comply
awesome-security-GRC
Our great sponsors
comply | awesome-security-GRC | |
---|---|---|
7 | 2 | |
1,236 | 526 | |
3.6% | - | |
0.0 | 1.7 | |
almost 2 years ago | 3 months ago | |
Go | ||
Apache License 2.0 | - |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
comply
-
SOC2: Drata, Scrut, Vanta
There are even some free open source policy generator tools like this one: https://github.com/strongdm/comply
-
SOC Compliance for Hardware/Software business
If you just want to understand the scope of work, check out this github repo with some examples; https://github.com/strongdm/comply/tree/master/example
-
Do you have any Information Security Policy or Program resources to share?
StrongDM Comply [repo to generate policies]
- Standard operating procedures creation
-
Ask HN: IT Security Checklist for Startups?
Resources I know of that may be of interest:
https://github.com/strongdm/comply
https://www.security4startups.com/
-
Knows good GitHub repo with policy templates?
Check out https://github.com/strongdm/comply.
-
SOC 2 compliance library policies
https://github.com/strongdm/comply is a good start. from there you can see how some have applied, e.g. https://github.com/gjyoung1974/soc2-policy-templates
awesome-security-GRC
What are some alternatives?
base16-universal-manager - A universal manager to set base16 themes for any supported application
Smart-Contract-Audits - Smart Contract security audit reports
settle-down - A simple SaaS invoice tool in the `go on rails` framework feedback
tern - Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.
scaffold - A cookie cutter alternative with in-project scaffolding for generating components, controllers, or other common code patterns.
threagile - Agile Threat Modeling Toolkit
soc2-policy-templates - Template SOC2 Policy Authority - documentation pipeline
awesome-malware-development - Organized list of my malware development resources
SecurityChecklists - The SaaS CTO Security Checklist Redux, The DevOps Security Checklist, and The Personal Infosec & Security Checklist
crev - Socially scalable Code REView and recommendation system that we desperately need. See http://github.com/crev-dev/cargo-crev for real implemenation.
gapps - Security compliance platform - SOC2, CMMC, ASVS, ISO27001, HIPAA, NIST CSF, NIST 800-53, CSC CIS 18, PCI DSS, SSF tracking. https://gapps.darkbanner.com
PoC_CVEs - PoC_CVEs