Standards

Frameworks we commonly
work with.

Relevance depends on the organization's operations, clients, contracts, and jurisdictions.

GDPR

EU General Data Protection Regulation

May apply to organizations handling personal data of EU residents, regardless of where the organization is based.

Often relevant for hospitality, tourism, and education businesses serving European customers.

Official Resource →
Indonesia PDP

Personal Data Protection Law (2022)

Indonesia's national data protection law, commonly relevant to organizations operating in or serving customers in Indonesia.

Closely aligned with GDPR in structure, which can simplify dual-compliance efforts.

Reference Summary →
NIST CSF 2.0

Cybersecurity Framework

A widely used framework for organizing cybersecurity governance and risk management, applicable across most industries.

Commonly used as a baseline regardless of specific regulatory obligations.

Official Resource →
NIST SP 800-53

Security & Privacy Controls

A detailed controls catalog often used in federal and high-assurance environments, and increasingly referenced in the private sector.

May be relevant for organizations with government-adjacent contracts or partners.

Official Resource →
NIST SP 800-37

Risk Management Framework

A structured process for managing security and privacy risk across an organization's systems.

Often paired with SP 800-53 for organizations needing a formal risk management process.

Official Resource →
ISO 27001

Information Security Management

An international standard for establishing and maintaining an information security management system.

Increasingly expected by enterprise clients and partners as a baseline trust signal.

Official Resource →
HIPAA

Health Insurance Portability & Accountability Act

US federal requirements that may apply to organizations handling protected health information.

Relevant for wellness providers and US-connected organizations with health data exposure.

Official Resource →
CMMC

Cybersecurity Maturity Model Certification

A certification framework commonly relevant to organizations contracting with the US Department of Defense.

May apply to organizations in or entering the defense contracting supply chain.

Official Resource →
SOC 2

Service Organization Control 2

An attestation standard often requested by enterprise clients evaluating a vendor's security practices.

Commonly relevant for technology and SaaS-adjacent organizations seeking enterprise clients.

Official Resource →

Framework applicability depends on each organization's specific operations, clients, contracts, and jurisdictions. This page is provided for general orientation and does not constitute legal advice. A consultation can help determine which frameworks are relevant to your situation.