gapps
comply
gapps | comply | |
---|---|---|
5 | 7 | |
344 | 1,236 | |
- | 3.6% | |
7.2 | 0.0 | |
14 days ago | almost 2 years ago | |
HTML | Go | |
GNU General Public License v3.0 or later | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
gapps
- Open source GRC platform for SOC2, CSC, CMMC and more
-
Tools for SOC2 Type II audit?
I work on a open source tool called Gapps. You can check it out here: https://github.com/bmarsh9/gapps
-
For CTOs / tech leads of SAAS: When did you become SOC2 compliant?
Check out https://github.com/bmarsh9/gapps if you are interested in preparing for the assessment (disclaimer: I’m the author)
-
Quick question - how to track security controls to be implemented?
Take a look at Gapps (https://github.com/bmarsh9/gapps) made by u/skywalker_1391
-
Software to Implement CIS Control IG1???
I have quickly reviewed Gapps, which is an open source product: https://github.com/bmarsh9/gapps
comply
-
SOC2: Drata, Scrut, Vanta
There are even some free open source policy generator tools like this one: https://github.com/strongdm/comply
-
SOC Compliance for Hardware/Software business
If you just want to understand the scope of work, check out this github repo with some examples; https://github.com/strongdm/comply/tree/master/example
-
Do you have any Information Security Policy or Program resources to share?
StrongDM Comply [repo to generate policies]
- Standard operating procedures creation
-
Ask HN: IT Security Checklist for Startups?
Resources I know of that may be of interest:
https://github.com/strongdm/comply
https://www.security4startups.com/
-
Knows good GitHub repo with policy templates?
Check out https://github.com/strongdm/comply.
-
SOC 2 compliance library policies
https://github.com/strongdm/comply is a good start. from there you can see how some have applied, e.g. https://github.com/gjyoung1974/soc2-policy-templates
What are some alternatives?
vapi - vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.
base16-universal-manager - A universal manager to set base16 themes for any supported application
CVWA - Conviso Vulnerable Web Application is the OSS project from the Conviso Application Security for the community. The project represents a vulnerable web application to practice security testing and improve your learning in AppSec..
awesome-security-GRC - Curated list of resources for security Governance, Risk Management, Compliance and Audit professionals and enthusiasts (if they exist).
steampipe-mod-aws-compliance - Run individual controls or full compliance benchmarks for CIS, PCI, NIST, HIPAA and more across all of your AWS accounts using Powerpipe and Steampipe.
settle-down - A simple SaaS invoice tool in the `go on rails` framework feedback
awesome-cloud-security - A curated list of awesome cloud security blogs, podcasts, standards, projects, and examples.
scaffold - A cookie cutter alternative with in-project scaffolding for generating components, controllers, or other common code patterns.
OSSEC - OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.
soc2-policy-templates - Template SOC2 Policy Authority - documentation pipeline
lunasec - LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/
SecurityChecklists - The SaaS CTO Security Checklist Redux, The DevOps Security Checklist, and The Personal Infosec & Security Checklist