The standards behind trustworthy recovery
100 plain-English explainers of the frameworks, controls and regulations that protect debtor data — what each standard is, why it matters in vendor due diligence, and what to ask a provider. Search or filter.
- Security Frameworks
ISO 27001: What It Is & Why It Matters
An overview of ISO 27001, the international standard for managing information security risk.
8 min - Security Frameworks
SOC 2: What It Is & Why It Matters
An overview of SOC 2, the independent audit report covering a service provider's controls.
8 min - Security Frameworks
Essential Eight: What It Is & Why It Matters
An overview of the Essential Eight, the ASD's baseline cyber mitigation strategies.
8 min - Security Frameworks
NIST Cybersecurity Framework: What It Is & Why It Matters
An overview of the NIST Cybersecurity Framework and its core functions.
8 min - Security Frameworks
CIS Controls: What They Are & Why They Matter
An overview of the CIS Controls, a prioritised set of practical security safeguards.
7 min - Security Frameworks
ISO 27017: What It Is & Why It Matters
An overview of ISO 27017, the code of practice for cloud security controls.
7 min - Security Frameworks
ISO 27018: What It Is & Why It Matters
An overview of ISO 27018, the code of practice for protecting personal data in the cloud.
7 min - Security Frameworks
PCI DSS: What It Is & Why It Matters
An overview of PCI DSS, the security standard for handling payment card data.
8 min - Security Frameworks
OWASP Top 10: What It Is & Why It Matters
An overview of the OWASP Top 10, the standard awareness list of web application risks.
7 min - Security Frameworks
Penetration Testing: What It Is & Why It Matters
An overview of penetration testing as an assurance practice in vendor security.
7 min - Security Frameworks
Vulnerability Management: What It Is & Why It Matters
An overview of vulnerability management as a continuous security discipline.
7 min - Security Frameworks
Security Awareness Training: What It Is & Why It Matters
An overview of security awareness training and why the human element matters.
6 min - Security Frameworks
Secure Software Development: What It Is & Why It Matters
An overview of secure software development practices across the lifecycle.
7 min - Security Frameworks
Zero Trust Architecture: What It Is & Why It Matters
An overview of zero trust architecture and the principle of never trusting by default.
7 min - Security Frameworks
Network Security: What It Is & Why It Matters
An overview of network security controls and why they protect data in transit.
7 min - Security Frameworks
Endpoint Protection: What It Is & Why It Matters
An overview of endpoint protection and why devices are a key security frontier.
6 min - Security Frameworks
Security Monitoring: What It Is & Why It Matters
An overview of security monitoring and the role of logging and visibility.
7 min - Security Frameworks
Threat Detection: What It Is & Why It Matters
An overview of threat detection and how suspicious activity is identified.
7 min - Security Frameworks
Security Hardening: What It Is & Why It Matters
An overview of security hardening and the goal of reducing the attack surface.
6 min - Security Frameworks
ASD ISM: What It Is & Why It Matters
An overview of the ASD Information Security Manual and its risk-based controls.
8 min - Privacy & Data Protection
The Privacy Act 1988: What It Is & Why It Matters
Australia's central privacy law and what it expects of organisations that handle personal information.
6 min read - Privacy & Data Protection
The Australian Privacy Principles: What They Are & Why They Matter
The core standards that guide collection, use, security and access for personal information in Australia.
6 min read - Privacy & Data Protection
The Notifiable Data Breaches Scheme: What It Is & Why It Matters
Australia's breach-notification scheme and what it expects when personal information is compromised.
6 min read - Privacy & Data Protection
The GDPR: What It Is & Why It Matters
Europe's data-protection regulation and when it can matter for an Australian provider.
6 min read - Privacy & Data Protection
The Consumer Data Right: What It Is & Why It Matters
Australia's data-portability framework and how it differs from general privacy law.
5 min read - Privacy & Data Protection
Data Sovereignty: What It Is & Why It Matters
Why the legal jurisdiction over data matters when a provider handles debtor information.
5 min read - Privacy & Data Protection
Data Residency: What It Is & Why It Matters
What it means for data to reside in a particular location and why clients ask about it.
5 min read - Privacy & Data Protection
Data Retention: What It Is & Why It Matters
Keeping personal information only as long as needed, then disposing of it responsibly.
5 min read - Privacy & Data Protection
Data Minimisation: What It Is & Why It Matters
Collecting and keeping only the personal information genuinely needed for the purpose.
5 min read - Privacy & Data Protection
The Right to Access: What It Is & Why It Matters
How individuals can seek access to personal information held about them.
5 min read - Privacy & Data Protection
The Right to Erasure: What It Is & Why It Matters
When individuals can ask for personal information about them to be deleted, and the limits.
5 min read - Privacy & Data Protection
Consent Management: What It Is & Why It Matters
Obtaining, recording and respecting consent where it is relied on for personal information.
5 min read - Privacy & Data Protection
Cross-Border Data Transfer: What It Is & Why It Matters
Moving personal information across borders and the extra obligations it can involve.
5 min read - Privacy & Data Protection
De-Identification: What It Is & Why It Matters
Altering information so individuals are no longer reasonably identifiable, and its limits.
5 min read - Privacy & Data Protection
Privacy by Design: What It Is & Why It Matters
Building privacy into systems and processes from the start rather than as an afterthought.
5 min read - Privacy & Data Protection
Privacy Impact Assessment: What It Is & Why It Matters
A structured way to identify and manage the privacy risks of a project or activity.
5 min read - Privacy & Data Protection
Sensitive Information Handling: What It Is & Why It Matters
Why certain categories of personal information warrant extra care and protection.
5 min read - Privacy & Data Protection
Data Subject Rights: What They Are & Why They Matter
The rights individuals hold over their personal information, and how good providers honour them.
5 min read - Privacy & Data Protection
Privacy Policy Standards: What They Are & Why They Matter
What a clear, useful privacy policy should contain and why it matters for trust.
5 min read - Privacy & Data Protection
Third-Party Data Sharing: What It Is & Why It Matters
Disclosing personal information to other organisations and how to do it responsibly.
5 min read - Operational Controls
Access Control: What It Is & Why It Matters
How access control limits who can see debtor data, why it matters, and what to ask a provider.
6 min - Operational Controls
Multi-Factor Authentication: What It Is & Why It Matters
What multi-factor authentication is, how it works, and why it protects access to debtor data.
6 min - Operational Controls
Role-Based Access Control: What It Is & Why It Matters
How role-based access control ties permissions to job roles and why it protects debtor data.
6 min - Operational Controls
Encryption At Rest: What It Is & Why It Matters
What encryption at rest protects, how it works, and why it matters for stored debtor data.
6 min - Operational Controls
Encryption In Transit: What It Is & Why It Matters
How encryption in transit protects moving data and why it matters for debtor information.
6 min - Operational Controls
Key Management: What It Is & Why It Matters
Why managing encryption keys well is what makes encryption effective at protecting debtor data.
6 min - Operational Controls
Data Backup: What It Is & Why It Matters
How data backup protects debtor records from loss and what good backup practice looks like.
6 min - Operational Controls
Disaster Recovery: What It Is & Why It Matters
How disaster recovery restores systems after a serious event and protects access to debtor data.
6 min - Operational Controls
Business Continuity: What It Is & Why It Matters
How business continuity keeps essential services running during disruption and protects obligations.
6 min - Operational Controls
Change Management: What It Is & Why It Matters
How change management keeps system changes safe and controlled, protecting debtor data.
6 min - Operational Controls
Configuration Management: What It Is & Why It Matters
How configuration management keeps systems securely set up and why it protects debtor data.
6 min - Operational Controls
Patch Management: What It Is & Why It Matters
How patch management closes known software weaknesses and why it protects debtor data.
6 min - Operational Controls
Logging And Monitoring: What It Is & Why It Matters
How logging and monitoring detect issues across systems and help protect debtor data.
6 min - Operational Controls
Audit Trails: What They Are & Why They Matter
How audit trails create accountable records of activity and why they matter for debtor data.
6 min - Operational Controls
Password Policy: What It Is & Why It Matters
How a strong password policy protects accounts and why it matters for debtor data.
6 min - Operational Controls
Privileged Access Management: What It Is & Why It Matters
How privileged access management protects powerful admin accounts and why it matters for debtor data.
7 min - Operational Controls
Secure Data Disposal: What It Is & Why It Matters
How secure data disposal removes debtor data beyond recovery and why it matters.
6 min - Operational Controls
Asset Management: What It Is & Why It Matters
How asset management gives visibility of systems and data so nothing is left unprotected.
6 min - Operational Controls
Physical Security: What It Is & Why It Matters
How physical security protects the facilities and equipment that hold debtor data.
6 min - Operational Controls
Remote Access Security: What It Is & Why It Matters
How remote access security protects off-site connections to systems holding debtor data.
6 min - Governance & Risk
Information Security Governance: What It Is & Why It Matters
How a provider sets direction, ownership and oversight for security across the whole business.
6 min - Governance & Risk
Risk Management Framework: What It Is & Why It Matters
The structured method a provider uses to identify, assess and treat security and business risks.
6 min - Governance & Risk
Vendor Risk Management: What It Is & Why It Matters
How a provider manages the risks introduced by the third parties it depends on.
7 min - Governance & Risk
Third-Party Due Diligence: What It Is & Why It Matters
The checks a provider performs on a third party before relying on it for data or services.
6 min - Governance & Risk
Security Policy Framework: What It Is & Why It Matters
How a provider documents and maintains the policies that set security expectations across the business.
6 min - Governance & Risk
Incident Response Plan: What It Is & Why It Matters
The documented plan a provider follows to detect, respond to and recover from security incidents.
7 min - Governance & Risk
Security Incident Management: What It Is & Why It Matters
The ongoing capability a provider uses to log, triage and resolve security events consistently.
6 min - Governance & Risk
Internal Audit: What It Is & Why It Matters
How a provider independently tests whether its own controls are working as intended.
6 min - Governance & Risk
Compliance Management: What It Is & Why It Matters
How a provider tracks its legal and regulatory obligations and demonstrates it meets them.
6 min - Governance & Risk
Security Roles & Responsibilities: What It Is & Why It Matters
How a provider defines who is responsible for which parts of security across the business.
5 min - Governance & Risk
Security Training Program: What It Is & Why It Matters
How a provider equips its people to recognise risks and handle data safely.
5 min - Governance & Risk
Supplier Security Assessment: What It Is & Why It Matters
How a provider examines and rates the security of the suppliers it relies on.
6 min - Governance & Risk
Sub-Processor Management: What It Is & Why It Matters
How a provider manages and discloses the further parties that help process customer data.
6 min - Governance & Risk
Service Level Agreements: What They Are & Why They Matter
How service level agreements set measurable commitments for the service a provider delivers.
6 min - Governance & Risk
Security Questionnaires: What They Are & Why They Matter
How structured questionnaires help clients assess a provider's security in a consistent way.
5 min - Governance & Risk
SOC 2 Readiness: What It Is & Why It Matters
What SOC 2 refers to in general terms and what readiness means for a provider's controls.
6 min - Governance & Risk
Continuous Monitoring: What It Is & Why It Matters
How a provider keeps an ongoing watch over its controls and environment rather than checking once.
6 min - Governance & Risk
Board Security Reporting: What It Is & Why It Matters
How a provider keeps senior leadership informed about security so oversight is meaningful.
5 min - Governance & Risk
Security Metrics: What They Are & Why They Matter
How a provider measures the performance of its security so it can be managed and improved.
5 min - Governance & Risk
Data Governance: What It Is & Why It Matters
How a provider sets accountability and rules for handling data responsibly through its lifecycle.
6 min - Industry & Regulatory
The Debt Collection Guideline: What It Is & Why It Matters
The joint regulator guideline is the benchmark for fair, lawful debt collection conduct.
6 min - Industry & Regulatory
ACCC & ASIC Debt Collection Guideline: What It Is & Why It Matters
ACCC and ASIC jointly guide debt collection conduct; their guidance shapes fair practice.
6 min - Industry & Regulatory
AFCA Membership & External Dispute Resolution: What It Means
AFCA offers free, independent external dispute resolution; many financial firms must be members.
6 min - Industry & Regulatory
AML/CTF Program: What It Is & Why It Matters
An AML/CTF program is the documented framework for managing financial-crime risk.
7 min - Industry & Regulatory
Anti-Money-Laundering (AML): What It Is & Why It Matters
AML is the set of laws and controls that stop criminal money looking legitimate.
6 min - Industry & Regulatory
Know Your Customer (KYC): What It Is & Why It Matters
KYC means verifying who you deal with, to manage risk and reach the right person.
6 min - Industry & Regulatory
Consumer Protection Standards: What They Are & Why They Matter
Consumer protection law sets baseline fair-dealing expectations that extend to collection.
6 min - Industry & Regulatory
Financial Services Compliance: What It Is & Why It Matters
Financial services compliance is meeting the licensing and conduct duties for credit activities.
6 min - Industry & Regulatory
Complaints Handling Standard: What It Is & Why It Matters
A complaints handling standard governs how complaints are received, recorded, and resolved fairly.
6 min - Industry & Regulatory
ISO 10002 Complaints Management: What It Is & Why It Matters
ISO 10002 is international guidance for managing complaints fairly and systematically.
6 min - Industry & Regulatory
Fair Debt Collection: What It Is & Why It Matters
Fair debt collection pursues genuine debts honestly, without harassment or undue pressure.
6 min - Industry & Regulatory
Credit Reporting Standards: What They Are & Why They Matter
Credit reporting standards govern how credit information is collected, used, and corrected.
6 min - Industry & Regulatory
Privacy & The Credit Reporting Code: What They Are & Why They Matter
Privacy law and the credit reporting code set out how personal and credit information is protected.
7 min - Industry & Regulatory
Telecommunications Consumer Protection: What It Is & Why It Matters
Telecommunications has sector-specific consumer protections, including for how telco debts are handled.
6 min - Industry & Regulatory
Payment Card Security: What It Is & Why It Matters
Payment card security standards set out how card data must be protected when taking payments.
6 min - Industry & Regulatory
Record-Keeping Obligations: What They Are & Why They Matter
Record-keeping obligations require accurate, retrievable records of dealings and payments.
6 min - Industry & Regulatory
Regulatory Reporting: What It Is & Why It Matters
Regulatory reporting is providing required information to regulators accurately and on time.
6 min - Industry & Regulatory
Whistleblower Protection: What It Is & Why It Matters
Whistleblower protections let people report wrongdoing safely and shield them from detriment.
6 min - Industry & Regulatory
Modern Slavery Statement: What It Is & Why It Matters
Modern slavery reporting describes slavery risks in operations and supply chains, and the response.
6 min - Industry & Regulatory
Ethical Collection Standards: What They Are & Why They Matter
Ethical collection standards go beyond minimum rules to make recovery genuinely fair.
6 min
No standards match. Try a different keyword or clear the filter.
Questions from your security team?
We're happy to walk procurement, privacy or risk through how Merion handles data.