ensure audit testing and information system assessments are planned and agreed to minimise disruption to business processes.
|
Technological | Compliance Management Policy | Annual |
Each control includes: Objective · Testing Methodology · Success Criteria · Test Frequency · Linked Policy
Load 93 controls into INSπRE →Ready-to-use assessment questionnaires for vendor risk, privacy impact, and compliance self-assessment. Send to stakeholders and track responses in INSπRE.
Assess the security posture of suppliers and third-party service providers
45 questions
Gap analysis questionnaire against all ISO 27001:2022 clauses and Annex A
93 questions
Assess GDPR compliance posture across all key obligations
38 questions
Assess compliance with India's Digital Personal Data Protection Act 2023
28 questions
Determine scope and readiness for PCI DSS v4.0 assessment
32 questions
Structured PIA questionnaire for new projects and processing activities
24 questions
Assess cloud provider security controls and shared responsibility
40 questions
Assess risks and governance for AI/ML systems and LLM deployments
30 questions