Standards and Compliance

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Reference clusters from the knowledge vault, one per standard, regulation or framework. Each cluster page is the map of its notes: provenance, structure, controls or articles, comparisons and controversies, plus a dated position and a list of anchors to primary sources. The notes were written from public sources and model knowledge; no standards text was machine-processed for them.

Every page in this space is a vault note that has not been reviewed against the standard or regulation it describes. Use it as a map, and read the primary text before relying on a clause.

Clusters

GroupClusters
Ai governanceEU AI Act, ISO 42001, NIST AI RMF, OECD AI
Ai securityOWASP LLM Top 10
Automotive cybersecurityISO 21434
Automotive regulationUN R155 R156
Business continuityISO 22301
Cloud securityCSA CCM
Cybersecurity frameworksNIST CSF
Enterprise architectureTOGAF
EU regulationCyber Resilience Act, DORA, NIS2
It governanceCOBIT
Payment securityPCI DSS
PrivacyGDPR
Process maturityCMMI
Project managementPRINCE2
Security complianceBSI IT-Grundschutz, FedRAMP CMMC, HITRUST, ISO 27001, SOC 2, TISAX
Service managementITIL
Supply chain securitySLSA SBOM
Threat intelligenceMITRE

Recently updated in this space