Resource Library
Frameworks · Standards · Regulations

Understand what governs you. See how it all connects.

One connected reference for the standards, regulations and governance frameworks shaping the modern enterprise.

22 References
06 Governance Domains
ONE Connected View

The Governance Challenge

Requirements multiply. Governance must connect.

Organizations rarely operate under one framework, one regulator or one set of controls.

A modern enterprise may simultaneously need to manage information-security standards, enterprise risk frameworks, privacy regulation, sector requirements, operational resilience expectations and emerging AI governance obligations.

Looking at each requirement independently creates duplication. The stronger approach is to understand how they relate — where controls overlap, where evidence can be reused and where the same risk, policy, asset or accountability supports several obligations at once.

Governance Reference

Explore the landscape.

Explore authoritative standards and regulations alongside Rezilens' governance perspective and their relationship with connected enterprise GRC.

22 FRAMEWORKS &
REGULATIONS
01

GOVERNANCE DOMAIN

Cybersecurity

Global frameworks and standards supporting information security, cybersecurity governance, control assurance, digital trust and critical infrastructure protection.
6 REFERENCES
01INTERNATIONAL STANDARD

ISO/IEC 27001

Information Security Management System

GLOBAL AUTHORITATIVE SOURCE International Organization for Standardization
OVERVIEW

ISO/IEC 27001 provides a structured management-system approach for protecting information and managing information-security risk. Rather than treating cybersecurity as a collection of isolated technical controls, it connects leadership, risk assessment, policies, responsibilities, controls, evidence and continual improvement. For organizations operating across complex digital environments, the standard provides a foundation for building a repeatable, measurable and auditable information-security program.

GOVERNANCE PERSPECTIVE

From a governance perspective, ISO/IEC 27001 requires organizations to understand their information-security context, identify relevant risks, establish responsibilities, select appropriate controls and demonstrate that those controls remain effective. This makes the standard particularly valuable where executives, regulators, customers and auditors expect evidence that information security is being governed systematically rather than managed reactively.

Security GovernanceRisk AssessmentRisk TreatmentSecurity ControlsEvidence & AssuranceContinual Improvement
02CYBERSECURITY FRAMEWORK

NIST Cybersecurity Framework

Enterprise Cybersecurity Risk Governance

GLOBAL AUTHORITATIVE SOURCE National Institute of Standards and Technology
OVERVIEW

The NIST Cybersecurity Framework provides organizations with a flexible, outcome-oriented approach for understanding and managing cybersecurity risk. It establishes a common language through which cybersecurity teams, enterprise risk functions, executives and business leaders can discuss cyber exposure and priorities. Its value extends beyond technical security by connecting cybersecurity outcomes with organizational objectives, risk decisions and governance responsibilities.

GOVERNANCE PERSPECTIVE

For governance teams, NIST CSF provides a structured way to understand current cybersecurity capability, define target outcomes and communicate improvement priorities. Its Govern function further reinforces the relationship between cybersecurity, enterprise risk management, leadership accountability and organizational context, helping cybersecurity become part of enterprise governance rather than an isolated technology activity.

GovernIdentifyProtectDetectRespondRecover
03CONTROL FRAMEWORK

NIST SP 800-53

Security & Privacy Control Governance

GLOBAL AUTHORITATIVE SOURCE National Institute of Standards and Technology
OVERVIEW

NIST SP 800-53 provides an extensive catalog of security and privacy controls designed to protect information systems, organizations and individuals. It covers a broad range of governance, technical and operational control areas and is particularly valuable for organizations requiring a highly structured security-control environment. The publication supports detailed traceability between information systems, safeguards, assessments, risks and assurance activities.

GOVERNANCE PERSPECTIVE

Its governance value comes from establishing a disciplined control architecture. Organizations can determine control applicability, assign accountability, collect evidence, assess implementation and effectiveness, and maintain continuing oversight over security and privacy safeguards. This creates a strong foundation for complex technology estates and environments with demanding assurance requirements.

Security ControlsPrivacy ControlsControl AssessmentAccess ManagementSystem ProtectionContinuous Monitoring
04CONTROL FRAMEWORK

CIS Controls

Prioritized Cybersecurity Safeguards

GLOBAL AUTHORITATIVE SOURCE Center for Internet Security
OVERVIEW

The CIS Controls provide a prioritized set of cybersecurity safeguards intended to help organizations defend against common and significant cyber threats. Their practical and implementation-oriented structure makes them useful for organizations seeking a clear cybersecurity baseline. The Controls help translate broad security objectives into concrete operational practices that can be assigned, implemented, measured and improved.

GOVERNANCE PERSPECTIVE

From a governance perspective, the CIS Controls can provide a measurable baseline for assessing cybersecurity capability, assigning accountability and prioritizing improvement. They can also complement broader management and risk frameworks such as ISO/IEC 27001 and NIST CSF, helping organizations connect strategic cyber governance with practical implementation.

Asset ManagementIdentity ManagementSecure ConfigurationVulnerability ManagementSecurity MonitoringIncident Response
05INDUSTRIAL STANDARD

ISA/IEC 62443

Industrial & Operational Technology Cybersecurity

GLOBAL AUTHORITATIVE SOURCE International Society of Automation
OVERVIEW

ISA/IEC 62443 addresses cybersecurity across industrial automation and control-system environments. It is particularly relevant to energy, utilities, manufacturing, transportation and other critical-infrastructure sectors where operational technology is directly connected to physical processes. The series recognizes that OT environments have distinct availability, safety, lifecycle and security considerations compared with conventional enterprise IT.

GOVERNANCE PERSPECTIVE

Its governance importance lies in establishing responsibilities across asset owners, automation solution providers, system integrators, service providers and product suppliers. Organizations can use the series to structure OT cybersecurity risk management, security zones and conduits, system requirements, secure product development and lifecycle assurance across complex industrial ecosystems.

Operational TechnologyIndustrial Control SystemsZones & ConduitsSystem IntegrityAccess GovernanceSupplier Security
06INDUSTRY STANDARD

PCI DSS

Payment Card Data Security

GLOBAL AUTHORITATIVE SOURCE PCI Security Standards Council
OVERVIEW

PCI DSS establishes security requirements for organizations that store, process or transmit payment account data. Its objective is to reduce exposure of payment environments through defined safeguards covering networks, systems, identities, vulnerabilities, monitoring and access to sensitive payment information. Maintaining compliance therefore requires continuing operational discipline rather than a one-time certification exercise.

GOVERNANCE PERSPECTIVE

For governance and assurance teams, PCI DSS creates clear accountability for protecting payment environments and demonstrating that required safeguards remain implemented and effective. Evidence collection, control testing, vulnerability management, issue remediation and recurring assessment become important components of the compliance lifecycle.

Payment SecurityNetwork ProtectionAccess ControlVulnerability ManagementMonitoringCompliance Evidence
02

GOVERNANCE DOMAIN

Risk & Governance

Standards and governance models supporting enterprise risk management, decision rights, accountability, technology governance and organizational oversight.
3 REFERENCES
01RISK MANAGEMENT STANDARD

ISO 31000

Enterprise Risk Management

GLOBAL AUTHORITATIVE SOURCE International Organization for Standardization
OVERVIEW

ISO 31000 provides principles, a framework and guidance for managing risk across an organization. Its purpose is not to create risk management as a separate administrative activity, but to integrate consideration of uncertainty into governance, strategy, planning, operations and decision-making. The approach can therefore be applied to strategic, operational, technology, cyber, financial, project and emerging risks.

GOVERNANCE PERSPECTIVE

The framework encourages organizations to establish clear responsibilities, understand internal and external context, identify and analyze uncertainty, evaluate risk and determine appropriate treatments. Continuous monitoring, communication and review strengthen the connection between enterprise objectives, risk appetite, decisions and executive oversight.

Risk GovernanceRisk IdentificationRisk AnalysisRisk EvaluationRisk TreatmentMonitoring & Review
02ENTERPRISE RISK FRAMEWORK

COSO ERM

Enterprise Risk, Strategy & Performance

GLOBAL AUTHORITATIVE SOURCE Committee of Sponsoring Organizations of the Treadway Commission
OVERVIEW

COSO Enterprise Risk Management provides a framework for integrating risk with strategy and organizational performance. Rather than treating risk as a reporting exercise performed after important decisions have already been made, COSO ERM encourages organizations to consider uncertainty while establishing strategy, defining objectives, evaluating alternatives and reviewing performance.

GOVERNANCE PERSPECTIVE

The framework is particularly relevant to boards and executive teams seeking to understand whether risk-taking remains aligned with enterprise objectives and risk appetite. It supports stronger conversations around performance, emerging exposure, strategic choices, governance culture and the creation and preservation of enterprise value.

StrategyRisk AppetitePerformanceGovernanceEnterprise ObjectivesDecision-Making
03GOVERNANCE FRAMEWORK

COBIT 2019

Governance of Enterprise Information & Technology

GLOBAL AUTHORITATIVE SOURCE ISACA
OVERVIEW

COBIT provides a structured framework for governing and managing enterprise information and technology. It helps organizations establish governance and management objectives, decision responsibilities and performance mechanisms around technology. This becomes increasingly important as digital capabilities, cybersecurity, data and technology investment become inseparable from business strategy and operational delivery.

GOVERNANCE PERSPECTIVE

COBIT helps leadership move beyond viewing IT purely as a technical function. It provides a governance structure through which stakeholder needs, value delivery, risk, resources, security, compliance and performance can be considered together and aligned with enterprise objectives.

Technology GovernanceDecision RightsValue DeliveryTechnology RiskPerformanceAccountability
03

GOVERNANCE DOMAIN

Operational Resilience

Frameworks supporting business continuity, operational resilience, disruption preparedness, critical-service protection and recovery governance.
2 REFERENCES
01INTERNATIONAL STANDARD

ISO 22301

Business Continuity Management System

GLOBAL AUTHORITATIVE SOURCE International Organization for Standardization
OVERVIEW

ISO 22301 establishes requirements for a structured Business Continuity Management System. It helps organizations understand disruptive risk, identify priority activities, determine continuity and recovery requirements, and maintain strategies and plans for responding to disruption. The standard treats continuity as an organizational capability that must be governed, exercised, reviewed and improved rather than as a collection of emergency documents.

GOVERNANCE PERSPECTIVE

Its value extends beyond recovery planning. ISO 22301 creates accountability around business impact analysis, continuity strategies, procedures, exercises, performance evaluation, management review and continual improvement. This gives leadership greater confidence that priority operations can continue or recover when technology, facilities, people, suppliers or other dependencies fail.

Business Impact AnalysisPriority ActivitiesContinuity StrategyRecovery ObjectivesExercises & TestingContinual Improvement
02GOVERNANCE DISCIPLINE

Operational Resilience

Protecting Critical Business Services

GLOBAL AUTHORITATIVE SOURCE Basel Committee on Banking Supervision
OVERVIEW

Operational resilience focuses on an organization’s ability to continue delivering important business services through disruption. It expands traditional continuity thinking by examining the complete ecosystem required to deliver an important service, including people, technology, facilities, information, processes and external dependencies. This creates a business-service perspective rather than a recovery plan centred only on individual systems.

GOVERNANCE PERSPECTIVE

The central resilience question therefore changes from “Can this system recover?” to “Can the organization continue delivering what matters?” Answering that question requires coordination between enterprise risk, cybersecurity, technology, continuity, third-party management, operations and executive governance, supported by scenario testing and clear tolerance for disruption.

Critical ServicesDependenciesImpact ToleranceScenario TestingThird PartiesDisruption Management
04

GOVERNANCE DOMAIN

Privacy & Data Protection

Privacy regulations and standards governing personal data, organizational accountability, privacy rights, data protection and information governance.
4 REFERENCES
01PRIVACY REGULATION

GDPR

General Data Protection Regulation

EU AUTHORITATIVE SOURCE European Union — EUR-Lex
OVERVIEW

The General Data Protection Regulation establishes a comprehensive framework for protecting personal data and governing how organizations collect, use, share, retain and protect information relating to individuals. It strengthened individual rights while introducing significant organizational accountability obligations and has influenced privacy and data-protection practices far beyond the European Union.

GOVERNANCE PERSPECTIVE

GDPR compliance is not simply a responsibility of the legal or privacy function. Effective implementation requires coordinated governance across processing activities, policies, lawful bases, security, third parties, individual rights, breach management, records, evidence and executive accountability. Privacy therefore becomes an enterprise governance issue involving multiple functions and systems.

Privacy RightsLawful ProcessingData GovernanceAccountabilityBreach ManagementThird Parties
02PRIVACY REGULATION

UAE PDPL

UAE Personal Data Protection

UAE AUTHORITATIVE SOURCE UAE Government
OVERVIEW

The UAE Personal Data Protection framework establishes requirements concerning the processing and protection of personal data. It forms an important part of the UAE’s evolving digital-governance environment and requires organizations within its scope to establish clearer accountability around how personal information is collected, processed, protected, transferred and governed.

GOVERNANCE PERSPECTIVE

Organizations need to translate privacy obligations into operational responsibilities, policies, controls, evidence and repeatable workflows. Privacy therefore needs to connect with cybersecurity, information governance, third-party management, enterprise risk and organizational accountability rather than operating as an isolated legal or documentation exercise.

Personal DataPrivacy GovernanceIndividual RightsProcessing GovernanceAccountabilityProtection Controls
03PRIVACY REGULATION

Saudi PDPL

Saudi Personal Data Protection

KSA AUTHORITATIVE SOURCE Saudi Data & AI Authority
OVERVIEW

Saudi Arabia’s Personal Data Protection Law establishes requirements governing the collection, processing, use and protection of personal data. It is an important component of the Kingdom’s wider data and digital-governance environment and creates accountability requirements for organizations handling personal information across business processes, systems and external relationships.

GOVERNANCE PERSPECTIVE

Effective compliance requires clear ownership, policies, processing governance, risk consideration, controls, evidence and mechanisms for addressing individual rights and data incidents. For larger organizations, these activities need to be coordinated across business units, technology platforms, vendors, data owners and governance functions.

Personal DataProcessing GovernanceIndividual RightsOrganizational AccountabilityData ProtectionCompliance Evidence
04PRIVACY STANDARD

ISO/IEC 27701

Privacy Information Management

GLOBAL AUTHORITATIVE SOURCE International Organization for Standardization
OVERVIEW

ISO/IEC 27701 extends information-security management practices into privacy information management. It provides organizations with a structured approach for defining privacy responsibilities, establishing relevant controls and demonstrating systematic governance of personally identifiable information. It can help create a more disciplined bridge between security management and organizational privacy responsibilities.

GOVERNANCE PERSPECTIVE

For organizations already working with ISO-based management systems, ISO/IEC 27701 supports a more integrated relationship between privacy, information security, risk, controls, evidence and assurance. This can reduce duplication and help privacy governance become part of an established management-system environment rather than a separate compliance stream.

Privacy ManagementPII GovernanceAccountabilityPrivacy ControlsEvidenceContinual Improvement
05

GOVERNANCE DOMAIN

AI Governance

Standards and frameworks supporting responsible AI adoption, AI risk management, accountability, explainability and organizational oversight.
3 REFERENCES
01AI MANAGEMENT STANDARD

ISO/IEC 42001

Artificial Intelligence Management System

GLOBAL AUTHORITATIVE SOURCE International Organization for Standardization
OVERVIEW

ISO/IEC 42001 provides a management-system approach for organizations developing, providing or using artificial intelligence. It moves AI governance beyond isolated technical controls by establishing organizational responsibilities, management processes, risk considerations, lifecycle oversight and mechanisms for monitoring and continual improvement. It provides a governance foundation for organizations seeking to institutionalize responsible AI practices.

GOVERNANCE PERSPECTIVE

The standard becomes increasingly relevant as AI adoption moves from experimentation into enterprise processes, products and decision-making. Organizations need to understand which AI systems they use, who owns them, how impacts and risks are evaluated, what controls apply and how performance, change and unintended consequences are monitored over time.

AI GovernanceAI LifecycleRisk ManagementAccountabilityResponsible AIContinual Improvement
02AI RISK FRAMEWORK

NIST AI RMF

Artificial Intelligence Risk Management

GLOBAL AUTHORITATIVE SOURCE National Institute of Standards and Technology
OVERVIEW

The NIST AI Risk Management Framework provides organizations with a structured approach for identifying, assessing and managing risks associated with artificial intelligence. It is intended to support trustworthy and responsible AI by integrating governance, contextual understanding, measurement and risk-management practices throughout the AI lifecycle.

GOVERNANCE PERSPECTIVE

Its value lies in helping organizations translate broad responsible-AI principles into operational practices. Leadership and governance teams can use the framework to clarify responsibilities, understand potential impacts, assess trustworthiness characteristics and establish mechanisms for treating and monitoring AI risk as technologies, uses and operating contexts evolve.

GovernMapMeasureManageTrustworthinessAI Risk
03GOVERNANCE MODEL

Responsible AI Governance

Accountable, Explainable & Governed AI

GLOBAL AUTHORITATIVE SOURCE OECD
OVERVIEW

Responsible AI governance establishes the organizational mechanisms needed to ensure artificial intelligence is developed and used consistently with enterprise values, risk appetite, legal obligations and stakeholder expectations. It extends beyond model performance into accountability, data governance, human oversight, transparency, explainability, security, fairness and operational impact.

GOVERNANCE PERSPECTIVE

A mature AI governance model establishes ownership from experimentation through deployment and ongoing monitoring. It defines decision rights, approval mechanisms, policies, controls, evidence requirements and escalation paths so organizations can accelerate AI adoption while maintaining appropriate accountability and oversight.

AccountabilityHuman OversightExplainabilityAI RiskData GovernanceAuditability
06

GOVERNANCE DOMAIN

GCC Regulations

Regional cybersecurity, privacy, technology and sector requirements relevant to organizations operating across the UAE and Saudi Arabia.
4 REFERENCES
01CYBERSECURITY CONTROLS

NCA ECC

Essential Cybersecurity Controls

KSA AUTHORITATIVE SOURCE Saudi National Cybersecurity Authority
OVERVIEW

The Saudi National Cybersecurity Authority Essential Cybersecurity Controls establish a structured cybersecurity baseline for organizations within their applicable scope. The controls address cybersecurity governance, defense, resilience, third-party cybersecurity and other essential areas intended to strengthen organizational and national cybersecurity capability.

GOVERNANCE PERSPECTIVE

For organizations, the challenge is not simply documenting compliance against individual controls. Effective implementation requires accountable control ownership, appropriate evidence, recurring assessment, remediation and management visibility across technology, cybersecurity, risk and third-party environments. The controls therefore need to become part of continuing governance rather than a static compliance register.

Cyber GovernanceCyber DefenseCyber ResilienceThird-Party SecurityControl AssuranceEvidence
02SECTOR FRAMEWORK

SAMA Cybersecurity Framework

Financial-Sector Cybersecurity Governance

KSA AUTHORITATIVE SOURCE Saudi Central Bank
OVERVIEW

The SAMA Cybersecurity Framework establishes cybersecurity governance expectations for regulated financial institutions in Saudi Arabia. It supports a structured approach to cybersecurity management, risk, controls, resilience and assurance in institutions whose technology environments are fundamental to financial services, operational stability and customer trust.

GOVERNANCE PERSPECTIVE

Financial institutions need to demonstrate that cybersecurity responsibilities are clearly assigned, risks are understood, controls remain effective and weaknesses are addressed in a disciplined manner. This requires continuous coordination between cybersecurity operations, technology, enterprise risk, compliance, audit and executive governance rather than isolated compliance activities.

Cyber GovernanceFinancial ServicesCyber RiskSecurity ControlsResilienceAssurance
03CYBERSECURITY FRAMEWORK

UAE Information Assurance

Information Assurance Governance

UAE AUTHORITATIVE SOURCE UAE Government
OVERVIEW

UAE information-assurance requirements provide an important governance and control reference for strengthening information security across applicable organizations and digital environments. They establish expectations around security governance, risk management, protection mechanisms, organizational responsibilities and assurance activities.

GOVERNANCE PERSPECTIVE

Implementation requires more than maintaining a checklist of controls. Organizations need to connect applicable requirements with systems, policies, risks, ownership, evidence, assessment results and remediation activities so compliance remains visible and sustainable as technologies, threats and business environments change.

Information AssuranceSecurity GovernanceRisk ManagementCyber ControlsEvidenceAssurance
04CYBERSECURITY REQUIREMENTS

DESC ISR

Dubai Information Security Requirements

DUBAI AUTHORITATIVE SOURCE Dubai Electronic Security Center
OVERVIEW

Dubai information-security requirements provide a structured approach for strengthening security governance and assurance across applicable government and digital environments. They support consistent management of cybersecurity responsibilities, controls, risk, information assets and compliance evidence within an organized governance model.

GOVERNANCE PERSPECTIVE

For organizations operating in complex digital environments, compliance needs to become an ongoing governance process rather than a periodic documentation exercise. Requirements should be connected to ownership, controls, evidence, assessment activities and remediation so leadership can understand both compliance status and remaining exposure.

Security GovernanceCyber ControlsRisk ManagementComplianceEvidenceAssurance

Connected Governance

Many frameworks. One control environment.

The same control may support ISO 27001, NIST, privacy obligations, regional regulation and internal policy simultaneously.

Connected governance creates one relationship between requirements, controls, evidence, risk and assurance — reducing duplication while improving enterprise visibility.

01UNDERSTANDRequirements
02MAPControls
03PROVEEvidence
04VALIDATEAssurance
05UNDERSTANDGovernance Intelligence

From Compliance To Governance

Manage many requirements. Govern them as one.

See how DiGRC connects frameworks, risks, controls, evidence, assessments and actions into one continuously governed enterprise environment.