SAMA CSF: What Maturity Level 3 Requires
The SAMA CSF is maturity-scored and level 3 is mandatory. What that requires, how much of ISO 27001 transfers, and why suppliers end up in scope.
Practical cybersecurity and compliance writing. No vendor pitches, no recycled threat reports.
The SAMA CSF is maturity-scored and level 3 is mandatory. What that requires, how much of ISO 27001 transfers, and why suppliers end up in scope.
The DSP Toolkit now runs on the Cyber Assessment Framework for large NHS organisations. What changed, who completes which version, and what suppliers are asked.
GovAssure assesses government departments against the NCSC Cyber Assessment Framework. The five stages, what the CAF actually is, and why it reaches suppliers.
The Digital Personal Data Protection Act reaches organisations with no presence in India. What it requires, and what changes if you already comply with GDPR.
The EU AI Act applies to providers outside the EU and phases in by date. What the risk tiers mean, what high-risk systems must do, and where ISO 42001 fits.
TISAX is effectively mandatory to supply the German automotive industry. What the assessment levels mean and how it differs from ISO 27001.
Singapore's PDPA requires a named DPO whose details are public, and breach notification within three days. What it demands and how it compares to GDPR.
HIPAA reaches overseas suppliers through Business Associate Agreements. What the Security Rule requires, what a BAA commits you to, and how SOC 2 relates.
They overlap heavily but answer different questions. How to choose, and what holding one buys you towards the other.
One is a five-control technical baseline. The other is a management system certification. When each is enough, and why one says little about the other.
If you run a GDPR programme and are entering India, most of the machinery transfers. The differences are lawful basis, consent, transfers and children.
What Australian buyers ask for: Essential Eight maturity levels, the Privacy Principles, and the notifiable breach scheme.
What the Gulf markets require. Saudi NCA Essential Cybersecurity Controls, UAE Information Assurance Standards, and how much of ISO 27001 carries over.
How the dark web works, what credential dumps and ransomware forums mean for your startup, and how to evaluate monitoring tools.