Search / openssf/osps-baseline-to-800-161
mapping
OSPS Baseline to NIST SP 800-161 Mapping Mapping Document
openssf/osps-baseline-to-800-161
Cross-walk from the Open Source Project Security (OSPS) Baseline controls to NIST SP 800-161. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.
Published by OSPS Baseline Authors
License No license declared
Pull latest (v0.0.0-dev-671f23f)
$grcli unpack --repository openssf/osps-baseline-to-800-161 --version v0.0.0-dev-671f23f Releases
1 live| Version | Manifest digest | Published | License | Status | |
|---|---|---|---|---|---|
| v0.0.0-dev-671f23f | 714cadc5df08c8… | 1mo ago | No license declared | Live unsigned | Details → |
Mapping references
external standards this artifact maps to (v0.0.0-dev-671f23f)-
The Open Source Project Security (OSPS) Baseline is a set of security criteria that projects should meet to demonstrate a strong security posture.
- NIST Special Publication 800-161 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations @r1-upd1 800-161
This publication provides guidance to organizations on identifying, assessing, and mitigating cybersecurity risks throughout the supply chain at all levels of their organizations. The publication integrates cybersecurity supply chain risk management (C-SCRM) into risk management activities by applying a multilevel, C-SCRM-specific approach, including guidance on the development of C-SCRM strategy implementation plans, C-SCRM policies, C-SCRM plans, and risk assessments for products and services.
Builds upon
artifacts this one extends, imports, or shares a lexicon withNo upstream references yet
This artifact doesn't extend, import, or share a lexicon with anything else in the registry.
Extended or imported by
other artifacts that build upon this oneNo dependents yet
Published artifacts that extend or import this one will appear here.