Rules
The rule sets behind the schedule
The core list for each jurisdiction, the add-ons the applicant ticks, the privacy lines and the optional lens, each with when it applies and the edition held.
| Rule set | Role | Where | When it applies |
|---|---|---|---|
| ACSC Essential Eight | core | Australia | The core list for Australia. ASD publishes the Essential Eight and its maturity levels; for a private business it is a baseline, not a law, and the target maturity level is the underwriter's choice. |
| Australian Privacy Principles (APPs) | privacy | Australia | Only when the Privacy Act 1988 applies to the business: for example annual turnover over AUD 3 million, a health service provider, or another case the Act lists. |
| Notifiable Data Breaches Scheme (Australia) | privacy | Australia | Only when the Privacy Act 1988 applies to the business (the entities APP 11 binds). |
| CIS Controls v8 | core | United States | Part of the core list for the United States. A consensus control set, not a law, cited by safeguard number. |
| ISO 27001:2022 | lens | Australia, United States, United Kingdom | An optional lens in any jurisdiction: shown as "also cited" beside a gap, never a gap on its own. |
| NIST Cybersecurity Framework 2.0 | core | United States | Part of the core list for the United States. A voluntary framework of outcomes, cited at subcategory level. |
| FTC GLBA Safeguards Rule (16 CFR Part 314) | addon | United States | Financial institutions under FTC jurisdiction, for example tax preparers, mortgage brokers and auto dealers that arrange financing. |
| HIPAA Security Rule | addon | United States | HIPAA covered entities (health plans, health care clearinghouses, health care providers that transmit health information electronically) and their business associates. |
| NY DFS 23 NYCRR 500 | addon | United States | Entities licensed by the New York Department of Financial Services. Section 500.19 sets limited exemptions for smaller covered entities: whether one applies is a question for the business, and this page never decides it. |
| PCI DSS 4.0 | addon | United States, Australia, United Kingdom | Any business that stores, processes or transmits payment card data, in any of the three jurisdictions. |
| UK Cyber Essentials | core | United Kingdom | The core list for the United Kingdom: the government-backed baseline scheme. The test steps of Cyber Essentials Plus are not used. |
Not in this product: the SEC cyber disclosure rule and SOX 404 (both bind public companies), the test steps of Cyber Essentials Plus, and any rule that binds the insurer rather than the applicant.