Curated list of resources for security Governance, Risk Management, Compliance and Audit professionals and enthusiasts (if they exist).
☆1,012Sep 7, 2025Updated 7 months ago
Alternatives and similar repositories for awesome-security-GRC
Users that are interested in awesome-security-GRC are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A minimalist risk management program!☆151Aug 10, 2022Updated 3 years ago
- A hands-on, real-world GRC lab series built for beginners and curious pros alike. No PDFs. No gatekeeping. Just practical labs for unders…☆111Nov 6, 2025Updated 5 months ago
- OWASP Foundation Web Respository☆78Mar 21, 2026Updated 3 weeks ago
- CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, Privacy, and Reporting. It supports…☆3,963Updated this week
- Config files for my GitHub profile.☆464Apr 2, 2026Updated 2 weeks ago
- Wordpress hosting with auto-scaling - Free Trial • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- An open source Governance Risk Compliance (GRC) solution for corporates and government☆37Jul 10, 2017Updated 8 years ago
- This GRC Portfolio Hub is my initiative to empower GRC professionals in showcasing their practical AWS GRC engineering implementation ski…☆46Aug 6, 2025Updated 8 months ago
- An open source, self-service GRC tool to automate security assessments and compliance.☆209Dec 10, 2024Updated last year
- SANS has developed a set of information security policy templates. These are free to use and fully customizable to your company's IT secu…☆57Oct 22, 2021Updated 4 years ago
- Compliance automation framework, focused on SOC2☆1,522Jul 21, 2022Updated 3 years ago
- ☁️Haven GRC - easier governance, risk, and compliance 👨⚕️👮♀️🦸♀️🕵️♀️👩🔬☆105Jun 14, 2021Updated 4 years ago
- The GitHub repo for the GRC Engineering For AWS Book. Everything You Need to Become a GRC Engineer in the Cloud GRC engineering bridges t…☆38Jul 25, 2025Updated 8 months ago
- collection of materials and resources I use to teach computer security classes☆12Jun 25, 2021Updated 4 years ago
- Useful templates and working document for implementing ISO 27001 - ISMS☆220Mar 30, 2026Updated 2 weeks ago
- Serverless GPU API endpoints on Runpod - Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- ☆14Jan 2, 2024Updated 2 years ago
- ☆58Apr 12, 2026Updated last week
- A set of policies, standards and control procedures with mapping to HIPAA, NIST CSF, PCI DSS, SOC2, FedRAMP, CIS Controls, and more.☆345Feb 19, 2026Updated 2 months ago
- compliance assessment and POA&M management for CMMC/NIST 800-171A☆111Jan 2, 2025Updated last year
- GRC (Governance, Risk and Compliance) Software, to manage risks and controls. It is based in best practices and helps organizations to ma…☆28Mar 8, 2023Updated 3 years ago
- A platform to automate and orchestrate security rules for governance, risk and compliance, and continuous assurance.☆40Apr 9, 2026Updated last week
- ☆642Mar 11, 2025Updated last year
- This GitHub page shows the CISO Tradecraft Podcast broken down by Topic☆145Jan 2, 2026Updated 3 months ago
- Maturity models help integrate traditionally separate organizational functions, set process improvement goals and priorities, provide gui…☆265Jul 5, 2025Updated 9 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- hyperGRC is a lightweight, in-browser tool for managing compliance-as-code repositories in OpenControl format.☆29Jan 19, 2022Updated 4 years ago
- These are files that a new CISO or someone introducing security to an organization can leverage to bridge the gap between security and th…☆77Oct 7, 2025Updated 6 months ago
- GOAL: Incident Response Playbooks Mapped to MITRE Attack Tactics and Techniques. [Contributors Friendly]☆1,552Jul 28, 2024Updated last year
- ☆1,054Apr 12, 2026Updated last week
- 🚨ATTENTION🚨 The NIST 800-53 mappings have migrated to the Center’s Mappings Explorer project. See README below. This repository is kept…☆496Apr 3, 2024Updated 2 years ago
- Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS…☆1,544Apr 3, 2026Updated 2 weeks ago
- This repository documents my hands on experience and assignments during the Columbia University Cybersecurity Program. It includes home l…☆12Aug 10, 2023Updated 2 years ago
- Management tool for the information security management system / Outil de gestion du système de management de la sécurité de l'informatio…☆346Updated this week
- Machine readable cybersecurity compliance standards library for Python, starting with FISMA and NIST Risk Management Framework☆63Apr 15, 2020Updated 6 years ago
- Serverless GPU API endpoints on Runpod - Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- A curated knowledge base to build, run and mature a SOC (including CSIRT).☆1,697Apr 11, 2026Updated last week
- This repository supports the blog site www.cloudauditcontrols.com.☆15Dec 3, 2025Updated 4 months ago
- Incident Response Methodologies 2022☆1,113Apr 11, 2025Updated last year
- An automation framework for deploying Microsoft Sentinel environments using pipelines. This project combines infrastructure-as-code (Bice…☆42Mar 23, 2026Updated 3 weeks ago
- An open-source listing of cybersecurity technology mapped to the NIST Cybersecurity Framework (CSF)☆132Jul 14, 2024Updated last year
- A curated list of tools for incident response☆8,951Jul 18, 2024Updated last year
- Repository for the Open Information Security Risk Universe☆64Jul 10, 2022Updated 3 years ago