Cloud & SaaS — 115 Nodes
- 44 USC § 3551 - Federal Information Security Modernization Act (FISMA) Purposes
44 USC § 3551 (Federal Information Security Modernization Act of 2014, Pub. L. 113-283 - replacing the Federal Information Security Management Act of 2002) establishes the purposes of FISMA Subchapter II: subsection (1)… - 44 USC § 3614 - Federal Risk and Authorization Management Program (FedRAMP)
44 USC § 3614 (enacted by the FedRAMP Authorization Act of 2022, Pub. L. 117-263 Title LIX) codifies the Federal Risk and Authorization Management Program (FedRAMP) as the government-wide standardized approach to… - AICPA Description Criteria (DC Section 200) for a SOC 2 System Description
The AICPA Description Criteria (DC section 200) define what a service organization must include when describing its system in a SOC 2 report. They are distinct from the Trust Services Criteria: the description criteria… - AICPA SOC 3 - Trust Services Report for General Use
SOC 3 is a general-use System and Organization Controls report based on the same Trust Services Criteria as SOC 2, but designed for broad distribution without the detailed description of controls and tests found in a… - AICPA Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (2017 Edition, Updated for 2024 Applicability)
This standard defines the Trust Services Criteria (TSC) used in SOC 2 Type II audits to evaluate controls over security, availability, processing integrity, confidentiality, and privacy in service organizations,… - Appian Intelligent Automation - Platform Governance: Process Modeller, Records Architecture, Security Groups, Environment Promotion and Compliance Reporting
This regulation establishes mandatory governance controls for Appian Intelligent Automation deployments, requiring documented process modeling standards, role-based access via Security Groups, auditable environment… - Attribute-based Access Control for Microservices-based Applications Using a Service Mesh
With the disappearance of a network perimeter due to the need to provide ubiquitous access to applications from multiple remote locations using different types of devices, it is necessary to build the concept of zero… - Attribute-based Access Control for Microservices-based Applications Using a Service Mesh
This document provides deployment guidance for building an authentication and authorization framework within a service mesh for microservices-based applications. In modern cloud-native architectures featuring loosely… - Australia IRAP — Information Security Registered Assessors Program (ASD ACSC)
The Information Security Registered Assessors Program (IRAP) is the Australian government cybersecurity assessment programme administered by the Australian Signals Directorate (ASD) through the Australian Cyber Security… - AWS Shared Responsibility Model - Customer Workload Obligations: Security IN the Cloud (OS Patching, Network Configuration, Application Security, Data Encryption), AWS Security OF the Cloud (Hypervisor, Physical Data Centres, Global Network) and Managed Service Boundary Variations
This regulation outlines the division of security responsibilities between AWS and its customers, where AWS is responsible for Security 'of' the Cloud (infrastructure, hardware, facilities), and customers are… - Canada CCCS Protected B Cloud Security Profile - ITSP.50.105 Government Cloud Authorization and Security Control Assessment
The Government of Canada Security Control Profile for Cloud-Based IT Services (GC Cloud Security Control Profile), also referenced as ITSP.50.105 and published by the Canadian Centre for Cyber Security (CCCS),… - CISA Secure by Design Guidance 2024 - Software Manufacturer Obligations: Shift Liability from Customers to Vendors, Memory-Safe Languages, Default-Secure Configurations, Eliminate Default Passwords, Vulnerability Disclosure Programmes and CVE Remediation Commitments
This guidance requires software manufacturers to implement Secure by Design principles by prioritizing customer security as a core business requirement, ensuring out-of-the-box secure configurations, eliminating default… - Cloud Computing Synopsis and Recommendations
This document reprises the NIST-established definition of cloud computing, describes cloud computing benefits and open issues, presents an overview of major classes of cloud technology, and provides guidelines and… - Cloud Shared Responsibility Model - AWS, Azure and GCP Security Responsibility Boundaries for IaaS, PaaS and SaaS
The Shared Responsibility Model delineates security and compliance obligations between a cloud service provider (CSP) and its customers. The CSP (AWS, Azure, GCP) is responsible for the security 'of' the cloud… - COBIT 2019: A Business Framework for the Governance and Management of Enterprise Information and Technology (I&T)
COBIT 2019 provides a comprehensive framework for governing and managing enterprise information and technology (I&T) to align with business goals. It establishes 40 core governance and management objectives, such as… - CSA Cloud Controls Matrix (CCM) v4.0
The Cloud Controls Matrix (CCM) is a cybersecurity control framework for cloud computing, providing a comprehensive set of 197 security controls across 17 domains. It is designed for both cloud service providers and… - CSA STAR Attestation - SOC 2 Examination Incorporating the Cloud Controls Matrix
CSA STAR Attestation is a Level 2 (third-party) assessment developed by the Cloud Security Alliance with the AICPA. It is a SOC 2 examination that incorporates the criteria of the CSA Cloud Controls Matrix (CCM) in… - CSA STAR Certification Level 2 - Cloud Controls Matrix + ISO/IEC 27001: Third-Party Audit Combining CCM v4 Assessment with ISO 27001 Certification, STAR Registry Publication, Annual Surveillance Audits and Cloud-Specific Control Augmentation
CSA STAR Certification Level 2 requires cloud service providers to undergo a third-party audit that combines ISO/IEC 27001 certification with the CSA Cloud Controls Matrix (CCM) to validate cloud-specific security… - Cyber Essentials Plus (UK)
Cyber Essentials Plus (UK) certification establishes a high-assurance cybersecurity posture, validated through a mandatory independent technical audit as specified in the NCSC Cyber Essentials Plus: Illustrative Test… - Directive (EU) 2022/2555 of the European Parliament and of the Council of 16 November 2022 on measures for a high common level of cybersecurity across the Union, amending and repealing Directive (EU) 2016/1148 (NIS2 Directive)
The NIS2 Directive imposes mandatory risk management and incident reporting obligations on Cloud Service Providers (CSPs) classified as Essential or Important Entities under Articles 21 and 23. These entities must… - eIDAS 2 Regulation 2024/1183 - EU Digital Identity Wallet & Electronic Attestation Framework
Regulation (EU) 2024/1183 amending eIDAS (Regulation 910/2014) establishes the EU Digital Identity Wallet (EUDI Wallet) framework. Every EU Member State must provide at least one EUDI Wallet to all citizens and… - ENISA European Cybersecurity Certification Scheme for Cloud Services (EUCS)
The EUCS establishes a voluntary, EU-wide cybersecurity certification framework for Cloud Service Providers (CSPs), defining three assurance levels (Basic, Substantial, High) to verify security and enhance trust in… - ENISA European Cybersecurity Certification Scheme for Cloud Services (EUCS)
The European Cybersecurity Certification Scheme for Cloud Services (EUCS) establishes a voluntary, EU-wide certification framework for Cloud Service Providers (CSPs) to demonstrate cybersecurity assurance. It defines… - ENISA Good Practices for Security of Cloud Services
This ENISA publication provides a comprehensive set of 263 good practice security measures across 11 domains for Cloud Service Providers (CSPs) and their customers to secure cloud services. It serves as a voluntary… - EU Cloud Switching and Porting (SWIPO) Codes of Conduct 2021 - Customer Portability: Infrastructure-as-a-Service and Software-as-a-Service Codes, Data Export Formats, Functional Portability Requirements, Transition Assistance Obligations and Data Act 2023 Legal Reinforcement
This regulation establishes binding codes of conduct for cloud service providers to ensure customer data portability, functional interoperability, and transition assistance during switching between IaaS and SaaS… - EU Data Act 2023/2854 - Cloud Data Portability, Vendor Lock-in Prevention, and Switching Obligations
EU Data Act (Regulation 2023/2854) imposes on cloud service providers obligations to enable customers to switch to alternative providers within maximum 30 days, eliminate switching charges by 2027, ensure data… - EU Data Act 2023/2854 - Cloud Switching, Data Sharing and Smart Contracts
Regulation (EU) 2023/2854 (Data Act) creates rights to share and access data generated by connected products and services; establishes cloud switching portability requirements with maximum 30-day notice and maximum… - EU Data Act 2023/2854 - IoT Data Sharing, Cloud Switching Rights, and B2B Data Access
Regulation (EU) 2023/2854 (Data Act, applicable from September 2025) establishes rules for data generated by connected products (IoT) and related services: users have a right to access and share their data with third… - EU DORA Subcontracting Chain Provisions - ICT Third-Party Risk for Cloud and Managed Service Providers in Financial Services
Under Article 30(3) of EU DORA, financial entities must ensure their contractual arrangements with ICT third-party service providers, such as cloud providers, explicitly govern the entire subcontracting chain, requiring… - EU EBA Guidelines on Cloud Outsourcing 2019 - Banking Cloud Procurement: Critical vs Non-Critical Function Classification, SLA Minimum Requirements, Right of Access for Competent Authorities, Exit Strategy, Sub-Outsourcing Approval and Register of Outsourcing Arrangements
These EBA Guidelines apply to credit institutions, investment firms under CRD, and payment/e-money institutions, requiring robust governance of outsourcing arrangements, including cloud services. Key obligations include… - European Cybersecurity Certification Scheme for Cloud Services (EUCS)
This draft certification scheme establishes cybersecurity requirements for cloud service providers seeking European Union cybersecurity certification under ENISA’s EUCS framework, with three defined assurance levels… - FedRAMP 20x - Modernized US Federal Cloud Security Assessment and Authorization (Key Security Indicators)
FedRAMP 20x is the FedRAMP program office modernization of US federal cloud security assessment and authorization, described by the program as a new approach to cloud security assessment and authorization that moves… - FedRAMP Moderate (NIST)
Adherence to the FedRAMP Moderate authorization baseline ensures cloud service offerings meet the stringent security and privacy controls defined in NIST Special Publication 800-53, Revision 5, for protecting controlled… - France ANSSI SecNumCloud — Qualification for Cloud Service Providers (Sovereign Cloud Reference)
SecNumCloud is the French national qualification scheme administered by the Agence Nationale de la Securite des Systemes d'Information (ANSSI) under which qualified cloud service providers (IaaS, PaaS, SaaS) receive an… - General Access Control Guidance for Cloud Systems
This document presents cloud access control (AC) characteristics and a set of general access control guidance for cloud service models: IaaS (Infrastructure as a Service), PaaS (Platform as a Service), and SaaS… - Germany BSI C5 — Cloud Computing Compliance Criteria Catalogue (C5:2026)
The Cloud Computing Compliance Criteria Catalogue (C5) is the German federal cloud assurance standard issued by the Federal Office for Information Security (Bundesamt fuer Sicherheit in der Informationstechnik / BSI).… - Google Cloud Compliance and Security Offerings 2024 - Assured Workloads for Regulatory Requirements, Sovereignty Controls (EU/US Data Residency), BeyondCorp Enterprise Zero Trust, VPC Service Controls, Access Transparency Logs and Compliance Reports Manager
This regulation outlines Google Cloud’s compliance posture and technical capabilities supporting customer adherence to global standards, laws, and frameworks. It applies to organizations leveraging Google Cloud for… - GovRAMP (formerly StateRAMP) - Cloud Security Verification for US State and Local Government
GovRAMP, formerly StateRAMP, is a nonprofit membership organization that brings governments and technology providers together to improve cybersecurity, protect public data, and enable trusted technology adoption. It… - HITRUST Common Security Framework (CSF) r2 2023 - Healthcare Cloud: 19 Control Categories, 75 Control Objectives, 156 Control Specifications, Implemented 1-Year and Certified 2-Year Assessments, HIPAA, NIST and ISO 27001 Control Mapping
The HITRUST CSF provides a comprehensive, integrated control framework for managing cybersecurity and compliance risk in cloud-based healthcare environments, harmonizing over 60 authoritative sources including HIPAA,… - IEEE/ISO/IEC 14515-1-2000 -- Information Technology -- Portable Operating System Interface (POSIX) -- Test methods for measuring conformance to POSIX -- Part 1: System interfaces
This standard defines the requirements for test methods used to verify conformance to POSIX.1 (ISO/IEC 9945-1:1990), specifying a POSIX.1-ordered list of assertions and associated test methods that must be applied by… - Implementation of DevSecOps for a Microservices-based Application with Service Mesh
Cloud-native applications have evolved into a standardized architecture consisting of multiple loosely coupled components called microservices, often implemented as containers, supported by an infrastructure for… - Implementation of DevSecOps for a Microservices-based Application with Service Mesh
Cloud-native applications have evolved into a standardized architecture consisting of multiple loosely coupled components called microservices that are supported by an infrastructure for providing application services,… - India MeitY Cloud Security Framework 2020 - GI Cloud Meghraj Empanelment, STQC Certification and Government Cloud Adoption
India's Ministry of Electronics and Information Technology (MeitY) published the Cloud Service Centre Security Framework (CSCF) and the Government Cloud (GI Cloud 'Meghraj') empanelment policy establishing the… - India Semiconductor Mission 2021 - INR 76,000 Crore Incentive Scheme for Semiconductor and Display Manufacturing
The India Semiconductor Mission (ISM) 2021 establishes a framework to incentivize domestic semiconductor, display, and compound semiconductor manufacturing through financial support of up to 50% of capital expenditure… - Information Security Registered Assessors Program: Cloud Service Assessment Methodology, PROTECTED/SECRET Level Controls, ISM Control Mapping, Continuous Monitoring Plan and ASD Endorsed Cloud Services List
This regulation requires cloud service providers (CSPs) handling Australian Government data at PROTECTED or SECRET levels to undergo a formal security assessment by an ASD-accredited IRAP assessor. Compliance is… - ISO 20000-1 (Service Mgt)
Compliance with ISO 20000-1 mandates the establishment and operation of a comprehensive Service Management System (SMS) to plan, design, transition, deliver, and improve services. Foundational requirements stipulate… - ISO 22301 (Business Cont)
ISO 22301:2019 is the premier international standard for Business Continuity Management Systems (BCMS). it specifies requirements for the organization to the 'Plan, Do, Check, Act' for the business resilience, ensuring… - ISO 22301:2019 - Security and Resilience: Business Continuity Management Systems Requirements
This international standard specifies requirements for establishing, implementing, maintaining, and continually improving a documented business continuity management system (BCMS) to protect against, reduce the… - ISO/IEC 15408: Information security, cybersecurity and privacy protection - Evaluation criteria for IT security
ISO/IEC 15408, the Common Criteria, establishes a standardized framework for evaluating and certifying the security of IT products, including telecom equipment. It requires that a product's security features be defined… - ISO/IEC 19770-1:2017 IT Asset Management - Software Asset Management Processes and Requirements
This standard specifies a tiered process framework for Software Asset Management (SAM) to enable organizations to prove they are performing SAM to a standard sufficient to satisfy corporate governance requirements and… - ISO/IEC 27017 (Cloud Controls)
The organizational posture concerning ISO/IEC 27017 establishes a comprehensive framework for cloud security controls, yet presents a material deviation regarding data jurisdiction. Adherence to controls for… - ISO/IEC 27017:2015 - Cloud-Specific Information Security Controls for Cloud Service Providers and Customers
ISO/IEC 27017 provides cloud-specific security control guidance extending ISO/IEC 27002 for cloud environments, addressing shared responsibilities between cloud service providers and customers, virtual machine… - ISO/IEC 27017:2015 - Code of Practice for Information Security Controls for Cloud Services
This standard provides guidelines for information security controls applicable to the provision and use of cloud services, supplementing the guidance in ISO/IEC 27002. It introduces cloud-specific controls and… - ISO/IEC 27017:2015 Code of Practice for Information Security Controls Based on ISO/IEC 27002 for Cloud Services
This standard provides guidelines for information security controls applicable to the provision and use of cloud services, offering implementation guidance for both cloud service providers and customers. It extends the… - ISO/IEC 27018 (PII Cloud)
ISO/IEC 27018 establishes a comprehensive code of practice for protecting Personally Identifiable Information (PII) within public cloud computing environments, acting as a guide for PII processors. The framework… - ISO/IEC 27018:2019 - Code of Practice for Protection of PII in Public Clouds Acting as PII Processors
This standard establishes control objectives and guidelines for protecting Personally Identifiable Information (PII) for public cloud service providers acting as PII processors. It extends the controls in ISO/IEC 27002… - ISO/IEC 27018:2019 Code of Practice for PII Protection in Public Cloud Services Acting as PII Processors
This standard establishes a code of practice for public cloud service providers acting as PII processors, providing specific controls and guidance to protect Personally Identifiable Information (PII). It extends the… - ISO/IEC 27031 (ICT Readiness)
ISO/IEC 27031:2011 (superseded by modern resilience standards but still foundational) provides the guidelines for Information and Communication Technology Readiness for Business Continuity (IRBC). it specifies the… - ISO/IEC/IEEE 12207:2017 - Systems and software engineering - Software life cycle processes
This standard defines a comprehensive set of software lifecycle processes for acquisition, supply, development, operation, maintenance, and supporting workflows. It applies to all organizations involved in software… - ITIL 4 Service Value System - Service Management Framework for IT Service Delivery, Value Creation and Continual Improvement
ITIL 4 provides a flexible framework for technology and digital service management, centered on the Service Value System (SVS) which describes how organizational components and activities work together to facilitate… - Microsoft Azure Compliance Framework 2024 - Azure Policy, Microsoft Purview Compliance Manager, Regulatory Compliance Dashboard, Built-In Policies for NIST/ISO/SOC2, Customer Lockbox, Confidential Computing Enclaves and Sovereign Cloud (Azure Government/China)
This framework outlines Microsoft Azure's compliance posture for global regulatory standards, including built-in controls for NIST, ISO, SOC2, and sovereign cloud offerings. It applies to organizations using Azure to… - Multi-Tier Cloud Security (MTCS) Certification - Tier 3 for High-Sensitivity Government Data
This standard establishes mandatory security requirements for cloud service providers handling high-sensitivity government data in Singapore. Compliance with Tier 3 of the MTCS framework, as administered by IMDA, is… - NIST Cloud Computing Forensic Science Challenges
This document summarizes research performed by the members of the NIST Cloud Computing Forensic Science Working Group and aggregates, categorizes, and discusses the forensics challenges faced by experts when responding… - NIST SP 800-144 - Guidelines on Security and Privacy in Public Cloud Computing
This publication provides guidelines for federal agencies to manage security and privacy risks when selecting and using public cloud computing services, focusing on the entire lifecycle from selection to termination. It… - NIST SP 800-190 (Containers)
Compliance with NIST SP 800-190 guidance for application container security necessitates a multi-layered control framework that addresses risks across the entire lifecycle. This node enforces critical security postures,… - NIST SP 800-204 (Microservices)
NIST SP 800-204 establishes stringent security strategies for microservice-based applications, mandating a defense-in-depth architecture. Compliance requires the deployment and configuration of an API gateway to mediate… - NIST SP 800-207A Zero Trust Architecture Multi-Cloud Environments - Implementation Guidance
This guidance provides federal agencies and other organizations with a roadmap for implementing a Zero Trust Architecture (ZTA) across multi-cloud environments. It addresses key challenges such as inconsistent identity… - NIST SP 800-61 (Incidents)
NIST SP 800-61 Rev 2 (Computer Security Incident Handling Guide) is the definitive U.S. standard for managing the lifecycle of the cyber incidents. it provides an operational framework for the established 'Incident… - NIST SP 800-88 (Sanitization)
NIST SP 800-88 Rev 1 (Guidelines for Media Sanitization) is the definitive U.S. standard for the secure destruction and the disposal of the information. it provides a systematic framework for the 'Sanitization' of the… - NIST Special Publication 800-210 General Access Control Guidance for Cloud Systems
This document presents cloud access control (AC) characteristics and a set of general access control guidance for cloud service models-IaaS (Infrastructure as a Service), PaaS (Platform as a Service), and SaaS (Software… - OpenAPI Specification 3.1 - API Governance for Workflow Automation: Paths, Operations, Parameters, Request Bodies, Responses and Security Schemes for Workflow APIs
This regulation defines the structural and semantic requirements for describing HTTP APIs in a standard, language-agnostic format to enable automated discovery, interaction, and governance of workflow APIs. It applies… - OpenAPI Specification 3.1.0 - REST API Documentation Standard: Paths, Components, Request/Response Schemas and OAuth/Security Scheme Definitions
This standard defines a consistent, machine-readable format for describing RESTful APIs, requiring the use of specific schema structures for paths, operations, parameters, request/response bodies, and security schemes.… - OWASP ASVS L1 (App Sec)
The OWASP Application Security Verification Standard (ASVS) Level 1 (Opportunistic) is the baseline requirement for all web applications. it focuses on the vulnerabilities that are the easy to the find and the automated… - OWASP ASVS L2 (Standard)
Conformance with the OWASP ASVS L2 (Standard) establishes a requisite security posture for applications verified to handle sensitive data. This framework mandates a comprehensive, defense-in-depth strategy, commencing… - OWASP ASVS L3 (Advanced)
OWASP Application Security Verification Standard (ASVS) Level 3 establishes the highest assurance benchmark, designed for applications processing high-value transactions, containing sensitive data, or performing… - OWASP SAMM (Governance)
The OWASP Software Assurance Maturity Model (SAMM) v2.0 is the premier framework for the analyzing and the improving the software security posture. it provides a measurable way for the organizations to the design,… - PCI DSS v4 Req 1 (NSC)
PCI DSS v4 Requirement 1 (Install and Maintain Network Security Controls) mandates the use of the 'Network Security Controls' (NSCs) (historically Firewalls) to the protect the Cardholder Data Environment (CDE). it… - PCI DSS v4 Req 2 (Hardening)
Requirement 2 mandates the application of secure configuration standards across all system components within the Cardholder Data Environment, explicitly prohibiting reliance on vendor-supplied defaults. Governing… - PCI DSS v4 Req 3 (Stored Data)
PCI DSS v4 Requirement 3 (Protect Stored Account Data) focuses on the security of the cardholder information residing on the persistent storage. it mandates the prohibition of the 'Sensitive Authentication Data' (SAD)… - PCI DSS v4 Req 4 (Transmission)
PCI DSS v4 Requirement 4 (Protect Cardholder Data with Strong Cryptography During Transmission) revolves around the security of the clear-text card data as it travels across the any 'Open, Public' networks (e.g., the… - PCI DSS v4 Req 5 (Malware)
PCI DSS v4 Requirement 5 (Protect All Systems and Networks from Malicious Software) mandates the implementation of the active malware protection across the all system components. it focuses on the continuous monitoring,… - PCI DSS v4 Req 6 (Software)
PCI DSS v4 Requirement 6 (Develop and Maintain Secure Systems and Software) specifies the requirements for the secure software development lifecycle (SDLC) and the vulnerability management. it mandates the protection of… - PCI DSS v4 Req 7 (Access Control)
Payment Card Industry Data Security Standard v4 Requirement 7 mandates a stringent framework for restricting access to system components and cardholder data based on an explicit business need-to-know. Compliance… - PCI DSS v4 Req 8 (Identity)
PCI DSS v4 Requirement 8 (Identify Users and Authenticate Access to System Components) specifies the authentication standards for the payment environments. it mandates the 'Unique ID' per individual and the 'Multifactor… - PCI DSS v4.0 Cloud Shared Responsibility - Payment Card Industry Requirements for Cloud Workloads: Responsibility Matrix by Service Model (IaaS/PaaS/SaaS), Compensating Controls for Multi-Tenant Environments, Tokenisation, P2PE and Cloud Service Provider PCI Compliance Reports
This regulation defines the shared responsibility model for PCI DSS compliance in cloud environments, specifying which security controls are the obligation of the cloud service provider versus the customer based on… - Regulation (EU) 2018/1807 of the European Parliament and of the Council of 14 November 2018 on a framework for the free flow of non-personal data in the European Union
This Regulation ensures the free flow of data other than personal data within the EU by prohibiting data localisation requirements unless justified on grounds of public security and proportionate (Articles 1 and 4). It… - Regulation (EU) 2022/2554 of the European Parliament and of the Council of 16 November 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2018/286
EU DORA mandates financial entities to manage risks from ICT third-party providers, particularly cloud services, by implementing contractual safeguards, exit strategies, multi-vendor policies, and subcontracting… - Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European data governance and amending Regulation (EU) 2018/1724 (Data Governance Act)
The EU Data Governance Act 2022 establishes a framework for cloud-based data intermediaries to facilitate secure, neutral, and transparent data sharing across sectors, requiring registration with national authorities… - Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European data governance and amending Regulation (EU) 2018/1724 (Data Governance Act)
The EU Data Governance Act (DGA) establishes a framework to increase data availability by regulating the reuse of public sector data, creating a new business category of neutral data intermediation services, and… - Regulation (EU) 2023/1230 of the European Parliament and of the Council of 14 June 2023 on machinery and repealing Directive 2006/42/EC of the European Parliament and of the Council and Council Directive 73/361/EEC
This regulation establishes harmonised safety requirements for machinery and related products placed on the EU market, addressing new risks from digital technologies like AI and collaborative robots. It mandates that… - Regulation (EU) 2023/1781 of the European Parliament and of the Council of 13 September 2023 establishing a framework of measures for strengthening Europe’s semiconductor ecosystem and amending Regulation (EU) 2021/694 (Chips Act)
The EU Chips Act establishes a framework to strengthen Europe’s semiconductor ecosystem through public-private investment, crisis response mechanisms, and support for Integrated Production Facilities (IPFs) and open EU… - Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act)
The EU Data Act 2023 establishes harmonised rules for fair access to and use of data generated by connected devices, requiring manufacturers and service providers to enable users to access and share data under fair,… - Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act)
The EU Data Act requires manufacturers of connected products and providers of related services to make product- and service-generated data accessible to users and designated third parties under fair, reasonable, and… - Regulation (EU) 2023/2854 of the European Parliament and of the Council of 14 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2019/770
The EU Data Act establishes rights and obligations regarding access to and use of machine-generated data, particularly in business-to-business (B2B) and business-to-government (B2G) contexts. It applies to… - Regulation (EU) 2024/903 - EU Interoperable Europe Act: Mandatory Interoperability Assessments for Cross-Border Public Services, European Interoperability Framework, Interoperable Europe Board, GovTech Sandbox, Open Source Preference, and Reusable Interoperability Solutions
Regulation (EU) 2024/903 (Interoperable Europe Act), entered into force 11 April 2024 and applicable from 12 July 2024, establishes the first EU-wide legally binding framework for public sector digital interoperability;… - Saudi Arabia CST/CITC Cloud Computing Regulatory Framework (CCRF)
The Cloud Computing Regulatory Framework (CCRF) is Saudi Arabia's national cloud regulation administered by the Communications, Space and Technology Commission (CST, formerly the Communications and Information… - Shared Responsibility Model
A clearly articulated Shared Responsibility Model delineates the distinct security and compliance obligations between the service provider and the customer, a principle established by foundational cloud computing… - Singapore IMDA Multi-Tier Cloud Security Standard (MTCS, SS 584:2020)
The Multi-Tier Cloud Security Standard (MTCS, SS 584) is Singapore's national cloud security standard administered by the Infocomm Media Development Authority (IMDA) under the Singapore Standards Council. The current… - SOC 2 (Availability)
Compliance with governing availability principles is demonstrated through a comprehensive framework of controls and procedural enforcement. The entity maintains robust system performance monitoring capabilities,… - SOC 2 (Confidentiality)
System and Organization Controls (SOC) 2 criteria for Confidentiality mandate the protection of information designated as confidential to meet organizational objectives. Compliance necessitates a comprehensive control… - SOC 2 (Privacy Criteria)
The SOC 2 Trust Services Criteria (TSC) for Privacy is the specialized audit framework for assessing how personal information is collected, used, retained, disclosed, and disposed of to meet the system's objectives.… - SOC 2 (Processing Integrity)
Compliance with SOC 2 Processing Integrity criteria necessitates system processing that is complete, valid, accurate, timely, and authorized. This configuration enforces these principles through a comprehensive suite of… - StateRAMP Authorization
The cloud service offering's compliance posture demonstrates substantial progress toward full StateRAMP Authorization but currently fails to meet the final requirement for listing on the Authorized Product List. As a… - Strategies for the Integration of Software Supply Chain Security in DevSecOps CI/CD pipelines
This NIST Special Publication provides actionable strategies to integrate software supply chain (SSC) security into DevSecOps CI/CD pipelines for cloud-native applications, focusing on source code integrity, artifact… - Supply-chain Levels for Software Artifacts (SLSA) v1.0
The SLSA framework establishes four levels of software security assurance to protect against supply chain threats by requiring verifiable provenance for software artifacts. Compliance, as detailed in the 'Requirements'… - The NIST Definition of Cloud Computing
Cloud computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be… - The NIST Definition of Cloud Computing (SP 800-145)
This foundational U.S. federal standard establishes the official definition of cloud computing, mandating that any service classified as 'cloud' must exhibit five essential characteristics (e.g., on-demand… - TISAX (Automotive Cyber)
TISAX (Trusted Information Security Assessment Exchange) is the definitive maturity-based security standard for the global automotive industry. Based on the VDA Information Security Assessment (ISA), it provides a… - TX-RAMP - Texas Risk and Authorization Management Program (Tex. Gov Code 2054.0593)
TX-RAMP is the Texas Risk and Authorization Management Program, mandated by Texas Government Code Section 2054.0593, which directs the Texas Department of Information Resources (DIR) to establish a state risk and… - UK NCSC 14 Cloud Security Principles 2023 - Guidance for Cloud Consumers: Data in Transit Protection, Asset Protection, Separation Between Customers, Governance Framework, Operational Security, Personnel Security, Secure Development, Supply Chain Security and Identity/Authentication
This guidance outlines 14 security principles that cloud service providers should meet to ensure secure delivery of cloud platforms and Software-as-a-Service. It applies to organisations evaluating cloud providers for… - US CLOUD Act 2018 - Government Access to Data Stored Overseas and Provider Obligations
The Clarifying Lawful Overseas Use of Data (CLOUD) Act (18 U.S.C. § 2713) requires US providers to disclose customer data in response to lawful US law enforcement process regardless of where the data is stored. It also… - US FedRAMP - Federal Risk and Authorization Management Program Cloud Security Authorization
FedRAMP establishes standardized security requirements for cloud services used by US federal agencies, requiring cloud service providers to obtain agency sponsorship, complete security assessment against NIST 800-53… - US FedRAMP - NIST SP 800-37 Cloud Service Authorization for Federal Use
The Federal Risk and Authorization Management Program (FedRAMP) provides a standardised approach for federal agencies to assess, authorise, and monitor cloud services using NIST SP 800-37 Risk Management Framework and… - US FedRAMP Authorization Framework 2023 - Federal Risk and Authorization Management Program for Cloud
The Federal Risk and Authorization Management Program (FedRAMP) is a U.S. government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products… - W3C JSON-LD 1.1 - Linked Data Format for Machine-Readable Compliance Workflows: Context Definitions, Compact IRIs and Graph Serialisation
This standard defines a JSON-based serialization format for Linked Data, enabling interoperable data exchange in machine-readable compliance workflows. It requires the use of context definitions ("@context"), compact…
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.