The regimes behind every finding
Seven regimes. A finding cites the clause each ticked regime has on the point; it does not mean every regime requires every finding. PCI DSS and CIS Controls set specific periods; ISO/IEC 27001, SOC 2 and NIST SP 800-53 leave the periods to you; NIS2 Article 21 is a broad obligation on the entity's measures. Sarbanes-Oxley section 404 and the IT general controls over access to programs and data; the PCAOB auditing standard for an audit of internal control over financial reporting (AS 2201); ISO/IEC 27002:2022, the guidance behind each Annex A control are named, not quoted.
- ISO/IEC 27001:2022 Annex A7 clauses
- SOC 2 (Trust Services Criteria, common criteria)3 clauses
- PCI DSS v4.014 clauses
- NIST SP 800-53 Rev. 513 clauses
- CIS Controls v88 clauses
- NIS2 Directive (EU) 2022/2555, Article 212 clauses
- ISO/IEC 42001:20232 clauses