Compliance Frameworks in CloudDR

Applies To: WatchGuard CloudDR

On the Compliance page in WatchGuard CloudDR, you can manage your compliance with major frameworks. CloudDR supports these frameworks:

ACSC Essential Eight

Overseeing Organization

Australian Cyber Security Centre (ACSC)

Focus/Applicability

The Essential Eight is a set of prioritized mitigation strategies for Australian organizations. It is mandatory for Australian federal entities and widely recommended for organizations of all sizes in Australia.

Principles

The Essential Eight emphasizes eight technical strategies with defined maturity levels (ML1–ML3), including application control, patching, multi-factor authentication, and regular backups. Organizations improve maturity progressively to reduce the likelihood and impact of cyber incidents.

APPI (Act on the Protection of Personal Information)

Overseeing Organization

Personal Information Protection Commission (PPC) — Japan

Focus/Applicability

APPI is Japan's primary data protection law. It applies to organizations that handle the personal information of individuals in Japan.

Principles

APPI emphasizes appropriate acquisition, use, and protection of personal information. PPC guidance describes organizational, human, physical, and technical safety management measures, including access control, authentication, prevention of unauthorized external access, and leakage prevention.

CCPA / CPRA

Overseeing Organization

California Privacy Protection Agency (CPPA)

Focus/Applicability

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), applies to businesses that meet California thresholds and that collect or process the personal information of California residents.

Principles

CCPA/CPRA emphasizes consumer privacy rights and business obligations for transparency, access, deletion, and opt-out of sale or sharing. It also requires reasonable security procedures and practices to protect personal information, including measures such as access control, encryption, and appropriate retention.

CIS Controls (Center for Internet Security)

Overseeing Organization

Center for Internet Security (CIS) — Non-profit organization

Focus/Applicability

CIS controls are a recommended set of best practices for cybersecurity across various IT assets like servers, endpoints, and cloud environments. They are not official regulations but are widely adopted by organizations of all sizes.

Principles

CIS controls are based on a defense-in-depth approach, and prioritize critical security controls to mitigate the most common cyberthreats.

CISA SCuBA — Google Workspace Baselines

Overseeing Organization

Cybersecurity and Infrastructure Security Agency (CISA)

Focus/Applicability

CISA SCuBA Google Workspace baselines provide secure configuration guidance for Google Workspace. They apply to US FCEB agencies and are usable by organizations globally that want aligned Google Workspace hardening guidance.

Principles

These baselines emphasize observable configuration settings for Google Workspace and complement the Microsoft 365 SCuBA baselines. Together they provide a consistent SCuBA approach across common cloud productivity suites.

CISA SCuBA — Microsoft 365 Secure Configuration Baselines

Overseeing Organization

Cybersecurity and Infrastructure Security Agency (CISA)

Focus/Applicability

CISA Secure Cloud Business Applications (SCuBA) Microsoft 365 Secure Configuration Baselines provide product-specific secure configuration guidance for Microsoft 365. They apply to US federal civilian executive branch (FCEB) agencies and are usable by organizations globally that want aligned Microsoft 365 hardening guidance.

Principles

SCuBA baselines emphasize observable, machine-checkable configuration settings across Microsoft 365 products. They align with CIS Microsoft 365 Foundations Benchmark guidance and support consistent secure configuration assessment for cloud productivity services.

CJIS Security Policy

Overseeing Organization

Federal Bureau of Investigation (FBI) Criminal Justice Information Services (CJIS) Division

Focus/Applicability

The CJIS Security Policy applies to US law enforcement agencies and to suppliers that process, store, or transmit Criminal Justice Information (CJI). Compliance is mandatory for entities that connect to CJIS systems or handle CJI.

Principles

CJIS Security Policy focuses on protecting the confidentiality, integrity, and availability of CJI. Key requirements include access control, multi-factor authentication, audit logging, encryption, and personnel security. State CJIS Systems Agencies typically assess compliance on a recurring cycle.

CMMC (Cybersecurity Maturity Model Certification)

Overseeing Organization

United States Department of Defense (DoD) Chief Information Officer (CIO)

Focus/Applicability

CMMC applies to organizations in the US defense supply chain that process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). It is mandatory through DoD contracts that require CMMC certification.

Principles

CMMC defines maturity levels that map security requirements to contract needs. Level 1 focuses on basic safeguarding of FCI. Level 2 aligns with NIST SP 800-171 requirements to protect CUI and typically requires third-party assessment for certification.

CSA STAR (Cloud Security Alliance Security Trust Assurance and Risk)

Overseeing Organization

Cloud Security Alliance (CSA)

Focus/Applicability

CSA STAR is a certification and assurance program designed to address cloud security. It applies to cloud service providers (CSPs) and their customers, and offers transparency and assurance of security practices in cloud environments.

Principles

CSA STAR emphasizes transparency by requiring CSPs to provide clear details about their security controls. It incorporates a three-level assurance model (self-assessment, third-party audit, and continuous monitoring), and aligns with frameworks like ISO 27001 and the Cloud Controls Matrix (CCM). Additionally, it supports organizations in the evaluation and management of cloud-related risks (risk management).

Cyber Essentials / Cyber Essentials Plus

Overseeing Organization

National Cyber Security Centre (NCSC) — United Kingdom / IASME

Focus/Applicability

Cyber Essentials is a UK certification scheme for organizations of all sizes. It is voluntary for many organizations and mandatory for many UK government contracts. Cyber Essentials Plus uses the same control themes with an independent technical assessment.

Principles

Cyber Essentials focuses on five technical control themes that reduce common cyberthreats: firewalls and internet gateways, secure configuration, security update management, user access control, and malware protection. Cyber Essentials Plus adds independent verification of the same themes.

DORA (Digital Operational Resilience Act)

Overseeing Organization

European Union (EU)

Focus/Applicability

DORA (EU 2022/2554) applies to financial entities in the European Union and to critical ICT third-party service providers that support them. It is a directly applicable regulation for digital operational resilience in the financial sector.

Principles

DORA emphasizes ICT risk management, incident reporting, digital operational resilience testing, and oversight of ICT third-party risk. For financial entities, it acts as lex specialis relative to NIS2 for overlapping ICT security obligations.

EU AI Act

Overseeing Organization

European Union (EU)

Focus/Applicability

The EU AI Act (EU 2024/1689) is a regulation that applies to providers and deployers of AI systems in the European Union. Obligations vary by risk level, with stricter requirements for high-risk AI systems.

Principles

The EU AI Act emphasizes risk-based AI governance, including prohibited practices, transparency obligations, and requirements for high-risk systems such as risk management, data governance, human oversight, and documentation. Organizations must inventory and classify AI systems to apply the correct obligations.

FedRAMP

Overseeing Organization

FedRAMP Program Management Office (PMO) / General Services Administration (GSA)

Focus/Applicability

FedRAMP provides standardized security authorization baselines for cloud service providers that sell cloud products to US federal agencies. Baselines include Low, Moderate, High, and LI-SaaS, based on NIST SP 800-53 Rev. 5 with FedRAMP-specific additions.

Principles

FedRAMP emphasizes reusable authorization packages, continuous monitoring, and consistent control baselines for federal cloud use. Cloud providers pursue authorization against a selected baseline. Customer organizations typically assess readiness against FedRAMP requirements rather than claiming FedRAMP authorization themselves.

FISMA (Federal Information Security Modernization Act)

Overseeing Organization

National Institute of Standards and Technology (NIST) / Office of Management and Budget (OMB) / Cybersecurity and Infrastructure Security Agency (CISA)

Focus/Applicability

FISMA applies to US federal agencies and to contractors that operate information systems on behalf of those agencies. Organizations implement FISMA through tailored NIST SP 800-53 control baselines selected by FIPS 199 impact level (Low, Moderate, or High).

Principles

FISMA emphasizes risk-based security authorization and continuous monitoring. Agencies select and implement NIST SP 800-53 baselines, document system security, assess residual risk, and maintain authorization to operate (ATO) through ongoing monitoring and remediation.

GDPR (General Data Protection Regulation)

Overseeing Organization

European Union (EU)

Focus/Applicability

GDPR is a regulation that governs the processing of personal data of individuals who reside in the European Economic Area (EEA). It applies to any organization that processes this data, regardless of the location of the organization.

Principles

GDPR emphasizes individual control over personal data. It outlines principles such as transparency, accountability, and data subject rights (access, rectification, erasure, restriction of processing).

GovRAMP / TX-RAMP

Overseeing Organization

GovRAMP (formerly StateRAMP)

Focus/Applicability

GovRAMP provides authorization baselines for cloud products used by US state, local, tribal, and education (SLED) organizations and their cloud vendors. TX-RAMP is the Texas state authorization program and provides reciprocity pathways with GovRAMP in participating contexts.

Principles

GovRAMP builds on NIST SP 800-53 Rev. 5 baselines with impact levels aligned to common cloud authorization models. It emphasizes standardized security packages, continuous monitoring, and authorization for cloud services sold into the SLED market.

HIPAA (Health Insurance Portability and Accountability Act)

Overseeing Organization

United States Department of Health and Human Services (HHS)

Focus/Applicability

HIPAA applies to healthcare providers, health plans, and healthcare clearinghouses that handle the protected health information (PHI) of individuals.

Principles

HIPAA focuses on protecting the privacy, security, and integrity of PHI. It outlines requirements for administrative, physical, and technical safeguards to achieve these goals.

ISO 27001:2022 (International Organization for Standardization)

Overseeing Organization

International Organization for Standardization (ISO)

Focus/Applicability

ISO 27001 is an information security management system (ISMS) standard that any organization can apply, regardless of size or industry. It provides a framework for the implementation and maintenance of a comprehensive information security program.

Principles

ISO 27001 follows a risk-based approach, and requires organizations to identify information assets, assess security risks, implement controls, and continuously improve their ISMS.

ISO/IEC 23894 (AI Risk Management)

Overseeing Organization

International Organization for Standardization (ISO) / International Electrotechnical Commission (IEC)

Focus/Applicability

ISO/IEC 23894 provides guidance on risk management for artificial intelligence. Any organization that develops or uses AI systems can apply it as voluntary guidance alongside broader AI governance frameworks.

Principles

ISO/IEC 23894 applies ISO 31000 risk-management principles to AI. It focuses on identifying, analyzing, evaluating, and treating AI-related risks across the AI system lifecycle, and complements certifiable AI management standards such as ISO/IEC 42001.

ISO/IEC 27017

Overseeing Organization

International Organization for Standardization (ISO) / International Electrotechnical Commission (IEC)

Focus/Applicability

ISO/IEC 27017 provides cloud-specific information security guidance based on ISO/IEC 27002 controls. It applies to cloud service providers and cloud customers that want to clarify shared security responsibilities in cloud environments.

Principles

ISO/IEC 27017 emphasizes shared responsibility between cloud providers and customers. It adds cloud-focused implementation guidance to established ISO/IEC 27002 controls and supports consistent security practices across cloud services.

ISO/IEC 27018

Overseeing Organization

International Organization for Standardization (ISO) / International Electrotechnical Commission (IEC)

Focus/Applicability

ISO/IEC 27018 provides guidance for the protection of personally identifiable information (PII) in public cloud environments when the cloud provider acts as a PII processor. It applies to cloud service providers and organizations that process PII in the public cloud.

Principles

ISO/IEC 27018 emphasizes privacy controls for PII processed in public clouds, including transparency, customer control of PII, and restrictions on secondary use. Organizations often use it as supporting evidence in vendor due diligence and data processing agreements.

ISO/IEC 27701 (Privacy Information Management System)

Overseeing Organization

International Organization for Standardization (ISO) / International Electrotechnical Commission (IEC)

Focus/Applicability

ISO/IEC 27701 is a certifiable extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management systems (PIMS). It applies to organizations that act as PII controllers or processors.

Principles

ISO/IEC 27701 emphasizes privacy governance integrated with information security management. It adds requirements and guidance for PII controllers and processors, and supports demonstration of privacy controls alongside an ISO/IEC 27001 ISMS.

ISO/IEC 42001 (AI Management System)

Overseeing Organization

International Organization for Standardization (ISO) / International Electrotechnical Commission (IEC)

Focus/Applicability

ISO/IEC 42001 is a certifiable standard for artificial intelligence management systems (AIMS). Any organization that develops, provides, or uses AI systems can apply it, regardless of size or industry.

Principles

ISO/IEC 42001 follows a management-system approach for responsible AI. It covers areas such as AI policy, roles and responsibilities, impact assessment, data governance, AI system lifecycle controls, and management of third-party AI suppliers.

NCSA Cybersecurity Act

Overseeing Organization

National Cyber Security Agency (NCSA) / National Cyber Security Committee (NCSC) — Thailand

Focus/Applicability

The Cybersecurity Act B.E. 2562 (2019) applies to state agencies and to Critical Information Infrastructure (CII) organizations in Thailand. CII covers public and private organizations that provide or support services essential to national security, public safety, economic stability, or critical public infrastructure.

Principles

The Act emphasizes protection of critical information infrastructure through cybersecurity risk management, readiness planning, incident reporting, and minimum security standards. CII organizations must implement controls aligned with confidentiality, integrity, and availability, report significant cyberthreats and incidents to the NCSA and supervising authorities, and maintain designated cybersecurity responsibilities.

NCSC Cyber Assessment Framework (CAF)

Overseeing Organization

National Cyber Security Centre (NCSC) — United Kingdom

Focus/Applicability

The Cyber Assessment Framework (CAF) applies to organizations in the UK critical national infrastructure (CNI) and public sector, and to other organizations in regulated sectors that assess cyber resilience against NCSC outcomes.

Principles

CAF focuses on outcome-based cyber resilience across objectives such as managing security risk, protecting against cyber attack, detecting cybersecurity events, and minimizing the impact of cybersecurity incidents. Regulators use CAF outcomes and indicators of good practice to assess organizational capability.

NIS2 Directive

Overseeing Organization

European Union (EU)

Focus/Applicability

The NIS2 Directive (EU 2022/2555) applies to essential and important entities in the European Union across critical and highly critical sectors. Member states implement the directive through national law.

Principles

NIS2 focuses on cybersecurity risk-management measures and incident reporting. Article 21 outlines categories of technical and organizational measures such as risk analysis, incident handling, supply chain security, and cryptography, rather than a fixed control catalog.

NIST AI RMF (Artificial Intelligence Risk Management Framework)

Overseeing Organization

National Institute of Standards and Technology (NIST) — United States Department of Commerce

Focus/Applicability

The NIST AI Risk Management Framework applies to organizations that design, develop, deploy, or use AI systems. It is voluntary and widely adopted in the United States and globally. A Generative AI Profile extends the framework for generative AI use cases.

Principles

NIST AI RMF focuses on managing AI risks through four core functions: Govern, Map, Measure, and Manage. It provides a process-oriented maturity approach rather than a fixed technical control catalog.

NIST CSF (National Institute of Standards and Technology Cybersecurity Framework)

Overseeing Organization

National Institute of Standards and Technology (NIST), part of the United States Department of Commerce

Focus/Applicability

NIST CSF applies to organizations across all sectors, primarily in the United States, but is widely adopted globally. It is designed for organizations of all sizes to improve cybersecurity risk management.

Principles

NIST CSF focuses on the management and reduction of cybersecurity risk through a structured approach. It provides a risk-based framework that consists of six core functions:

  • Govern – Establish and monitor cybersecurity risk management strategy, policies, and oversight.
  • Identify – Understand assets, systems, data, and risks.
  • Protect – Implement safeguards to limit or contain the impact of potential events.
  • Detect – Develop activities to identify the occurrence of a cybersecurity event.
  • Respond – Take action related to a detected cybersecurity incident.
  • Recover – Restore capabilities and services impaired because of a cybersecurity event.

NIST SP 800-53

Overseeing Organization

National Institute of Standards and Technology (NIST) — United States Department of Commerce.

Focus/Applicability

NIST SP 800-53 provides a catalog of security and privacy controls designed to protect information systems and organizations. It is applicable to US federal agencies, contractors, and organizations that handle government data, but it is also widely used in the private sector as a best-practice framework.

Principles

NIST SP 800-53 emphasizes a risk-based approach to cybersecurity, and organizes controls into families (such as, Access Control, Risk Assessment, Incident Response). Key principles include implementing multiple layers of security (defense-in-depth), continuous monitoring of risks and compliance, and tailoring controls to specific organizational needs (flexibility).

NIST SP 800-171 Rev. 3

Overseeing Organization

National Institute of Standards and Technology (NIST) — United States Department of Commerce.

Focus/Applicability

NIST SP 800-171 provides security requirements to protect the confidentiality of Controlled Unclassified Information (CUI) in non-federal systems and organizations. It applies to contractors and other organizations that process, store, or transmit CUI for US federal agencies.

Principles

NIST SP 800-171 organizes security requirements into families (such as, Access Control, Audit and Accountability, and System and Communications Protection). Revision 3 aligns requirements with NIST SP 800-53, increases specificity, and introduces organization-defined parameters (ODPs) so organizations can tailor selected requirements to their operational needs.

NIST SP 800-172 Rev. 3

Overseeing Organization

National Institute of Standards and Technology (NIST) — United States Department of Commerce.

Focus/Applicability

NIST SP 800-172 provides enhanced security requirements to protect the confidentiality, integrity, and availability of Controlled Unclassified Information (CUI) associated with critical programs or high value assets in nonfederal systems and organizations. It supplements NIST SP 800-171 and applies when US federal agencies select these requirements in contracts or other agreements to manage risks to CUI.

Principles

NIST SP 800-172 emphasizes defense-in-depth and cyber resiliency to protect against advanced persistent threats (APTs). Revision 3 aligns enhanced requirements with NIST SP 800-171 Rev. 3 and NIST SP 800-53, and expands coverage beyond confidentiality to include integrity and availability. Federal agencies select the enhanced requirements based on mission needs and risk assessments.

PCI DSS (Payment Card Industry Data Security Standard)

Overseeing Organization

Payment Card Industry Security Standards Council (PCI SSC)

Focus/Applicability

PCI DSS is a global standard that applies to all entities that store, process, or transmit credit card information. It is designed to protect payment card data and prevent fraud.

Principles

PCI DSS focuses on the protection of cardholder data through measures like encryption, masking, and tokenization (data protection). It emphasizes restricting access to sensitive data to authorized personnel (access control) and regularly monitoring and testing networks to detect vulnerabilities (monitoring and testing). Organizations must comply with stringent controls to make sure that they handle payment data safely (compliance enforcement).

SMB1001

Overseeing Organization

SMB1001 scheme owner

Focus/Applicability

SMB1001 is a tiered cybersecurity certification designed for small and medium-sized businesses, primarily in Australia. It is voluntary and intended for organizations that want a practical, certifiable security baseline.

Principles

SMB1001 emphasizes scalable security controls appropriate for smaller organizations. It aligns with widely used guidance such as CIS Controls and the ACSC Essential Eight, and provides a certification path that matches common MSP and SMB operational needs.

SOC 2 (Service Organization Controls)

Overseeing Organization

American Institute of Certified Public Accountants (AICPA)

Focus/Applicability

SOC 2 is an auditing standard for service providers that store or process customer data. It focuses on internal controls related to security, availability, integrity, confidentiality, and privacy.

Principles

SOC 2 reports come in three trust service principles (TSPs): Security, Availability, and Confidentiality (or Privacy). Organizations can select which principles to be audited for, based on their specific services and customer requirements.

UK GDPR (United Kingdom General Data Protection Regulation)

Overseeing Organization

Information Commissioner's Office (ICO) — United Kingdom

Focus/Applicability

UK GDPR governs the processing of personal data of individuals in the United Kingdom. It applies to organizations that process this data, regardless of where the organization is located.

Principles

UK GDPR emphasizes individual control over personal data and aligns closely with EU GDPR principles such as transparency, accountability, and data subject rights. It includes requirements for appropriate technical and organizational measures to protect personal data.

Related Topics

Manage Compliance in CloudDR