Choosing the right compliance frameworks
CybAura supports multiple frameworks out of the box, including GDPR, ISO 27001, SOC 2, HIPAA, NIST CSF, and DORA. This guide helps you choose the right ones and explains how CybAura reduces duplicated effort across them.
Which frameworks apply to you?
Your DNA profile already suggests relevant frameworks based on your industry and jurisdiction. As a rule of thumb:
- GDPR — if you process personal data of people in the UK/EU.
- ISO 27001 — a broad, internationally recognised security management standard; often requested by enterprise customers.
- SOC 2 — common for B2B SaaS selling into the US market.
- HIPAA — if you handle US healthcare data.
- DORA — for financial-sector entities operating in the EU.
- NIST CSF — a flexible control catalogue, useful as a baseline.
Start with the one or two frameworks your customers or regulators actually require. You can add more at any time.
Activating a framework
Go to Compliance → Frameworks and toggle a framework on. CybAura maps the controls to your existing posture and shows your current coverage and gaps immediately.
Cross-framework mapping
The biggest time-saver is that frameworks don't exist in isolation. When you implement a control for one framework, CybAura automatically credits the equivalent controls in others. For example, implementing access-control evidence for ISO 27001 also progresses the related SOC 2 criteria and GDPR articles.
This means one action can close gaps across several frameworks at once.
Evidence and ownership
Every control has an owner, a due date, and an evidence trail. Assign owners under each control and upload evidence (documents, screenshots, or links). When audit time comes, your evidence is already organised by framework.
Tip: Don't activate every framework on day one. Each one adds controls to track. Begin with what's required, then expand as your compliance programme matures.