Frameworks
Controls overlap heavily between frameworks. Evidence collected for one requirement is applied everywhere it counts.
SOC 2
Trust Services Criteria
68%
Security, availability, confidentiality, processing integrity and privacy criteria for service organizations.
ISO 27001
Annex A controls
54%
Information security management system requirements, including risk treatment and Annex A controls.
GDPR
EU data protection
61%
Lawful basis, data subject rights, processor agreements and cross-border transfer safeguards.
HIPAA
Security & privacy rules
39%
Administrative, physical and technical safeguards for protected health information.
PCI DSS
Cardholder data security
27%
Requirements for protecting cardholder data across networks, applications and operations.