Search / openssf/osps-baseline-to-pcidss / v0.0.0-dev-671f23f

Release · v0.0.0-dev-671f23f

openssf/osps-baseline-to-pcidss Mapping Document

openssf/osps-baseline-to-pcidss

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to PCI DSS. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

Published by OSPS Baseline Authors

License No license declared

Install

OCI v1.1
$grcli unpack --repository openssf/osps-baseline-to-pcidss --version v0.0.0-dev-671f23f

grcli unpack verifies this signature against the recorded identity below and fails closed before writing any files — no separate verify step needed. Pass --no-verify to skip.

Coordinate
oci.grc.store/openssf/osps-baseline-to-pcidss:v0.0.0-dev-671f23f
Manifest digest
sha256:7e2d0d0c398dae64f0262dc9563921da8723fd3ffadc19c02b07c07b531a5340
Signed by
no signature recorded

Identity recorded by this hub when the version was published; unpack (above) checks the signature against it.

Verify in CI — check the signature without downloading
$grcli verify --repository openssf/osps-baseline-to-pcidss --version v0.0.0-dev-671f23f

Read-only: downloads nothing and exits non-zero if the signature or the recorded identity doesn't match — use it as an admission/policy gate.

Provenance

1 layer
Digest Media type Size
7b78f725e2e9… application/vnd.gemara.artifact.v1+yaml 10.4 KiB
Bundle config blob
{
  "bundle-version": "1.0",
  "gemara-version": "1.2.0",
  "metadata": {
    "provenance": {
      "buildDefinition": {
        "buildType": "https://grc.store/grcli/buildtype/v0",
        "externalParameters": {
          "artifact": {
            "id": "osps-baseline-to-pcidss",
            "type": "MappingDocument"
          },
          "target": {
            "registry": "oci.grc.store",
            "repository": "openssf/osps-baseline-to-pcidss",
            "tag": "v0.0.0-dev-671f23f"
          }
        },
        "internalParameters": {
          "CI": "true",
          "GITHUB_ACTIONS": "true",
          "GITHUB_ACTOR": "eddie-knight",
          "GITHUB_REF": "refs/heads/main",
          "GITHUB_REPOSITORY": "eddie-knight/security-baseline",
          "GITHUB_RUN_ATTEMPT": "1",
          "GITHUB_RUN_ID": "26617016306",
          "GITHUB_SHA": "671f23f015e4b0f6108ab8f82f0eba7f89d55dce",
          "GITHUB_WORKFLOW": "Publish to grc.store",
          "RUNNER_OS": "Linux"
        },
        "resolvedDependencies": [
          {
            "name": "/home/runner/work/_temp/staged/osps-to-pcidss.yaml",
            "uri": "file:///home/runner/work/_temp/staged/osps-to-pcidss.yaml",
            "digest": {
              "sha256": "7b78f725e2e90bc6de5f83934b5d2e4b16e49298befa189026889b5bdd378f82"
            }
          },
          {
            "name": "source",
            "uri": "git+https://github.com/eddie-knight/security-baseline@671f23f015e4b0f6108ab8f82f0eba7f89d55dce",
            "digest": {
              "gitCommit": "671f23f015e4b0f6108ab8f82f0eba7f89d55dce"
            }
          }
        ]
      },
      "runDetails": {
        "builder": {
          "id": "https://github.com/eddie-knight/security-baseline/actions/runs/26617016306",
          "version": {
            "go": "go1.25.0",
            "go-arch": "amd64",
            "go-os": "linux",
            "grcli": "v0.2.2"
          }
        },
        "metadata": {
          "invocationId": "26617016306-1",
          "startedOn": "2026-05-29T03:57:19.80673596Z",
          "finishedOn": "2026-05-29T03:57:19.904472259Z"
        },
        "byproducts": [
          {
            "name": "osps-to-pcidss.yaml",
            "digest": {
              "sha256": "7b78f725e2e90bc6de5f83934b5d2e4b16e49298befa189026889b5bdd378f82"
            }
          }
        ]
      }
    }
  },
  "artifacts": [
    {
      "name": "osps-to-pcidss.yaml",
      "type": "MappingDocument",
      "id": "osps-baseline-to-pcidss",
      "role": "artifact"
    }
  ]
}

No rich preview yet

This UI can't render MappingDocument artifacts richly yet. The raw content is shown below, and the artifact stays pullable via the coordinate above.

mappings:
  - id: M-OSPS-AC-01-PCIDSS
    relationship: relates-to
    source: OSPS-AC-01
    targets:
      - entry-id: 2.2.1
      - entry-id: 8.2.1
      - entry-id: 8.3.1
  - id: M-OSPS-AC-02-PCIDSS
    relationship: relates-to
    source: OSPS-AC-02
    targets:
      - entry-id: 2.2.1
  - id: M-OSPS-AC-03-PCIDSS
    relationship: relates-to
    source: OSPS-AC-03
    targets:
      - entry-id: 2.2.1
  - id: M-OSPS-AC-04-PCIDSS
    relationship: relates-to
    source: OSPS-AC-04
    targets:
      - entry-id: 2.2.1
      - entry-id: 8.2.1
  - id: M-OSPS-BR-01-PCIDSS
    relationship: relates-to
    source: OSPS-BR-01
    targets:
      - entry-id: 2.2.1
      - entry-id: 6.4.1
  - id: M-OSPS-BR-02-PCIDSS
    relationship: relates-to
    source: OSPS-BR-02
    targets:
      - entry-id: 6.4.3
  - id: M-OSPS-BR-03-PCIDSS
    relationship: relates-to
    source: OSPS-BR-03
    targets:
      - entry-id: 2.2.1
      - entry-id: 2.2.7
      - entry-id: 4.2.1
      - entry-id: 4.2.2
      - entry-id: 6.4.1
      - entry-id: 8.3.2
  - id: M-OSPS-BR-04-PCIDSS
    relationship: relates-to
    source: OSPS-BR-04
    targets:
      - entry-id: 6.2.1
      - entry-id: 6.4.1
      - entry-id: 6.5.1
      - entry-id: 6.5.2
      - entry-id: 10.2.2
  - id: M-OSPS-BR-05-PCIDSS
    relationship: relates-to
    source: OSPS-BR-05
    targets:
      - entry-id: 6.4.3
  - id: M-OSPS-BR-06-PCIDSS
    relationship: relates-to
    source: OSPS-BR-06
    targets:
      - entry-id: 2.2.1
      - entry-id: 2.2.7
      - entry-id: 3.5.1
      - entry-id: 4.2.1
      - entry-id: 4.2.2
      - entry-id: 6.4.1
      - entry-id: 8.3.2
  - id: M-OSPS-DO-01-PCIDSS
    relationship: relates-to
    source: OSPS-DO-01
    targets:
      - entry-id: 2.1.1
      - entry-id: 2.2.1
      - entry-id: 3.1.1
      - entry-id: 4.1.1
      - entry-id: 5.1.1
      - entry-id: 6.1.1
      - entry-id: 6.2.1
      - entry-id: 7.1.1
      - entry-id: 8.1.1
      - entry-id: 11.1.1
      - entry-id: 12.10.5
  - id: M-OSPS-DO-02-PCIDSS
    relationship: relates-to
    source: OSPS-DO-02
    targets:
      - entry-id: 6.3.2
      - entry-id: 6.3.3
      - entry-id: 6.5.1
      - entry-id: 6.5.2
      - entry-id: 12.10.2
  - id: M-OSPS-DO-03-PCIDSS
    relationship: relates-to
    source: OSPS-DO-03
    targets:
      - entry-id: 3.1.1
      - entry-id: 3.5.1
      - entry-id: 4.1.1
      - entry-id: 5.1.1
      - entry-id: 6.1.1
      - entry-id: 6.2.1
      - entry-id: 7.1.1
      - entry-id: 8.1.1
      - entry-id: 11.1.1
  - id: M-OSPS-DO-04-PCIDSS
    relationship: relates-to
    source: OSPS-DO-04
    targets:
      - entry-id: 2.1.1
      - entry-id: 3.1.1
      - entry-id: 3.2.1
      - entry-id: 4.1.1
      - entry-id: 5.1.1
      - entry-id: 6.1.1
      - entry-id: 6.3.3
      - entry-id: 7.1.1
      - entry-id: 8.1.1
      - entry-id: 11.1.1
  - id: M-OSPS-DO-05-PCIDSS
    relationship: relates-to
    source: OSPS-DO-05
    targets:
      - entry-id: 3.1.1
      - entry-id: 3.2.1
      - entry-id: 4.1.1
      - entry-id: 5.1.1
      - entry-id: 6.1.1
      - entry-id: 6.3.2
      - entry-id: 7.1.1
      - entry-id: 8.1.1
      - entry-id: 11.1.1
  - id: M-OSPS-DO-06-PCIDSS
    relationship: relates-to
    source: OSPS-DO-06
    targets:
      - entry-id: 2.1.1
      - entry-id: 3.1.1
      - entry-id: 4.1.1
      - entry-id: 5.1.1
      - entry-id: 6.1.1
      - entry-id: 6.3.2
      - entry-id: 6.4.3
      - entry-id: 7.1.1
      - entry-id: 8.1.1
      - entry-id: 11.1.1
      - entry-id: 12.5.2
  - id: M-OSPS-GV-01-PCIDSS
    relationship: relates-to
    source: OSPS-GV-01
    targets:
      - entry-id: 2.1.2
      - entry-id: 3.1.1
      - entry-id: 3.1.2
      - entry-id: 4.1.1
      - entry-id: 4.1.2
      - entry-id: 5.1.1
      - entry-id: 5.1.2
      - entry-id: 6.1.1
      - entry-id: 6.1.2
      - entry-id: 6.5.4
      - entry-id: 7.1.1
      - entry-id: 7.1.2
      - entry-id: 8.1.1
      - entry-id: 8.1.2
      - entry-id: 11.1.1
      - entry-id: 11.1.2
      - entry-id: 12.1.3
      - entry-id: 12.5.2
  - id: M-OSPS-GV-02-PCIDSS
    relationship: relates-to
    source: OSPS-GV-02
    targets:
      - entry-id: 12.5.2
  - id: M-OSPS-GV-03-PCIDSS
    relationship: relates-to
    source: OSPS-GV-03
    targets:
      - entry-id: 2.1.1
      - entry-id: 6.5.4
      - entry-id: 8.2.1
      - entry-id: 12.5.2
  - id: M-OSPS-GV-04-PCIDSS
    relationship: relates-to
    source: OSPS-GV-04
    targets:
      - entry-id: 2.1.1
      - entry-id: 6.5.4
      - entry-id: 8.2.1
      - entry-id: 8.2.2
  - id: M-OSPS-LE-01-PCIDSS
    relationship: relates-to
    source: OSPS-LE-01
    targets:
      - entry-id: 12.8.5
  - id: M-OSPS-LE-02-PCIDSS
    relationship: relates-to
    source: OSPS-LE-02
    targets:
      - entry-id: 3.2.1
  - id: M-OSPS-LE-03-PCIDSS
    relationship: relates-to
    source: OSPS-LE-03
    targets:
      - entry-id: 3.2.1
  - id: M-OSPS-QA-01-PCIDSS
    relationship: relates-to
    source: OSPS-QA-01
    targets:
      - entry-id: 2.1.1
      - entry-id: 6.2.1
      - entry-id: 6.5.1
      - entry-id: 6.5.2
  - id: M-OSPS-QA-02-PCIDSS
    relationship: relates-to
    source: OSPS-QA-02
    targets:
      - entry-id: 6.3.2
      - entry-id: 6.4.3
      - entry-id: 12.5.1
  - id: M-OSPS-QA-03-PCIDSS
    relationship: relates-to
    source: OSPS-QA-03
    targets:
      - entry-id: 6.3.1
      - entry-id: 6.3.2
      - entry-id: 6.5.2
  - id: M-OSPS-QA-04-PCIDSS
    relationship: relates-to
    source: OSPS-QA-04
    targets:
      - entry-id: 6.4.2
  - id: M-OSPS-QA-05-PCIDSS
    relationship: relates-to
    source: OSPS-QA-05
    targets:
      - entry-id: 6.4.3
  - id: M-OSPS-QA-06-PCIDSS
    relationship: relates-to
    source: OSPS-QA-06
    targets:
      - entry-id: 6.2.3
      - entry-id: 6.3.1
      - entry-id: 6.3.2
      - entry-id: 6.4.2
  - id: M-OSPS-QA-07-PCIDSS
    relationship: relates-to
    source: OSPS-QA-07
    targets:
      - entry-id: 6.2.3.1
      - entry-id: 6.4.2
      - entry-id: 6.5.4
  - id: M-OSPS-SA-01-PCIDSS
    relationship: relates-to
    source: OSPS-SA-01
    targets:
      - entry-id: 2.2.1
      - entry-id: 2.2.3
      - entry-id: 2.2.4
      - entry-id: 2.2.5
      - entry-id: 2.2.6
      - entry-id: 3.1.1
      - entry-id: 4.1.1
      - entry-id: 5.1.1
      - entry-id: 6.1.1
      - entry-id: 6.2.1
      - entry-id: 7.1.1
      - entry-id: 8.1.1
      - entry-id: 11.1.1
      - entry-id: 12.3.1
      - entry-id: 12.5.3
  - id: M-OSPS-SA-02-PCIDSS
    relationship: relates-to
    source: OSPS-SA-02
    targets:
      - entry-id: 2.2.1
      - entry-id: 2.2.3
      - entry-id: 2.2.4
      - entry-id: 2.2.5
      - entry-id: 2.2.6
      - entry-id: 6.2.1
      - entry-id: 12.3.1
      - entry-id: 12.8.1
  - id: M-OSPS-SA-03-PCIDSS
    relationship: relates-to
    source: OSPS-SA-03
    targets:
      - entry-id: 2.2.4
      - entry-id: 2.2.5
      - entry-id: 2.2.6
      - entry-id: 6.2.1
      - entry-id: 6.2.3.1
      - entry-id: 6.3.2
      - entry-id: 6.4.2
      - entry-id: 11.3.1
      - entry-id: 12.3.1
  - id: M-OSPS-VM-01-PCIDSS
    relationship: relates-to
    source: OSPS-VM-01
    targets:
      - entry-id: 2.1.1
      - entry-id: 3.1.1
      - entry-id: 4.1.1
      - entry-id: 5.1.1
      - entry-id: 6.1.1
      - entry-id: 6.3.1
      - entry-id: 6.3.2
      - entry-id: 7.1.1
      - entry-id: 8.1.1
      - entry-id: 11.1.1
      - entry-id: 11.2.1
      - entry-id: 12.1.1
      - entry-id: 12.1.3
  - id: M-OSPS-VM-02-PCIDSS
    relationship: relates-to
    source: OSPS-VM-02
    targets:
      - entry-id: 6.3.3
      - entry-id: 12.1.1
      - entry-id: 12.10.2
  - id: M-OSPS-VM-03-PCIDSS
    relationship: relates-to
    source: OSPS-VM-03
    targets:
      - entry-id: 6.3.1
      - entry-id: 6.3.3
      - entry-id: 12.10.2
  - id: M-OSPS-VM-04-PCIDSS
    relationship: relates-to
    source: OSPS-VM-04
    targets:
      - entry-id: 6.2.3
      - entry-id: 6.3.1
      - entry-id: 6.3.2
      - entry-id: 6.3.3
      - entry-id: 11.3.1
  - id: M-OSPS-VM-05-PCIDSS
    relationship: relates-to
    source: OSPS-VM-05
    targets:
      - entry-id: 6.2.3
      - entry-id: 6.3.1
      - entry-id: 6.3.2
      - entry-id: 6.4.1
      - entry-id: 6.4.2
  - id: M-OSPS-VM-06-PCIDSS
    relationship: relates-to
    source: OSPS-VM-06
    targets:
      - entry-id: 6.2.3
      - entry-id: 6.3.1
      - entry-id: 6.3.2
      - entry-id: 6.4.1
      - entry-id: 6.4.2
      - entry-id: 6.5.2
metadata:
  author:
    id: openssf
    name: OSPS Baseline Authors
    type: Human
  description: |
    Cross-walk from the Open Source Project Security (OSPS) Baseline
    controls to PCI DSS. Each mapping asserts a "relates-to"
    relationship; strength, confidence-level, and rationale are left
    unset and should be added as the mappings are individually
    reviewed.
  draft: true
  gemara-version: 1.2.0
  id: osps-baseline-to-pcidss
  mapping-references:
    - description: |
        The Open Source Project Security (OSPS) Baseline is a set of security
        criteria that projects should meet to demonstrate a strong security
        posture.
      id: osps-baseline
      title: Open Source Project Security Baseline
      url: https://github.com/ossf/security-baseline
      version: draft
    - description: "PCI Security Standards are technical and operational requirements
        set by the PCI Security Standards Council (PCI SSC) to protect
        cardholder data. The standards apply to all entities that store, process
        or transmit cardholder data – with requirements for software developers
        and manufacturers of applications and devices used in those
        transactions. The Council is responsible for managing the security
        standards, while compliance with the PCI set of standards is enforced by
        the founding members of the Council: American Express, Discover
        Financial Services, JCB, MasterCard and Visa Inc. The PCI Data Security
        Standard (PCI DSS) applies to all entities that store, process, and/or
        transmit cardholder data. It covers technical and operational system
        components included in or connected to cardholder data. If you accept or
        process payment cards, PCI DSS applies to you."
      id: PCIDSS
      title: Payment Card Industry Data Security Standard
      url: https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0_1.pdf
      version: 4.0.1
  type: MappingDocument
  version: v0.0.0-dev-671f23f
source-reference:
  entry-type: Control
  reference-id: osps-baseline
target-reference:
  entry-type: Guideline
  reference-id: PCIDSS
title: OSPS Baseline to PCI DSS Mapping