ComplianceAsCode / auditree-frameworkLinks
The Auditree framework tool to run compliance control checks as unit tests.
☆71Updated last year
Alternatives and similar repositories for auditree-framework
Users that are interested in auditree-framework are comparing it to the libraries listed below
Sorting:
- Open source tool for processing OSCAL based FedRAMP SSPs☆43Updated last year
- An opinionated tooling platform for managing compliance as code, using continuous integration and NIST's OSCAL standard.☆225Updated this week
- Utilities for programmatic analysis of Cartography data.☆40Updated 2 weeks ago
- The Auditree common fetchers, checks and harvest reports library.☆20Updated 2 years ago
- Joint NIST/FedRAMP tool to interact with OSCAL files via a browser-based GUI☆45Updated 5 years ago
- Demo setup for compliance-trestle☆36Updated last month
- Examples on how to maintain security/compliance as code and to automate SecOps using the JupiterOne platform.☆55Updated last month
- NIST OSCAL SDK and CLI☆38Updated 5 years ago
- Compliance-to-Policy (C2P) provides the framework to bridge the gap between compliance and policy administration.☆34Updated 9 months ago
- Automate the creation of a System Security Plan (SSP)☆45Updated last week
- A library of React components and an example user interface application that provides a direct UI into NIST's Open Security Controls Asse…☆63Updated last year
- A list of tools, blog posts, and other resources that further the use and adoption of OSCAL standards.☆199Updated 6 months ago
- ☁️Haven GRC - easier governance, risk, and compliance 👨⚕️👮♀️🦸♀️🕵️♀️👩🔬☆103Updated 4 years ago
- Tools for the OSCAL project☆36Updated 2 years ago
- Scripts to import OSCAL example content into the Neo4J graph database☆30Updated 2 years ago
- NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations☆40Updated 2 months ago
- YAML schema, examples, and validators for OpenControl format.☆76Updated 6 years ago
- Privateer is a plugin-based framework to validate the status of deployed resources.☆16Updated 2 weeks ago
- in-toto is a framework to secure the software supply chain.☆71Updated last month
- DEPRECATED: A set of utilities for converting and working with compliance data for viewing in the heimdall applications☆35Updated 3 years ago
- A BOM repository server for distributing CycloneDX BOMs☆85Updated 6 months ago
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆22Updated 2 years ago
- Various deployments of the OSCAL editor☆47Updated last year
- Heimdall Enterprise Server 2 lets you view, store, and compare automated security control scan results.☆242Updated this week
- An open source, self-service GRC tool to automate security assessments and compliance.☆202Updated last year
- A collection of DoD and Federal Government Cloud Computing Resources☆49Updated 4 years ago
- Posture Attribute Collection and Evaluation☆23Updated 2 years ago
- ☆59Updated this week
- OWASP Foundation Web Respository☆56Updated 3 months ago
- ☆115Updated 5 months ago