The frameworks you need
Lavawall® covers the frameworks your clients are most often asked about, including:Security Frameworks
- Australia Essential Eight
- C-SOX (NI 52-109 for Canadian companies listed on the TSX or TSXV)
- CIS Critical Security Controls v8.1 (IG1, IG2 and IG3)
- CMMC 2.0 Levels 1, 2 and 3
- Canadian Centre for Cyber Security baseline controls
- Canadian Program for Cyber Security Certification (CPCSC)
- Canadian Cyber Essentials
- EU Cyber Resilience Act (manufacturers and importers of products with digital elements in the EU)
- EU NIS2 Directive (EU) 2022/2555
- ISO/IEC 27001
- NIST Cybersecurity Framework 2.0
- NIST SP 800-171
- Ontario Cyber Security Framework (public sector)
- Sarbanes-Oxley (SOX) for US publicly traded companies
- SOC 2 Type 1 and Type 2 (Security, Availability, Processing Integrity, Confidentiality and Privacy)
- UK Cyber Essentials
- CJIS Security Policy 6.1 (FBI Criminal Justice Information Services), alongside the pre-modernization 5.9.5 requirements that remain sanctionable
- NIST SP 800-53 Rev. 5 (Low, Moderate and High baselines)
- EU AI Act
- ISO/IEC 42001 (AI management systems)
- NIST AI Risk Management Framework (AI RMF)
- Alberta PIPA (Personal Information Protection Act)
- Alberta POPA (Protection of Privacy Act, for public bodies including municipalities)
- Australian Privacy Act
- BC PIPA (British Columbia Personal Information Protection Act)
- Quebec Law 25
- Canada PIPEDA
- California CCPA/CPRA
- EU GDPR (General Data Protection Regulation)
- UK GDPR and Data Protection Act 2018
- PCI DSS v4.0.1 SAQ A (the website sends card entry to the payment provider in a fully outsourced iframe or hosted page)
- PCI DSS v4.0.1 SAQ A-EP (the website hosts the payment form or scripts, and card data goes straight from the browser to the payment processor)
- PCI DSS v4.0.1 SAQ B (imprint machines or standalone terminals that dial out)
- PCI DSS v4.0.1 SAQ B-IP (standalone payment terminals connected over an IP network)
- PCI DSS v4.0.1 SAQ C (a payment application or POS system connected to the internet)
- PCI DSS v4.0.1 SAQ C-VT (card numbers keyed into a web-based virtual terminal)
- PCI DSS v4.0.1 SAQ D (you store, process or transmit card numbers)
- HIPAA Security Rule
- HITRUST (Health Information Trust Alliance)
- Alberta Health Information Act (AB HIA)
- British Columbia health information privacy (BC HIA)
- Ontario PHIPA (Personal Health Information Protection Act)
- CIRO (Canadian Investment Regulatory Organization) cybersecurity requirements, including incident reporting under IDPC Rule 3703
- CSA Staff Notice 33-322 (cybersecurity for registered firms)
- DORA (EU Digital Operational Resilience Act for EU financial entities)
- FINTRAC / PCMLTFA (Financial Transactions and Reports Analysis Centre of Canada; Proceeds of Crime (Money Laundering) and Terrorist Financing Act)
- FTC Safeguards Rule (US Federal Trade Commission rule for auto dealers, mortgage brokers, tax preparers, payday lenders and other non-bank financial institutions)
- GLBA (US Gramm-Leach-Bliley Act of 1999)
- NYDFS 23 NYCRR Part 500 (New York Department of Financial Services)
- NERC CIP (North American Electric Reliability Corporation Critical Infrastructure Protection)
Unified Controls
In today’s world, most companies need to comply with more than one framework. Traditional GRC tools require multiple questionnaires and evidence for each.Lavawall® was designed by an auditor who founded an MSP, so it avoids this work and makes life really simple by only asking questions once.
Answers you didn’t know you had
Lavawall® knows what’s on your computers, your Google Workspace apps, your Microsoft 365 and Azure Apps, your network, everything on your domain, and even your Active Directory.We use that information to fill in your GRC information and provide evidence based on what we discover. If we can see 100% coverage, we'll suggest that you mark the control as implemented. In other cases, we may suggest that it is in progress.
Don’t waste time writing policies from scratch
The most time-consuming part of any compliance effort is writing policies and gathering evidence.Lavawall® comes with tonnes of built-in templates for each required control, recommends the best options, and makes them easy to fill in.
The templates have built-in variables to make your life super easy. Just fill in the blanks and Lavawall® does the rest.
If you have any questions or need further assistance, feel free to reach out through our chat, phone or email on our contact page!