OWASP Top 10Injection, broken access control, authentication failures, misconfiguration, and the rest of the 2021 Top 10.
PCI DSS v4.0Cardholder-data exposure, injection prevention, strong access control, and secure transmission.
HIPAA Security RulePHI handling, access control, audit integrity, and encryption of protected health information.
SOC 2 Type IIAccess control, change management, and the security & availability trust-services criteria.
NIST SP 800-53System and information integrity, identity management, and secure development controls including CI/CD pipeline and supply-chain integrity.
ISO/IEC 27001Information-security controls, access management, and cryptographic protection.
GDPR Article 32Security of processing: PII handling, data minimisation, and encryption of personal data.
EU DORADigital operational resilience for financial entities: ICT protection and prevention, third-party and supply-chain risk, and threat-led resilience testing.
OWASP MASVSMobile application security: secure storage, transport, platform interaction, code quality, and resilience for Android and iOS app packages.
CIS AWS Foundations BenchmarkCloud configuration hardening for AWS: public storage exposure, over-permissive IAM, and internet-exposed services, assessed read-only against a live account.