> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/compliance-standards-updates/april-2026.md).

# April 2026

## New built-in compliance standards

The following compliance standards were added to the Standards Catalog. You can now access them from the **Posture Management → Compliance → Catalogs → Standards** page.

| Compliance Standard                                            | Description                                                                                                                                                                                                                                                                                                            |   |
| -------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | - |
| CIS Amazon Web Services Foundations Benchmark v6.0.0 - Level 1 | This benchmark provides a foundational set of security best practices for AWS environments that are clear to implement and carry low risk of service disruption. It focuses on essential security hygiene, such as identity management and basic logging, to reduce the overall attack surface.                        |   |
| CIS Amazon Web Services Foundations Benchmark v6.0.0 - Level 2 | Designed for environments requiring higher levels of security, this benchmark introduces advanced "defense-in-depth" configurations. It includes more restrictive policies and enhanced monitoring requirements intended for sensitive workloads where security is the primary concern.                                |   |
| CIS Microsoft Azure Foundations Benchmark - v5.0.0 Level 1     | This level provides specialized, high-security configurations for Azure environments handling highly sensitive data. It builds upon the foundational layer with stricter encryption standards and more granular access requirements for comprehensive risk mitigation.                                                 |   |
| CIS Microsoft Azure Foundations Benchmark - v5.0.0 Level 2     | This updated framework harmonizes multiple global security and privacy standards into a single, unified assessment model. Version 11.7.0 streamlines compliance efforts by focusing on high-impact controls and integrating the latest regulatory requirements to reduce administrative overlap.                       |   |
| HITRUST CSF 11.7.0                                             | This version offers a baseline security roadmap for Azure tenants, focusing on essential identity and access controls. It ensures that cloud resources are configured with fundamental protections to prevent common vulnerabilities without impacting operational agility.                                            |   |
| OWASP Top 10 for Agentic Applications 2026                     | This standard provides a dedicated security framework for managing the unique risks associated with autonomous AI agents. It focuses on preventing unauthorized goal manipulation and ensuring that AI-driven tools and actions remain within secure, intended operational boundaries.                                 |   |
| The Digital Personal Data Protection Act 2023                  | This regulation establishes a comprehensive legal framework for digital privacy, emphasizing user consent and the rights of individuals over their personal information. It mandates strict data handling practices and accountability for organizations processing personal data to ensure transparency and security. |   |

## Updated built-in compliance standards

The underlying rules were updated for the following compliance standards:

{% hint style="info" %}
Updates to compliance standards may affect assessment results.
{% endhint %}

| Compliance Standard                                   | Change Description                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ----------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| CIS Critical Security Controls v8                     | Introduced our first set of SaaS-specific security configuration rules against the CIS v8 benchmarks. This enables organizations to identify and remediate SaaS misconfigurations, establishing a baseline for foundational security hygiene.                                                                                                                                                                                                                    |
| CIS GitLab Benchmark 1.0.1                            | Appended new rules to the existing framework to strengthen the security of GitLab repository management and build environments. This detects insecure repository settings and access controls, protecting the integrity of the source code and CI/CD workflows.                                                                                                                                                                                                  |
| CIS GitHub Benchmark 1.0.0                            | Appended new rules to the existing framework to strengthen the security of GitHub developer workflows and configurations. This provides automated oversight of GitHub security settings, preventing unauthorized code changes and enhancing supply chain protection.                                                                                                                                                                                             |
| CIS Microsoft Windows Server 2022 Benchmark v3.0.0    | Introduced our first set of network scanning rules to audit hardened configurations for Windows Server 2022. This allows for automated discovery of OS-level configuration drifts and security gaps across server endpoints via network scanning.                                                                                                                                                                                                                |
| CIS Microsoft Windows 11 Enterprise Benchmark v.4.0.0 | Introduced our first set of network scanning rules to audit security baselines for Windows 11 endpoints. This provides a centralized view of endpoint compliance, ensuring that remote and enterprise workstations adhere to hardened security standards.                                                                                                                                                                                                        |
| Cloud Security Assurance Program (CSAP) - IaaS        | Introduced a comprehensive set of workload security rules mapped to the CSAP-IaaS standard to ensure the rigorous security levels required for South Korean public sector cloud services. This enables automated validation of strict logical isolation, network segmentation, and access controls, ensuring that cloud workloads meet the high-integrity mandates necessary for government-regulated software environments and public procurement.              |
| CSA Cloud Controls Matrix (CCM) 4.0.12                | Introduced our first set of attack surface management controls for cloud-native applications. This broadens cloud monitoring to include external exposure and misconfiguration risks, helping ensure software deployed in the cloud aligns with industry-standard benchmarks.                                                                                                                                                                                    |
| HITRUST CSF 11.2.0                                    | Introduced our first set of application-layer security rules to strengthen the security within the HITRUST framework. This enables automated discovery of application vulnerabilities and security gaps, ensuring high-assurance data protection for regulated software environments.                                                                                                                                                                            |
| ISO/IEC 42001:2023                                    | Appended new rules to the existing framework to strengthen the governance and management of AI systems. This provides a more comprehensive assessment of AI risk management practices, ensuring alignment with international safety and ethical standards.                                                                                                                                                                                                       |
| Korea – Information Security Management System (ISMS) | Introduced a comprehensive set of workload security rules mapped to the K-ISMS framework to strengthen the security posture of organizations operating within the South Korean private sector. This enables automated discovery of configuration gaps and security risks across KISA’s mandatory control items, ensuring high-assurance data protection and continuous compliance with national regulatory requirements for large-scale enterprise environments. |
| NIST SP 800-53 Rev. 5                                 | Appended new rules to the existing framework to strengthen the data security and privacy controls of information systems. This increases the depth of automated compliance checks, facilitating a more robust audit trail for federal and enterprise security requirements.                                                                                                                                                                                      |
| NIST AI 600-1                                         | Appended new rules to the existing framework to strengthen the management of generative AI risks and safety. This delivers enhanced visibility into AI-specific vulnerabilities, helping organizations mitigate risks associated with transparency and algorithmic bias.                                                                                                                                                                                         |
| OWASP TOP 10 CI/CD Security Risks 2025                | Introduced the first set of attack surface management rules to strengthen software delivery pipeline security, while also adding new CI/CD-specific rules to the existing framework. This update expands visibility across exposed assets and pipeline misconfigurations, helping teams reduce risk before going to production.                                                                                                                                  |
| OWASP Top 10 for LLM Applications 2025                | Appended new rules to the existing framework to strengthen the defense against Large Language Model vulnerabilities. This ensures your AI applications are evaluated against the latest industry threats, such as prompt injection and training data poisoning.                                                                                                                                                                                                  |
| Secure Controls Framework (SCF) 2024.2                | Introduced our first set of application-layer security rules to strengthen the security and privacy controls. This delivers a comprehensive view of how application security impacts overall compliance, reducing the risk of software-based regulatory failures.                                                                                                                                                                                                |
| SOC 2                                                 | Introduced our first set of SaaS-specific security configurations rules against the SOC2 benchmarks. This provides real-time visibility into your SaaS compliance status, significantly reducing the manual effort required for SOC 2 audit preparation.                                                                                                                                                                                                         |
| All applicable compliance standards                   | <p>The following rule was removed from all applicable compliance standards:<br>CUSTOMIZE: Non-corporate accounts have access to Google Cloud Platform (GCP) resources.</p>                                                                                                                                                                                                                                                                                       |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/compliance-standards-updates/april-2026.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
