Cybersecurity risk outcomes
NIST Cybersecurity Framework 2.0
A flexible outcome taxonomy with Govern added in 2.0. Profiles and informative references make it useful without turning it into a checklist.
Free
Curated reference · Gixo Lex
Primary framework, control and regulatory sources for security, privacy, payment, cloud, software and AI programmes.
This directory distinguishes voluntary frameworks, certification standards, attestation criteria and law. Mapping one to another does not make their evidence or scope interchangeable.
Cybersecurity risk outcomes
A flexible outcome taxonomy with Govern added in 2.0. Profiles and informative references make it useful without turning it into a checklist.
Free
Security and privacy controls
A deep control catalogue, not a certification by itself. Baselines and tailoring live in related NIST publications.
Free
Prioritised cyber safeguards
A pragmatic implementation sequence with implementation groups; confirm licensing terms before redistributing control text.
Free access with terms
Information security management systems
A certifiable management-system standard. Annex A is only one part; scope, risk treatment and operating evidence decide the system.
Paid standard; public overview
Payment-card data security
Use the current PCI SSC documents and applicability guidance; merchant/service-provider validation paths differ.
Free documents; registration may apply
Service-organisation attestation
SOC 2 is an attestation engagement against Trust Services Criteria, not a certification badge or public control list.
Mixed public/member resources
Cloud control assurance
A cloud-focused meta-framework with mappings and CAIQ companion material; version-lock mappings used in evidence work.
Free download with terms
Software assurance maturity
An open maturity model for evaluating and improving a secure-development programme across governance, design, implementation, verification and operations.
Free and open
Application security verification
A testable requirements baseline for web applications. State the ASVS version and level used in any claim.
Free and open
GDPR and EU privacy law
Use the official regulatory text and supervisory guidance; a control mapping cannot answer jurisdiction, role or lawful-basis questions alone.
Free law and guidance
US health-information safeguards
Official HHS guidance for regulated entities and business associates. Privacy, Breach Notification and Security rules have distinct obligations.
Free
Enterprise governance of information and technology
A governance system and objectives model, broader than security controls. ISACA licensing affects detailed content reuse.
Public overview; licensed publications
US federal cloud authorisation
Rev. 5 packages are transitioning under FedRAMP's 2026 rules, so confirm the active process and current machine-readable requirements before using a legacy template.
Free
US defence industrial-base cybersecurity
CMMC connects contract requirements, assessment levels and NIST SP 800-171 practices. Check the rule and contract clause actually applicable.
Free
AI risk governance
A voluntary framework organised around Govern, Map, Measure and Manage, with profiles and a playbook rather than certification.
Free
AI management systems
A certifiable management-system standard for organisational AI governance; it does not certify that an individual model is safe or accurate.
Paid standard; public overview
The directory stays free and outward-linking. Gixo Lex adds saved workspaces, reviews, evidence and clean deliverables.