Let’s talk

Cyvora / Frameworks

Cyber security frameworks.
Practical compliance support.

Framework alignment, compliance preparation and practical implementation support for Australian organisations.

Choose the right scope

One environment.
Different obligations.

Cyvora can assist with gap assessments, evidence reviews, policies, control implementation plans and remediation roadmaps. Select the framework or standard according to your industry, customer requirements, contractual commitments and business risks.

Some frameworks are voluntary; some standards or regulatory requirements apply only in particular circumstances. Applicability must be confirmed. Assessments support preparation and improvement; they do not guarantee legal compliance, regulatory approval or certification.

Australian mitigation baseline

ASD Essential Eight

Use the maturity model to assess eight baseline mitigation strategies and plan improvements appropriate to the organisation’s risk and environment.

How Cyvora can assist

Maturity assessment, evidence review and a prioritised uplift roadmap.

Official ASD Essential Eight guidance

Australian security control framework

ASD Information Security Manual (ISM)

Apply a risk-based approach to selecting and assessing controls for information technology and operational technology systems.

How Cyvora can assist

Control mapping, security documentation and gap assessment within the agreed system scope.

Official ASD Information Security Manual (ISM) guidance

Information security management standard

ISO/IEC 27001:2022

Develop and improve an information security management system (ISMS) with defined scope, risk treatment and ongoing review.

How Cyvora can assist

Readiness assessment, risk registers, policies and implementation planning. Certification is performed by an independent certification body.

Official ISO/IEC 27001:2022 guidance

Cyber risk management framework

NIST Cybersecurity Framework 2.0

Organise cyber risk outcomes across Govern, Identify, Protect, Detect, Respond and Recover.

How Cyvora can assist

Current and target profiles, gap analysis and a business-aligned roadmap.

Official NIST Cybersecurity Framework 2.0 guidance

Prioritised safeguards

CIS Controls v8.1

Use prioritised safeguards and implementation groups to organise practical security improvements.

How Cyvora can assist

Safeguard review, implementation-group scoping and remediation priorities.

Official CIS Controls v8.1 guidance

Payment-card security standard

PCI DSS v4.0.1

Support organisations with payment-card responsibilities by reviewing the relevant cardholder-data environment and control requirements.

How Cyvora can assist

Scope and gap analysis, evidence preparation and remediation planning. Validation requirements depend on the payment arrangements; no QSA status is represented.

Official PCI DSS v4.0.1 guidance

Prudential information security requirements

APRA CPS 234

Support applicable APRA-regulated entities with information-security capability, controls, testing and governance aligned to their obligations.

How Cyvora can assist

Control and evidence reviews, accountability mapping and improvement planning. Applicability must be confirmed for the entity.

Official APRA CPS 234 guidance

AI management system standard

ISO/IEC 42001:2023

Structure AI governance, responsibilities and risk-management practices within an AI management system.

How Cyvora can assist

AI governance gap assessment, policy support and implementation planning. Independent certification is separate.

Official ISO/IEC 42001:2023 guidance

Voluntary AI risk framework

NIST AI Risk Management Framework

Use Govern, Map, Measure and Manage to structure consideration of risks associated with AI systems.

How Cyvora can assist

Use-case mapping, AI risk assessment and recommended governance controls.

Official NIST AI Risk Management Framework guidance

Your next step

Agree the standard.
Then assess the gaps.

Start with the applicable version, system boundaries and required outcome. Agree an evidence plan, prioritise remediation and clarify who performs any independent audit or validation.

Framework references checked on 6 October 2026. Standards and guidance change; confirm the applicable edition when scoping the engagement.