intuitem / ciso-assistant-community

CISO Assistant is a one-stop-shop for GRC, covering Risk, AppSec and Audit Management and supporting +44 frameworks worldwide: NIST CSF, ISO 27001, SOC2, CIS, PCI DSS, NIS2, CMMC, PSPF, GDPR, HIPAA, Essential Eight, NYDFS-500, DORA, NIST AI RMF, 800-53, 800-171, CyFun, CJIS, AirCyber and so much more
https://intuitem.com
GNU Affero General Public License v3.0
442 stars 70 forks source link

Pull risk metrics from audits #373

Open ab-smith opened 1 month ago

ab-smith commented 1 month ago

Frameworks items are supposed to reflect a requirement to cover a risk. Auditing against the framework should be used to report the status of such risks and combine them with the specialized risk assessment. We already have the pieces for this, given that we keep enriching the frameworks 😊