Reference Library

Compliance Framework Reference

Accurate, practitioner-grade reference for the frameworks that actually matter in information security and data protection. Every page includes verified source information and ready-to-use AI prompt recipes.

12 frameworks

Standard
Global

ISO/IEC 27001

ISO / IEC · 2022

The international standard for Information Security Management Systems.

4 prompt recipesExplore →
Framework
United StatesGlobal

SOC 2

AICPA · 2017 TSC

The AICPA attestation standard for service organizations managing customer data.

4 prompt recipesExplore →
Framework
United StatesGlobal

NIST Cybersecurity Framework

NIST · 2.0

NIST's voluntary, risk-based framework for managing cybersecurity risk across any organization.

4 prompt recipesExplore →
Standard
Global

PCI DSS

PCI Security Standards Council · v4.0.1

The global security standard for any organization that stores, processes, or transmits payment card data.

4 prompt recipesExplore →
Regulation
United States

HIPAA Security Rule

U.S. Department of Health and Human Services · 1996 / 2013 Omnibus

Federal law governing the security and privacy of protected health information in the United States.

4 prompt recipesExplore →
Regulation
European UnionGlobal

GDPR

European Parliament and Council of the EU · Regulation 2016/679

EU regulation governing personal data processing with global reach wherever EU residents' data is involved.

4 prompt recipesExplore →
Framework
United States

FedRAMP

U.S. General Services Administration · Rev 5 Baselines

The US federal authorization program for cloud services used by government agencies.

4 prompt recipesExplore →
Framework
United States

CMMC 2.0

U.S. Department of Defense · 2.0

DoD's mandatory cybersecurity certification program for defense contractors handling CUI or FCI.

4 prompt recipesExplore →
Standard
Global

ISO/IEC 42001

ISO / IEC · 2023

The first international standard for AI Management Systems, covering governance, risk, and accountability for AI.

4 prompt recipesExplore →
Regulation
India

DPDPA 2023

Ministry of Electronics and Information Technology, Government of India · 2023

India's Digital Personal Data Protection Act — the primary legislation governing personal data in India.

4 prompt recipesExplore →
Directive
India

CERT-In Directions 2022

Indian Computer Emergency Response Team (CERT-In), Ministry of Electronics and IT · 2022

Mandatory cybersecurity directions for Indian organizations covering incident reporting, log retention, and NTP synchronization.

3 prompt recipesExplore →
Custom
Global

Custom Control Framework

Organization-defined · Concept Reference

A structured approach to building a bespoke compliance program when no single standard fits your risk profile.

3 prompt recipesExplore →

Framework versions and control counts are sourced from official issuing bodies. All prompt recipes are designed for use with current large language models and are based on real practitioner assessment workflows.