TrustDyne maps every finding against the frameworks below. This is a plain-language reference for what each one actually covers, not a substitute for the framework text itself or legal advice on which ones apply to your product.
EU regulation setting risk-based obligations for AI systems, including transparency, risk management, and conformity assessment for high-risk AI.
International standard specifying requirements for an AI management system (AIMS): governance, risk, and lifecycle controls for organizations that develop or use AI.
NIST's voluntary framework for managing risk in AI systems across the govern, map, measure, and manage functions.
AICPA auditing standard evaluating a service organization's controls across security, availability, confidentiality, processing integrity, and privacy.
Application Security Verification Standard: a checklist of security requirements for designing, testing, and verifying web application security.
OWASP's list of the most critical security risks specific to large language model applications, such as prompt injection and insecure output handling.
Secure Software Development Framework (NIST SP 800-218): guidance for building secure practices into the software development lifecycle.
Common Weakness Enumeration: a community-maintained taxonomy of software and hardware weakness types used to classify vulnerabilities.
UK Product Security and Telecommunications Infrastructure Act: baseline security requirements, including a ban on default passwords, for consumer connectable products sold in the UK.
EU Cyber Resilience Act: cybersecurity requirements for hardware and software products with digital elements placed on the EU market.
International standard series for the security of industrial automation and control systems (IACS/OT).
FDA's premarket cybersecurity guidance for medical devices, requiring documented security risk management before market clearance.
UN regulation requiring vehicle manufacturers to implement a Cyber Security Management System (CSMS) across the vehicle lifecycle.
Mobile Application Security Verification Standard: baseline security requirements for mobile apps covering storage, cryptography, authentication, and network communication.
EU Digital Operational Resilience Act: operational resilience, incident reporting, and third-party risk requirements for financial entities and their ICT providers.
Payment Card Industry Data Security Standard: security requirements for organizations that store, process, or transmit cardholder data.
UK Financial Conduct Authority's Systems and Controls sourcebook, setting operational resilience and risk management expectations for regulated firms.
EU Revised Payment Services Directive: mandates strong customer authentication and secure communication for payment service providers.
US Health Insurance Portability and Accountability Act: security and privacy requirements for protected health information.
NHS Digital Technology Assessment Criteria: UK baseline standard covering clinical safety, data protection, technical security, and interoperability for digital health products.
FDA cybersecurity requirements for connected medical devices across their lifecycle, including postmarket vulnerability management.
EU Medical Device Regulation: safety, performance, and cybersecurity requirements for medical devices sold in the EU.
International standard for information security management systems (ISMS), covering risk assessment and a broad set of security controls.