How can we help?
Search 5,951 articles across cloud security controls, compliance frameworks (CIS, ISO 27001 / 27701 / 42001, SOC 2, HIPAA, NIST 800-53 & 800-171, CMMC, GDPR, DPDP, BSI C5), cost savings, and getting-started guides.
Compliance implementation guides
Practical, step-by-step guides: who each framework applies to, how to scope it, a phased roadmap, the hardest controls on AWS, Azure and GCP, and how the audit or assessment runs.
NIST SP 800-53 Rev. 5 Controls
Every control and control enhancement from NIST Special Publication 800-53 Revision 5 — the U.S. federal catalogue for security and privacy. Organised by 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR). FedRAMP, FISMA, CMMC and many state regulations point directly at SP 800-53 baselines.
- NIST SP 800-53 Rev. 5 AC-1 — Policy And Procedures
- NIST SP 800-53 Rev. 5 AC-2 — Account Management
- NIST SP 800-53 Rev. 5 AC-2(1) — Automated System Account Management
- NIST SP 800-53 Rev. 5 AC-2(2) — Automated Temporary And Emergency Account Management
- NIST SP 800-53 Rev. 5 AC-2(3) — Disable Accounts
AWS Checks New Version
- CIS Critical Security Controls v8.1 — overview
- CIS 1.1 — Establish and Maintain Detailed Enterprise Asset Inventory
- CIS 2.1 — Establish and Maintain a Software Inventory
- CIS 2.2 — Ensure Authorized Software is Currently Supported
- CIS 3.1 — Establish and Maintain a Data Management Process
CIS Amazon Linux 2 Benchmark v3.0.0
- Ensure Audit Logging of Network Environment Modification Events
- Ensure Audit Logging of Privileged Command Usage
- Ensure Audit Logging of Unsuccessful File Access Attempts
- Ensure Audit Logging of User and Group Modification Events
- Ensure Audit Logging of Discretionary Access Control Permission Modifications
General
- How to add additional aws accounts to your plan ?
- How do i check my existing subscription plan ?
- How does good Cybersecurity operate?
- What are the costs of a Cybersecurity attack?
- EC2 Approved AMIs Check (by AMI Tag)
Security Controls
- Ensure there are no EC2 AMIs set as Public
- Ensure there are no ECR repositories set as Public
- Ensure there are no Public Accessible RDS instances
- Ensure Security Groups do not allow unrestricted ingress access to any port
- Ensure Security Groups do not allow unrestricted ingress access to Oracle Ports 1521 or 2483
HIPAA Security, Privacy & Breach-Notification Rules
All 195 administrative, physical, technical, organisational and documentation safeguards from 45 CFR Parts 160 and 164, as amended by the 2013 Omnibus Final Rule. Applies to Covered Entities and their Business Associates handling Protected Health Information (PHI).
- HIPAA (45 CFR Part 164) 164.306(a) — General Requirements
- HIPAA (45 CFR Part 164) 164.306(b) — Flexibility of approach
- HIPAA (45 CFR Part 164) 164.308(a) — Security Management Process
- HIPAA (45 CFR Part 164) 164.308(a)(1)(ii)(A) — Security Management Process - Risk Analysis
- HIPAA (45 CFR Part 164) 164.308(a)(1)(ii)(B) — Security Management Process - Risk Management
NIST
- NIST SP 800-53 Rev 5 — overview
- NIST800 53 AC-1 — Policy And Procedures
- NIST800 53 AC-2(7) — Privileged User Accounts
- NIST800 53 AC-2 — Account Management
- NIST800 53 AC-2(1) — Automated System Account Management
CIS Critical Security Controls v8
The Center for Internet Security's prioritised set of 18 controls and 153 safeguards for cyber defence. Implementation Groups IG1, IG2 and IG3 stage adoption from a hygiene baseline up to advanced defence.
- CIS Controls v8 1.1 — Establish and Maintain Detailed Enterprise Asset Inventory
- CIS Controls v8 1.2 — Address Unauthorized Assets
- CIS Controls v8 1.3 — Utilize an Active Discovery Tool
- CIS Controls v8 1.4 — Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory
- CIS Controls v8 1.5 — Use a Passive Asset Discovery Tool
CIS Microsoft Azure Foundations Benchmark v4.0.0
- Ensure Critical Data is Encrypted with Microsoft Managed Keys (MMK)
- Ensure Critical Data is Encrypted with Customer Managed Keys (CMK)
- Ensure Public Network Access is Disabled (Automated)
- Ensure Network Access Rules are Set to Deny-by-Default (Automated)
- Ensure Private Endpoints are Used to Access {Service} (Automated)
CIS Kubernetes Benchmark v1.9.0
- Ensure that the API Server Pod Specification File Permissions Are Set to 600 or More Restrictive
- Ensure that the API server pod specification file ownership is set to root:root
- Ensure that the controller manager pod specification file permissions are set to 600 or more restrictive
- Ensure that the controller manager pod specification file ownership is set to root:root
- Ensure that the scheduler pod specification file permissions are set to 600 or more restrictive
BSI C5:2020 (Cloud Computing Compliance Criteria)
The German Federal Office for Information Security's 2020 Cloud Computing Compliance Criteria Catalogue — the baseline German public-sector buyers and many DAX-listed enterprises expect from their cloud providers. Each criterion has Basic and Additional objectives; attestation is performed under ISAE 3000 / IDW PS 860 as a Type 1 or Type 2 report.
- BSI C5:2020 AM-01 — Asset Inventory
- BSI C5:2020 AM-02 — Acceptable Use and Safe Handling of Assets Policy
- BSI C5:2020 AM-03 — Commissioning of Hardware
- BSI C5:2020 AM-04 — Decommissioning of Hardware
- BSI C5:2020 AM-05 — Commitment to Permissible Use, Safe Handling and Return of Assets
GCP Benchmarks
- 1.1 Ensure Corporate Login Credentials Are Used (Manual)
- 1.2 Ensure Multi-Factor Authentication is Enabled for All Non-Service Accounts (Manual)
- 1.3 Ensure Security Key Enforcement is Enabled for All Admin Accounts (Manual)
- 1.4 Ensure Only GCP-Managed Service Account Keys Are Used for Each Service Account (Automated)
- 1.5 Ensure Service Accounts Do Not Have Admin Privileges (Automated)
CIS GitHub Benchmark v1.0.0
- Ensure Track All Code Changes Using a Version Control System
- Ensure Trace Code Changes to Their Corresponding Tasks or Issues
- Ensure Enforce Two-Person Code Change Approval with Strong Authentication
- Ensure Invalidate Prior Approvals Upon Code Change Updates
- Ensure Restrict Permissions for Dismissing Code Review Approvals
CIS Docker Benchmark v1.7.0
- Ensure a Separate Partition for Containers Has Been Created
- Ensure Only Trusted Users Are Allowed to Control Docker Daemon
- Ensure Auditing is Configured for the Docker Daemon
- Ensure Auditing is Configured for Docker Files and Directories - /run/containerd
- Ensure Auditing is Configured for Docker Files and Directories - /var/lib/docker
GDPR
- GDPR — overview
- GDPR Article 5 — Principles relating to processing of personal data
- GDPR Article 6 — Lawfulness of processing
- GDPR Article 7 — Conditions for consent
- GDPR Article 9 — Processing of special categories of personal data
NIST SP 800-171 Rev. 3 Requirements
The 100 security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems — the technical baseline that CMMC Level 2 inherits and that every DoD prime and subcontractor must implement to keep CUI contracts.
- NIST SP 800-171 Rev. 3 3.1.1 — Account Management
- NIST SP 800-171 Rev. 3 3.1.2 — Access Enforcement
- NIST SP 800-171 Rev. 3 3.1.3 — Information Flow Enforcement
- NIST SP 800-171 Rev. 3 3.1.4 — Separation of Duties
- NIST SP 800-171 Rev. 3 3.1.5 — Least Privilege
GDPR (Regulation (EU) 2016/679)
All 99 articles of the EU General Data Protection Regulation — the world's most-cited modern privacy law. Applies to any organisation offering goods or services to, or monitoring, individuals in the EU/EEA, regardless of where the organisation is established.
- GDPR Article 1 — Subject-matter and objectives
- GDPR Article 2 — Material Scope
- GDPR Article 3 — Territorial Scope
- GDPR Article 4 — Definitions
- GDPR Article 5 — Principles relating to processing of personal data
CyberSecurity Taxonomy
View all 97 articles →CMMC
- CMMC 2.0 AC.1.001 Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems)
- CMMC 2.0 AC.1.002 Limit system access to the types of transactions and functions that authorized users are permitted to execute.
- CMMC 2.0 AC.1.003 Verify and control/limit connections to and use of external information systems.
- CMMC 2.0 AC.1.004 Control Public Information Control information posted or processed on publicly accessible information systems.
- CMMC 2.0 AC.2.016 Control CUI Flow Control the flow of CUI in accordance with approved authorizations.
ISO/IEC 27001:2022 Annex A Controls
All 93 Annex A controls of ISO/IEC 27001:2022 — the international standard for an Information Security Management System. The 2022 revision consolidated the 114 controls of the 2013 edition into 93 across four themes (organizational, people, physical, technological) and tagged each with new attributes (preventive / detective / corrective; confidentiality / integrity / availability).
- ISO/IEC 27001:2022 A.5.1 — Policies for information security
- ISO/IEC 27001:2022 A.5.2 — Information security roles and responsibilities
- ISO/IEC 27001:2022 A.5.3 — Segregation of duties
- ISO/IEC 27001:2022 A.5.4 — Management responsibilities
- ISO/IEC 27001:2022 A.5.5 — Contact with authorities
HIPAA Readiness
- HIPAA Security & Privacy Rules — overview
- Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password
- Ensure MFA is enabled for the "root" account
- Ensure the S3 bucket used to store CloudTrail logs is not publicly accessible
- Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket
ISO/IEC 27701:2025 PIMS Controls
The Privacy Information Management System extension to ISO/IEC 27001 — controls for PII controllers and processors that evidence GDPR-style accountability and form the most-recognised international way to demonstrate alignment with major privacy regulations.
- ISO/IEC 27701:2025 A.1.2.2 — Identify and document purpose
- ISO/IEC 27701:2025 A.1.2.3 — Identify lawful basis
- ISO/IEC 27701:2025 A.1.2.4 — Determine when/how consent obtained
- ISO/IEC 27701:2025 A.1.2.5 — Obtain & record consent
- ISO/IEC 27701:2025 A.1.2.6 — Privacy impact assessment
Version Control System (VCS)
Documents related to VCS controls
- Branch protection enabled on default branch
- Pull Requests Require Approval Before Merge
- Branch protection enabled on default branch
- At least one reviewer required before merge
- Pull Requests Are Not Merged Without Review Approvals
Azure CIS Benchmark Level 1 & Level 2
- Ensure that 'Multi-Factor Auth Status' is 'Enabled' for all Privileged Users
- Ensure that 'Multi-Factor Auth Status' is 'Enabled' for all Non-Privileged Users
- Ensure Guest Users Are Reviewed on a Regular Basis
- 1.4 Ensure that 'Allow users to remember multi-factor authentication on devices they trust' is 'Disabled
- Ensure that 'Number of methods required to reset' is set to '2'
CIS AWS Compute Services Benchmark v1.1.0
- Ensure Consistent Naming Convention is Used for Organizational AMI
- Ensure Amazon Machine Images (AMIs) Are Encrypted
- Ensure Only Approved Amazon Machine Images (AMIs) Are Used
- Ensure Images (AMI) Are Not Older Than 90 Days
- Ensure Images Are Not Publicly Available
Azure Storage Services Benchmark v1.0.0
- Ensure 'Allowed Protocols' for Shared Access Signature (SAS) Tokens Are Restricted to HTTPS Only for Secrets and Keys
- Ensure that shared access signature (SAS) tokens expire within an hour for Secrets and Keys
- Ensure stored access policies (SAP) are used when generating shared access signature (SAS) tokens
- Ensure Critical Data is Encrypted with Microsoft Managed Keys (MMK)
- Ensure 'Versioning' is set to 'Enabled' on Azure Blob Storage storage accounts
AWS CIS V.4 Level 1 Benchmarks
- 5.7 Ensure that the EC2 Metadata Service Only Allows IMDSv2 (Automated)
- 2.2.4 Ensure Multi-AZ deployments are used for enhanced availability in Amazon RDS
- 2.2.3 Ensure that RDS instances are not publicly accessible
- 2.2.2 Ensure the Auto Minor Version Upgrade feature is enabled for RDS instances
- 2.2.1 Ensure that encryption-at-rest is enabled for RDS instances
CIS Amazon Web Services Foundations Benchmark v5.0.0
- 1.1 Maintain current contact details (Manual)
- 1.2 Ensure security contact information is registered (Manual)
- 1.3 Ensure no 'root' user account access key exists (Automated)
- 1.4 Ensure MFA is enabled for the 'root' user account (Automated)
- 1.5 Ensure hardware MFA is enabled for the 'root' user account (Manual)
CIS AWS Database Services Benchmark v1.0.0
- Ensure Amazon VPC (Virtual Private Cloud) has been created
- Ensure the Use of Security Groups
- Ensure Data at Rest is Encrypted
- Ensure Data in Transit is Encrypted
- Ensure IAM Roles and Policies are Created
SOC 2 Trust Services Criteria (2017, with 2022 points of focus)
The AICPA's Trust Services Criteria — the security, availability, processing integrity, confidentiality and privacy criteria a SOC 2 auditor tests against. The Common Criteria (CC1–CC9) are mandatory; the category-specific criteria (A, C, PI, P) are in-scope based on the engagement's selected categories.
- SOC 2 (2017 TSC) A1.1 — Monitoring and Managing System Capacity
- SOC 2 (2017 TSC) A1.2 — Management of Backup, Recovery, and Environmental Controls
- SOC 2 (2017 TSC) A1.3 — Testing of System Recovery Procedures
- SOC 2 (2017 TSC) C1.1 — Confidential Information Identification and Maintenance
- SOC 2 (2017 TSC) C1.2 — Confidential Information Disposal
AWS Cloud
- Ensure Security Alternate Contact is Registered
- Ensure ACM Certificates Use a Secure Key Algorithm
- Ensure API Gateway REST API Stage Cache Data is Encrypted at Rest
- Ensure API Gateway REST API Stage Has Logging Enabled
- Ensure API Gateway REST API Stage Variables Do Not Contain Secrets
Policy Documents
One page per icompaas-tracked policy document (Information Security Policy, Acceptable Use Policy, Access Control Policy, ...). Each article describes the policy itself — purpose, typical structure, why every organization needs one, the icompaas lifecycle — and links to every compliance control across all 11 frameworks that references it.
- Acceptable Use Policy
- Access Control Policy
- Asset Management Policy
- Audit And Monitoring Policy
- Audit And Review Policy
CIS AWS Storage Services Benchmarks v1.0.0
- AWS Storage Backups
- Ensure Securing AWS Backups
- Ensure to Create Backup Template and Name
- Ensure to Create AWS IAM Policies
- Ensure to Create IAM Roles for Backup
Oracle Cloud
- Ensure Cloud Guard is enabled in the root compartment of the tenancy
- Ensure user IAM database password was created within the last 90 days
- Ensure OCI IAM policy does not grant 'manage all-resources in tenancy' unless it is the Tenant Admin Policy
- Ensure user auth token age is 90 days or less
- Ensure IAM password policy requires passwords to be at least 14 characters long
CIS Azure Kubernetes Service (AKS) Benchmark v1.7.0
- Enable Audit Logs
- Ensure that the kubeconfig file permissions are set to 644 or more restrictive
- Ensure that the kubelet kubeconfig file ownership is set to root:root
- Ensure that the azure.json file has permissions set to 644 or more restrictive
- Ensure that the azure.json file ownership is set to root:root
CIS Amazon EKS
- Enable Audit Logs
- Ensure Audit Logs are Collected and Managed
- Ensure that the kubeconfig file permissions are set to 644 or More Restrictive
- Ensure that the kubelet kubeconfig file ownership is set to root:root
- Ensure that the kubelet configuration file has permissions set to 644 or More Restrictive
DigitalOcean Cloud
Security and compliance rules iCompaas evaluates against your DigitalOcean account — covering Droplets, Managed Databases, Kubernetes, networking, storage and more.
- Ensure Droplet Is Not Publicly Accessible
- Ensure Droplet Backups Are Enabled
- Ensure Droplet Is Attached To A Cloud Firewall
- Ensure Database Connections Enforce SSL/TLS
- Ensure Database Is Not Publicly Accessible
BSI C5 (German Cloud)
German Federal Office for Information Security catalog for cloud-service-provider security — the baseline for German public-sector cloud procurement.
- BSI C5:2020 — overview
- BSI C5 AM-04 — Decommissioning of Hardware
- BSI C5 AM-01 — Asset Inventory
- BSI C5 AM-02 — Acceptable Use and Safe Handling of Assets Policy
- BSI C5 OPS-06 — Data Protection and Recovery - Concept
NIST SP 800-171 Readiness
110 security requirements for protecting Controlled Unclassified Information (CUI) — the basis of CMMC Level 2.
- NIST SP 800-171 Rev 2 — overview
- NIST800 171 3.1.5 — Least Privilege
- NIST800 171 3.1.6 — Least Privilege - Privileged Accounts
- NIST800 171 3.1.7 — Least Privilege - Privileged Functions
- NIST800 171 3.1.12 — Remote Access
ISO/IEC 42001:2023 (AI Management System) Annex A Controls
The first international AI Management System (AIMS) standard. 38 Annex A controls covering AI policy, AI lifecycle, data for AI, information for interested parties, and use of AI systems by or from third parties. Pairs directly with EU AI Act compliance and is increasingly required in enterprise AI vendor risk reviews.
- ISO/IEC 42001:2023 A.2.2 — Policies for the responsible development or use of AI systems
- ISO/IEC 42001:2023 A.2.3 — Alignment with other organizational policies
- ISO/IEC 42001:2023 A.2.4 — Review of policies for responsible AI
- ISO/IEC 42001:2023 A.3.2 — AI roles and responsibilities
- ISO/IEC 42001:2023 A.3.3 — Reporting of concerns
AWS CIS Benchmark Level 1
- Ensure root account user is not used
- Ensure multi-factor authentication (MFA) is enabled for all users
- Ensure credentials unused for 90 days or greater are disabled
- Ensure access keys are rotated every 90 days or less
- Ensure IAM password policy requires at least one uppercase letter
Digital Personal Data Protection Act, 2023 (India)
India's Digital Personal Data Protection Act 2023 obligations, translated from statute into 36 implementable controls for Data Fiduciaries operating in or processing the data of Data Principals in India. Enforced by the Data Protection Board of India once notified by the Central Government.
- India DPDP Act 2023 DP-001 — Data Processing Agreements (DPA) - Full Compliance
- India DPDP Act 2023 DS-001 — Data Subject Access Request (DSAR) - Information Rights
- India DPDP Act 2023 DS-002 — Right of Access - Data Copy Provision
- India DPDP Act 2023 DS-003 — Right to Rectification - Correction, Completion & Update
- India DPDP Act 2023 DS-004 — Right to Erasure - Technical Deletion & Processor Cascade
Supabase cloud
- Ensure MFA is enabled for organization members
- Ensure SSO/SAML is enforced for organization login
- Ensure publishable/secret API keys are rotated periodically
- Ensure legacy anon/service_role API keys are not still in use
- Ensure Row Level Security (RLS) is enabled on all public schema tables
Utho Cloud
- Ensure Utho API Tokens are rotated periodically (e.g., every 90 days)
- Ensure Multi-Factor Authentication (2FA) is enabled on the Utho account
- Ensure there are no unused EBS volumes in Utho
- Ensure there are no internet facing Cloud Instances in Utho
- Ensure no security groups allow ingress from all IPs to SSH Port in Utho
Cloudflare
- Ensure DNS records pointing to hostnames have valid targets without takeover risk
- Ensure DNS records do not use wildcard entries
- Ensure DNS records do not expose internal IP addresses
- Ensure Cloudflare proxy is enabled for applicable DNS records
- Ensure WAF is enabled
Azure Database Services Benchmark v1.0.0
- Enable Microsoft Entra Authentication for Azure SQL Servers to Centralize Identity and Access Management
- Enforce SSL-Only Access for Azure Cache for Redis to Secure Data in Transit
- Set Minimum TLS Version to 1.2 or Higher for Secure Azure Services
- Implement and Periodically Review Access Policies for Azure Cache for Redis to Enforce RBAC and Least Privilege
- Enable System Assigned Managed Identity on Azure Cache for Redis to Enhance Secure Access
Vercel cloud
- Ensure Vercel project has skew protection enabled to prevent version mismatches during deployments
- Ensure Vercel project has deployment protection enabled on preview deployments
- Ensure Vercel project has no environment variables targeting all three environments
- Ensure Vercel project has automatic exposure of system environment variables disabled
- Ensure Vercel project has no secret-like environment variables stored as plain text
Identity Provider (IDP)
- MFA enforced for all org members
- Super admin count is restricted to 2 or fewer
- Inactive and suspended accounts are disabled
- Guest access is properly restricted
- SSO enforced for all org members
ISO/IEC 27701 (Privacy Information Management)
Extension of ISO/IEC 27001 to a Privacy Information Management System (PIMS) — the international standard for evidencing GDPR-style accountability.
- ISO/IEC 27701:2019 — overview
- ISO/IEC 27701 A.3.11 — Incident management planning
- ISO/IEC 27701 A.3.12 — Response to incidents
- ISO/IEC 27701 A.3.23 — Secure authentication
- ISO/IEC 27701 A.3.25 — Logging
DPDP Act (India)
India's Digital Personal Data Protection Act, 2023 — applies extra-territorially to processing of personal data of individuals in India.
- India's Digital Personal Data Protection Act 2023 — overview
- Digital Personal Data Protection Act SC-002 — Data Principal Identification & Guardian Consent Management
- Digital Personal Data Protection Act SC-008 — Children's Data Processing Controls
- Digital Personal Data Protection Act SC-001 — Digital Personal Data Inventory
- Digital Personal Data Protection Act SC-003 — Data Fiduciary Role Assignment & ROPA
SOC2 Readiness
- SOC 2 — overview
- Ensure S3 buckets have custom backup schedule configured
- Ensure EFS storage have backup schedule configured
- Ensure FSx Lustre has backup schedule configured
- Ensure FSx for Windows File System has backup schedule configured
CIS Azure Compute Services Benchmarks V1.0.0
- Ensure ‘HTTPS Only’ is Enabled for Azure App Services
- Ensure App Service Authentication is set up for apps in Azure App Service
- Ensure ‘FTP State’ is Set to ‘FTPS Only’ or ‘Disabled’ for Azure App Services
- Ensure Web App is using the latest version of TLS encryption
- Ensure the web app has 'Client Certificates (Incoming client certificates)' set to 'On'
Getting Started With iCompaas
- Completing the compliance questionnaire - Proposal Scoping, Web-VAPT and Mobile-VAPT
- Connecting Amazon Web Services (AWS) to iCompaas
- Connecting GitHub to iCompaas
- Connecting Google Workspace to iCompaas
- iCompaas onboarding — connect clouds, people and repos
AWS CIS Benchmark Level 2
- Ensure IAM instance roles are used for AWS resource access from instances
- Ensure hardware MFA is enabled for the "root" account
- Ensure CloudTrail log file validation is enabled
- Ensure CloudTrail logs are encrypted at rest using KMS CMKs
- Ensure rotation for customer created CMKs is enabled
Cost Saving Recommendations
- Cloud Resource Instance Upgrade
- Right Sizing Resource
- Deleting Orphan EBS Volumes - Instance Storage
- Database Upgrade - Consider upgrading instance class from db.r4 to db.r5
- Cache Upgrade - Consider upgrading ElastiCache instance class from cache.r4 to cache.r5
ISO/IEC 27001:2022
Information Security Management System (ISMS) standard. 93 Annex A controls + 10 management-system clauses.
- ISO/IEC 27001:2022 — overview
- ISO/IEC 27001 6.8 — Information security event reporting
- ISO/IEC 27001 6.3 — Information security awareness, education and training
- ISO/IEC 27001 6.4 — Disciplinary process
- ISO/IEC 27001 5.1 — Policies for information security
Information Collected
- Security Headers Remediation - Content Security Policy
- Why do we need to use Proxy
- WAF Recommendation - Cloudflare
- Security Header Remediation: X Frame Options
- Security Header Remediation: Referrer-Policy
ISO/IEC 42001 (AI Management System)
The first international standard for an AI management system — 38 Annex A controls covering AI policies, data, lifecycle and third-party AI.
- ISO/IEC 42001 — overview
- ISO/IEC 42001 A.2.2 — Policies for the responsible development or use of AI systems
- ISO/IEC 42001 A.2.3 — Alignment with other organizational policies
- ISO/IEC 42001 A.6.1.2 — Objectives for responsible development of AI systems
- ISO/IEC 42001 A.6.1.3 — AI system design and development process
Data Breach Notification
- GDPR breach notification — the 72-hour clock and what it covers
- HIPAA Breach Notification Rule — Covered Entities and Business Associates
- India DPDP Act — personal data breach notification
- Using the iCompaas Breach Notification workflow
Coupons
- How to apply a coupon code at checkout
- Finding current iCompaas offers and partner coupons
- My coupon code isn't working — troubleshooting