Home · Synthesis

106 hand-authored synthesis clusters

A synthesis cluster takes one operational concern (e.g., incident response timelines, cryptographic key custody, data subject rights) and resolves it across every framework that addresses it. The result: one strictest-clause specification that satisfies all contributing frameworks by construction, with full source attribution.

Each card is a cluster. Click into any cluster for the full synthesis, source controls, and five-dimension strictest analysis (scope, threshold, method, frequency, evidence).
🌐
Spans 38 frameworks. Indian regulators, global standards, AI governance, privacy laws. The synthesis surface is the same; the source controls vary.
⚖️
NIST IR 8477 methodology. Each synthesis is the strictest articulation across contributing frameworks — not the lowest common denominator. One implementation, every framework satisfied.

Board-approved policy framework anchoring derived operational controls (legacy "supplier-policy" cluster name)

cl-supplier-policy19 frameworks

NOTE: Despite the legacy cluster name "supplier-policy", this cluster's controls primarily address the Board-approved policy framework and the derived operational controls that flo…

View synthesis →

Workforce security awareness, role-based training, and human-factor controls

cl-awareness17 frameworks

Workforce security awareness operates as: (1) general awareness training for all personnel at induction + annual refresher (>95% completion target per SEBI CSCRF PR.5); (2) role-ba…

View synthesis →

Data classification with protection controls — DLP, masking, retention, secure disposal

cl-data-classification16 frameworks

Data classification operates as the foundation for data protection: (1) documented classification scheme (typical: Public / Internal / Confidential / Restricted) per SEBI CSCRF ID…

View synthesis →

Cryptographic controls, key management, and post-quantum readiness

cl-cryptography-mgmt16 frameworks

Cryptography across the organisation operates under: (1) an approved-algorithms and key-length policy; (2) hardware security module (HSM) custody for high-value keys including paym…

View synthesis →

Board-approved security policy framework — IS policy, cyber security policy, and derived operational policies

cl-policy14 frameworks

The security policy framework operates as a Board-governed structure: (1) two DISTINCT Board-approved policies per RBI ITGRCA GV.9 — an Information Security Policy covering all inf…

View synthesis →

Ransomware-resilient backup architecture

cl-backup14 frameworks

Backup of information, software, and systems shall be designed for ransomware resilience: multiple copies including at least one immutable (WORM / Object Lock) and at least one off…

View synthesis →

Mandatory assurance regime — periodic audit, VAPT, third-party assessment, risk review

cl-mandatory-audit14 frameworks

The mandatory assurance regime operates as a coordinated set of recurring controls: (1) annual third-party cyber security audit by CERT-In empanelled auditor (CERT-In Directions 5…

View synthesis →

Business continuity and ICT recovery readiness

cl-bcp-ict-readiness14 frameworks

ICT readiness for business continuity provides: (1) documented BCP and DR plans with explicit RTO (recovery time objective) and RPO (recovery point objective) per critical system…

View synthesis →

Secure configuration baselines and hardening discipline

cl-hardening14 frameworks

Secure configuration baselines shall be documented for each platform class — operating system, database, application server, web server, network device, cloud service. Configuratio…

View synthesis →

Multi-regulator incident notification with coordinated submission timelines

cl-incident-reporting-external14 frameworks

External incident notification operates as a coordinated multi-regulator submission with the tightest concurrent clocks: CERT-In 6 hours from detection (mandatory for all in-scope…

View synthesis →

Cross-jurisdiction consumer / Data Principal rights — operational fabric

cl-us-state-privacy-consumer-rights14 frameworks

Consumer / Data Subject / Data Principal rights operate across multiple jurisdictions with overlapping but distinct specifications. The audit-defensible rights fabric provides: (1)…

View synthesis →

Processor / service provider contract requirements across jurisdictions

cl-us-state-privacy-service-provider-contracts14 frameworks

Contracts with service providers / processors handling personal information shall include the mandatory contractual terms required by the applicable jurisdictions: (1) purpose limi…

View synthesis →

Comprehensive asset inventory with classification and ownership

cl-asset-inventory13 frameworks

A current inventory of ALL asset types — hardware, software, network devices, data assets, services, third-party dependencies, cryptographic assets, and intangible IT assets — shal…

View synthesis →

Privileged access management and access rights lifecycle

cl-access-rights13 frameworks

Access rights — particularly privileged access — operate under: least-privilege role-based design; segregation of duties (SoD) enforcement with conflict detection; joiner-mover-lea…

View synthesis →

Centralised logging with retention, tamper protection, and integrity

cl-logging13 frameworks

Logs of activities, exceptions, faults, and security events shall be: (1) produced on ALL ICT systems including servers, network devices, cloud instances, applications, databases…

View synthesis →

Network protection — segmentation, monitoring, perimeter, and data leak prevention

cl-network-protection13 frameworks

Network protection operates as a layered architecture: (1) network segmentation isolating critical systems from general corporate IT, with zero-trust principles (no implicit trust…

View synthesis →

Vulnerability management programme — discovery, prioritisation, remediation

cl-vuln-identification13 frameworks

The vulnerability management programme operates as: (1) continuous discovery across all IT systems via scheduled scanning (critical externally-facing weekly, internal monthly, code…

View synthesis →

Security reporting governance — CISO, DPO, incident reporting, compliance reporting

cl-ir-reporting13 frameworks

The security reporting structure operates across: (1) CISO appointment with reporting independence — outside operational IT, direct access to Board IT Committee (SEBI GV.3 + IRDAI…

View synthesis →

Sensitive personal information — heightened protection across jurisdictions

cl-us-state-privacy-spi-sensitive-data13 frameworks

Sensitive Personal Information (SPI) — including health data, biometrics, racial / ethnic origin, religious beliefs, sexual orientation, precise geolocation, government IDs, financ…

View synthesis →

Authentication architecture and multi-factor authentication

cl-authentication12 frameworks

Authentication operates under: documented authentication policy with allowed methods and forbidden methods; multi-factor authentication (MFA) mandatory for all administrative, remo…

View synthesis →

Incident response execution — detection through eradication, recovery, and lessons learned

cl-incident-response-execution12 frameworks

IR execution operates as a documented sequence: (1) detection via monitoring and event reporting; (2) assessment and categorisation of events as incidents (ISO 27001 A.5.25); (3) r…

View synthesis →

Cyber security roles, responsibilities, and authority — Board through operational team

cl-roles-responsibilities12 frameworks

Cyber roles and responsibilities operate as: (1) Board-level accountability for cyber risk; (2) CISO appointment with reporting line outside operational IT and direct Board IT Comm…

View synthesis →

Data-at-rest protection — encryption, access, processor controls

cl-data-at-rest12 frameworks

Data at rest is protected through: (1) encryption at rest using FIPS 140-2 / industry-standard algorithms; (2) access restriction per classification and least-privilege (ISO A.8.3)…

View synthesis →

Cyber risk assessment — technology, process, people, third-party, supply chain, post-quantum

cl-risk-assessment12 frameworks

Cyber risk assessment operates as a comprehensive periodic process covering: (1) technology risks, process risks, people risks, third-party risks (SEBI ID.3); (2) post-quantum cryp…

View synthesis →

Anti-malware protection with EDR and email/web safeguards

cl-malware11 frameworks

Anti-malware protection operates layered: (1) endpoint anti-malware with EDR (behavioural detection beyond signatures) deployed on ALL endpoints — servers, workstations, mobile, ga…

View synthesis →

Continuous monitoring of networks, systems, applications, and outsourced development

cl-monitoring-activities11 frameworks

Continuous monitoring covers: (1) networks, systems, and applications for anomalous behaviour (ISO A.8.16) with appropriate actions evaluating potential incidents; (2) outsourced d…

View synthesis →

Incident response plan preparation, independent review, and risk-response planning

cl-ir-plan-prep11 frameworks

IR plan preparation is the upstream of incident response execution: (1) plan, prepare, and communicate IR management (ISO A.5.24); (2) independent review of the security approach i…

View synthesis →

Secure SDLC — threat modelling, secure coding, SAST/DAST, dependency scanning, DevSecOps

cl-sdlc-framework11 frameworks

Secure SDLC operates as a pipeline-integrated discipline: (1) threat modelling for material changes (SEBI PR.12); (2) secure coding training for developers; (3) SAST on every commi…

View synthesis →

Cloud Security Posture Management — continuous configuration assessment

cl-cspm-cloud-posture11 frameworks

CSPM operates as: (1) continuous assessment of cloud configurations against benchmarks (CIS Cloud, vendor security best practices) per RBI CSF PR.26 for Maturity Level 4 banks; (2)…

View synthesis →

PII principal rights — comprehensive ISO 27701-anchored programme

cl-pims-data-subject-rights-comprehensive11 frameworks

PII principal rights operate per ISO 27701 PIMS specifications: (1) determine information to provide to PII principals (A.1.3.1); (2) provide privacy notice at collection (A.1.3.2)…

View synthesis →

VAPT cycle — vulnerability assessment and penetration testing programme

cl-vapt-cycle10 frameworks

VAPT cycle operates as: (1) Vulnerability Assessment + Penetration Testing after every major release (SEBI PR.4 — new feature, significant change, circular implementation, infrastr…

View synthesis →

Network segmentation with zero-trust principles

cl-network-segmentation10 frameworks

Network segmentation isolates critical systems from general corporate IT: (1) documented zones with controlled connections (SEBI PR.2); (2) zero-trust principles — no implicit trus…

View synthesis →

Privacy governance — legal, regulatory, contractual, and algorithmic obligations

cl-privacy10 frameworks

Privacy governance operates as: (1) identify and meet PII protection requirements per applicable laws (ISO A.5.34); (2) legal / regulatory / contractual requirements understood and…

View synthesis →

GDPR data subject rights — Articles 12-22 operational implementation

cl-gdpr-data-subject-rights10 frameworks

GDPR data subject rights operate per Articles 12-22: (1) transparent information modalities (Art. 12); (2) information at direct collection (Art. 13); (3) information at indirect c…

View synthesis →

Physical access controls — secure areas, entry monitoring, asset protection

cl-physical-access9 frameworks

Physical access operates as: (1) continuous monitoring of premises for unauthorised access (ISO A.7.4); (2) secure areas protected by entry controls and access points (ISO A.7.2)…

View synthesis →

Security Operations Centre — SIEM, EDR, forensics, MITRE-aligned detection

cl-soc-capability9 frameworks

SOC capability operates as: (1) SIEM with correlation across log sources, MITRE ATT&CK-aligned detection rules (SEBI DE.4); (2) EDR on all endpoints with continuous behavioural mon…

View synthesis →

Data Loss Prevention — multi-channel egress protection

cl-dlp9 frameworks

DLP operates across four channels: (1) endpoint DLP for sensitive data; (2) email DLP for outbound; (3) network DLP for egress; (4) cloud DLP for SaaS (SEBI PR.17). Email security…

View synthesis →

Secure disposal of equipment, media, and personal information

cl-secure-disposal9 frameworks

Secure disposal operates as: (1) equipment containing storage media verified for data removal or secure overwrite before disposal/re-use (ISO A.7.14); (2) separation of dev/test/pr…

View synthesis →

Data-in-transit protection and physical media handling

cl-data-in-transit9 frameworks

Data in transit is protected through: (1) confidentiality, integrity, and availability of data-in-transit (NIST PR.DS-02) — TLS 1.2+ minimum, TLS 1.3 preferred, with strong cipher…

View synthesis →

Cyber resilience metrics — KPIs, KRIs, Board reporting cadence

cl-cyber-resilience-metrics9 frameworks

Cyber resilience metrics operate as: (1) comprehensive metrics programme reporting to Board IT Strategy Committee (RBI GV.6 for Maturity Level 4 banks); (2) defined metrics includi…

View synthesis →

Consent management — capture, modify, withdraw across jurisdictions

cl-pims-consent-management9 frameworks

Consent management operates per multi-jurisdiction requirements: (1) ISO 27701 — determine when/how consent obtained, obtain and record consent, provide mechanisms to modify or wit…

View synthesis →

Automated Decision-Making Technology — pre-use notice, opt-out, access rights

cl-us-state-privacy-ai-admt9 frameworks

ADMT operations operate per evolving US state law: (1) CPPA Regulation § 7150 — risk assessment for high-risk processing (effective 1 Jan 2026, first attestation due 1 Apr 2028); (…

View synthesis →

Children's privacy across US states — heightened protections

cl-us-state-privacy-children9 frameworks

Children's privacy operates per multi-state requirements: (1) CCPA — opt-in for sale/sharing for consumers under 16 (1798.120 implications); (2) CTDPA Public Act 24-148 — children…

View synthesis →

Change management — IT systems, configuration, supplier services, risk

cl-change-management8 frameworks

Change management operates as a documented discipline: (1) all changes to IT systems pass through change management procedures (ISO A.8.32); (2) configuration management practices…

View synthesis →

DevSecOps maturity — security-as-code, pipeline-enforced controls, API security

cl-devsecops-maturity8 frameworks

DevSecOps maturity operates as: (1) security integrated across the development lifecycle with security-as-code, pipeline-enforced controls, continuous feedback loops (RBI PR.25 for…

View synthesis →

PCI DSS PAN protection — storage minimisation, masking, encryption

cl-pan-protection8 frameworks

PAN (Primary Account Number) protection per PCI DSS v4.0.1: (1) storage limited to legitimate business need; SAD not retained after authorisation (PCI 3.1 + 3.3.1); (2) PAN masked…

View synthesis →

PCI DSS v4.0.1 universal MFA expansion to all CDE access

cl-pci-mfa-expansion8 frameworks

PCI DSS v4.0.1 expanded MFA requirements: (1) MFA for all access into CDE (PCI 8.2); (2) MFA for ALL access into CDE — administrative AND non-administrative — regardless of access…

View synthesis →

Software installation discipline — authorised software, configuration, source code access

cl-software-installation7 frameworks

Software installation operates as: (1) procedures and measures to securely manage software installation on operational systems (ISO A.8.19); (2) installation and execution of unaut…

View synthesis →

Board-level IT/IT Strategy Committee with documented charter

cl-board-it-committee7 frameworks

Board IT Committee operates as: (1) Board-level IT Strategy Committee with experienced directors advising on IT strategy, governance, oversight (RBI ITGRCA GV.1); (2) Board IT Comm…

View synthesis →

AI data governance — provenance, preparation, external reporting

cl-ai-data-governance7 frameworks

AI data governance operates per ISO 42001 + DPDPA + emerging frameworks: (1) data provenance — tracking where each dataset came from and what has happened (creation, updates, trans…

View synthesis →

Data subject / Data Principal rights — operational rights mechanism

cl-data-subject-rights7 frameworks

Operational mechanism providing data subjects (DPDPA Data Principals, GDPR data subjects, ISO 27701 PII principals) with rights to access, correction, erasure, grievance redressal…

View synthesis →

PIMS context — Clauses 4-5 management system context and leadership

cl-pims-context7 frameworks

PIMS context per ISO 27701 Clauses 4-5: determine external/internal issues, interested parties, scope, role determination (controller/processor/joint), leadership commitment, roles…

View synthesis →

AI post-deployment monitoring and incident response

cl-ai-incident-and-postdeployment-monitoring7 frameworks

AI post-deployment monitoring operates per NIST AI RMF MANAGE-4.1 (capturing user/AI actor input, evaluating system performance, drift detection) + MANAGE-2.3 (procedures for previ…

View synthesis →

GDPR Article 35 DPIA + cross-jurisdiction high-risk assessment

cl-gdpr-dpia-art357 frameworks

GDPR Article 35 DPIA for high-risk processing + Article 36 prior consultation. DPDPA Rule 13(2) annual SDF DPIA. CCPA Reg 7150 risk assessment. MODPA data protection assessment. EU…

View synthesis →

Universal Opt-Out Mechanism (UOOM) / Global Privacy Control honour across US states

cl-us-state-privacy-uoom-gpc7 frameworks

Universal Opt-Out Mechanism honour required by CO (Jul 2024) + CT (Jul 2024) + OR (Jul 2024) + TX (Jul 2024 — opt-in by Jan 2025). California per Reg 7025. UOOM is the browser/devi…

View synthesis →

Cloud data privacy lifecycle — CSA CCM v4 DSP control family

cl-ccm-v4-data-privacy-lifecycle7 frameworks

Cloud data privacy lifecycle per CSA CCM v4 DSP series: policy + data flow mapping + automated sensitive data discovery + classification + DLP. Layered with GDPR + DPDPA + ISO 2770…

View synthesis →

Forensic capability and evidence collection

cl-forensic-evidence-collection6 frameworks

Forensic capability — internal team OR CERT-In empanelled external vendor on retainer (SEBI RS.3 + RBI RS.3). Chain-of-custody preserved. ISO A.5.28 evidence collection procedure…

View synthesis →

Event-to-incident categorisation and assessment

cl-event-assessment6 frameworks

Event assessment: ISO A.5.25 assess events and decide if categorised as incidents. ISO A.8.15 logs analysed. NIST CSF event analysis + supply chain risk integration. NIS2 incident…

View synthesis →

AI incident reporting — serious incidents to authorities

cl-ai-incident-reporting6 frameworks

AI incident reporting per EU AI Act Article 73 (serious incidents — 15 days general / 2 days fundamental-rights infringement / 10 days for fatality) + Article 52 GPAI systemic risk…

View synthesis →

Cloud Identity and Access Management — federation, vulnerability testing, monitoring

cl-cloud-iam6 frameworks

Cloud IAM operates as ISO 27001 A.5.23 cloud services management + CSA TVM-03 cloud penetration testing + CSA LOG-04 cloud-specific detections + CSA LOG-01 cloud logging coverage +…

View synthesis →

India-specific AI risk classification reflecting societal context

cl-ai-india-risk-class6 frameworks

MeitY AIGG2025.4 India-specific AI risk classification reflecting societal harms in Indian context (caste, linguistic, religious diversity, demographic patterns). ISO 42001 A.6.1.2…

View synthesis →

Zero Trust Architecture — never trust, always verify

cl-zero-trust-architecture6 frameworks

Zero Trust Architecture per RBI CSF PR.23 (Maturity Level 4) for sensitive access: payment systems, customer data, privileged operations. SEBI CSCRF PR.7 + RBI CSF PR.3 privileged…

View synthesis →

Processor (PII Processor) obligations — ISO 27701 controller relationship

cl-pims-processor-obligations6 frameworks

Processor obligations per ISO 27701 A.2.x: written contract (A.1.2.7 + A.2.2.1) + processor own-purposes restriction (A.2.2.2) + infringing instruction notification (A.2.2.4) + cus…

View synthesis →

PCI DSS v4.0.1 customised approach with targeted risk analysis

cl-pci-customised-approach6 frameworks

PCI DSS v4.0.1 customised approach — PCI 3.5.1.1 (keyed hash with full PAN coverage) example. Customised approach allows entities to design their own controls meeting the objective…

View synthesis →

PCI DSS Targeted Risk Analysis (TRA) — flexibility and customised approach

cl-pci-targeted-risk-analysis6 frameworks

PCI DSS v4.0.1 TRA per PCI 12.3 (annual risk assessment) + 12.3.1 (frequency-based controls TRA — for requirements like 5.2.3.1, 7.2.5.1, 8.6.3) + 12.3.2 (customised approach TRA)…

View synthesis →

Multi-factor authentication — universal MFA across access types

cl-multi-factor-authentication6 frameworks

MFA per CSA IAM-14 (cloud — all human, console, CLI, API), PCI 8.4.2 + 8.5.1 (universal CDE MFA, replay-resistant, non-bypassable, ≥2 categories), ISO 27001 A.5.16 + A.5.17 + A.8.5…

View synthesis →

Data Protection Impact Assessment / risk assessment for high-risk processing

cl-dpia-impact-assessment6 frameworks

Impact assessment for high-risk processing: GDPR Art 35 + 36 + CCPA Reg 7150 (effective Jan 2026, attestation Apr 2028) + MODPA 14-4607 + EU AI Act Art 27 FRIA + CSA cloud + ISO 42…

View synthesis →

Logical and physical access restriction — least privilege baseline

cl-access-restriction5 frameworks

Access restriction per ISO A.8.3 (information access restriction) + A.8.5 (secure authentication) + A.8.4 (source code access) + SOC 2 CC6.1 (logical and physical) + CC6.6 (communi…

View synthesis →

CISO role — independence, authority, Board access

cl-ciso-role5 frameworks

CISO role per SEBI GV.3 (independence from operational IT, direct Board IT Committee access), RBI CSF (cyber security policy ownership), IRDAI (sector-specific), MeitY CSP, NCIIPC…

View synthesis →

AI system impact assessment (AISIA / FRIA / DPIA convergence)

cl-ai-impact-assessment5 frameworks

AI impact assessment per ISO 42001 Clause 6 (AI risk assessment) + Clause 8 (operational planning) + EU AI Act Art 27 FRIA + DPDPA SDF DPIA + NIST AI RMF MAP + MeitY. Convergent ar…

View synthesis →

Responsible AI use — operational guardrails

cl-ai-responsible-use5 frameworks

Responsible AI use per ISO 42001 A.9.2 (processes for responsible use) + A.9.3 (objectives) + DPDPA purpose limitation + accuracy + retention cap + MeitY + EU AI Act + NIST AI RMF…

View synthesis →

SDF algorithmic due diligence and traffic-data localisation

cl-sdf-algorithmic5 frameworks

SDF algorithmic due diligence per DPDPA Rule 13(3): SDFs must verify technical measures including algorithmic software are not likely to pose risk to Section 8/9 obligations. Rule…

View synthesis →

Cloud shared responsibility — CSC/CSP RACI

cl-cloud-shared-responsibility5 frameworks

Cloud shared responsibility per CSA GRC-06 (governance responsibility model) + CSA HRS-05 (cloud awareness training) + CSA IAM-11 (CSC privileged access compliance) + ISO 27017 + S…

View synthesis →

Processing integrity — change management, redundancy, clock synchronisation, storage integrity

cl-processing-integrity5 frameworks

Processing integrity per ISO A.8.32 change management + A.8.17 clock synchronisation + A.8.14 redundancy + SOC 2 PI1.5.a/b storage integrity + NIST CSF + ISO 42001. The integrity o…

View synthesis →

AI principles — Seven Sutras + ISO 42001 + NIST + EU AI Act literacy

cl-ai-sutras-principles5 frameworks

Foundational AI principles: MeitY AIGG2025.3 Seven Sutras (Trust, Inclusion, Transparency, Accountability, Safety, Innovation, Sustainable Growth) + ISO 42001 A.2.2 AI policy + A.2…

View synthesis →

AI-generated content provenance — C2PA, watermarking, SGI

cl-ai-content-provenance5 frameworks

AI content provenance per MeitY AIGG2025.11 (C2PA-aligned provenance) + ITR2026.1 + ITR2026.3 (SGI identification and watermarking for significant intermediaries) + NIST GenAI Prof…

View synthesis →

PCI DSS e-skimming protection — payment page script integrity

cl-pci-eskimming5 frameworks

PCI DSS v4.0.1 6.4.3 e-skimming protection — manage payment page scripts, integrity-check, alert on unauthorised modification + 11.6.1 detection mechanism. CSA AIS-04 DAST + AIS-06…

View synthesis →

AI governance lifecycle — GOVERN function and inventory

cl-ai-governance-lifecycle5 frameworks

AI governance lifecycle per NIST AI RMF GOVERN-1 (policies, processes, procedures across MAP/MEASURE/MANAGE) + GOVERN-1.1 (legal/regulatory) + GOVERN-1.4 (risk management process)…

View synthesis →

GDPR Article 33 / 34 breach notification + multi-jurisdiction coordination

cl-gdpr-breach-notification5 frameworks

GDPR Art 33 supervisory authority notification within 72 hours + Art 34 communication to data subjects without undue delay when likely to result in high risk to rights and freedoms…

View synthesis →

GDPR accountability principle — Art 5(2) demonstrate compliance

cl-gdpr-accountability5 frameworks

GDPR accountability principle Art 5(2): controller responsible for AND able to demonstrate compliance with Article 5(1) principles. Art 24 appropriate measures + Art 25 data protec…

View synthesis →

Cross-jurisdiction breach notification timelines

cl-breach-notification-timelines5 frameworks

Cross-jurisdiction breach notification timelines: GDPR 72h (Art 33) + DPDPA 72h detailed (Rule 7) + CERT-In 6h (Direction 70B) + RBI CIMS 6h + SEBI per CSCRF + IRDAI 24h + CCPA + N…

View synthesis →

Consumer / Data Subject / Data Principal rights response SLA

cl-consumer-rights-sla5 frameworks

Rights response SLA across jurisdictions: GDPR Art 12(3) one month (extendable by two for complex) + CCPA 1798.130 45 days + DPDPA Rule (forthcoming, expect 30-90 days) + VCDPA 45…

View synthesis →

Encryption at rest — sensitive data and key management

cl-encryption-at-rest5 frameworks

Encryption at rest per PCI 3.5.1 PAN rendered unreadable + PCI 3.6.1 key management + CSA CEK-07 cloud data stores with CMK/BYOK + CSA CEK-10 FIPS 140-3 validated key generation +…

View synthesis →

AI policy and AIMS leadership commitment

cl-ai-policy4 frameworks

AI policy per ISO 42001 Clauses 5 + 7 + A.2.4 (review) + EU AI Act Article 53 (GPAI obligations including technical documentation) + MeitY AIGG2025.14 (regulatory sandbox participa…

View synthesis →

AI transparency — fairness, explainability, deep fake disclosure

cl-ai-transparency4 frameworks

AI transparency per ISO 42001 A.6.1.2 (responsible-development objectives — fairness, transparency, robustness, privacy, safety) + A.5.4 (impact on individuals/groups) + EU AI Act…

View synthesis →

AI resource inventory — data, tooling, systems, people across AI lifecycle

cl-ai-resource-inventory4 frameworks

AI resource inventory per ISO 42001 A.4.2 + Clauses 5 + 7 + EU AI Act Article 17 QMS + CERT-In + NIST AI RMF GOVERN-1.6. The inventory is the operational foundation for AI governan…

View synthesis →

AI content labelling — testing consent, deep fakes, SGI, deployer notices

cl-ai-content-labelling4 frameworks

AI content labelling per EU AI Act Article 61 (informed consent for real-world testing) + Article 50.4 (deep fake disclosure) + Article 53 (GPAI technical documentation) + MeitY IT…

View synthesis →

Personal data erasure — trigger-driven with propagation

cl-personal-data-erasure4 frameworks

Personal data erasure per DPDPA Section 6 + DPDP.6 (consent withdrawal / purpose expiry / specified retention end) + ISO A.8.11 masking + A.8.12 DLP + A.7.14 secure disposal + ISO…

View synthesis →

Data localisation — DPDPA SDF traffic data + sectoral requirements

cl-data-localisation4 frameworks

Data localisation per DPDPA Rule 13(4) SDF traffic-data localisation + RBI payment data localisation + CERT-In log retention in India + ISO 27018 PII transfer + RBI CSF cyber range…

View synthesis →

Cloud cryptographic key management — CMK/BYOK/HYOK

cl-cloud-key-management4 frameworks

Cloud key management per ISO A.8.24 + A.5.23 + ISO 27017 + SEBI cloud + DPDPA. CMK/BYOK/HYOK for cloud-stored sensitive data. Key custody segregation between cloud provider and cus…

View synthesis →

PIMS cross-border PII transfers

cl-pims-cross-border-transfers4 frameworks

PIMS transfers per ISO 27701 A.1.5.1 + A.1.5.2 + A.2.5.1 + A.2.5.2 + DPDPA notice (DPDP.16) + GDPR + CSA. PIMS transfer controls layered with regulatory addenda.

View synthesis →

GDPR Articles 44-49 international transfers

cl-gdpr-international-transfers4 frameworks

GDPR transfers Arts 44-49: general principle (44) + adequacy (45) + appropriate safeguards SCCs/BCRs (46) + BCRs intra-group (47) + derogations (49). Plus DPDPA + ISO 27701 + CSA…

View synthesis →

AI roles and responsibilities across the lifecycle

cl-ai-roles3 frameworks

AI roles per ISO 42001 Clause 4 + A.4.6 (human resources) + A.3.2 (AI roles). Define accountable and responsible across AI lifecycle — developers, operators, deployers, oversight…

View synthesis →

AI lifecycle — policies, safety mindset, environmental impact

cl-ai-lifecycle3 frameworks

AI lifecycle per NIST AI RMF GOVERN-4.1 (critical-thinking + safety-first mindset) + GOVERN-2.1 (roles across lifecycle and actor types) + GenAI MG-1 (environmental impact) + EU AI…

View synthesis →

AI supplier management — third-party AI systems and components

cl-ai-supplier-management3 frameworks

AI supplier management per ISO 42001 A.3.2 + Clauses 5 + 9 + EU AI Act Art 99 penalty awareness + Art 9 risk management for HRAIS providers + NIST AI RMF. Supply chain AI risks — p…

View synthesis →

AI risk classification — EU AI Act high-risk + GPAI + NIST risks

cl-ai-risk-classification3 frameworks

AI risk classification per EU AI Act Art 6 high-risk + Art 7 Annex III dynamic amendments + Art 51 GPAI systemic risk + NIST AI RMF MEASURE-3 risk tracking + MEASURE-2.8 transparen…

View synthesis →

Cloud network security — remote access, vulnerability scanning, monitoring

cl-cloud-network3 frameworks

Cloud network per CSA UEM-03 (remote access — MFA + encrypted connections) + TVM-02 (continuous or weekly IaaS scanning + 24h new deployment) + LOG-07 (logging scope including netw…

View synthesis →

General-Purpose AI model provider obligations

cl-ai-gpai-obligations3 frameworks

GPAI obligations per EU AI Act Article 53 (technical documentation, downstream provider info, copyright/TDM, training data summary) + Article 54 (authorised representative for thir…

View synthesis →

AI conformity assessment, EU database registration, regulatory sandbox

cl-ai-conformity-assessment3 frameworks

AI conformity per EU AI Act Article 49 (EU database registration for HRAIS prior to market placement) + Article 57 (regulatory sandboxes — national competent authorities) + Article…

View synthesis →

Data broker registration and obligations (US states)

cl-us-state-privacy-data-broker3 frameworks

Data broker registration per CCPA California Delete Act SB 362 (registration with CPPA + DROP one-stop deletion mechanism by Aug 2026) + Texas TDPSA broker provisions + Oregon OCPA…

View synthesis →

Cloud supply chain transparency — STA control family

cl-ccm-v4-supply-chain-transparency3 frameworks

Cloud supply chain per CSA STA-01 (CSP transparency review — subprocessors, locations, certifications) + STA-02 (multi-tenant isolation verification) + STA-03 (third-party cloud se…

View synthesis →

EU AI Act prohibited practices + India AI capacity building

cl-ai-prohibited-practices2 frameworks

EU AI Act Article 5 prohibited practices (eight categories + Dec 2026 addition for nudifier/CSAM) + Article 2 jurisdictional scope + Article 10 data and data governance for HRAIS…

View synthesis →

Cloud cryptography and key management — CSA CEK control family

cl-ccm-v4-key-management-full1 frameworks

Cloud cryptography per CSA CEK-01 (policy) + CEK-02 (FIPS 140-2/3 key generation) + CEK-03 (purpose-specific keys) + CEK-04 (rotation schedules — DEKs ≤1 year, TLS ≤1 year/2 max) +…

View synthesis →

Cloud IAM complete — CSA IAM control family

cl-ccm-v4-iam-complete1 frameworks

Cloud IAM per CSA IAM-01 (least-privilege via RBAC, JIT elevation, named roles) + IAM-02 (privileged access — standing-zero policy, session recording) + IAM-03 (federation — Azure…

View synthesis →

Cloud logging and monitoring — CSA LOG control family

cl-ccm-v4-logging-monitoring1 frameworks

Cloud logging per CSA LOG-01 (control plane + data plane + network + application logs) + LOG-02 (tamper-evident storage + retention per regulatory floor — 180 days CERT-In) + LOG-0…

View synthesis →

Cloud-accessed endpoint management — CSA UEM control family

cl-ccm-v4-endpoint-management1 frameworks

Endpoint management for cloud access per CSA UEM-01 (MDM/UEM enrolment + conditional access by posture) + UEM-02 (mobile device policy) + UEM-03 (remote access security — MFA + VPN…

View synthesis →