Compliance Framework Content Registry
ZenGRC offers a comprehensive compliance framework content registry supporting over 30 standards and regulations—including HIPAA, SOX, NIST SP 800-171, GDPR, and PCI—providing pre-loaded content to streamline gap analysis and management of multiple programs, with the flexibility to add custom frameworks, and detailed guidance on specific frameworks like SOX and NIST 800-171 to help organizations meet regulatory requirements efficiently.
The Content You Need to Be Compliant
ZenGRC solutions can support any framework and provide content for over 30 various standards and regulations. Using pre-loaded content saves time and helps quickly identify gaps and overlaps that can occur when simultaneously running multiple programs. If you need to comply with a standard or regulation that is not listed, it can be easily loaded into ZenGRC and managed through the application.
Framework Guide
ZenGRC addresses the challenges associated with the following frameworks:
- HIPAA
- COSO SSAE
- ISO
- SSAE 18
- CCPA
- NIST
- GDPR
- SOC
- PCI
- CMMC
- COBIT
SOX
Publicly-traded U.S. corporations must maintain compliance with provisions of the Sarbanes-Oxley Act of 2002 (SOX). The U.S. Securities and Exchange Commission (SEC) enforces this law directly and through oversight of the Public Company Accounting Oversight Board (PCAOB). Companies subject to SOX must establish and evaluate internal controls in accordance with other established controls frameworks such as COSO and COBIT. While there are high-level requirements, SOX is not prescriptive regarding the scope and approach to conducting a SOX assessment of internal controls. Corporate management establishes the design and evaluates the effectiveness of internal controls, which are also assessed externally by public accounting firms.
NIST SP 800-171
The purpose of NIST 800-171 is to provide agencies with recommended requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when resident in nonfederal information systems and organizations. The requirements apply only to components of nonfederal information systems that process, store, or transmit CUI, or that provide security protection for such components. The CUI requirements are intended for use by federal agencies in appropriate contractual vehicles or other agreements established between those agencies and nonfederal organizations.
Framework Directory (Descriptions and Useful Links)
California Consumer Privacy Act (CCPA)
The California Consumer Privacy Act (CCPA) is a state statute intended to enhance privacy rights and consumer protection for residents of California, United States.
Compliance Controls Catalogue (C5)
The Cloud Computing Compliance Controls Catalogue (C5) is intended primarily for professional cloud service providers, their auditors, and customers. It defines requirements (controls) that cloud providers must comply with or minimum requirements they should meet.
CJIS
The Criminal Justice Information Services (CJIS) Security Policy provides requirements for criminal justice and associated agencies to use when accessing Criminal Justice Information (CJI). The policy prescribes safeguards that must be in place to secure CJI at rest and in transit and is audited periodically by the FBI for compliance.
COBIT
COBIT (Control Objectives for Information and Related Technologies) is a framework created by ISACA for IT management and governance. It is generic and useful for enterprises of all sizes and sectors. The framework incorporates globally accepted principles, practices, analytical tools, and models to help increase trust in, and value from, information systems.
COSO Internal Control–Integrated Framework
The Committee of Sponsoring Organizations of the Treadway Commission (COSO) provides non-prescriptive guidance on internal controls, enterprise risk management, and fraud deterrence. COSO Integrated Control-Integrated Framework is recognized as leading guidance for designing and implementing internal controls and assessing their effectiveness.
CSA Cloud Controls Matrix
The Cloud Security Alliance Cloud Controls Matrix (CCM) is designed to provide fundamental security principles to guide cloud vendors and assist prospective cloud customers in assessing the overall security risk of a cloud provider. The CCM provides a controls framework aligned to the Cloud Security Alliance guidance in 13 domains.
CIS Controls
Sponsored by the Center for Internet Security (CIS), the CIS Controls is a prioritized list of recommended controls for cyber defense based on collective best practices and real-world risks, threats, and responses.
Cybersecurity Maturity Model Certification (CMMC)
The Cybersecurity Maturity Model Certification (CMMC) framework consists of maturity processes and cybersecurity best practices from multiple cybersecurity standards, frameworks, and other references, as well as inputs from the Defense Industrial Base (DIB) and Department of Defense (DoD) stakeholders. The model organizes these processes and practices into domains and maps them across five levels.
EU/US Privacy Shield
The EU-U.S. and Swiss-U.S. Privacy Shield Frameworks were designed to provide companies with a mechanism to comply with data protection requirements when transferring personal data from the European Union and Switzerland to the United States. Organizations self-certify to the Department of Commerce and publicly commit to comply with the Framework’s requirements.
General Data Protection Regulation (GDPR)
The General Data Protection Regulation (EU) 2016/679 (GDPR) is a regulation in EU law on data protection and privacy in the European Union (EU) and the European Economic Area (EEA). It also addresses the transfer of personal data outside the EU and EEA areas.
HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) defines rules for the security and privacy of healthcare information, called Protected/Personal Health Information (PHI). The US Department of Health & Human Services (HHS) is responsible for enforcement. You may be subject to HIPAA if you are a:
- Covered Entity: a business that generates or processes PHI
- Business Associate: a business supporting a Covered Entity
ISO 27001/2, 27017, 27018, 27701
The ISO/IEC 27000 family of standards helps organizations keep information assets secure. Within the ISO 27000 family, there are frameworks focusing on specific areas of information security:
- 27001:2013: Requirements for an information security management system (ISMS)
- 27002:2013: Guidelines for organizational information security standards and management practices
- 27017:2015: Guidance for information security controls for cloud services
- 27018:2014: Guidelines for protecting Personally Identifiable Information (PII) in public cloud computing
- 27701:2019: Guidance for establishing and maintaining a Privacy Information Management System (PIMS)
NIST CSF
The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) is designed to drive an organization’s cybersecurity efforts through a risk-based management process. It contains requirements structured into Functions, Categories, and Subcategories, as well as Informative References to other security frameworks. The framework is structured into three parts:
- 1.Framework Core: Set of cybersecurity requirements and desired outcomes
- 2.Implementation Tiers: Levels of achievement in cybersecurity risk assessment and management
- 3.Framework Profile: Represents the state of an organization’s cybersecurity efforts
NIST SP 800-53
The Federal Information Security Modernization Act (FISMA) requires civilian agencies of the US Federal Government to report on the security posture of their information systems. NIST SP 800-53 provides a catalog of controls to choose from, with three risk-based baselines: Low, Moderate, and High.
NY DFS
The New York Cybersecurity Regulation (NY DFS 23 NYCRR 500) mandates a set of cybersecurity requirements for financial services companies operating within the state. It is designed to promote the protection of customer information and information technology systems of regulated entities.
PCI-DSS
The Payment Card Industry Data Security Standard (PCI-DSS) was created by the major credit card brands to enhance the security of credit card data. The DSS is a prescriptive set of requirements for securing credit card data at rest and in transit, mandated by the major card brands and required of all organizations accepting credit card payment transactions.
Secure Controls Framework (SCF)
The Secure Controls Framework (SCF) is a comprehensive catalog of controls designed to enable companies to design, build, and maintain secure processes, systems, and applications. The SCF addresses both cybersecurity and privacy, allowing several thousand unique controls to be addressed by fewer, well-worded SCF controls.
SOC 1
SOC 1 reports, prepared in accordance with SSAE No. 18, are intended to meet the needs of management and auditors of user entities as they evaluate the effect of controls at a service organization on user entities’ financial statement assertions. There are two types of reports:
- Type 1: Report on the fairness of the presentation of management’s description and the suitability of the design of controls as of a specified date.
- Type 2: Report on the fairness of the presentation and the suitability of the design and operating effectiveness of controls throughout a specified period.
SOC 2
SOC 2 is intended to meet the needs of a broad range of users that need information and assurance about the controls at a service organization that affect the security, availability, and processing integrity of the systems, as well as the confidentiality and privacy of the information processed by these systems.