SD Elements Datasheet v2026.5.2

Updated May 2026

The SD Elements v2026 platform and its comprehensive content library are built for managing security, privacy, and compliance requirements for applications across many industries and within almost any development environment.

For additional information, please visit the SD Elements website.

Licensing Model

Annual Subscription based on the number of projects being managed within SD Elements.

Deployment Options

Dedicated SaaS, Shared Cloud SaaS, On-Premise Deployment

Single Sign-On (SSO)

LDAP/Active Directory, SAML, Trusted Authentication

Expert Security and Compliance Content Library

Threat Information

  • MITRE CAPEC

  • MITRE ATT&CK

  • MITRE ATLAS

  • MITRE EMB3D

  • STRIDE Mapping

Internet of Things (IoT)

  • Consumer IoT: ETSI EN 303 645

  • Authentication and Access Control

  • Availability and Systems DoS Protection

  • Communication Protocols

    • Bluetooth, HyperCat, MQTT, Pub/Sub, Thread, WiFi, XMPP, ZigBee, AMQP, QUIC & HTTP/2

    • Server Message Block Protocol (SMB)

  • RFID Solutions

  • OWASP IoT Top 10 (OWASP IoT Attack Surface [Archived])

AI, ML, and LLMs*

  • NIST AI Risk Management Framework (RMF)

  • OWASP LLM Top 10 2025 (Large Language Models)

  • Agentic AI: OWASP Agentic AI Threats and Mitigations

  • MITRE ATLAS

  • CSA MAESTRO Threat Modeling Framework

  • Model Context Protocol (MCP) Clients and Servers

  • LLM-based Code Generation Security

  • OWASP ML Security Top Ten and ENISA Security ML Algorithms

  • EU AI Act

  • AI/Data Engineering Cloud Services: AWS Sagemaker, AWS Bedrock, AWS Lake Formation, Azure OpenAI, Azure Data Lake Storage, GCP Vertex AI

  • AI Use Cases: Fine-tuning, RAG, Use of vector databases

  • Implementation guidelines for AI Tools (Tensorflow, Pytorch, etc.)

*Artificial Intelligence (AI), Machine Learning (ML) and Large Language Models (LLMs)

Automotive Cybersecurity

  • Connected cars' communication protocols, secure updates, privacy, access control, and encryption requirements.

  • UNECE WP29/R155

  • ISO/SAE 21434:2021 Road vehicles — Cybersecurity engineering

Blockchain and Cryptocurrency

  • Blockchain and Smart Contracts

Healthcare and Medical Devices

  • HIPAA

  • Germany BSI TR-03161 Security requirements for eHealth applications

  • FDA pre- and post-market controls for medical devices

  • FCC consumer IoT product Cyber Trust mark controls

  • Health-data hosting requirements under France’s Hébergeur de Données de Santé (HDS) framework

ERP Solutions

  • SAP/ABAP

  • SAP Security Baseline Template 2.6

  • Host Operating System for SAP Servers

  • SAP ABAP Application Server

  • SAP Java Application Server

  • SAP HANA

  • SAP Graphical User Interface (GUI)

  • SAP Business Technology Platform (BTP)

  • SAP Web Dispatcher

Regulatory and Compliance

  • ANSI/ISA/IEC 62443-3-3

  • ANSI/ISA/IEC 62443-4-1

  • ANSI/ISA/IEC 62443-4-2

  • ANSSI/France Digital Signature and Encryption Requirements

  • Australia Information Security Manual (ISM)

  • BACEN (Banco Central do Brasil) Cybersecurity Regulations (CMN Resolution No. 4893/2021, BCB Resolution No. 85/2021, Joint Resolution No. 6, 2023) and Securities and Exchange Commission of Brazil (CVM) Report based on Resolution 35/2021

  • Chinese Cybersecurity Law

  • CNSSI 1253

  • CSA Cloud Controls Matrix (CCM) v3 & v4

  • Cybersecurity Maturity Model Certification (CMMC) [v1 and v2]

  • DIACAP

  • EN 18031-1 to 3 (EU-Radio Equipment)

  • European Banking Authority (EBA) Security of Internet Payments

  • EU Cyber Resilience Act (CRA)

  • EU Data Act

  • EU Digital Operational Resilience Act (DORA)

  • EU Network and Information Security 2 (NIS2) Directive

  • FedRAMP

  • GLBA

  • ISASecure CSA 311

  • ISASecure SSA 311

  • ISO 27001:2013 (SOX)

  • ISO 27001:2022 (SOX)

  • MAS-TRMG

  • NIST Cybersecurity Framework

  • NYDFS

Privacy Related:

* ISO 27701 * Anti-Spam Guidelines/CASL * Brazilian LGPD * California Consumer Privacy Act (CCPA) * California Online Privacy Protection Act (CalOPPA) * California Privacy Rights Act (CPRA) (California Civil Code) * CNIL Cookie Guidelines * COPPA * EU Privacy and Cookie Laws * GAPP * GDPR (& /UK) * New York Shield Act (S5575B) * India Digital Personal Data Protection Act (DPDPA) * NIST 800-53 Privacy Controls * PA-DSS 3.2 * PCI DSS 4.0.1, PCI DSS 3.2 * Personal Information Protection Law (PIPL) - China’s Privacy Law * PIPEDA/ECPA/CAN-SPAM * SOC2 (Based on AICPA TrustServices Criteria) * U.S. states' privacy law tracker (California, Colorado, Connecticut, Delaware, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah, and Virginia)

Industry Standards

  • Web Content Accessibility Guidelines (WCAG)

  • ASD-STIG r6

  • ASVS 4.0

  • CWE Top 25, 2024

  • CWE 4.16

  • CVSS 3 and 4 (Custom Importable Bundle)

  • MDS2-2013

  • OWASP Top 10 2017, 2021, and 2025

  • OWASP API Top 10, 2023

  • OWASP Top 10 Privacy Risks v2.0

  • OWASP Low-Code/No-Code Top 10

  • OWASP SAMM

  • Secure Controls Framework (SCF)

  • PCI SSF: SSLC (1.1) & SSS (1.2.1)

  • DISA Control Correlation Identifier (CCI) Framework

* NIST 800-147/800-155 BIOS/FW * NIST 800-171 Non-Federal Systems * NIST 800-53r4 * NIST 800-53r5 * DoD Zero Trust Overlay for NIST 800-53 Controls * NIST 800-82 Industrial Control Systems * NIST 800-95 Web Services * NIST 800-190 Containers * NIST 800-218 SSDF * NISTIR 8397 (Verification Req.) * EO14028: NIST Critical Software Req. * Consumer IoT: ETSI EN 303 645

Application Development and Web Services

  • Low-Code/No-Code

  • Microsoft Power Pages

  • Microsoft Power Platform

  • Angular

  • Apex for Force.com

  • C#/ASP.net (.NET 8, WCF, and Core 3)

  • Django (Python)

  • GoLang

  • HTML5 and CSP

  • Java Libraries and Frameworks: ESAPI, Struts, Spring, Apache Wicket, Hibernate

  • Java SE / EE

  • JavaScript

  • TypeScript

* JSP, Servlets * NGINX * Node.js * Vue.js * NoSQL / SQL * PL/SQL * OAuth and OIDC * PHP * Python * React * Ruby on Rails * Rust * SOAP / REST * GraphQL * Web servers: Apache and IIS * XML and YAML Security

Operational and Deployment Security

  • Process-level Cloud Security Guidelines

  • Provider-agnostic Story-driven Cloud Content

  • Amazon Web Services (AWS)(Foundations and 3-Tier CIS Benchmarks)[AWS Services: AMI, API Gateway, Aurora, Auto Scaling, CloudFront, CloudWatch, Cognito, Config, DynamoDB, EBS, EC2, ECS, EKS, ELB, IAM, Kinesis Data Firehose, Kinesis Data Streams, KMS, Lambda, RDS, Route53, S3, SageMaker, SNS, SQS, VPC, WAF, Certificate Manager, CloudFormation, Elastic Container Registry, Elastic File System, ElastiCache, Managed Streaming for Apache Kafka, MQ, OpenSearch Service, RedShift, Secrets Manager, Simple Email Service, Step Functions, Systems Manager, Transfer Family, AWS CodePipeline, CodeArtifact, Elasticache, X-Ray, Athena, Backup, DataSync, Direct Connect, EventBridge, Fargate, AWS FSx, GuardDuty, Inspector, Neptune, Rekognition]

  • Google Cloud Platform [Google Cloud Services: BigQuery, Cloud Audit Logs, Cloud DNS, Cloud IAM, Cloud Key Management Service, Cloud SQL, Cloud Storage, Compute Engine, Kubernetes Engine, Stackdriver, Virtual Private Cloud (VPC), Vertex AI]

  • Apache HTTP Server

  • Apache Kafka

  • Apache Tomcat Server

  • Containerization Tools: Docker, OpenShift, Kubernetes, PodMan, Apptainer (formerly Singularity), ContainerD, Generic Containers

  • CI/CD Tools: CircleCI, JFrog

  • Cron Jobs

  • Secret/Password Management and Access Control: Hashicorp Vault, Okta, CyberArk Secret Management

  • IaC Tools: Terraform, Azure Resource Manager (ARM), Ansible

  • Microservices Infrastructure

  • Micronaut (Microservices)

  • Microsoft IIS Server

  • Microsoft SQL Server

* MySQL * Serialization * Network [QUIC & HTTP/2, WiFi, Bluetooth, FTP, Directory Server, DNS Server, Firewall, FTP Server, IDS/IPS, Load Balancer, Message Broker, File Transfer Protocol (FTP), Virtual Private Network (VPN), Proxy Server, Router, Service Bus, Virtual Private Network (VPN) Server, 3G, 4G/LTE, 5G, LoRa, Modbus, Advanced Message Queuing Protocol (AMQP), gRPC, Content Delivery Network (CDN)] * Data serialization formats [Protocol Buffers] * Data Platforms: Snowflake * Databases [Generic Database, Oracle, PostgreSQL, InfluxDB, Neo4j, MariaDB, CockroachDB, Apache Cassandra, MarkLogic, IBM DB2, and SQLite] * GitHub * IBM Cloud: VPC, ObjectStorage, KeyManagementServices, ContainerRegistry, Database, Cloudant, InternetServices, KeyProtect, BlockStorage, ActivityTracker, KubernetesService * Alibaba Cloud: [Foundation CIS Benchmark] IDM, Logging and monitoring, Networking, VM, Storage, RDB, Kubernetes, Security Center * Oracle Cloud Infrastructure CIS Benchmark [Computation instance, Object Storage, Block Volume, File Storage] * Microsoft Azure (Microsoft Cloud Security, Azure Foundations and Kubernetes CIS Benchmarks, Azure Compute CIS Benchmark) [Azure Subscriptions & Resources, Azure Pipelines, Azure Windows Server, Azure Services: Active Directory, AKS, Azure Functions, Key Vault, Monitor, Multi-Factor Authentication, Network Watcher, Security Center, SQL Database, Storage, Virtual Machines, Virtual Network, Azure AI Bot Service, Azure Databricks, Azure Machine Learning, Azure OpenAI Service, Azure Analysis Services, Azure Data Explorer, Azure Data Lake Analytics, Azure Event Hubs, Azure Stream Analytics, Azure Synapse Analytics, Azure App Service, Azure Batch, Azure Linux Virtual Machines, Azure Spring Apps, Azure Virtual Desktop, Azure Virtual Machine Scale Sets, Azure VMware Solution, Azure Windows Virtual Machines, Azure Container Apps, Azure Container Instances, Azure Container Registry, Azure CycleCloud, Azure Red Hat OpenShift, Azure Cache for Redis, Azure Cosmos DB, Azure Data Factory, Azure Database for MariaDB, Azure Database for MySQL, Azure Managed Instance for Apache Cassandra, Azure SQL, Azure App Configuration, Azure DevTest Labs, Azure Arc, Azure Stack Edge, Azure Active Directory External Identities, Azure API Management, Azure Event Grid, Azure Logic Apps, Azure Service Bus, Azure Web PubSub, Azure IoT Central, Azure IoT Hub, Azure Notification Hubs, Azure Automation, Azure Cloud Shell, Azure Cost Management, Azure Lighthouse, Azure Managed Applications, Azure Policy, Azure Purview, Azure Resource Manager templates, Azure Resource Mover, Azure Media Services, Azure Database Migration Service, Azure Migrate, Azure Site Recovery, Azure Digital Twins, Azure Remote Rendering, Azure Spatial Anchors, Azure Application Gateway, Azure Bastion, Azure Communications Gateway, Azure Content Delivery Network, Azure DDoS Protection, Azure DNS, Azure Firewall, Azure Firewall Manager, Azure Front Door, Azure Load Balancer, Azure NAT Gateway, Azure Network Watcher, Azure Private Link, Azure Traffic Manager, Azure Virtual WAN, Azure VPN Gateway, Azure Web Application Firewall, Azure PostgreSQL Database, Azure Attestation, Azure Dedicated HSM, Azure Defender for Cloud, Azure Information Protection, Azure Key Vault Managed HSM, Azure Sentinel, Azure Backup, Azure Data Box, Azure Data Share, Azure HPC Cache, Azure Managed Lustre, Azure NetApp Files, Azure Communication Services, Azure SignalR Service, Azure Blob Storage, Azure Data Lake Storage, SQL Managed Instance, Azure Static Web Apps, Azure Repos, Azure Entra]

Just-in-time Training

  • Over 750 bite-sized training modules associated directly with specific Countermeasures, to teach developers about secure coding.

Contact us for a free demonstration at info@securitycompass.com

results matching ""

    No results matching ""