Besides NIS2 and ISO 27001, Frameworks can show your readiness for five more frameworks. You use the same controls: link a control to a requirement and it counts there too.
The frameworks
Open Frameworks in the menu and go to the More frameworks panel. Pick a framework to see its requirements:
- DORA (Regulation 2022/2554): for financial entities. Articles 5 to 30 and 45, on ICT risk management, incidents, testing, third parties and information sharing.
- Cyber Resilience Act Annex I: for makers of products with digital elements. Part I essential requirements (I.1 and I.2(a) to (m)) and Part II vulnerability handling (II.1 to II.8).
- ISO 22301:2019: business continuity management, clauses 4.1 to 10.2.
- TISAX (VDA ISA 6): the VDA ISA 6 control numbers used in TISAX assessments.
- SOC 2 Trust Services Criteria: CC1.1 to CC9.2, A1, C1, PI1 and P1 to P8.
CloudSignLab stores the codes only. The texts of these standards are copyrighted, so keep your own copy at hand.
How to link a control
- Open the control in Controls.
- In its Framework reference, write the framework name followed by the code, for example:
- Save.
The framework name must come first. This way a code never counts for another framework by mistake. One control can name several frameworks.
How to read your readiness
A framework's readiness card appears on Frameworks once at least one control names it. The list shows each requirement's state (No control yet, Not started, In progress or Implemented) and the controls linked to it.
Tips
- Pick only the frameworks that really apply to you; DORA, for example, concerns financial entities.
- Reuse controls: one backup control can count for NIS2, ISO 27001, ISO 22301 and SOC 2 at once.
- Readiness shows your controls as recorded.