Compliance Frameworks in CloudDR
Applies To: WatchGuard CloudDR
On the Compliance page in WatchGuard CloudDR, you can manage your compliance with major frameworks. CloudDR supports these frameworks:
- ACSC Essential Eight
- APPI (Act on the Protection of Personal Information)
- CCPA / CPRA
- CIS Controls (Center for Internet Security)
- CISA SCuBA — Google Workspace Baselines
- CISA SCuBA — Microsoft 365 Secure Configuration Baselines
- CJIS Security Policy
- CMMC (Cybersecurity Maturity Model Certification)
- CSA STAR (Cloud Security Alliance Security Trust Assurance and Risk)
- Cyber Essentials / Cyber Essentials Plus
- DORA (Digital Operational Resilience Act)
- EU AI Act
- FedRAMP
- FISMA (Federal Information Security Modernization Act)
- GDPR (General Data Protection Regulation)
- GovRAMP / TX-RAMP
- HIPAA (Health Insurance Portability and Accountability Act)
- ISO 27001:2022 (International Organization for Standardization)
- ISO/IEC 23894 (AI Risk Management)
- ISO/IEC 27017
- ISO/IEC 27018
- ISO/IEC 27701 (Privacy Information Management System)
- ISO/IEC 42001 (AI Management System)
- NCSA Cybersecurity Act
- NCSC Cyber Assessment Framework (CAF)
- NIS2 Directive
- NIST AI RMF (Artificial Intelligence Risk Management Framework)
- NIST CSF (National Institute of Standards and Technology Cybersecurity Framework)
- NIST SP 800-53
- NIST SP 800-171 Rev. 3
- NIST SP 800-172 Rev. 3
- PCI DSS (Payment Card Industry Data Security Standard)
- SMB1001
- SOC 2 (Service Organization Controls)
- UK GDPR (United Kingdom General Data Protection Regulation)
ACSC Essential Eight
Overseeing Organization
Australian Cyber Security Centre (ACSC)
Focus/Applicability
The Essential Eight is a set of prioritized mitigation strategies for Australian organizations. It is mandatory for Australian federal entities and widely recommended for organizations of all sizes in Australia.
Principles
The Essential Eight emphasizes eight technical strategies with defined maturity levels (ML1–ML3), including application control, patching, multi-factor authentication, and regular backups. Organizations improve maturity progressively to reduce the likelihood and impact of cyber incidents.
APPI (Act on the Protection of Personal Information)
Overseeing Organization
Personal Information Protection Commission (PPC) — Japan
Focus/Applicability
APPI is Japan's primary data protection law. It applies to organizations that handle the personal information of individuals in Japan.
Principles
APPI emphasizes appropriate acquisition, use, and protection of personal information. PPC guidance describes organizational, human, physical, and technical safety management measures, including access control, authentication, prevention of unauthorized external access, and leakage prevention.
CCPA / CPRA
Overseeing Organization
California Privacy Protection Agency (CPPA)
Focus/Applicability
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), applies to businesses that meet California thresholds and that collect or process the personal information of California residents.
Principles
CCPA/CPRA emphasizes consumer privacy rights and business obligations for transparency, access, deletion, and opt-out of sale or sharing. It also requires reasonable security procedures and practices to protect personal information, including measures such as access control, encryption, and appropriate retention.
CIS Controls (Center for Internet Security)
Overseeing Organization
Center for Internet Security (CIS) — Non-profit organization
Focus/Applicability
CIS controls are a recommended set of best practices for cybersecurity across various IT assets like servers, endpoints, and cloud environments. They are not official regulations but are widely adopted by organizations of all sizes.
Principles
CIS controls are based on a defense-in-depth approach, and prioritize critical security controls to mitigate the most common cyberthreats.
CISA SCuBA — Google Workspace Baselines
Overseeing Organization
Cybersecurity and Infrastructure Security Agency (CISA)
Focus/Applicability
CISA SCuBA Google Workspace baselines provide secure configuration guidance for Google Workspace. They apply to US FCEB agencies and are usable by organizations globally that want aligned Google Workspace hardening guidance.
Principles
These baselines emphasize observable configuration settings for Google Workspace and complement the Microsoft 365 SCuBA baselines. Together they provide a consistent SCuBA approach across common cloud productivity suites.
CISA SCuBA — Microsoft 365 Secure Configuration Baselines
Overseeing Organization
Cybersecurity and Infrastructure Security Agency (CISA)
Focus/Applicability
CISA Secure Cloud Business Applications (SCuBA) Microsoft 365 Secure Configuration Baselines provide product-specific secure configuration guidance for Microsoft 365. They apply to US federal civilian executive branch (FCEB) agencies and are usable by organizations globally that want aligned Microsoft 365 hardening guidance.
Principles
SCuBA baselines emphasize observable, machine-checkable configuration settings across Microsoft 365 products. They align with CIS Microsoft 365 Foundations Benchmark guidance and support consistent secure configuration assessment for cloud productivity services.
CJIS Security Policy
Overseeing Organization
Federal Bureau of Investigation (FBI) Criminal Justice Information Services (CJIS) Division
Focus/Applicability
The CJIS Security Policy applies to US law enforcement agencies and to suppliers that process, store, or transmit Criminal Justice Information (CJI). Compliance is mandatory for entities that connect to CJIS systems or handle CJI.
Principles
CJIS Security Policy focuses on protecting the confidentiality, integrity, and availability of CJI. Key requirements include access control, multi-factor authentication, audit logging, encryption, and personnel security. State CJIS Systems Agencies typically assess compliance on a recurring cycle.
CMMC (Cybersecurity Maturity Model Certification)
Overseeing Organization
United States Department of Defense (DoD) Chief Information Officer (CIO)
Focus/Applicability
CMMC applies to organizations in the US defense supply chain that process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). It is mandatory through DoD contracts that require CMMC certification.
Principles
CMMC defines maturity levels that map security requirements to contract needs. Level 1 focuses on basic safeguarding of FCI. Level 2 aligns with NIST SP 800-171 requirements to protect CUI and typically requires third-party assessment for certification.
CSA STAR (Cloud Security Alliance Security Trust Assurance and Risk)
Overseeing Organization
Cloud Security Alliance (CSA)
Focus/Applicability
CSA STAR is a certification and assurance program designed to address cloud security. It applies to cloud service providers (CSPs) and their customers, and offers transparency and assurance of security practices in cloud environments.
Principles
CSA STAR emphasizes transparency by requiring CSPs to provide clear details about their security controls. It incorporates a three-level assurance model (self-assessment, third-party audit, and continuous monitoring), and aligns with frameworks like ISO 27001 and the Cloud Controls Matrix (CCM). Additionally, it supports organizations in the evaluation and management of cloud-related risks (risk management).
Cyber Essentials / Cyber Essentials Plus
Overseeing Organization
National Cyber Security Centre (NCSC) — United Kingdom / IASME
Focus/Applicability
Cyber Essentials is a UK certification scheme for organizations of all sizes. It is voluntary for many organizations and mandatory for many UK government contracts. Cyber Essentials Plus uses the same control themes with an independent technical assessment.
Principles
Cyber Essentials focuses on five technical control themes that reduce common cyberthreats: firewalls and internet gateways, secure configuration, security update management, user access control, and malware protection. Cyber Essentials Plus adds independent verification of the same themes.
DORA (Digital Operational Resilience Act)
Overseeing Organization
European Union (EU)
Focus/Applicability
DORA (EU 2022/2554) applies to financial entities in the European Union and to critical ICT third-party service providers that support them. It is a directly applicable regulation for digital operational resilience in the financial sector.
Principles
DORA emphasizes ICT risk management, incident reporting, digital operational resilience testing, and oversight of ICT third-party risk. For financial entities, it acts as lex specialis relative to NIS2 for overlapping ICT security obligations.
EU AI Act
Overseeing Organization
European Union (EU)
Focus/Applicability
The EU AI Act (EU 2024/1689) is a regulation that applies to providers and deployers of AI systems in the European Union. Obligations vary by risk level, with stricter requirements for high-risk AI systems.
Principles
The EU AI Act emphasizes risk-based AI governance, including prohibited practices, transparency obligations, and requirements for high-risk systems such as risk management, data governance, human oversight, and documentation. Organizations must inventory and classify AI systems to apply the correct obligations.
FedRAMP
Overseeing Organization
FedRAMP Program Management Office (PMO) / General Services Administration (GSA)
Focus/Applicability
FedRAMP provides standardized security authorization baselines for cloud service providers that sell cloud products to US federal agencies. Baselines include Low, Moderate, High, and LI-SaaS, based on NIST SP 800-53 Rev. 5 with FedRAMP-specific additions.
Principles
FedRAMP emphasizes reusable authorization packages, continuous monitoring, and consistent control baselines for federal cloud use. Cloud providers pursue authorization against a selected baseline. Customer organizations typically assess readiness against FedRAMP requirements rather than claiming FedRAMP authorization themselves.
FISMA (Federal Information Security Modernization Act)
Overseeing Organization
National Institute of Standards and Technology (NIST) / Office of Management and Budget (OMB) / Cybersecurity and Infrastructure Security Agency (CISA)
Focus/Applicability
FISMA applies to US federal agencies and to contractors that operate information systems on behalf of those agencies. Organizations implement FISMA through tailored NIST SP 800-53 control baselines selected by FIPS 199 impact level (Low, Moderate, or High).
Principles
FISMA emphasizes risk-based security authorization and continuous monitoring. Agencies select and implement NIST SP 800-53 baselines, document system security, assess residual risk, and maintain authorization to operate (ATO) through ongoing monitoring and remediation.
GDPR (General Data Protection Regulation)
Overseeing Organization
European Union (EU)
Focus/Applicability
GDPR is a regulation that governs the processing of personal data of individuals who reside in the European Economic Area (EEA). It applies to any organization that processes this data, regardless of the location of the organization.
Principles
GDPR emphasizes individual control over personal data. It outlines principles such as transparency, accountability, and data subject rights (access, rectification, erasure, restriction of processing).
GovRAMP / TX-RAMP
Overseeing Organization
GovRAMP (formerly StateRAMP)
Focus/Applicability
GovRAMP provides authorization baselines for cloud products used by US state, local, tribal, and education (SLED) organizations and their cloud vendors. TX-RAMP is the Texas state authorization program and provides reciprocity pathways with GovRAMP in participating contexts.
Principles
GovRAMP builds on NIST SP 800-53 Rev. 5 baselines with impact levels aligned to common cloud authorization models. It emphasizes standardized security packages, continuous monitoring, and authorization for cloud services sold into the SLED market.
HIPAA (Health Insurance Portability and Accountability Act)
Overseeing Organization
United States Department of Health and Human Services (HHS)
Focus/Applicability
HIPAA applies to healthcare providers, health plans, and healthcare clearinghouses that handle the protected health information (PHI) of individuals.
Principles
HIPAA focuses on protecting the privacy, security, and integrity of PHI. It outlines requirements for administrative, physical, and technical safeguards to achieve these goals.
ISO 27001:2022 (International Organization for Standardization)
Overseeing Organization
International Organization for Standardization (ISO)
Focus/Applicability
ISO 27001 is an information security management system (ISMS) standard that any organization can apply, regardless of size or industry. It provides a framework for the implementation and maintenance of a comprehensive information security program.
Principles
ISO 27001 follows a risk-based approach, and requires organizations to identify information assets, assess security risks, implement controls, and continuously improve their ISMS.
ISO/IEC 23894 (AI Risk Management)
Overseeing Organization
International Organization for Standardization (ISO) / International Electrotechnical Commission (IEC)
Focus/Applicability
ISO/IEC 23894 provides guidance on risk management for artificial intelligence. Any organization that develops or uses AI systems can apply it as voluntary guidance alongside broader AI governance frameworks.
Principles
ISO/IEC 23894 applies ISO 31000 risk-management principles to AI. It focuses on identifying, analyzing, evaluating, and treating AI-related risks across the AI system lifecycle, and complements certifiable AI management standards such as ISO/IEC 42001.
ISO/IEC 27017
Overseeing Organization
International Organization for Standardization (ISO) / International Electrotechnical Commission (IEC)
Focus/Applicability
ISO/IEC 27017 provides cloud-specific information security guidance based on ISO/IEC 27002 controls. It applies to cloud service providers and cloud customers that want to clarify shared security responsibilities in cloud environments.
Principles
ISO/IEC 27017 emphasizes shared responsibility between cloud providers and customers. It adds cloud-focused implementation guidance to established ISO/IEC 27002 controls and supports consistent security practices across cloud services.
ISO/IEC 27018
Overseeing Organization
International Organization for Standardization (ISO) / International Electrotechnical Commission (IEC)
Focus/Applicability
ISO/IEC 27018 provides guidance for the protection of personally identifiable information (PII) in public cloud environments when the cloud provider acts as a PII processor. It applies to cloud service providers and organizations that process PII in the public cloud.
Principles
ISO/IEC 27018 emphasizes privacy controls for PII processed in public clouds, including transparency, customer control of PII, and restrictions on secondary use. Organizations often use it as supporting evidence in vendor due diligence and data processing agreements.
ISO/IEC 27701 (Privacy Information Management System)
Overseeing Organization
International Organization for Standardization (ISO) / International Electrotechnical Commission (IEC)
Focus/Applicability
ISO/IEC 27701 is a certifiable extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management systems (PIMS). It applies to organizations that act as PII controllers or processors.
Principles
ISO/IEC 27701 emphasizes privacy governance integrated with information security management. It adds requirements and guidance for PII controllers and processors, and supports demonstration of privacy controls alongside an ISO/IEC 27001 ISMS.
ISO/IEC 42001 (AI Management System)
Overseeing Organization
International Organization for Standardization (ISO) / International Electrotechnical Commission (IEC)
Focus/Applicability
ISO/IEC 42001 is a certifiable standard for artificial intelligence management systems (AIMS). Any organization that develops, provides, or uses AI systems can apply it, regardless of size or industry.
Principles
ISO/IEC 42001 follows a management-system approach for responsible AI. It covers areas such as AI policy, roles and responsibilities, impact assessment, data governance, AI system lifecycle controls, and management of third-party AI suppliers.
NCSA Cybersecurity Act
Overseeing Organization
National Cyber Security Agency (NCSA) / National Cyber Security Committee (NCSC) — Thailand
Focus/Applicability
The Cybersecurity Act B.E. 2562 (2019) applies to state agencies and to Critical Information Infrastructure (CII) organizations in Thailand. CII covers public and private organizations that provide or support services essential to national security, public safety, economic stability, or critical public infrastructure.
Principles
The Act emphasizes protection of critical information infrastructure through cybersecurity risk management, readiness planning, incident reporting, and minimum security standards. CII organizations must implement controls aligned with confidentiality, integrity, and availability, report significant cyberthreats and incidents to the NCSA and supervising authorities, and maintain designated cybersecurity responsibilities.
NCSC Cyber Assessment Framework (CAF)
Overseeing Organization
National Cyber Security Centre (NCSC) — United Kingdom
Focus/Applicability
The Cyber Assessment Framework (CAF) applies to organizations in the UK critical national infrastructure (CNI) and public sector, and to other organizations in regulated sectors that assess cyber resilience against NCSC outcomes.
Principles
CAF focuses on outcome-based cyber resilience across objectives such as managing security risk, protecting against cyber attack, detecting cybersecurity events, and minimizing the impact of cybersecurity incidents. Regulators use CAF outcomes and indicators of good practice to assess organizational capability.
NIS2 Directive
Overseeing Organization
European Union (EU)
Focus/Applicability
The NIS2 Directive (EU 2022/2555) applies to essential and important entities in the European Union across critical and highly critical sectors. Member states implement the directive through national law.
Principles
NIS2 focuses on cybersecurity risk-management measures and incident reporting. Article 21 outlines categories of technical and organizational measures such as risk analysis, incident handling, supply chain security, and cryptography, rather than a fixed control catalog.
NIST AI RMF (Artificial Intelligence Risk Management Framework)
Overseeing Organization
National Institute of Standards and Technology (NIST) — United States Department of Commerce
Focus/Applicability
The NIST AI Risk Management Framework applies to organizations that design, develop, deploy, or use AI systems. It is voluntary and widely adopted in the United States and globally. A Generative AI Profile extends the framework for generative AI use cases.
Principles
NIST AI RMF focuses on managing AI risks through four core functions: Govern, Map, Measure, and Manage. It provides a process-oriented maturity approach rather than a fixed technical control catalog.
NIST CSF (National Institute of Standards and Technology Cybersecurity Framework)
Overseeing Organization
National Institute of Standards and Technology (NIST), part of the United States Department of Commerce
Focus/Applicability
NIST CSF applies to organizations across all sectors, primarily in the United States, but is widely adopted globally. It is designed for organizations of all sizes to improve cybersecurity risk management.
Principles
NIST CSF focuses on the management and reduction of cybersecurity risk through a structured approach. It provides a risk-based framework that consists of six core functions:
- Govern – Establish and monitor cybersecurity risk management strategy, policies, and oversight.
- Identify – Understand assets, systems, data, and risks.
- Protect – Implement safeguards to limit or contain the impact of potential events.
- Detect – Develop activities to identify the occurrence of a cybersecurity event.
- Respond – Take action related to a detected cybersecurity incident.
- Recover – Restore capabilities and services impaired because of a cybersecurity event.
NIST SP 800-53
Overseeing Organization
National Institute of Standards and Technology (NIST) — United States Department of Commerce.
Focus/Applicability
NIST SP 800-53 provides a catalog of security and privacy controls designed to protect information systems and organizations. It is applicable to US federal agencies, contractors, and organizations that handle government data, but it is also widely used in the private sector as a best-practice framework.
Principles
NIST SP 800-53 emphasizes a risk-based approach to cybersecurity, and organizes controls into families (such as, Access Control, Risk Assessment, Incident Response). Key principles include implementing multiple layers of security (defense-in-depth), continuous monitoring of risks and compliance, and tailoring controls to specific organizational needs (flexibility).
NIST SP 800-171 Rev. 3
Overseeing Organization
National Institute of Standards and Technology (NIST) — United States Department of Commerce.
Focus/Applicability
NIST SP 800-171 provides security requirements to protect the confidentiality of Controlled Unclassified Information (CUI) in non-federal systems and organizations. It applies to contractors and other organizations that process, store, or transmit CUI for US federal agencies.
Principles
NIST SP 800-171 organizes security requirements into families (such as, Access Control, Audit and Accountability, and System and Communications Protection). Revision 3 aligns requirements with NIST SP 800-53, increases specificity, and introduces organization-defined parameters (ODPs) so organizations can tailor selected requirements to their operational needs.
NIST SP 800-172 Rev. 3
Overseeing Organization
National Institute of Standards and Technology (NIST) — United States Department of Commerce.
Focus/Applicability
NIST SP 800-172 provides enhanced security requirements to protect the confidentiality, integrity, and availability of Controlled Unclassified Information (CUI) associated with critical programs or high value assets in nonfederal systems and organizations. It supplements NIST SP 800-171 and applies when US federal agencies select these requirements in contracts or other agreements to manage risks to CUI.
Principles
NIST SP 800-172 emphasizes defense-in-depth and cyber resiliency to protect against advanced persistent threats (APTs). Revision 3 aligns enhanced requirements with NIST SP 800-171 Rev. 3 and NIST SP 800-53, and expands coverage beyond confidentiality to include integrity and availability. Federal agencies select the enhanced requirements based on mission needs and risk assessments.
PCI DSS (Payment Card Industry Data Security Standard)
Overseeing Organization
Payment Card Industry Security Standards Council (PCI SSC)
Focus/Applicability
PCI DSS is a global standard that applies to all entities that store, process, or transmit credit card information. It is designed to protect payment card data and prevent fraud.
Principles
PCI DSS focuses on the protection of cardholder data through measures like encryption, masking, and tokenization (data protection). It emphasizes restricting access to sensitive data to authorized personnel (access control) and regularly monitoring and testing networks to detect vulnerabilities (monitoring and testing). Organizations must comply with stringent controls to make sure that they handle payment data safely (compliance enforcement).
SMB1001
Overseeing Organization
SMB1001 scheme owner
Focus/Applicability
SMB1001 is a tiered cybersecurity certification designed for small and medium-sized businesses, primarily in Australia. It is voluntary and intended for organizations that want a practical, certifiable security baseline.
Principles
SMB1001 emphasizes scalable security controls appropriate for smaller organizations. It aligns with widely used guidance such as CIS Controls and the ACSC Essential Eight, and provides a certification path that matches common MSP and SMB operational needs.
SOC 2 (Service Organization Controls)
Overseeing Organization
American Institute of Certified Public Accountants (AICPA)
Focus/Applicability
SOC 2 is an auditing standard for service providers that store or process customer data. It focuses on internal controls related to security, availability, integrity, confidentiality, and privacy.
Principles
SOC 2 reports come in three trust service principles (TSPs): Security, Availability, and Confidentiality (or Privacy). Organizations can select which principles to be audited for, based on their specific services and customer requirements.
UK GDPR (United Kingdom General Data Protection Regulation)
Overseeing Organization
Information Commissioner's Office (ICO) — United Kingdom
Focus/Applicability
UK GDPR governs the processing of personal data of individuals in the United Kingdom. It applies to organizations that process this data, regardless of where the organization is located.
Principles
UK GDPR emphasizes individual control over personal data and aligns closely with EU GDPR principles such as transparency, accountability, and data subject rights. It includes requirements for appropriate technical and organizational measures to protect personal data.