Skip to main content

Glossary category

Standards & Frameworks

Plain-language definitions for the standards and frameworks that show up in compliance work: ISO 27001, NIS2, SOC 2, GDPR, Annex A.

Standards and frameworks are what auditors, regulators, and customers point at when they want to see that a security programme is real. ISO 27001 is the international standard for an information security management system. NIS2 is the EU directive extending cybersecurity obligations across critical sectors. SOC 2 is the trust services framework large US buyers expect from their vendors. GDPR is the EU's data protection regulation. Annex A is the catalogue of controls inside ISO 27001 itself. Most European SMEs end up dealing with several of these, often at the same time and on someone else's deadline.

Terms in this category.

5 entries.