Search

Find an Artifact

Compliance, control, and guidance catalogs published as content-addressed OCI artifacts. Filter by kind, search by title, and pull any release with grcli.

84
Catalogs
4
Organizations →
2
Registered users
6
Kinds supported
openssf/osps-baseline-to-uksscop

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to UK NCSC Software Security Code of Practice. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

v0.0.0-dev-671f23f by OSPS Baseline Authors 5d ago
openssf/osps-baseline-to-ssdf

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to NIST SSDF. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

v0.0.0-dev-671f23f by OSPS Baseline Authors 5d ago
openssf/osps-baseline-to-slsa

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to SLSA. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

v0.0.0-dev-671f23f by OSPS Baseline Authors 5d ago
openssf/osps-baseline-to-scorecard

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to OpenSSF Scorecard. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

v0.0.0-dev-671f23f by OSPS Baseline Authors 5d ago
openssf/osps-baseline-to-samm

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to OWASP SAMM. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

v0.0.0-dev-671f23f by OSPS Baseline Authors 5d ago
openssf/osps-baseline-to-psscrm

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to P-SSCRM. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

v0.0.0-dev-671f23f by OSPS Baseline Authors 5d ago
openssf/osps-baseline-to-pcidss

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to PCI DSS. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

v0.0.0-dev-671f23f by OSPS Baseline Authors 5d ago
openssf/osps-baseline-to-opencre

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to OpenCRE. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

v0.0.0-dev-671f23f by OSPS Baseline Authors 5d ago
openssf/osps-baseline-to-iso-18974

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to ISO/IEC 18974. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

v0.0.0-dev-671f23f by OSPS Baseline Authors 5d ago
openssf/osps-baseline-to-csf

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to NIST CSF 2.0. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

v0.0.0-dev-671f23f by OSPS Baseline Authors 5d ago
openssf/osps-baseline-to-cra

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to EU Cyber Resilience Act. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

v0.0.0-dev-671f23f by OSPS Baseline Authors 5d ago
openssf/osps-baseline-to-bsi-tr-03185-2

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to BSI TR-03185-2. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

v0.0.0-dev-671f23f by OSPS Baseline Authors 5d ago
openssf/osps-baseline-to-bpb

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to OpenSSF Best Practices Badge. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

v0.0.0-dev-671f23f by OSPS Baseline Authors 5d ago
openssf/osps-baseline-to-800-161

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to NIST SP 800-161. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

v0.0.0-dev-671f23f by OSPS Baseline Authors 5d ago
complytime/cis-fedora-l1-guidance

Guidance catalog for the CIS Fedora Linux Level 1 Benchmark. Provides rationale and context for each control family covering filesystem hardening, service minimization, network security, firewall configuration, access controls, logging, and system maintenance. Shared across Server and Workstation profiles.

dev-20260527.2 by ComplyTime 7d ago
finos-aigf/air-nist-map-001

Maps FINOS AI Governance Framework mitigations (guidelines) to NIST SP 800-53 Revision 5 security and privacy controls. References derived from AIGF mitigation frontmatter.

0.2.0 by FINOS-AIGF 7d ago

AI Governance Framework

Guidance Catalog
finos-aigf/finos-air

A Gemara representation of the FINOS AI Governance Framework mitigations. All 23 AIGF mitigations are represented as guidelines; see the gemara/ README for the migration roadmap. The Markdown collections remain the canonical source of truth.

0.2.0 by FINOS-AIGF 7d ago
finos-aigf/air-vec

AIGF risks expressed as Gemara vectors. Each vector describes a pathway through which AI system failures or negative outcomes may be realized in financial services deployments.

0.2.0 by FINOS-AIGF 7d ago
finos-aigf/air-prin

Core principles underpinning the FINOS AI Governance Framework. Each principle represents a foundational value that one or more AIGF mitigations (guidelines) are designed to uphold.

0.2.0 by FINOS-AIGF 7d ago
← Previous page