IT & cloud security
AppSec, infrastructure security, and product-security obligations.
- ·Cyber Resilience Act (Reg (EU) 2024/2847)
- ·NIS2 (Dir (EU) 2022/2555)
- ·GDPR Art. 32 — security of processing
- ·US federal cybersecurity regulation
- ·NIST SP 800-53r5 · CSF 2.0 · SSDF 800-218 · AI RMF — served as full text
- ·Control mapping: OWASP ASVS · ISO 27001 Annex A · CIS
- ·Control mapping: BSI IT-Grundschutz · C5 · Technische Richtlinien · KRITIS · Mindeststandards
- ·MITRE ATT&CK · CAPEC · CWE · D3FEND
- ·ENISA Threat Landscape
- ·Software supply-chain security · cryptographic algorithm guidance · premium
- ·CVE · CISA KEV · EPSS — live vulnerability context