Home/Frameworks
Frameworks

Every engagement maps to a framework

We speak the language your regulators, auditors and board already use. This reference shows how Resilitech’s services line up against the standards that matter in South Africa and internationally.

South African law & regulation

The statutes and codes you’re accountable to locally
Framework
What it governs
How we help
Data protectionPOPIA
The Protection of Personal Information Act: lawful processing, security safeguards (§19) and mandatory breach notification to the Information Regulator.
Governance codeKing IV & King III
The King Reports on Corporate Governance: technology & information governance (King IV Principle 12) and the board’s oversight of risk, including legacy King III-aligned reviews.
Criminal lawCybercrimes Act
Act 19 of 2020: criminalises cyber offences and creates reporting duties for electronic communications and financial-service providers.

International standards

Globally recognised security and resilience standards
Framework
What it governs
How we help
ISMSISO/IEC 27001
Requirements for an Information Security Management System: the certifiable baseline for managing information risk.
ContinuityISO 22301
Business continuity management: preparing for, responding to and recovering from disruptive incidents.
Risk frameworkNIST CSF 2.0
Govern, Identify, Protect, Detect, Respond and Recover: a flexible model for expressing and improving cyber-risk posture.
ControlsCIS Controls v8.1 & Benchmarks
A prioritised set of Critical Security Controls (v8.1) plus configuration Benchmarks for hardening systems and cloud environments.
AI governanceISO/IEC 42001 & NIST AI RMF
Standards for governing artificial intelligence: AI management systems, risk management and control effectiveness over AI.
PaymentsPCI DSS 4.0
The Payment Card Industry Data Security Standard: protecting cardholder data, including mandatory penetration testing (Req. 11.4).

Governance & attestation

Control frameworks and independent service-org reports
Framework
What it governs
How we help
IT governanceCOBIT
A framework for the governance and management of enterprise IT: aligning IT objectives with business goals and King IV.
Service managementITIL
The IT service-management framework: change, incident, problem and configuration management practices that underpin reliable IT operations.
ERP controlsSAP GRC & Basis
Governance, risk and compliance and Basis controls across the SAP landscape: segregation of duties, configurable controls and ITGCs over FI, MM and HCM.
AttestationSOC 1 (ISAE 3402)
A report on controls at a service organisation relevant to a client’s financial reporting.
AttestationSOC 2
A report on controls relevant to security, availability, processing integrity, confidentiality and privacy.

This is a mapping, not a promise of certification. Resilitech is an independent assurance and testing partner: we prepare you for, and evidence against, these frameworks. Formal certification is issued by accredited certification bodies and registered auditors.

Which framework are you working toward?

Tell us your target, a certification, an audit, or a regulator’s expectation, and we’ll map the shortest credible path to it.