127 indexed

COMPLIANCECompliance controls

127 controls across 14 compliance frameworks, grouped by framework. For cross-framework Jaccard overlap see /explore/crosswalk. Authored by Adam Lundqvist.

6 in GDPR · 127 total

IDTitleSummary
GDPR-Art25Data protection by design and by default
GDPRpentest:high
The controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technic…
GDPR-Art32GDPR-Art32
GDPR
GDPR Article 32 — Security of processing: Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of …
GDPR-Art33Notification of a personal data breach to the supervisory authority
GDPRpentest:medium
In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, n…
GDPR-Art34Communication of a personal data breach to the data subject
GDPRpentest:medium
When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal d…
GDPR-Art35Data protection impact assessment
GDPRpentest:medium
Where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, car…
GDPR-Art5Principles relating to processing of personal data
GDPRpentest:high
Personal data shall be: (a) processed lawfully, fairly and in a transparent manner; (b) collected for specified, explicit and legitimate purposes; (c) adequate…
Sourced from EUR-Lex (DORA, NIS2, GDPR, AI Act, CRA), ISO, NIST, OWASP, CIS, PCI SSC, ENISA TIBER-EU. Curated by Adam Lundqvist, Founder at SQUR.
Compliance controls — by framework | SQUR Knowledge Base