Which use case do you want to implement?
Talk to us. We are happy to answer your initial questions about Cyber Security & Compliance for your company!
With its flexible architecture, an extensive library of various national and international frameworks, and dedicated risk profiles, Cyber Security Audit Pro is suitable for both small and large companies.
Manage internal and external compliance audits centrally. At the same time, provide all stakeholders with a secure, protected platform for submitting data & documents. Whether for supplier audits or internal compliance monitoring.
Simplify your compliance processes with the right plugin. If you are missing a particular framework or need an integration not yet listed, get in touch with us! We are happy to implement your requirements quickly.
21 CFR Part 11 is the US FDA regulation that establishes the criteria for the trustworthiness of electronic records and electronic signatures in FDA-regulated industries.
Applies to: Pharmaceutical, biotech and medical device companies as well as CROs with FDA exposure
FedRAMP standardizes the security assessment and authorization of cloud services for US federal agencies based on NIST SP 800-53 and enables an authorization to be reused across multiple agencies.
Applies to: Cloud Service Providers (CSPs) serving US federal agencies
The Health Insurance Portability and Accountability Act is the US federal law protecting health data (PHI) and governs privacy, security and notification obligations for covered entities and business associates.
Applies to: US healthcare providers, health insurers and their business associates
The HITRUST Common Security Framework is a meta-framework that consolidates requirements from more than 50 standards (including HIPAA, ISO 27001, NIST, PCI DSS) and is established as a certifiable compliance benchmark in US healthcare.
Applies to: Healthcare organizations, business associates and cloud providers in US healthcare
ICH E6 (R2) Good Clinical Practice is the internationally recognized standard for the design, conduct and documentation of clinical trials; this plugin focuses on the IT and cybersecurity aspects of computerized trial systems.
Applies to: Pharmaceutical companies (sponsors), CROs, clinical trial sites and technology providers (EDC, eTMF)
ISO/IEC 27001:2022 is the world's most widely recognized standard for information security management systems (ISMS) and, with its 93 Annex A controls, forms the basis for numerous industry-specific frameworks.
Applies to: Organizations of all industries and sizes that want to build or certify an ISMS
ISO/IEC 27799:2016 is not a standalone control list but rather the sector-specific interpretation guide for ISO 27001/27002 in healthcare, including controls for emergency access and medical device security.
Applies to: Hospitals, clinics, medical practices and health IT providers internationally
NERC CIP is the mandatory cybersecurity standards framework for the North American power sector (Bulk Electric System), developed by the North American Electric Reliability Corporation and enforced by FERC.
Applies to: Operators and owners of the North American transmission and generation grid (US, Canada, Mexico)
The NIST Cybersecurity Framework 2.0 provides an internationally recognized taxonomy for managing cybersecurity risk with the six core functions Govern, Identify, Protect, Detect, Respond and Recover.
Applies to: Organizations of all industries and sizes, usable internationally
This plugin implements the NIST Secure Software Development Framework (SP 800-218) with a particular focus on secure open-source software development, supply chain security and OpenSSF best practices.
Applies to: Software developers, open-source projects and DevSecOps teams
PCI DSS v4.0 is the global security standard of the Payment Card Industry for all organizations that store, process or transmit credit card data.
Applies to: Merchants, payment service providers and financial institutions handling card payment processing
SLSA (Supply-chain Levels for Software Artifacts) is a progressive framework backed by OpenSSF for securing the software supply chain through cryptographically verifiable build provenance.
Applies to: Software developers, open-source projects and cloud-native organizations
SOC 2 is based on the AICPA's Trust Services Criteria and is the de facto compliance standard for SaaS and cloud providers to demonstrate security, availability, confidentiality and privacy.
Applies to: SaaS providers, cloud providers and technology-based service providers
The SWIFT Customer Security Programme requires all institutions connected to the SWIFT network to implement and annually self-attest to the security controls of the Customer Security Controls Framework (CSCF).
Applies to: Banks and financial institutions connected to the SWIFT payment network
The Chemicals & Raw Materials Sector Plugin addresses the unique cybersecurity requirements of the chemical industry, in particular process safety, Safety Instrumented Systems (SIS) and REACH/Seveso III compliance.
Applies to: Basic, specialty and petrochemical, polymer, agrochemical and raw material processing companies
The Cloud, SaaS & Data Services Sector Plugin addresses the specific security requirements of multi-tenant architectures, API-first systems and cloud-native technologies such as Kubernetes and serverless.
Applies to: SaaS providers, cloud service providers, managed service providers and platform operators
The Energy & Renewables Sector Plugin covers SCADA/ICS security, smart grid, wind and PV plants as well as energy trading systems for conventional and renewable energy producers.
Applies to: Energy suppliers, grid operators and operators of renewable energy facilities
The Financial Services Sector Plugin covers the full spectrum from retail to investment banking, with a focus on payment security, open banking (PSD2), trading systems, fraud detection and AML.
Applies to: Banks, insurers, payment service providers and investment firms
The Healthcare & Medicine Sector Plugin provides controls for hospital information systems, electronic health records, medical devices (IoMT), telemedicine, as well as German-specific requirements (PatRG, SGB V/Telematics Infrastructure).
Applies to: Hospitals, clinics, medical practices, telemedicine providers and pharmacies
The Industrial Manufacturing Sector Plugin addresses Industry 4.0 technologies, OPC UA security, MES, robotics/cobots, CAD/PLM data protection as well as TISAX compliance for the manufacturing industry.
Applies to: Metal, electrical and mechanical engineering as well as automotive suppliers (Tier 1-3)
The OEM Automotive Sector Plugin addresses the UN R155/R156 requirements (CSMS/SUMS) mandatory since 2024 for vehicle type approval, as well as V2X, VSOC and ECU security for vehicle manufacturers.
Applies to: Vehicle manufacturers (OEMs) of passenger cars, commercial vehicles, electric and autonomous vehicles
The Online Platforms & E-Commerce Sector Plugin addresses business-specific security requirements of online retail: checkout security, fraud detection, account takeover prevention and marketplace trust systems.
Applies to: B2C/B2B e-commerce, marketplaces, subscription commerce and digital goods
The Pharma & Life Science Sector Plugin covers all GxP areas (GMP, GCP, GLP, GDP) as well as FDA 21 CFR Part 11, EU GMP Annex 11, ISO 13485 and EU MDR/IVDR for pharmaceutical and medical technology companies.
Applies to: Pharmaceutical manufacturers, biotech companies, CROs, medical device manufacturers and QC laboratories
The Telecommunications & Networks Sector Plugin covers 5G/4G core networks, SS7/signaling, VoIP/IMS, BSS/OSS, lawful interception and DDoS protection for telecommunications operators and ISPs.
Applies to: Mobile and fixed-line network operators, internet service providers and data center operators
BAIT (Bank Supervisory Requirements for IT) is a BaFin circular that specifies IT-specific requirements for German credit institutions. BAIT is the implementation and elaboration of MaRisk AT 7.2 (IT resources) and BTR 5 (operational risks) specifically for IT topics.
Applies to: German credit institutions (banks, savings banks, cooperative banks)
BSI IT-Grundschutz is the German information security management standard developed by the Federal Office for Information Security (BSI). It forms the basis for ISO 27001 certification based on IT-Grundschutz and underlies the KRITIS evidence requirement.
Applies to: German public authorities, companies of all sizes, KRITIS operators
The BSI-KRITIS Regulation specifies, based on Sections 8a, 8b of the BSIG, which facilities are considered critical infrastructure and governs the IT security requirements for their operators across nine sectors.
Applies to: Operators of critical infrastructure in Germany (energy, water, healthcare, finance, IT/telecom, transport, among others)
MaRisk (Minimum Requirements for Risk Management) are BaFin circulars that specify the risk management requirements for German credit and financial services institutions, with a particular focus on IT security (AT 9) and outsourcing (AT 7.2).
Applies to: German credit and financial services institutions
The Loi de Programmation Militaire 2024-2030 tightens the cybersecurity requirements for French operators of vital importance (OIV) and their critical information systems (SIIV), enforced by ANSSI.
Applies to: French Opérateurs d'Importance Vitale (OIV) across 10 strategic sectors (energy, defense, finance, healthcare, among others)
The Référentiel Général de Sécurité v2.0 is the French security framework for public authorities and public online services, structured according to the DICA principle (Disponibilité, Intégrité, Confidentialité, Authenticité).
Applies to: French public authorities, public administrations and trust service providers
The Cyber Resilience Act (EU 2024/2847) establishes horizontal cybersecurity requirements for products with digital elements across their entire lifecycle and is a prerequisite for CE marking.
Applies to: Manufacturers, importers and distributors of hardware and software products in the EU
The Digital Operational Resilience Act (EU 2022/2554) requires financial entities in the EU to meet uniform requirements for ICT risk management, incident reporting, resilience testing and third-party risk management.
Applies to: EU financial entities (banks, insurers, payment service providers, crypto service providers, among others)
The EBA ICT Guidelines Framework consolidates the European Banking Authority's requirements for ICT and security risk management into a unified control framework for financial institutions.
Applies to: Credit institutions, investment firms, payment and e-money institutions in the EU
The eIDAS Regulation (EU 910/2014) creates the legal framework for electronic identification and trust services in the EU single market and ensures cross-border recognition of qualified electronic signatures.
Applies to: Trust service providers (TSP/QTSP) and organizations with eIDAS-compliant systems
The EU AI Act (EU 2024/1689) is the world's first comprehensive legal framework for artificial intelligence and establishes risk-based requirements for the development, placing on the market and use of AI systems.
Applies to: Providers, deployers, importers and distributors of AI systems with a connection to the EU
The General Data Protection Regulation (EU 2016/679) is the world's most significant data protection regulation and applies to all organizations that process personal data of individuals in the EU, regardless of the organization's location.
Applies to: All organizations that process personal data of EU citizens
The Markets in Crypto-Assets Regulation (EU 2023/1114) creates the first uniform EU legal framework for crypto-assets, Crypto-Asset Service Providers (CASPs) as well as asset-referenced and e-money tokens.
Applies to: Crypto exchanges, custodians, brokers and issuers of crypto tokens in the EU
The NIS-2 Directive (EU 2022/2555) extends EU-wide minimum cybersecurity requirements to 18 critical sectors and, in Germany, is implemented via the NIS2 Implementation Act.
Applies to: Essential and important entities in 18 critical sectors in the EU
The REMIT Regulation (EU 1227/2011) prevents market manipulation and insider trading in European wholesale energy markets and requires market participants to report transactions to ACER.
Applies to: Market participants in European wholesale electricity and gas trading (generators, traders, exchanges, banks)
TIBER-EU is the framework developed by the European Central Bank for threat-led red team testing (Threat-Led Penetration Testing) in the financial sector and forms the basis for the DORA TLPT requirement.
Applies to: Financial institutions and systemically important financial market infrastructure in the EU
TISAX is the Europe-wide recognized assessment standard for the automotive industry, operated by the ENX Association and based on the VDA ISA catalog, for evaluating the information security of OEMs and suppliers.
Applies to: Automotive manufacturers and suppliers (Tier 1-3) in the European supply chain
The Asana integration enables automatic creation of tasks from audit findings and gap analyses with bidirectional status synchronization between Asana and the audit system.
Applies to: Teams managing remediation actions and findings in Asana
The JIRA integration enables automatic creation of tickets from audit findings and gap analyses with bidirectional status synchronization between JIRA and the audit system.
Applies to: Teams managing remediation actions and findings in JIRA
The Network Scanner is an Nmap-based network security scanner for host discovery, port scanning, service and OS fingerprinting as well as vulnerability scans.
Applies to: IT infrastructure and networks that need to be checked for open ports and vulnerabilities
The OWASP Dependency-Check scanner performs Software Composition Analysis (SCA) and identifies known vulnerabilities (CVEs) in project dependencies across 11 package manager ecosystems.
Applies to: Software development teams analyzing open-source dependencies
The SBOM Scanner provides complete lifecycle management for Software Bills of Materials: generation, validation, license analysis, vulnerability enrichment, version comparison and compliance checking.
Applies to: DevSecOps teams, software vendors and compliance managers
|
Which use case do you want to implement? Talk to us. We are happy to answer your initial questions about Cyber Security & Compliance for your company! |