IAM compliance frameworks — the IAM controls each framework actually requires.
Practitioner deep dives into the IAM-relevant provisions of NIST 800-53, ISO 27001:2022, GDPR, NYDFS Part 500, CMMC Level 2, and NIS2. Each covers controls + evidence patterns + common findings + penalties.
NIST 800-53 IAM
The IAM-relevant controls in NIST SP 800-53 Rev. 5 — Identification & Authentication, Access Control, and Audit families — with evidence patterns auditors actually accept.
13 controls covered · NIST
ISO 27001 IAM
The IAM-relevant Annex A controls in ISO/IEC 27001:2022 + ISO 27002 implementation guidance — with practical evidence patterns for ISMS auditors.
10 controls covered · ISO
GDPR IAM
How GDPR's Articles 25 (data protection by design), 32 (security of processing), and 5 (storage limitation) translate to specific IAM controls in 2026.
8 controls covered · European
NYDFS Part 500 IAM
New York DFS Part 500 cybersecurity regulation IAM provisions — including the 2023 second amendment + phased deadlines through November 2025.
7 controls covered · New
CMMC Level 2 IAM
IAM requirements at CMMC Level 2 — built on NIST SP 800-171 Rev 2 + the 2024 final rule that activated CMMC for defense contractors.
11 controls covered · US
NIS2 IAM
EU NIS2 Directive IAM provisions — Article 21 measures, the MFA + access-control requirements, and the patchy member-state transposition through 2025.
7 controls covered · European