magoo / minimalist-risk-management
A minimalist risk management program!
☆119Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for minimalist-risk-management
- read the docs version of risk management☆24Updated last year
- Repository for the Open Information Security Risk Universe☆63Updated 2 years ago
- a curated list of useful threat modeling resources☆125Updated 4 months ago
- Vendor Security Model Contract☆97Updated 2 years ago
- ☆43Updated last year
- Machine readable cybersecurity compliance standards library for Python, starting with FISMA and NIST Risk Management Framework☆58Updated 4 years ago
- Segment's Threat Modeling training for our engineers☆238Updated 3 years ago
- The SOCless automation framework☆134Updated 2 months ago
- 🖇️ STRIDE vs. ASVS equivalence table☆75Updated 3 months ago
- Repository for the Open Security Reference Architecture☆123Updated 2 weeks ago
- An open-source listing of cybersecurity technology mapped to the NIST Cybersecurity Framework (CSF)☆109Updated 4 months ago
- NIST CyberSecurity Framework management tool☆157Updated 3 years ago
- A set of policies, standards and control procedures with mapping to HIPAA, NIST CSF, PCI DSS, SOC2, FedRAMP, CIS Controls, and more.☆295Updated 5 months ago
- These are files that a new CISO or someone introducing security to an organization can leverage to bridge the gap between security and th…☆69Updated last month
- An open source, self-service GRC tool to automate security assessments and compliance.☆181Updated this week
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆169Updated this week
- This GitHub page shows the CISO Tradecraft Podcast broken down by Topic☆110Updated last week
- Maturity models help integrate traditionally separate organizational functions, set process improvement goals and priorities, provide gui…☆212Updated 2 years ago
- OWASP Foundation Web Respository☆22Updated last year
- A place to gather and organize information about using threat modeling frameworks to deal with social conflict in online systems☆56Updated 10 months ago
- ☆61Updated last year
- The Security Champion Framework provides both a measuring stick and a roadmap generator for Champion Programs.☆104Updated 10 months ago
- A small set of scripts to summarize AWS Security Groups, and generate visualizations of the rules.☆62Updated 4 years ago
- Questions to ask about the team and company when you're interviewing for a CISO position☆12Updated 3 years ago
- SimpleRisk Docker Repository☆29Updated this week
- ☆70Updated 3 weeks ago
- A MITRE ATT&CK Navigator export for AWS GuardDuty Findings☆136Updated 3 years ago
- Examples on how to maintain security/compliance as code and to automate SecOps using the JupiterOne platform.☆53Updated 10 months ago
- A collection of awesome security controls mapping for solutions across frameworks.☆52Updated 4 years ago
- Template SOC2 Policy Authority - documentation pipeline☆102Updated 4 years ago