Governance. Risk. Compliance. Cybersecurity.
Standards & Regulations

Every framework that matters to regulated enterprises — covered end to end.

MAST consultants are certified across the global standards and regional regulations our clients are measured against. Browse the full list, or talk to us about a specific obligation.

Rows of compliance binders representing ISO, SOC, PCI, GDPR and regional regulatory frameworks covered by MAST.
Core standards we implement & certify
ISO/IEC 20000-1
IT Service Management
IT Service Management
Scope & ApplicabilityControls & RequirementsImplementation RoadmapAudit & CertificationFAQs
ISO 22301
Business Continuity
Business Continuity
Scope & ApplicabilityControls & RequirementsImplementation RoadmapAudit & CertificationFAQs
ISO/IEC 27001
Information Security
Info & Cyber Security
Scope & ApplicabilityControls & RequirementsImplementation RoadmapAudit & CertificationFAQs
ISO/IEC 27701
Privacy Information
Data Privacy & Protection
Scope & ApplicabilityControls & RequirementsImplementation RoadmapAudit & CertificationFAQs
ISO/IEC 42001
AI Management System
AI Governance
Scope & ApplicabilityControls & RequirementsImplementation RoadmapAudit & CertificationFAQs
SOC 2 Type 1
SOC 2 Type 1 (Design of Controls)
Assurance & Attestation
Scope & ApplicabilityControls & RequirementsImplementation RoadmapAudit & CertificationFAQs
SOC 2 Type 2
SOC 2 Type 2 (Operating Effectiveness)
Assurance & Attestation
Scope & ApplicabilityControls & RequirementsImplementation RoadmapAudit & CertificationFAQs
UAE IAF
UAE Information Assurance Framework
UAE Regulatory
Scope & ApplicabilityControls & RequirementsImplementation RoadmapAudit & CertificationFAQs
ADHICS v2
Abu Dhabi Healthcare Information & Cyber Security Standard v2
Healthcare
Scope & ApplicabilityControls & RequirementsImplementation RoadmapAudit & CertificationFAQs
SAMA CSF
SAMA Cyber Security Framework
KSA Regulatory
Scope & ApplicabilityControls & RequirementsImplementation RoadmapAudit & CertificationFAQs
NCA ECC
NCA Essential Cybersecurity Controls
KSA Regulatory
Scope & ApplicabilityControls & RequirementsImplementation RoadmapAudit & CertificationFAQs
NCEMA 7000
NCEMA AE/SCNS/NCEMA 7000 Business Continuity
UAE Regulatory
Scope & ApplicabilityControls & RequirementsImplementation RoadmapAudit & CertificationFAQs
UAE PDPL
UAE Personal Data Protection Law
Data Privacy & Protection
Scope & ApplicabilityControls & RequirementsImplementation RoadmapAudit & CertificationFAQs
KSA PDPL
KSA Personal Data Protection Law
Data Privacy & Protection
Scope & ApplicabilityControls & RequirementsImplementation RoadmapAudit & CertificationFAQs
GDPR
General Data Protection Regulation
Data Privacy & Protection
Scope & ApplicabilityControls & RequirementsImplementation RoadmapAudit & CertificationFAQs
HIPAA
Health Insurance Portability and Accountability Act
Healthcare
Scope & ApplicabilityControls & RequirementsImplementation RoadmapAudit & CertificationFAQs
Deep dive — every standard, four layers

Regional & sector regulations (50)
50 results

GCC(22)

Regulation / StandardDomain
ADGM Data Protection Regulations
ADGM Financial Services Regulatory Authority
Data Privacy & Protection
CBUAE AI / ML Guidance
Central Bank of the UAE
AI Governance
CBUAE Business Continuity Standards
Central Bank of the UAE
Business Continuity
CBUAE Information Security Regulation
Central Bank of the UAE
Information Security
CBUAE IT Risk Regulation
Central Bank of the UAE
Financial Services
CBUAE Outsourcing Regulation
Central Bank of the UAE
Financial Services
CST Cloud Computing Regulatory Framework
Communications, Space & Technology Commission
Cloud Security
DESC Cloud Security Standard
Dubai Electronic Security Center
Cloud Security
DIFC Data Protection Law
DIFC Authority
Data Privacy & Protection
Dubai DESC Information Security Regulation
Dubai Electronic Security Center
Information Security
KSA Personal Data Protection Law
Saudi Data & AI Authority
Data Privacy & Protection
NCA Cloud Cybersecurity Controls (CCC-1)
National Cybersecurity Authority
Cloud Security
NCA Essential Cybersecurity Controls (ECC-1)
National Cybersecurity Authority
Cybersecurity
NCA OT Cybersecurity Controls (OTCC-1)
National Cybersecurity Authority
OT / ICS Security
NCEMA 7000 — Business Continuity Standard
National Emergency Crisis & Disasters Management Authority
Business Continuity
SAMA Business Continuity Framework
Saudi Central Bank (SAMA)
Business Continuity
SAMA Cybersecurity Framework
Saudi Central Bank (SAMA)
Financial Services
SAMA Technology Risk Framework
Saudi Central Bank (SAMA)
Risk Management
SDAIA AI Ethics Principles
Saudi Data & AI Authority
AI Governance
UAE Information Assurance Framework
Telecom & Digital Government Regulatory Authority
Cybersecurity
UAE IoT Security Policy
Telecom & Digital Government Regulatory Authority
Cybersecurity
UAE Personal Data Protection Law
UAE Data Office
Data Privacy & Protection

Global(19)

Regulation / StandardDomain
CIS Controls
Center for Internet Security
Cybersecurity
COBIT
ISACA (COBIT)
IT Service Management
GDPR — EU General Data Protection Regulation
European Commission (GDPR)
Data Privacy & Protection
IEC 62443 — OT/ICS Security
International Electrotechnical Commission
OT / ICS Security
ISO 22301 — Business Continuity Management
International Organization for Standardization
Business Continuity
ISO 31000 — Risk Management
International Organization for Standardization
Risk Management
ISO/IEC 20000-1 — IT Service Management
International Organization for Standardization
IT Service Management
ISO/IEC 27001 — Information Security Management
International Organization for Standardization
Information Security
ISO/IEC 27002 — Information Security Controls
International Organization for Standardization
Information Security
ISO/IEC 27005 — Information Security Risk Management
International Organization for Standardization
Risk Management
ISO/IEC 27701 — Privacy Information Management
International Organization for Standardization
Data Privacy & Protection
ISO/IEC 42001 — AI Management System
International Organization for Standardization
AI Governance
NIST AI Risk Management Framework
National Institute of Standards and Technology
AI Governance
NIST Cybersecurity Framework
National Institute of Standards and Technology
Cybersecurity
PCI DSS
PCI Security Standards Council
Financial Services
SOC 1 Type 1
American Institute of CPAs (SOC reports)
Financial Services
SOC 1 Type 2
American Institute of CPAs (SOC reports)
Financial Services
SOC 2 Type 1
American Institute of CPAs (SOC reports)
Information Security
SOC 2 Type 2
American Institute of CPAs (SOC reports)
Information Security

South Asia(9)

Regulation / StandardDomain
Aadhaar Data Protection Requirements
Unique Identification Authority of India
Data Privacy & Protection
CERT-In Directions 2022
Indian Computer Emergency Response Team
Cybersecurity
Digital Personal Data Protection Act 2023
Ministry of Electronics and Information Technology
Data Privacy & Protection
IRDAI Cybersecurity Guidelines
Insurance Regulatory and Development Authority of India
Financial Services
MeitY Responsible AI Guidance
Ministry of Electronics and Information Technology
AI Governance
RBI Cybersecurity Framework
Reserve Bank of India
Financial Services
RBI Digital Payment Security Controls
Reserve Bank of India
Financial Services
RBI Outsourcing Guidelines
Reserve Bank of India
Financial Services
SEBI Cybersecurity Framework
Securities and Exchange Board of India
Financial Services
Deep dive — every regulation, four layers

Each regulation below is summarised across four layers — context and applicability, scope and controls, our delivery approach, and the business impact. Designed to give buyers, boards, auditors and search engines a complete, structured answer in one place.

Frequently asked questions