Documentation Index

Fetch the complete documentation index at: https://help.scrut.io/llms.txt

Use this file to discover all available pages before exploring further.

Which Frameworks Does Scrut Support?

Prev Next

Scrut supports 70+ frameworks right out of the box. Each framework serves a specific purpose, catering to different compliance needs. Here's a brief overview of each framework to help you understand how they can strengthen your security posture.

21 CFR Part 11

21 CFR Part 11 is a U.S. FDA regulation that establishes requirements for treating electronic records and electronic signatures as equivalent to paper records. It applies to FDA-regulated industries, including pharmaceuticals, medical devices, and biotechnology, and focuses on maintaining data integrity in digital systems. Compliance is critical for organizations operating in life sciences.

Australia ISM Dec 2024

The Australia Information Security Manual (ISM) is a cybersecurity framework by the Australian Signals Directorate (ASD) that outlines security controls for protecting government and sensitive data. The Dec 2024 update introduces enhanced measures to address evolving cyber threats and improve organizational resilience.

Botswana Data Protection Act 2024

The Botswana Data Protection Act, 2024 (Act No. 18 of 2024) is Botswana’s updated data privacy legislation, replacing the earlier 2018 Act. It establishes a legal framework for the collection, processing, storage, and transfer of personal data, aligning closely with global privacy standards, such as the GDPR.

CCPA (California Consumer Privacy Act)

The CCPA (California Consumer Privacy Act) framework enhances data privacy for California residents by giving them control over their personal data. Businesses in California must comply to avoid fines and legal issues, build trust with privacy-conscious consumers, and reduce data-breach risks.

CIS (Center for Internet Security)

The CIS (Center for Internet Security) framework is a set of best practices to help organizations improve their cybersecurity posture. It provides actionable guidelines to defend against common cyber threats.

CIS v8.1

The CIS v8.1 is the latest version of the Center for Internet Security benchmarks, offering comprehensive security controls to mitigate risks and protect systems. It helps organizations strengthen their cybersecurity posture and meet compliance requirements.

CMMC 2.0 Level 1

CMMC (Cybersecurity Maturity Model Certification) 2.0 Level 1 is crucial for U.S. government contractors, as it establishes a baseline of cybersecurity measures essential for securing contracts and creating a safe digital environment.

CMMC 2.0 Level 2

CMMC (Cybersecurity Maturity Model Certification) 2.0 Level 2 builds upon Level 1, specifically for organizations managing Controlled Unclassified Information (CUI) that require advanced security measures.

CMMC 2.0 Level 3

CMMC (Cybersecurity Maturity Model Certification) 2.0 Level 3 builds upon the foundational cybersecurity practices of Levels 1 and 2. It is essential for organizations seeking to bid on or maintain contracts with the U.S. Department of Defense.

COBIT 2019

The COBIT 2019 framework, created by ISACA, provides a comprehensive model for IT governance and management. It helps organizations align IT processes with business objectives, address risks, and meet control requirements effectively.

COPPA (Children's Online Privacy Protection Act)

COPPA (Children's Online Privacy Protection Act) is a federal law that protects the online privacy of children under 13. It requires parental consent and strict data protection measures for websites and services that collect children's personal information.

CSA STAR

The CSA STAR (Cloud Security Alliance Security, Trust, Assurance, and Risk) framework is vital for organisations using cloud services, offering a common security language. It helps assess and reduce risks, fosters trust, secures data, and navigates cloud security effectively.

Cyber Essentials v3.2

The Cyber Essentials v3.2 is the latest version of the Cyber Essentials framework by the UK's National Cyber Security Centre (NCSC). It helps organizations guard against common cyber threats, and compliance is critical for businesses working with UK government contracts or handling sensitive data within the UK.

Cyber Security Framework SAMA (Saudi Arabian Monetary Authority)

The SAMA CSF (Saudi Arabian Monetary Authority Cyber Security Framework) is a tailored cybersecurity guide for financial institutions in Saudi Arabia, aligning with global standards like NIST and ISO. It is essential to fortify defenses, mitigate risks, and ensure compliance, safeguarding against cyber threats and enhancing the overall cybersecurity posture of the financial sector.

DORA

The DORA strengthens the financial system's resilience against cyberattacks and operational disruptions by protecting financial stability, enhancing consumer protection, and promoting consistent standards across the EU financial sector. Compliance is required for credit institutions, investment firms, and critical third-party information and communication technology (ICT) service providers.

DPA Seychelles

The Data Protection Act (DPA) Seychelles is a legal framework that ensures the protection of personal data for organizations operating in Seychelles. It establishes guidelines for complying with regional privacy requirements and safeguarding individual rights.

DPDPA 2023 (Integrated 2025 Rules)

The DPDPA (Digital Personal Data Protection Act) is a landmark piece of legislation in India that aims to safeguard individuals' privacy in the digital age. It came into effect on September 1, 2023, and applies to all organizations that process personal data of individuals in India. Scrut’s implementation covers the entire India DPDPA (Act + 2025 Rules) Framework.

DTAC (Digital Technology Assessment Criteria)

DTAC (Digital Technology Assessment Criteria) is an NHS framework that evaluates the safety, security, and quality of digital health technologies, ensuring they meet high standards in clinical safety, data protection, and usability.

EASA Regulation 2022/1645

EASA (European Aviation Safety Agency) Regulation 2022/1645 is a European Union regulation for the validation and verification of safety-related software and firmware in aviation. It applies to organizations involved in the development, modification, or maintenance of safety-related software and firmware for aircraft.

Essential Cybersecurity Controls ECC-1:2018

The ECC-1:2018 (Essential Cybersecurity Controls) framework bolsters information security for Saudi Arabian organizations, private companies, and individuals. Compliance ensures alignment with national regulations, safeguards sensitive data, and minimizes operational disruptions through proactive risk management.

Essential Eight Level 1

Essential Eight Level 1 is a cybersecurity framework developed by the Australian Cyber Security Centre to provide a baseline level of protection against cyber threats. It's recommended for organizations operating in Australia, especially those handling sensitive data.

Essential Eight Level 2

Essential Eight Level 2 is a cybersecurity framework developed by the Australian Cyber Security Centre that provides a more advanced level of protection against cyber threats. It builds upon the strategies outlined in Level 1 and can help organizations demonstrate a strong commitment to cybersecurity.

Essential Eight Level 3

Essential Eight Level 3 is a cybersecurity framework developed by the Australian Cyber Security Centre that provides the highest level of protection against cyber threats. It builds upon the strategies outlined in Levels 1 and 2.

EU AI Act

The EU AI Act is a comprehensive legal framework for artificial intelligence that promotes human-centric and trustworthy AI while safeguarding health, safety, and fundamental rights. It impacts organizations that develop, import, distribute, or use AI systems within the European Union, regardless of their location.

FedRAMP Moderate

The FedRAMP Moderate is a U.S. government program that standardizes security assessment, authorization, and continuous monitoring for cloud products and services. The Moderate Impact Level is the most common authorization for Cloud Service Providers (CSPs) that manage non-public data, like Personally Identifiable Information (PII).

FERPA (Family Educational Rights and Privacy Act)

FERPA (Family Educational Rights and Privacy Act) is a U.S. federal law that protects the privacy of student education records. It grants parents and eligible students rights over these records while ensuring educational institutions maintain confidentiality.

GDPR (General Data Protection Regulation)

The GDPR (General Data Protection Regulation) is a legal framework that sets guidelines for the collection and processing of personal data from individuals within the European Union (EU) and the European Economic Area (EEA). It aims to give individuals control over their data and simplify the regulatory environment for international business by unifying data protection laws across the European Union.

Gramm-Leach-Bliley Act (GLBA)

The Gramm-Leach-Bliley Act (GLBA) is a U.S. federal law that requires financial institutions to protect the privacy and security of consumers' personal financial information. Compliance is essential for organizations in the financial services sector, including banks, insurance companies, and fintechs, that handle non-public personal information (NPI).

HIPAA (Health Insurance Portability and Accountability Act)

HIPAA (Health Insurance Portability and Accountability Act) is a framework ensuring the security and privacy of individuals' health information. The HIPAA is crucial for healthcare organizations to comply with legal standards, safeguard patient data, and maintain trust in the healthcare system.

HITRUST e1 (Essentials 1-year)

The HITRUST e1 (Essentials 1-year) is a minimum assurance level report based on the foundational security and privacy requirements drawn from the full HITRUST CSF. It's crucial for organizations that need to demonstrate a fundamental level of security assurance without the complexity and cost of a full r2 (Risk-based) assessment.

HITRUST i1 (Implemented 1-year)

The HITRUST i1 (Implemented 1-year) assessment is a moderate-assurance report. It provides a higher degree of assurance than the e1, validating that essential controls have been properly implemented and are operating effectively.

ISO 9001:2015

ISO 9001:2015 is a global standard for quality management systems, ensuring consistent delivery of high-quality products and services. Compliance boosts customer satisfaction, operational efficiency, and signifies dedication to quality, benefiting organisations of all sizes and industries. It is crucial for companies looking to enhance their quality practices, demonstrate excellence, and meet stakeholder expectations.

ISO 13485:2016

ISO 13485:2016 is an international standard for quality management systems in the medical device sector that covers the entire device lifecycle. Compliance is crucial for medical device manufacturers to meet regulatory standards, ensure product quality and safety, and effectively manage risks. It applies to organizations of all sizes involved in any stage of the medical device lifecycle, from design to distribution.

ISO 20000-1:2018

ISO 20000-1:2018 is a global standard for IT Service Management (ITSM), ensuring consistent and effective service delivery. Compliance enhances service quality and reliability, improving incident management and customer satisfaction. It showcases an organization's dedication to IT service excellence, benefiting companies of all sizes, particularly those in industries with strict IT compliance requirements.

ISO 22301:2019

ISO 22301:2019 is a business continuity management framework that ensures organizations can continue their operations during disruptions. Crucial for resilience, it guides the development of robust plans, safeguards critical functions, and enhances an organization's ability to navigate and recover from unexpected events.

ISO 27001:2013

ISO 27001:2013 is an information security management framework that ensures organizations protect sensitive data. Vital for cybersecurity, it establishes systematic controls, safeguards against data breaches, and promotes a secure environment, instilling confidence in stakeholders and meeting regulatory requirements.

ISO 27001:2022

ISO 27001:2022 is an updated information security management framework that refines controls and aligns with ISO/IEC 27002:2022. It ensures robust planning, improved monitoring standards, and addresses evolving threats. The framework is crucial for organizations to safeguard data, foster trust, and adapt to the changing landscape of information security.

ISO 27017:2015

The ISO 27017:2015 framework is intended to enhance cloud security. This benefits cloud service providers by ensuring secure environments and meeting customer expectations for data privacy.

ISO 27018:2019

ISO 27018:2019 extends security standards to cloud environments, including the protection of personally identifiable information (PII). Compliance ensures strong data privacy controls, builds customer trust, and aids regulatory adherence. It's crucial for both cloud service providers (CSPs) and users to demonstrate a commitment to data privacy to attract privacy-conscious clients.

ISO 27018:2025

ISO 27018:2025 is the latest update to ISO 27018 and reflects modern privacy challenges, aligning with evolving global data protection laws such as the GDPR. It sets the standards for protecting Personally Identifiable Information (PII) in public clouds.

ISO 27701:2025

ISO 27701:2025 extends ISO 27001 to manage personal information, support privacy compliance, and reinforce trust. It ensures the responsible handling of personal data and meets regulatory requirements for enhanced data protection.

ISO 42001:2023

ISO 42001:2023 framework supports the promotion of responsible AI development and deployment. This benefits organizations by establishing best practices, mitigating risks, and building trust in ethical AI.

ISR V2

The ISR V2 framework enhances compliance efforts by aligning with the latest Information Security Regulation standards. It provides robust security controls to mitigate cyber risks and safeguard sensitive data for organizations in Dubai and beyond.

Law 25

The Law 25 framework provides a structured approach to help organizations comply with Quebec's updated privacy law. It includes pre-built controls, risk assessments, and compliance mappings to simplify adherence, mitigate privacy risks, and streamline implementation.

MAS TRM 2021

MAS TRM 2021 framework (Monetary Authority of Singapore Technology Risk Management) is a framework mandated for all financial institutions in Singapore. It guides them in managing technology risks and bolstering cyber resilience through strong governance and comprehensive cybersecurity measures, ensuring the protection of data and IT systems.

NEN 7510-1: 2024

NEN 7510-1: 2024 is the premier Dutch standard for information security within the healthcare sector. It builds upon ISO/IEC 27001 but adds specific requirements and controls designed to protect sensitive patient data and ensure the availability of critical healthcare services. It is often mandatory for organizations operating in or providing services to the Dutch healthcare market.

New Jersey Data Privacy Law (NJDPL)

The New Jersey Data Privacy Law (NJDPL) is a state-level regulation that enhances consumer privacy rights and sets strict requirements for businesses handling personal data. It aligns with global standards, such as GDPR and CCPA, focusing on transparency, consent, and data security.

NIS 2 Directive

The NIS 2 Directive framework is intended to help EU organizations enhance cybersecurity and meet regulatory standards. This framework is crucial for critical sectors, promoting a harmonized approach to cybersecurity and strengthening digital resilience across the European Union.

NIST 800-53 REV5 (High Baseline)

The NIST 800-53 REV5 (High Baseline) is a security framework that provides stringent security controls for high-impact systems. It is designed for organizations handling highly sensitive data, such as government agencies and critical infrastructure, to protect against advanced cyber threats.

NIST 800-53 REV5 (Low Baseline)

The NIST 800-53 REV5 (Low Baseline) is a specialized subset of the NIST 800-53 framework designed for systems that require low-impact security controls. It helps organizations ensure compliance, minimize risks, and maintain robust security without unnecessary complexity.

NIST 800-53 REV5 (Privacy Baseline)

The NIST 800-53 REV5 (Privacy Baseline) is a specialized subset of the NIST 800-53 framework designed for systems that require enhanced privacy measures. The Privacy Baseline focuses on safeguarding personal information and is crucial for organizations that handle sensitive data.

NIST 800-53 Revision 5 (Moderate Baseline)

The NIST 800-53 Revision 5 (Moderate Baseline) is a cybersecurity framework that provides guidelines for federal information systems. It ensures robust security controls, protecting sensitive information and infrastructure. Crucial for government agencies, it establishes a comprehensive approach to safeguarding data and mitigating cybersecurity risks effectively.

NIST 800-171 Revision 2

NIST 800-171 Revision 2 is vital for securing sensitive information (CUI) in non-federal systems, thereby supporting federal missions. It offers key security guidelines, ensuring confidentiality, with minor edits in this revision.

NIST 800-171 Revision 3

NIST 800-171 Revision 3 updates the security requirements and associated assessment procedures for non-federal entities that process, store, or transmit Controlled Unclassified Information (CUI) on behalf of federal agencies. Compliance is critical for government contractors and other non-federal organizations handling CUI.

NIST 800-171A

The NIST 800-171A framework is for organizations handling Controlled Unclassified Information (CUI) under DoD contracts. This framework benefits defense contractors, government agencies, and the U.S. government by ensuring robust security practices and safeguarding sensitive information crucial for national security.

NIST AI RMF (Risk Management Framework)

The NIST AI RMF (Risk Management Framework) helps align AI projects with established standards, ensuring the development of trustworthy systems. It covers risk culture, identifies and prioritizes AI risks, and outlines effective risk management. Essential for responsible AI, compliance, and industry standards.

NIST CSF 2.0 (Cybersecurity Framework)

The NIST CSF 2.0 (Cybersecurity Framework) is a voluntary, risk-based framework that provides a set of industry-recognized cybersecurity outcomes for organizations to identify, prioritize, and manage their cybersecurity risks.

NIST CSF v1.1 (Cybersecurity Framework)

The NIST CSF v1.1 (Cybersecurity Framework) is a flexible cybersecurity guide that enables organizations to tailor practices to their specific needs. It's a trusted industry standard that promotes strong cybersecurity, fosters effective communication, and builds trust in supply chains by aligning technical and business priorities.

NYDFS 23 NYCRR 500

The NYDFS 23 NYCRR 500 framework is for financial institutions, enforcing strict standards to protect sensitive data and transactions. It boosts cybersecurity readiness, builds trust by safeguarding customer assets, and helps avoid penalties through compliance.

PCI DSS v4.0

PCI DSS v4.0 is the latest standard issued by the PCI Security Standards Council, ensuring security for organizations that handle card payments. Compliance protects cardholder data, reduces financial risks, and builds trust with stakeholders.

PCI DSS v4.0.1

PCI DSS v4.0.1 is a limited revision to the Payment Card Industry Data Security Standard, building upon the significant changes made in Version 4.0 (March 2022). This update provides essential corrections and clarifications to enhance usability, consistency, and effectiveness for organizations that handle cardholder data and sensitive authentication data.

PDPA Singapore

The PDPA (Personal Data Protection Act) Singapore regulates the collection, use, and disclosure of personal data, and applies to all organizations. Compliance is vital for businesses in Singapore or those handling data of Singapore residents to avoid penalties and maintain their reputations. It promotes responsible data practices, affecting Singapore-based businesses and those globally that handle data of Singapore residents.

PHIPA (Personal Health Information Protection Act)

The PHIPA (Personal Health Information Protection Act) outlines the rules for the collection, use and disclosure of personal health information. Compliance is vital for all health information custodians operating in the province of Ontario, Canada, and for individuals and organizations that receive personal health information from them.

PIPEDA (Personal Information Protection and Electronic Documents Act)

PIPEDA (Personal Information Protection and Electronic Documents Act) is Canada's federal law overseeing personal information handling by private sector entities, ensuring privacy rights and establishing data handling guidelines. Compliance with PIPEDA is essential for Canadian businesses or those handling Canadian personal data to evade fines and maintain data privacy standards. It fosters responsible data practices and applies to all private-sector organizations in Canada, as well as to international businesses that handle the personal data of Canadian residents.

RBI CSF (Reserve Bank of India Cyber Security Framework)

The RBI CSF (Reserve Bank of India Cyber Security Framework) is vital for financial institutions, guiding them in bolstering cybersecurity and securing financial transactions. Compliance is necessary to maintain the integrity of banking systems and uphold customer trust.

RBI DPSC (Digital Payment Security Controls)

The RBI DPSC (Digital Payment Security Controls) framework ensures the security of digital payment systems and safeguards sensitive financial data. Compliance is essential for financial entities to mitigate cyber threats, uphold customer confidence, and maintain the integrity of digital payment channels.

RBI PA/PG (Payment Aggregators and Payment Gateways)

The RBI PA/PG (Payment Aggregators and Payment Gateways) framework focuses on securing payment gateways and ensuring the integrity of online transactions. Compliance is crucial for financial entities to protect customer financial data, prevent fraud, and maintain a trustworthy online payment ecosystem.

SAMA CRFR (Cyber Resilience Fundamental Requirements)

The SAMA CRFR (Cyber Resilience Fundamental Requirements) is designed to ensure that financial institutions comply with the regulations in place to protect the country's financial system. The CRFR Compliance program requires financial institutions to implement specific measures to ensure compliance with CRFR regulations.

SAMA MVC (Minimum Verification Controls)

The SAMA MVC framework (Minimum Verification Controls), governed by the Saudi Arabian Monetary Authority (SAMA), sets compliance standards for financial institutions in Saudi Arabia. It ensures adherence to regulations, safeguards financial data, and fosters a secure financial environment. Compliance is crucial to avoid penalties, mitigate cyber threats, and build trust with stakeholders.

Saudi Arabia PDPL (Personal Data Protection Law)

The Saudi Arabia PDPL (Personal Data Protection Law) is a comprehensive data privacy law that protects individuals' personal data, ensuring enhanced security, individual control, and organizational transparency. It applies to any entity processing personal data of Saudi residents, including local businesses, multinationals, and organizations offering services to them.

SEBI CSCRF (Securities and Exchange Board of India Cyber Security & Cyber Resilience)

The SEBI CSCRF (Securities and Exchange Board of India Cyber Security & Cyber Resilience) framework is a regulatory framework designed to strengthen the cybersecurity and resilience of financial market entities in India. It mandates comprehensive security measures, incident reporting, risk assessments, and governance controls to safeguard critical financial infrastructure from cyber threats.

SOC 2 (Service Organization Control 2)

The SOC 2 (Service Organization Control 2) framework is crucial for service providers managing client data, demonstrating adherence to robust security and privacy controls. It builds client trust by ensuring the safeguarding of sensitive information and upholding high standards in data security and privacy. Compliance is imperative for businesses operating in the digital era, assuring clients of data security.

TISAX v5.1

TISAX v5.1 (Trusted Information Security Assessment Exchange), developed by the German Association of the Automotive Industry (VDA), ensures standardized security evaluations across the automotive supply chain. Compliance is essential for manufacturers and suppliers to show security commitment, gain trust, and access markets, applying to all handling sensitive automotive data.

TISAX v6.0.3

TISAX v6.0.3 (Trusted Information Security Assessment Exchange) is an information security standard specifically tailored for the automotive industry. TISAX compliance is non-negotiable for organizations that wish to be part of the supply chain for major European and international automotive manufacturers (OEMs).

UAE PDPL (Personal Data Protection Law)

The UAE Personal Data Protection Law (PDPL) is a comprehensive federal legislation for personal data protection in the United Arab Emirates. It establishes an integrated, modern framework to safeguard individuals' privacy. Compliance is mandatory for organizations operating in or engaging with the UAE.

UK GDPR

The UK GDPR, or United Kingdom General Data Protection Regulation, is the UK's primary data protection law that establishes rules for the processing of personal data of individuals within the UK. It is crucial for organizations processing personal data within or for individuals in the UK.

US Data Privacy (USDP)

US Data Privacy (USDP) ensures that organizations comply with all applicable US state-level privacy legislations, including CCPA, CDPA, CPA, DPDPA, ICDPA, MTCDPA, NCDPL, NHPA, NJDPL, OCPA, TDPSA, TIPA, UCPA, and VCDPA. It provides a comprehensive solution for organizations that handle Personally Identifiable Information (PII) to comply with various state-level privacy regulations in the US.

Heads Up!

If you follow a custom framework suited to your organizational needs, then we have you covered under Custom Framework.