Frameworks

The framework catalog with ids, display names, and category.

Noru ships 31 frameworks. Each is either regulatory (a law whose requirements you track) or auditable (a standard you can be assessed against); the distinction changes how controls are verified.

Catalog

IdDisplay nameCategoryNotes
soc_2SOC 2auditable
iso_27001ISO 27001auditableEnabled together with iso_27002; the pair is displayed as ISO 27001 and billed as one framework
iso_27002ISO 27002auditableHidden in Settings; follows iso_27001
iso_27017ISO 27017auditableCloud services controls
iso_27018ISO 27018auditablePII in public clouds
iso_22301ISO 22301auditableBusiness continuity
iso_42001ISO 42001auditableAI management systems
gdprGDPRregulatoryIncluded for every organization
ccpaCCPAregulatory
eu_ai_actEU AI Actregulatory
eu_cyber_resilience_actEU Cyber Resilience Actauditable
nis2NIS2auditable
doraDORA (Financial Entities)auditable103 controls
dora_tppDORA (ICT TPP)auditable56 controls; for ICT third-party providers
dora_ctppDORA (Critical ICT TPP)auditable92 controls; for critical ICT third-party providers
psd2PSD2auditable
nist_cybersecurityNIST Cybersecurityauditable
cis_v8CIS V8auditableSkips the verification phase
bsi_c5BSI C5auditable
cyber_essentials_ukCyber Essentials UKauditable
ensENSauditableSpain
mlpsMLPSauditableChina
tx_ramp_l1TX_RAMP L1auditableTexas
fedramp_tailoredFedRAMP Tailoredauditable
fedramp_moderateFedRAMP Moderateauditable
hipaa_securityHIPAA Securityauditable
irapIRAPauditableAustralia
ismapISMAPauditableJapan
masMASauditableSingapore
kfsiKFSIauditableKorea
pci_dss_4_0PCI-DSS 4.0auditable
svensk_elegSvensk e-legitimationauditableSweden

Categories

CategoryFrameworksWhat changes
regulatorygdpr, ccpa, eu_ai_actRequirements are tracked but controls skip the verification phase
auditableEverything elseControls go through verification; cis_v8 is the exception and also skips it

Last updated on