Regulatory frameworks, decoded for your enterprise
Open Security Alliance is a trusted compliance advisory partner across India and global mandates. Explore the frameworks we implement, audit, and defend — from RBI and SEBI CSCRF to ISO 27001, PCI DSS, HIPAA, GDPR, SOC 2, and NIST CSF 2.0.
RBI Cyber Security Framework
Reserve Bank of India cyber resilience mandates for banks, NBFCs, payment operators and PAPG-regulated entities.
SEBI Cyber Security & Cyber Resilience Framework
Cyber Security and Cyber Resilience Framework for SEBI-regulated intermediaries — MIIs, brokers, mutual funds, portfolio managers.
Digital Personal Data Protection Act
India's comprehensive personal data protection law governing collection, processing, cross-border transfer, and consent management.
ISO/IEC 27001:2022
International standard for Information Security Management Systems (ISMS) — the de-facto enterprise security certification.
CERT-In Directions
Indian Computer Emergency Response Team directions on incident reporting, log retention, KYC for VPN/cloud, and cyber hygiene.
PCI DSS 4.0
Payment Card Industry Data Security Standard — mandatory for organisations that store, process, or transmit cardholder data.
HIPAA Security Rule
Health Insurance Portability and Accountability Act — protects electronic Protected Health Information (ePHI).
GDPR
EU General Data Protection Regulation — extraterritorial data protection law with strict consent, DPIA and breach obligations.
SOC 2 Type II
AICPA System and Organization Controls report on Security, Availability, Confidentiality, Processing Integrity, and Privacy.
NIST Cybersecurity Framework 2.0
NIST Cybersecurity Framework 2.0 — the industry-standard voluntary framework for managing cyber risk.
Need a compliance readiness assessment?
Our compliance desk delivers end-to-end programs across all frameworks above — gap analysis, control design, evidence packs, and audit representation.