How can we help?

Search 5,951 articles across cloud security controls, compliance frameworks (CIS, ISO 27001 / 27701 / 42001, SOC 2, HIPAA, NIST 800-53 & 800-171, CMMC, GDPR, DPDP, BSI C5), cost savings, and getting-started guides.

NIST SP 800-53 Rev. 5 Controls

Every control and control enhancement from NIST Special Publication 800-53 Revision 5 — the U.S. federal catalogue for security and privacy. Organised by 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR). FedRAMP, FISMA, CMMC and many state regulations point directly at SP 800-53 baselines.

View all 1103 articles →

AWS Checks New Version

View all 660 articles →

CIS Amazon Linux 2 Benchmark v3.0.0

View all 290 articles →

General

View all 247 articles →

Security Controls

View all 218 articles →

HIPAA Security, Privacy & Breach-Notification Rules

All 195 administrative, physical, technical, organisational and documentation safeguards from 45 CFR Parts 160 and 164, as amended by the 2013 Omnibus Final Rule. Applies to Covered Entities and their Business Associates handling Protected Health Information (PHI).

View all 195 articles →

NIST

View all 161 articles →

CIS Critical Security Controls v8

The Center for Internet Security's prioritised set of 18 controls and 153 safeguards for cyber defence. Implementation Groups IG1, IG2 and IG3 stage adoption from a hygiene baseline up to advanced defence.

View all 153 articles →

CIS Microsoft Azure Foundations Benchmark v4.0.0

View all 139 articles →

CIS Kubernetes Benchmark v1.9.0

View all 129 articles →

BSI C5:2020 (Cloud Computing Compliance Criteria)

The German Federal Office for Information Security's 2020 Cloud Computing Compliance Criteria Catalogue — the baseline German public-sector buyers and many DAX-listed enterprises expect from their cloud providers. Each criterion has Basic and Additional objectives; attestation is performed under ISAE 3000 / IDW PS 860 as a Type 1 or Type 2 report.

View all 121 articles →

GCP Benchmarks

View all 121 articles →

CIS GitHub Benchmark v1.0.0

View all 117 articles →

CIS Docker Benchmark v1.7.0

View all 116 articles →

GDPR

View all 115 articles →

NIST SP 800-171 Rev. 3 Requirements

The 100 security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems — the technical baseline that CMMC Level 2 inherits and that every DoD prime and subcontractor must implement to keep CUI contracts.

View all 100 articles →

GDPR (Regulation (EU) 2016/679)

All 99 articles of the EU General Data Protection Regulation — the world's most-cited modern privacy law. Applies to any organisation offering goods or services to, or monitoring, individuals in the EU/EEA, regardless of where the organisation is established.

View all 99 articles →

CyberSecurity Taxonomy

View all 97 articles →

CMMC

View all 96 articles →

ISO/IEC 27001:2022 Annex A Controls

All 93 Annex A controls of ISO/IEC 27001:2022 — the international standard for an Information Security Management System. The 2022 revision consolidated the 114 controls of the 2013 edition into 93 across four themes (organizational, people, physical, technological) and tagged each with new attributes (preventive / detective / corrective; confidentiality / integrity / availability).

View all 93 articles →

HIPAA Readiness

View all 80 articles →

ISO/IEC 27701:2025 PIMS Controls

The Privacy Information Management System extension to ISO/IEC 27001 — controls for PII controllers and processors that evidence GDPR-style accountability and form the most-recognised international way to demonstrate alignment with major privacy regulations.

View all 78 articles →

Version Control System (VCS)

Documents related to VCS controls

View all 73 articles →

Azure CIS Benchmark Level 1 & Level 2

View all 68 articles →

CIS AWS Compute Services Benchmark v1.1.0

View all 68 articles →

Azure Storage Services Benchmark v1.0.0

View all 64 articles →

AWS CIS V.4 Level 1 Benchmarks

View all 63 articles →

CIS Amazon Web Services Foundations Benchmark v5.0.0

View all 63 articles →

CIS AWS Database Services Benchmark v1.0.0

View all 61 articles →

SOC 2 Trust Services Criteria (2017, with 2022 points of focus)

The AICPA's Trust Services Criteria — the security, availability, processing integrity, confidentiality and privacy criteria a SOC 2 auditor tests against. The Common Criteria (CC1–CC9) are mandatory; the category-specific criteria (A, C, PI, P) are in-scope based on the engagement's selected categories.

View all 61 articles →

AWS Cloud

View all 59 articles →

Policy Documents

One page per icompaas-tracked policy document (Information Security Policy, Acceptable Use Policy, Access Control Policy, ...). Each article describes the policy itself — purpose, typical structure, why every organization needs one, the icompaas lifecycle — and links to every compliance control across all 11 frameworks that references it.

View all 58 articles →

CIS AWS Storage Services Benchmarks v1.0.0

View all 56 articles →

Oracle Cloud

View all 53 articles →

CIS Azure Kubernetes Service (AKS) Benchmark v1.7.0

View all 48 articles →

CIS Amazon EKS

View all 46 articles →

DigitalOcean Cloud

Security and compliance rules iCompaas evaluates against your DigitalOcean account — covering Droplets, Managed Databases, Kubernetes, networking, storage and more.

View all 45 articles →

BSI C5 (German Cloud)

German Federal Office for Information Security catalog for cloud-service-provider security — the baseline for German public-sector cloud procurement.

View all 41 articles →

NIST SP 800-171 Readiness

110 security requirements for protecting Controlled Unclassified Information (CUI) — the basis of CMMC Level 2.

View all 41 articles →

ISO/IEC 42001:2023 (AI Management System) Annex A Controls

The first international AI Management System (AIMS) standard. 38 Annex A controls covering AI policy, AI lifecycle, data for AI, information for interested parties, and use of AI systems by or from third parties. Pairs directly with EU AI Act compliance and is increasingly required in enterprise AI vendor risk reviews.

View all 38 articles →

AWS CIS Benchmark Level 1

View all 37 articles →

Digital Personal Data Protection Act, 2023 (India)

India's Digital Personal Data Protection Act 2023 obligations, translated from statute into 36 implementable controls for Data Fiduciaries operating in or processing the data of Data Principals in India. Enforced by the Data Protection Board of India once notified by the Central Government.

View all 36 articles →

Supabase cloud

View all 35 articles →

Utho Cloud

View all 33 articles →

Cloudflare

View all 29 articles →

Azure Database Services Benchmark v1.0.0

View all 28 articles →

Vercel cloud

View all 27 articles →

Identity Provider (IDP)

View all 25 articles →

ISO/IEC 27701 (Privacy Information Management)

Extension of ISO/IEC 27001 to a Privacy Information Management System (PIMS) — the international standard for evidencing GDPR-style accountability.

View all 24 articles →

DPDP Act (India)

India's Digital Personal Data Protection Act, 2023 — applies extra-territorially to processing of personal data of individuals in India.

View all 23 articles →

SOC2 Readiness

View all 23 articles →

CIS Azure Compute Services Benchmarks V1.0.0

View all 22 articles →

Getting Started With iCompaas

View all 19 articles →

AWS CIS Benchmark Level 2

View all 12 articles →

Cost Saving Recommendations

View all 12 articles →

ISO/IEC 27001:2022

Information Security Management System (ISMS) standard. 93 Annex A controls + 10 management-system clauses.

View all 10 articles →

Information Collected

View all 5 articles →

ISO/IEC 42001 (AI Management System)

The first international standard for an AI management system — 38 Annex A controls covering AI policies, data, lifecycle and third-party AI.

View all 5 articles →

Data Breach Notification

View all 4 articles →

Coupons

View all 3 articles →

Trust Center - Safety & Security Posture

View all 3 articles →

Orders and Invoices

View all 2 articles →