Standards & legislation

Standards and legislation in the library

The Audirium framework library connects frameworks, controls and legislation. These pages explain per standard what it requires and how the library covers it.

41

frameworks

1,807

controls

2,224

cross-references

136

shared controls

ISO 27001

ISO/IEC 27001:2022 is the international standard for an information security management system (ISMS). Certifiable, risk-driven and the most widely used anchor for security framewo…

NIS2 and the Dutch Cybersecurity Act

NIS2 (Directive (EU) 2022/2555) obliges essential and important entities to a duty of care, incident reporting and board-level accountability for cybersecurity. In the Netherlands,…

GDPR

The General Data Protection Regulation (Regulation (EU) 2016/679) governs the protection of personal data across the EU: 99 articles on lawfulness, data subject rights, accountabil…

DORA

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) requires financial institutions to demonstrate digital resilience: ICT risk management, incident reporting, resil…

BIO and BIO2

The Baseline Informatiebeveiliging Overheid (Dutch Government Information Security Baseline) is the mandatory security framework for Dutch central and local government, based on IS…

NEN 7510

NEN 7510:2024 is the Dutch standard for information security in healthcare: ISO 27001 extended with care-specific controls for patient data, medical devices and chain care.…

ISO 42001

ISO/IEC 42001:2023 is the first certifiable management system standard for artificial intelligence: responsible use of AI, from risk assessment and data governance to human oversig…

Wpg (Dutch Police Data Act)

The Wet politiegegevens governs the processing of police data, including by special investigating officers (boa's) at Dutch municipalities and regional services. Annual internal au…

Want to know more about the library?