Curated list of resources for security Governance, Risk Management, Compliance and Audit professionals and enthusiasts (if they exist).
☆998Sep 7, 2025Updated 6 months ago
Alternatives and similar repositories for awesome-security-GRC
Users that are interested in awesome-security-GRC are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A minimalist risk management program!☆150Aug 10, 2022Updated 3 years ago
- A hands-on, real-world GRC lab series built for beginners and curious pros alike. No PDFs. No gatekeeping. Just practical labs for unders…☆104Nov 6, 2025Updated 4 months ago
- OWASP Foundation Web Respository☆78Mar 21, 2026Updated last week
- Security compliance platform - SOC2, CMMC, ASVS, ISO27001, HIPAA, NIST CSF, NIST 800-53, CSC CIS 18, PCI DSS, SSF tracking☆659Mar 1, 2026Updated 3 weeks ago
- CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, Privacy, and Reporting. It supports…☆3,731Updated this week
- Wordpress hosting with auto-scaling on Cloudways • AdFully Managed hosting built for WordPress-powered businesses that need reliable, auto-scalable hosting. Cloudways SafeUpdates now available.
- Config files for my GitHub profile.☆445Dec 29, 2025Updated 3 months ago
- An open source Governance Risk Compliance (GRC) solution for corporates and government☆36Jul 10, 2017Updated 8 years ago
- This GRC Portfolio Hub is my initiative to empower GRC professionals in showcasing their practical AWS GRC engineering implementation ski…☆45Aug 6, 2025Updated 7 months ago
- An open source, self-service GRC tool to automate security assessments and compliance.☆207Dec 10, 2024Updated last year
- SANS has developed a set of information security policy templates. These are free to use and fully customizable to your company's IT secu…☆56Oct 22, 2021Updated 4 years ago
- Compliance automation framework, focused on SOC2☆1,508Jul 21, 2022Updated 3 years ago
- ☁️Haven GRC - easier governance, risk, and compliance 👨⚕️👮♀️🦸♀️🕵️♀️👩🔬☆104Jun 14, 2021Updated 4 years ago
- The GitHub repo for the GRC Engineering For AWS Book. Everything You Need to Become a GRC Engineer in the Cloud GRC engineering bridges t…☆36Jul 25, 2025Updated 8 months ago
- collection of materials and resources I use to teach computer security classes☆12Jun 25, 2021Updated 4 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Useful templates and working document for implementing ISO 27001 - ISMS☆217Mar 10, 2026Updated 2 weeks ago
- ☆13Jan 2, 2024Updated 2 years ago
- ☆56Mar 23, 2026Updated last week
- A set of policies, standards and control procedures with mapping to HIPAA, NIST CSF, PCI DSS, SOC2, FedRAMP, CIS Controls, and more.☆345Feb 19, 2026Updated last month
- compliance assessment and POA&M management for CMMC/NIST 800-171A☆110Jan 2, 2025Updated last year
- A platform to automate and orchestrate security rules for governance, risk and compliance, and continuous assurance.☆40Mar 12, 2026Updated 2 weeks ago
- ☆640Mar 11, 2025Updated last year
- This GitHub page shows the CISO Tradecraft Podcast broken down by Topic☆145Jan 2, 2026Updated 2 months ago
- Maturity models help integrate traditionally separate organizational functions, set process improvement goals and priorities, provide gui…☆264Jul 5, 2025Updated 8 months ago
- Wordpress hosting with auto-scaling on Cloudways • AdFully Managed hosting built for WordPress-powered businesses that need reliable, auto-scalable hosting. Cloudways SafeUpdates now available.
- hyperGRC is a lightweight, in-browser tool for managing compliance-as-code repositories in OpenControl format.☆29Jan 19, 2022Updated 4 years ago
- These are files that a new CISO or someone introducing security to an organization can leverage to bridge the gap between security and th…☆77Oct 7, 2025Updated 5 months ago
- This repository documents my hands on experience and assignments during the Columbia University Cybersecurity Program. It includes home l…☆12Aug 10, 2023Updated 2 years ago
- GOAL: Incident Response Playbooks Mapped to MITRE Attack Tactics and Techniques. [Contributors Friendly]☆1,548Jul 28, 2024Updated last year
- ☆1,052Aug 22, 2025Updated 7 months ago
- 🚨ATTENTION🚨 The NIST 800-53 mappings have migrated to the Center’s Mappings Explorer project. See README below. This repository is kept…☆496Apr 3, 2024Updated last year
- Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS…☆1,535Jan 28, 2026Updated 2 months ago
- Management tool for the information security management system / Outil de gestion du système de management de la sécurité de l'informatio…☆341Mar 18, 2026Updated last week
- Machine readable cybersecurity compliance standards library for Python, starting with FISMA and NIST Risk Management Framework☆63Apr 15, 2020Updated 5 years ago
- NordVPN Threat Protection Pro™ • AdTake your cybersecurity to the next level. Block phishing, malware, trackers, and ads. Lightweight app that works with all browsers.
- A curated knowledge base to build, run and mature a SOC (including CSIRT).☆1,679Updated this week
- This repository supports the blog site www.cloudauditcontrols.com.☆15Dec 3, 2025Updated 3 months ago
- Incident Response Methodologies 2022☆1,109Apr 11, 2025Updated 11 months ago
- Open-source GRC platform for modern security teams. Manage compliance (SOC 2, ISO 27001, HIPAA), risk registers, vendor assessments, and …☆103Mar 23, 2026Updated last week
- An automation framework for deploying Microsoft Sentinel environments using pipelines. This project combines infrastructure-as-code (Bice…☆36Mar 20, 2026Updated last week
- An open-source listing of cybersecurity technology mapped to the NIST Cybersecurity Framework (CSF)☆130Jul 14, 2024Updated last year
- A curated list of tools for incident response☆8,901Jul 18, 2024Updated last year