Control Catalogue

Comprehensive security and privacy controls derived from European regulations and standards.

Under Development

The control catalogue is currently being developed. View the latest controls in the GitHub repository.

Access Control (AC)

6 controls

Identity, authentication, authorization, and access management controls.

Artificial Intelligence (AI)

12 controls

AI system lifecycle, risk management, and ethical AI controls.

Asset Management (AM)

4 controls

Asset inventory, classification, and lifecycle management.

Audit & Accountability (AU)

3 controls

Audit logging, monitoring, and accountability controls.

Business Continuity (BC)

6 controls

Business continuity planning, disaster recovery, and resilience.

Change Management (CM)

2 controls

Change management, configuration management, and version control.

101 010

Cryptography (CR)

2 controls

Encryption, key management, and cryptographic controls.

Data Protection & Privacy (DP)

5 controls

Data privacy, processing, retention, and subject rights.

Governance & Strategy (GOV)

6 controls

Strategy, policy, roles, and organizational governance.

Human Resources Security (HR)

4 controls

HR security, background checks, and personnel management.

Incident Response (IR)

8 controls

Detection, response, and recovery from security incidents.

Network Security (NS)

4 controls

Network architecture, segmentation, and traffic controls.

Physical Security (PS)

2 controls

Physical security, access control, and environmental protection.

Risk Management (RM)

3 controls

Risk assessment, treatment, monitoring, and review.

Security Awareness & Training (SA)

4 controls

Security awareness training and education programs.

Supply Chain Security (SC)

3 controls

Third-party risk, vendor management, and supply chain security.

Secure Development (SD)

3 controls

Secure coding, DevSecOps, and application security.

Vulnerability & Assessment (VA)

3 controls

Vulnerability management, penetration testing, and security assessments.