mappings:
- id: M-OSPS-AC-01-PCIDSS
relationship: relates-to
source: OSPS-AC-01
targets:
- entry-id: 2.2.1
- entry-id: 8.2.1
- entry-id: 8.3.1
- id: M-OSPS-AC-02-PCIDSS
relationship: relates-to
source: OSPS-AC-02
targets:
- entry-id: 2.2.1
- id: M-OSPS-AC-03-PCIDSS
relationship: relates-to
source: OSPS-AC-03
targets:
- entry-id: 2.2.1
- id: M-OSPS-AC-04-PCIDSS
relationship: relates-to
source: OSPS-AC-04
targets:
- entry-id: 2.2.1
- entry-id: 8.2.1
- id: M-OSPS-BR-01-PCIDSS
relationship: relates-to
source: OSPS-BR-01
targets:
- entry-id: 2.2.1
- entry-id: 6.4.1
- id: M-OSPS-BR-02-PCIDSS
relationship: relates-to
source: OSPS-BR-02
targets:
- entry-id: 6.4.3
- id: M-OSPS-BR-03-PCIDSS
relationship: relates-to
source: OSPS-BR-03
targets:
- entry-id: 2.2.1
- entry-id: 2.2.7
- entry-id: 4.2.1
- entry-id: 4.2.2
- entry-id: 6.4.1
- entry-id: 8.3.2
- id: M-OSPS-BR-04-PCIDSS
relationship: relates-to
source: OSPS-BR-04
targets:
- entry-id: 6.2.1
- entry-id: 6.4.1
- entry-id: 6.5.1
- entry-id: 6.5.2
- entry-id: 10.2.2
- id: M-OSPS-BR-05-PCIDSS
relationship: relates-to
source: OSPS-BR-05
targets:
- entry-id: 6.4.3
- id: M-OSPS-BR-06-PCIDSS
relationship: relates-to
source: OSPS-BR-06
targets:
- entry-id: 2.2.1
- entry-id: 2.2.7
- entry-id: 3.5.1
- entry-id: 4.2.1
- entry-id: 4.2.2
- entry-id: 6.4.1
- entry-id: 8.3.2
- id: M-OSPS-DO-01-PCIDSS
relationship: relates-to
source: OSPS-DO-01
targets:
- entry-id: 2.1.1
- entry-id: 2.2.1
- entry-id: 3.1.1
- entry-id: 4.1.1
- entry-id: 5.1.1
- entry-id: 6.1.1
- entry-id: 6.2.1
- entry-id: 7.1.1
- entry-id: 8.1.1
- entry-id: 11.1.1
- entry-id: 12.10.5
- id: M-OSPS-DO-02-PCIDSS
relationship: relates-to
source: OSPS-DO-02
targets:
- entry-id: 6.3.2
- entry-id: 6.3.3
- entry-id: 6.5.1
- entry-id: 6.5.2
- entry-id: 12.10.2
- id: M-OSPS-DO-03-PCIDSS
relationship: relates-to
source: OSPS-DO-03
targets:
- entry-id: 3.1.1
- entry-id: 3.5.1
- entry-id: 4.1.1
- entry-id: 5.1.1
- entry-id: 6.1.1
- entry-id: 6.2.1
- entry-id: 7.1.1
- entry-id: 8.1.1
- entry-id: 11.1.1
- id: M-OSPS-DO-04-PCIDSS
relationship: relates-to
source: OSPS-DO-04
targets:
- entry-id: 2.1.1
- entry-id: 3.1.1
- entry-id: 3.2.1
- entry-id: 4.1.1
- entry-id: 5.1.1
- entry-id: 6.1.1
- entry-id: 6.3.3
- entry-id: 7.1.1
- entry-id: 8.1.1
- entry-id: 11.1.1
- id: M-OSPS-DO-05-PCIDSS
relationship: relates-to
source: OSPS-DO-05
targets:
- entry-id: 3.1.1
- entry-id: 3.2.1
- entry-id: 4.1.1
- entry-id: 5.1.1
- entry-id: 6.1.1
- entry-id: 6.3.2
- entry-id: 7.1.1
- entry-id: 8.1.1
- entry-id: 11.1.1
- id: M-OSPS-DO-06-PCIDSS
relationship: relates-to
source: OSPS-DO-06
targets:
- entry-id: 2.1.1
- entry-id: 3.1.1
- entry-id: 4.1.1
- entry-id: 5.1.1
- entry-id: 6.1.1
- entry-id: 6.3.2
- entry-id: 6.4.3
- entry-id: 7.1.1
- entry-id: 8.1.1
- entry-id: 11.1.1
- entry-id: 12.5.2
- id: M-OSPS-GV-01-PCIDSS
relationship: relates-to
source: OSPS-GV-01
targets:
- entry-id: 2.1.2
- entry-id: 3.1.1
- entry-id: 3.1.2
- entry-id: 4.1.1
- entry-id: 4.1.2
- entry-id: 5.1.1
- entry-id: 5.1.2
- entry-id: 6.1.1
- entry-id: 6.1.2
- entry-id: 6.5.4
- entry-id: 7.1.1
- entry-id: 7.1.2
- entry-id: 8.1.1
- entry-id: 8.1.2
- entry-id: 11.1.1
- entry-id: 11.1.2
- entry-id: 12.1.3
- entry-id: 12.5.2
- id: M-OSPS-GV-02-PCIDSS
relationship: relates-to
source: OSPS-GV-02
targets:
- entry-id: 12.5.2
- id: M-OSPS-GV-03-PCIDSS
relationship: relates-to
source: OSPS-GV-03
targets:
- entry-id: 2.1.1
- entry-id: 6.5.4
- entry-id: 8.2.1
- entry-id: 12.5.2
- id: M-OSPS-GV-04-PCIDSS
relationship: relates-to
source: OSPS-GV-04
targets:
- entry-id: 2.1.1
- entry-id: 6.5.4
- entry-id: 8.2.1
- entry-id: 8.2.2
- id: M-OSPS-LE-01-PCIDSS
relationship: relates-to
source: OSPS-LE-01
targets:
- entry-id: 12.8.5
- id: M-OSPS-LE-02-PCIDSS
relationship: relates-to
source: OSPS-LE-02
targets:
- entry-id: 3.2.1
- id: M-OSPS-LE-03-PCIDSS
relationship: relates-to
source: OSPS-LE-03
targets:
- entry-id: 3.2.1
- id: M-OSPS-QA-01-PCIDSS
relationship: relates-to
source: OSPS-QA-01
targets:
- entry-id: 2.1.1
- entry-id: 6.2.1
- entry-id: 6.5.1
- entry-id: 6.5.2
- id: M-OSPS-QA-02-PCIDSS
relationship: relates-to
source: OSPS-QA-02
targets:
- entry-id: 6.3.2
- entry-id: 6.4.3
- entry-id: 12.5.1
- id: M-OSPS-QA-03-PCIDSS
relationship: relates-to
source: OSPS-QA-03
targets:
- entry-id: 6.3.1
- entry-id: 6.3.2
- entry-id: 6.5.2
- id: M-OSPS-QA-04-PCIDSS
relationship: relates-to
source: OSPS-QA-04
targets:
- entry-id: 6.4.2
- id: M-OSPS-QA-05-PCIDSS
relationship: relates-to
source: OSPS-QA-05
targets:
- entry-id: 6.4.3
- id: M-OSPS-QA-06-PCIDSS
relationship: relates-to
source: OSPS-QA-06
targets:
- entry-id: 6.2.3
- entry-id: 6.3.1
- entry-id: 6.3.2
- entry-id: 6.4.2
- id: M-OSPS-QA-07-PCIDSS
relationship: relates-to
source: OSPS-QA-07
targets:
- entry-id: 6.2.3.1
- entry-id: 6.4.2
- entry-id: 6.5.4
- id: M-OSPS-SA-01-PCIDSS
relationship: relates-to
source: OSPS-SA-01
targets:
- entry-id: 2.2.1
- entry-id: 2.2.3
- entry-id: 2.2.4
- entry-id: 2.2.5
- entry-id: 2.2.6
- entry-id: 3.1.1
- entry-id: 4.1.1
- entry-id: 5.1.1
- entry-id: 6.1.1
- entry-id: 6.2.1
- entry-id: 7.1.1
- entry-id: 8.1.1
- entry-id: 11.1.1
- entry-id: 12.3.1
- entry-id: 12.5.3
- id: M-OSPS-SA-02-PCIDSS
relationship: relates-to
source: OSPS-SA-02
targets:
- entry-id: 2.2.1
- entry-id: 2.2.3
- entry-id: 2.2.4
- entry-id: 2.2.5
- entry-id: 2.2.6
- entry-id: 6.2.1
- entry-id: 12.3.1
- entry-id: 12.8.1
- id: M-OSPS-SA-03-PCIDSS
relationship: relates-to
source: OSPS-SA-03
targets:
- entry-id: 2.2.4
- entry-id: 2.2.5
- entry-id: 2.2.6
- entry-id: 6.2.1
- entry-id: 6.2.3.1
- entry-id: 6.3.2
- entry-id: 6.4.2
- entry-id: 11.3.1
- entry-id: 12.3.1
- id: M-OSPS-VM-01-PCIDSS
relationship: relates-to
source: OSPS-VM-01
targets:
- entry-id: 2.1.1
- entry-id: 3.1.1
- entry-id: 4.1.1
- entry-id: 5.1.1
- entry-id: 6.1.1
- entry-id: 6.3.1
- entry-id: 6.3.2
- entry-id: 7.1.1
- entry-id: 8.1.1
- entry-id: 11.1.1
- entry-id: 11.2.1
- entry-id: 12.1.1
- entry-id: 12.1.3
- id: M-OSPS-VM-02-PCIDSS
relationship: relates-to
source: OSPS-VM-02
targets:
- entry-id: 6.3.3
- entry-id: 12.1.1
- entry-id: 12.10.2
- id: M-OSPS-VM-03-PCIDSS
relationship: relates-to
source: OSPS-VM-03
targets:
- entry-id: 6.3.1
- entry-id: 6.3.3
- entry-id: 12.10.2
- id: M-OSPS-VM-04-PCIDSS
relationship: relates-to
source: OSPS-VM-04
targets:
- entry-id: 6.2.3
- entry-id: 6.3.1
- entry-id: 6.3.2
- entry-id: 6.3.3
- entry-id: 11.3.1
- id: M-OSPS-VM-05-PCIDSS
relationship: relates-to
source: OSPS-VM-05
targets:
- entry-id: 6.2.3
- entry-id: 6.3.1
- entry-id: 6.3.2
- entry-id: 6.4.1
- entry-id: 6.4.2
- id: M-OSPS-VM-06-PCIDSS
relationship: relates-to
source: OSPS-VM-06
targets:
- entry-id: 6.2.3
- entry-id: 6.3.1
- entry-id: 6.3.2
- entry-id: 6.4.1
- entry-id: 6.4.2
- entry-id: 6.5.2
metadata:
author:
id: openssf
name: OSPS Baseline Authors
type: Human
description: |
Cross-walk from the Open Source Project Security (OSPS) Baseline
controls to PCI DSS. Each mapping asserts a "relates-to"
relationship; strength, confidence-level, and rationale are left
unset and should be added as the mappings are individually
reviewed.
draft: true
gemara-version: 1.2.0
id: osps-baseline-to-pcidss
mapping-references:
- description: |
The Open Source Project Security (OSPS) Baseline is a set of security
criteria that projects should meet to demonstrate a strong security
posture.
id: osps-baseline
title: Open Source Project Security Baseline
url: https://github.com/ossf/security-baseline
version: draft
- description: "PCI Security Standards are technical and operational requirements
set by the PCI Security Standards Council (PCI SSC) to protect
cardholder data. The standards apply to all entities that store, process
or transmit cardholder data – with requirements for software developers
and manufacturers of applications and devices used in those
transactions. The Council is responsible for managing the security
standards, while compliance with the PCI set of standards is enforced by
the founding members of the Council: American Express, Discover
Financial Services, JCB, MasterCard and Visa Inc. The PCI Data Security
Standard (PCI DSS) applies to all entities that store, process, and/or
transmit cardholder data. It covers technical and operational system
components included in or connected to cardholder data. If you accept or
process payment cards, PCI DSS applies to you."
id: PCIDSS
title: Payment Card Industry Data Security Standard
url: https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0_1.pdf
version: 4.0.1
type: MappingDocument
version: v0.0.0-dev-671f23f
source-reference:
entry-type: Control
reference-id: osps-baseline
target-reference:
entry-type: Guideline
reference-id: PCIDSS
title: OSPS Baseline to PCI DSS Mapping
Search / openssf/osps-baseline-to-pcidss / v0.0.0-dev-671f23f
Release · v0.0.0-dev-671f23f
openssf/osps-baseline-to-pcidss Mapping Document
openssf/osps-baseline-to-pcidss
Cross-walk from the Open Source Project Security (OSPS) Baseline controls to PCI DSS. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.
Published by OSPS Baseline Authors
License No license declared
Install
OCI v1.1$grcli unpack --repository openssf/osps-baseline-to-pcidss --version v0.0.0-dev-671f23f grcli unpack verifies this signature against the
recorded identity below and fails closed before writing
any files — no separate verify step needed. Pass
--no-verify to skip.
- Coordinate
- oci.grc.store/openssf/osps-baseline-to-pcidss:v0.0.0-dev-671f23f
- Manifest digest
- sha256:7e2d0d0c398dae64f0262dc9563921da8723fd3ffadc19c02b07c07b531a5340
- Signed by
- no signature recorded
Identity recorded by this hub when the version was published;
unpack (above) checks the signature against it.
Verify in CI — check the signature without downloading
$grcli verify --repository openssf/osps-baseline-to-pcidss --version v0.0.0-dev-671f23f Read-only: downloads nothing and exits non-zero if the signature or the recorded identity doesn't match — use it as an admission/policy gate.
Provenance
1 layer| Digest | Media type | Size |
|---|---|---|
| 7b78f725e2e9… | application/vnd.gemara.artifact.v1+yaml | 10.4 KiB |
Bundle config blob
{
"bundle-version": "1.0",
"gemara-version": "1.2.0",
"metadata": {
"provenance": {
"buildDefinition": {
"buildType": "https://grc.store/grcli/buildtype/v0",
"externalParameters": {
"artifact": {
"id": "osps-baseline-to-pcidss",
"type": "MappingDocument"
},
"target": {
"registry": "oci.grc.store",
"repository": "openssf/osps-baseline-to-pcidss",
"tag": "v0.0.0-dev-671f23f"
}
},
"internalParameters": {
"CI": "true",
"GITHUB_ACTIONS": "true",
"GITHUB_ACTOR": "eddie-knight",
"GITHUB_REF": "refs/heads/main",
"GITHUB_REPOSITORY": "eddie-knight/security-baseline",
"GITHUB_RUN_ATTEMPT": "1",
"GITHUB_RUN_ID": "26617016306",
"GITHUB_SHA": "671f23f015e4b0f6108ab8f82f0eba7f89d55dce",
"GITHUB_WORKFLOW": "Publish to grc.store",
"RUNNER_OS": "Linux"
},
"resolvedDependencies": [
{
"name": "/home/runner/work/_temp/staged/osps-to-pcidss.yaml",
"uri": "file:///home/runner/work/_temp/staged/osps-to-pcidss.yaml",
"digest": {
"sha256": "7b78f725e2e90bc6de5f83934b5d2e4b16e49298befa189026889b5bdd378f82"
}
},
{
"name": "source",
"uri": "git+https://github.com/eddie-knight/security-baseline@671f23f015e4b0f6108ab8f82f0eba7f89d55dce",
"digest": {
"gitCommit": "671f23f015e4b0f6108ab8f82f0eba7f89d55dce"
}
}
]
},
"runDetails": {
"builder": {
"id": "https://github.com/eddie-knight/security-baseline/actions/runs/26617016306",
"version": {
"go": "go1.25.0",
"go-arch": "amd64",
"go-os": "linux",
"grcli": "v0.2.2"
}
},
"metadata": {
"invocationId": "26617016306-1",
"startedOn": "2026-05-29T03:57:19.80673596Z",
"finishedOn": "2026-05-29T03:57:19.904472259Z"
},
"byproducts": [
{
"name": "osps-to-pcidss.yaml",
"digest": {
"sha256": "7b78f725e2e90bc6de5f83934b5d2e4b16e49298befa189026889b5bdd378f82"
}
}
]
}
}
},
"artifacts": [
{
"name": "osps-to-pcidss.yaml",
"type": "MappingDocument",
"id": "osps-baseline-to-pcidss",
"role": "artifact"
}
]
} No rich preview yet
This UI can't render MappingDocument artifacts richly yet. The raw content is shown below, and the artifact stays pullable via the coordinate above.