mappings:
- id: M-OSPS-AC-01-SSDF
relationship: relates-to
source: OSPS-AC-01
targets:
- entry-id: PO.3.2
- entry-id: PS.1
- entry-id: PS.2
- id: M-OSPS-AC-02-SSDF
relationship: relates-to
source: OSPS-AC-02
targets:
- entry-id: PO.2
- entry-id: PO.3.2
- entry-id: PS.1
- entry-id: PS.2
- id: M-OSPS-AC-03-SSDF
relationship: relates-to
source: OSPS-AC-03
targets:
- entry-id: PO.3.2
- entry-id: PS.1
- entry-id: PS.2
- id: M-OSPS-AC-04-SSDF
relationship: relates-to
source: OSPS-AC-04
targets:
- entry-id: PO.2
- entry-id: PO.3.2
- entry-id: PS.1
- entry-id: PS.2
- id: M-OSPS-BR-01-SSDF
relationship: relates-to
source: OSPS-BR-01
targets:
- entry-id: PO.3.2
- entry-id: PO.5.2
- entry-id: PS.1
- entry-id: PS.2
- id: M-OSPS-BR-02-SSDF
relationship: relates-to
source: OSPS-BR-02
targets:
- entry-id: PO.3.2
- entry-id: PS.1
- entry-id: PS.2
- entry-id: PS.3
- id: M-OSPS-BR-03-SSDF
relationship: relates-to
source: OSPS-BR-03
targets:
- entry-id: PO.3.2
- entry-id: PO.5.2
- entry-id: PS.1
- entry-id: PS.2
- id: M-OSPS-BR-04-SSDF
relationship: relates-to
source: OSPS-BR-04
targets:
- entry-id: PS.1
- entry-id: PS.2
- entry-id: PS.3
- entry-id: PW.1.2
- id: M-OSPS-BR-05-SSDF
relationship: relates-to
source: OSPS-BR-05
targets:
- entry-id: PO.3.2
- entry-id: PS.1
- entry-id: PS.2
- id: M-OSPS-BR-06-SSDF
relationship: relates-to
source: OSPS-BR-06
targets:
- entry-id: PO.5.2
- entry-id: PS.2
- entry-id: PS.2.1
- entry-id: PW.6.2
- id: M-OSPS-BR-07-SSDF
relationship: relates-to
source: OSPS-BR-07
targets:
- entry-id: PO.1.1
- entry-id: P0.3.1
- entry-id: P0.4.2
- entry-id: PO.5.1
- entry-id: PW.1.2
- entry-id: PW.1.3
- entry-id: PW.5.1
- id: M-OSPS-DO-01-SSDF
relationship: relates-to
source: OSPS-DO-01
targets:
- entry-id: PW.1.2
- id: M-OSPS-DO-02-SSDF
relationship: relates-to
source: OSPS-DO-02
targets:
- entry-id: PW.1.2
- entry-id: RV.1.1
- entry-id: RV.2.1
- entry-id: RV.1.2
- id: M-OSPS-DO-03-SSDF
relationship: relates-to
source: OSPS-DO-03
targets:
- entry-id: PO.4.2
- entry-id: PS.2
- entry-id: PS.2.1
- entry-id: PS.3.1
- entry-id: RV.1.3
- id: M-OSPS-DO-04-SSDF
relationship: relates-to
source: OSPS-DO-04
targets:
- entry-id: PO.4.2
- entry-id: PS.3.1
- entry-id: RV.1.3
- id: M-OSPS-GV-02-SSDF
relationship: relates-to
source: OSPS-GV-02
targets:
- entry-id: PS.3
- entry-id: PW.1.2
- id: M-OSPS-GV-03-SSDF
relationship: relates-to
source: OSPS-GV-03
targets:
- entry-id: PW.1.2
- id: M-OSPS-GV-04-SSDF
relationship: relates-to
source: OSPS-GV-04
targets:
- entry-id: PO.2
- entry-id: PO.3.2
- id: M-OSPS-LE-01-SSDF
relationship: relates-to
source: OSPS-LE-01
targets:
- entry-id: PO.3.2
- entry-id: PS.1
- entry-id: PW.1.2
- entry-id: PW.2.1
- id: M-OSPS-LE-02-SSDF
relationship: relates-to
source: OSPS-LE-02
targets:
- entry-id: PO.3.2
- id: M-OSPS-LE-03-SSDF
relationship: relates-to
source: OSPS-LE-03
targets:
- entry-id: PO.3.2
- id: M-OSPS-QA-01-SSDF
relationship: relates-to
source: OSPS-QA-01
targets:
- entry-id: PS.1
- entry-id: PS.2
- entry-id: PS.3
- entry-id: PW.1.2
- entry-id: PW.2.1
- id: M-OSPS-QA-02-SSDF
relationship: relates-to
source: OSPS-QA-02
targets:
- entry-id: PO.3.3
- entry-id: PS.1
- entry-id: PS.2
- entry-id: PS.3.2
- entry-id: PW.4
- id: M-OSPS-QA-03-SSDF
relationship: relates-to
source: OSPS-QA-03
targets:
- entry-id: PO.4.1
- entry-id: PS.1
- entry-id: PS.2
- entry-id: RV.1.2
- id: M-OSPS-QA-04-SSDF
relationship: relates-to
source: OSPS-QA-04
targets:
- entry-id: PO.3.2
- entry-id: PO.4.1
- entry-id: PS.1
- entry-id: PS.2
- entry-id: RV.1.2
- id: M-OSPS-QA-05-SSDF
relationship: relates-to
source: OSPS-QA-05
targets:
- entry-id: PS.1
- entry-id: PS.2
- id: M-OSPS-QA-06-SSDF
relationship: relates-to
source: OSPS-QA-06
targets:
- entry-id: PW.8.2
- id: M-OSPS-SA-01-SSDF
relationship: relates-to
source: OSPS-SA-01
targets:
- entry-id: PO.1
- entry-id: PO.2
- entry-id: PO.3.2
- id: M-OSPS-SA-02-SSDF
relationship: relates-to
source: OSPS-SA-02
targets:
- entry-id: PW.1.2
- id: M-OSPS-SA-03-SSDF
relationship: relates-to
source: OSPS-SA-03
targets:
- entry-id: PO.5.1
- entry-id: PW.1.1
- id: M-OSPS-VM-01-SSDF
relationship: relates-to
source: OSPS-VM-01
targets:
- entry-id: RV.1.3
- id: M-OSPS-VM-02-SSDF
relationship: relates-to
source: OSPS-VM-02
targets:
- entry-id: RV.1.3
- id: M-OSPS-VM-04-SSDF
relationship: relates-to
source: OSPS-VM-04
targets:
- entry-id: PO.4.1
- entry-id: RV.2.1
- entry-id: RV.2.2
- id: M-OSPS-VM-05-SSDF
relationship: relates-to
source: OSPS-VM-05
targets:
- entry-id: PO.4
- entry-id: PW.1.2
- entry-id: PW.8.1
- entry-id: RV.1.2
- entry-id: RV.1.3
- entry-id: RV.2.1
- entry-id: RV.2.2
- id: M-OSPS-VM-06-SSDF
relationship: relates-to
source: OSPS-VM-06
targets:
- entry-id: PO.4
- entry-id: PW.1.2
- entry-id: PW.8.1
- entry-id: RV.1.2
- entry-id: RV.1.3
- entry-id: RV.2.1
- entry-id: RV 2.2
metadata:
author:
id: openssf
name: OSPS Baseline Authors
type: Human
description: |
Cross-walk from the Open Source Project Security (OSPS) Baseline
controls to NIST SSDF. Each mapping asserts a "relates-to"
relationship; strength, confidence-level, and rationale are left
unset and should be added as the mappings are individually
reviewed.
draft: true
gemara-version: 1.2.0
id: osps-baseline-to-ssdf
mapping-references:
- description: |
The Open Source Project Security (OSPS) Baseline is a set of security
criteria that projects should meet to demonstrate a strong security
posture.
id: osps-baseline
title: Open Source Project Security Baseline
url: https://github.com/ossf/security-baseline
version: draft
- description: The Secure Software Development Framework (SSDF) is a set of
fundamental, sound, and secure software development practices based on
established secure software development practice documents from
organizations such as BSA, OWASP, and SAFECode. Few software development
life cycle (SDLC) models explicitly address software security in detail,
so practices like those in the SSDF need to be added to and integrated
with each SDLC implementation. Following the SSDF practices should help
software producers reduce the number of vulnerabilities in released
software, reduce the potential impact of the exploitation of undetected
or unaddressed vulnerabilities, and address the root causes of
vulnerabilities to prevent recurrences. Also, because the SSDF provides
a common language for describing secure software development practices,
software producers and acquirers can use it to foster their
communications for procurement processes and other management
activities.
id: SSDF
title: Secure Software Development Framework
url: https://csrc.nist.gov/pubs/sp/800/218/final
version: "1.1"
type: MappingDocument
version: v0.0.0-dev-671f23f
source-reference:
entry-type: Control
reference-id: osps-baseline
target-reference:
entry-type: Guideline
reference-id: SSDF
title: OSPS Baseline to NIST SSDF Mapping
Search / openssf/osps-baseline-to-ssdf / v0.0.0-dev-671f23f
Release · v0.0.0-dev-671f23f
openssf/osps-baseline-to-ssdf Mapping Document
openssf/osps-baseline-to-ssdf
Cross-walk from the Open Source Project Security (OSPS) Baseline controls to NIST SSDF. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.
Published by OSPS Baseline Authors
License No license declared
Install
OCI v1.1$grcli unpack --repository openssf/osps-baseline-to-ssdf --version v0.0.0-dev-671f23f grcli unpack verifies this signature against the
recorded identity below and fails closed before writing
any files — no separate verify step needed. Pass
--no-verify to skip.
- Coordinate
- oci.grc.store/openssf/osps-baseline-to-ssdf:v0.0.0-dev-671f23f
- Manifest digest
- sha256:6a047812544311cbf4c9e8eb4ddf6beaac96923c079e3cb9d472e653eed5cee1
- Signed by
- no signature recorded
Identity recorded by this hub when the version was published;
unpack (above) checks the signature against it.
Verify in CI — check the signature without downloading
$grcli verify --repository openssf/osps-baseline-to-ssdf --version v0.0.0-dev-671f23f Read-only: downloads nothing and exits non-zero if the signature or the recorded identity doesn't match — use it as an admission/policy gate.
Provenance
1 layer| Digest | Media type | Size |
|---|---|---|
| f5c26bc67b8f… | application/vnd.gemara.artifact.v1+yaml | 8.0 KiB |
Bundle config blob
{
"bundle-version": "1.0",
"gemara-version": "1.2.0",
"metadata": {
"provenance": {
"buildDefinition": {
"buildType": "https://grc.store/grcli/buildtype/v0",
"externalParameters": {
"artifact": {
"id": "osps-baseline-to-ssdf",
"type": "MappingDocument"
},
"target": {
"registry": "oci.grc.store",
"repository": "openssf/osps-baseline-to-ssdf",
"tag": "v0.0.0-dev-671f23f"
}
},
"internalParameters": {
"CI": "true",
"GITHUB_ACTIONS": "true",
"GITHUB_ACTOR": "eddie-knight",
"GITHUB_REF": "refs/heads/main",
"GITHUB_REPOSITORY": "eddie-knight/security-baseline",
"GITHUB_RUN_ATTEMPT": "1",
"GITHUB_RUN_ID": "26617016306",
"GITHUB_SHA": "671f23f015e4b0f6108ab8f82f0eba7f89d55dce",
"GITHUB_WORKFLOW": "Publish to grc.store",
"RUNNER_OS": "Linux"
},
"resolvedDependencies": [
{
"name": "/home/runner/work/_temp/staged/osps-to-ssdf.yaml",
"uri": "file:///home/runner/work/_temp/staged/osps-to-ssdf.yaml",
"digest": {
"sha256": "f5c26bc67b8fb57613201cd228e3d28fd75979aeb132e52772c98c191a661f98"
}
},
{
"name": "source",
"uri": "git+https://github.com/eddie-knight/security-baseline@671f23f015e4b0f6108ab8f82f0eba7f89d55dce",
"digest": {
"gitCommit": "671f23f015e4b0f6108ab8f82f0eba7f89d55dce"
}
}
]
},
"runDetails": {
"builder": {
"id": "https://github.com/eddie-knight/security-baseline/actions/runs/26617016306",
"version": {
"go": "go1.25.0",
"go-arch": "amd64",
"go-os": "linux",
"grcli": "v0.2.2"
}
},
"metadata": {
"invocationId": "26617016306-1",
"startedOn": "2026-05-29T03:57:20.803011511Z",
"finishedOn": "2026-05-29T03:57:20.914077584Z"
},
"byproducts": [
{
"name": "osps-to-ssdf.yaml",
"digest": {
"sha256": "f5c26bc67b8fb57613201cd228e3d28fd75979aeb132e52772c98c191a661f98"
}
}
]
}
}
},
"artifacts": [
{
"name": "osps-to-ssdf.yaml",
"type": "MappingDocument",
"id": "osps-baseline-to-ssdf",
"role": "artifact"
}
]
} No rich preview yet
This UI can't render MappingDocument artifacts richly yet. The raw content is shown below, and the artifact stays pullable via the coordinate above.