9 Compliance Frameworks, Explained Briefly

    What each one actually is, why it exists, and which industry it covers, in plain terms, not legal language.

    CIS AWS Foundations

    Standard

    CIS Amazon Web Services Foundations Benchmark

    AWS's default account settings alone don't guarantee a secure configuration. CIS brings together security practitioners to agree on a prescriptive, vendor-neutral baseline, specific IAM, logging, networking, and monitoring settings, that represent a reasonable security floor for any AWS account.

    Read more

    PCI DSS

    Industry Requirement

    Payment Card Industry Data Security Standard

    To reduce credit card fraud by giving every business that touches payment card data a common set of technical and operational security requirements, rather than leaving each card brand to set its own rules.

    Read more

    SOC 2

    Standard

    System and Organization Controls 2

    To give a service organization's customers and partners independent, CPA-audited assurance that its controls around security, availability, processing integrity, confidentiality, and privacy actually work, without each customer having to audit the vendor themselves.

    Read more

    ISO/IEC 27001

    Standard

    ISO/IEC 27001 Information Security Management

    To give organizations of any size or sector a systematic, internationally recognized framework, an Information Security Management System (ISMS), for identifying, treating, and continually improving how they manage information security risk.

    Read more

    GDPR

    Regulation

    General Data Protection Regulation

    To give individuals in the EU/EEA real rights over their personal data (access, correction, erasure, portability) and to force any organization processing that data to justify why, secure it properly, and report breaches quickly.

    Read more

    HIPAA

    Regulation

    Health Insurance Portability and Accountability Act

    To protect the privacy and security of individuals' health information while still allowing it to flow where it's legitimately needed, between providers, insurers, and the systems that keep healthcare running.

    Read more

    NIST 800-53

    Standard

    NIST Special Publication 800-53: Security and Privacy Controls

    Originally built to secure US federal information systems under FISMA. It has since become the reference control catalog that other frameworks, including FedRAMP, build on, because it's exhaustive, regularly maintained, and free to use.

    Read more

    DORA

    Regulation

    Digital Operational Resilience Act

    Financial services now run almost entirely on digital infrastructure, including cloud providers who are themselves outside financial regulators' direct reach. DORA harmonizes ICT risk management, mandatory incident reporting, resilience testing, and, notably, direct oversight of critical third-party ICT providers across the EU financial sector.

    Read more

    FFIEC

    Examiner Guidance

    Federal Financial Institutions Examination Council

    To give US banking regulators, and the institutions they examine, a consistent, repeatable way to assess technology and cybersecurity risk across the banking system, instead of every examiner improvising their own standard.

    Read more

    Frequently Asked Questions

    KloudSec, built by the team behind Toc Consulting

    See all 9 frameworks checked automatically, continuously

    What you just read is a manual, one-time check. KloudSec runs this and 400+ more automated checks across 90+ AWS services, continuously, agentless, live in about 5 minutes.

    Try KloudSec free
    See how KloudSec maps every one of these automatically