Open bmarsh9 opened 1 year ago
opensourceGRC has a public mapping across several frameworks (does not include SOC), CIS also has several mappings (includes SOC) https://www.opensourcegrc.org/compliance-requirements https://www.cisecurity.org/controls/cis-controls-navigator/
Thanks - that looks like a good place to explore
As an idea, provide an interface to do this through UI, it's more flexible to the users.
Similar to opensourceGRC, the Secure Controls Framework has also premapped one to many different security/compliance frameworks together: https://securecontrolsframework.com/
Ideally if you complete a SOC2 project, you should be able to automatically map it to the other frameworks and see what controls are already satisfied/missing