bmarsh9 / gapps

Security compliance platform - SOC2, CMMC, ASVS, ISO27001, HIPAA, NIST CSF, NIST 800-53, CSC CIS 18, PCI DSS, SSF tracking. https://gapps.darkbanner.com
Other
437 stars 99 forks source link

Create mapping between controls of the various frameworks #32

Open bmarsh9 opened 1 year ago

bmarsh9 commented 1 year ago

Ideally if you complete a SOC2 project, you should be able to automatically map it to the other frameworks and see what controls are already satisfied/missing

sbrunston commented 1 year ago

opensourceGRC has a public mapping across several frameworks (does not include SOC), CIS also has several mappings (includes SOC) https://www.opensourcegrc.org/compliance-requirements https://www.cisecurity.org/controls/cis-controls-navigator/

bmarsh9 commented 1 year ago

Thanks - that looks like a good place to explore

RootMePLS commented 1 year ago

As an idea, provide an interface to do this through UI, it's more flexible to the users.

NoahJaehnert commented 1 year ago

Similar to opensourceGRC, the Secure Controls Framework has also premapped one to many different security/compliance frameworks together: https://securecontrolsframework.com/