All Frameworks & Risk Lists
Complete listing of all security frameworks and risk lists. 20,614 total items across 101 frameworks and 4 risk lists.
> Frameworks (101)
NIST SP 800-53
Security and Privacy Controls for Information Systems and Organizations
FedRAMP Rev 5
Federal Risk and Authorization Management Program Security Baselines
FedRAMP 20x KSI
Key Security Indicators for FedRAMP 20x authorization
DoD SRG
DoD Cloud Computing Security Requirements Guide - FedRAMP+ controls by Impact Level
CIS Controls
Critical Security Controls for Effective Cyber Defense
SOC 2
Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy
Kubernetes STIG
DoD Security Technical Implementation Guide for Kubernetes container orchestration
NIST AI RMF
AI Risk Management Framework Playbook - Suggested actions for trustworthy AI
ISO/IEC 42001
AI Management System - Requirements with guidance for use (placeholder framework)
EU AI Act
European Union Artificial Intelligence Act - Risk-based regulatory framework for AI systems
ITSG-33
IT Security Risk Management - Canadian Government Security Control Catalogue
NIST SSDF
Secure Software Development Framework - Practices for integrating security into SDLC
NIST SP 800-171
Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
Adobe CCF
Adobe Common Controls Framework - Open-source unified control framework mapping to 20+ compliance standards
Cyber Essentials
UK NCSC Cyber Essentials certification - 5 technical controls to protect against common cyber attacks
BSI C5
Cloud Computing Compliance Criteria Catalogue - German Federal Office for Information Security
TX-RAMP
Texas Risk and Authorization Management Program - Security assessment and certification for cloud computing services used by Texas state agencies
SCF
Secure Controls Framework - A comprehensive meta-framework harmonizing 100+ security standards
HIPAA Security Rule
Health Insurance Portability and Accountability Act - Security safeguards for electronic protected health information (ePHI)
NIS2 Directive
Network and Information Security Directive 2 - EU cybersecurity legislation
Saudi Arabia IoT Guidelines
Saudi Arabia IoT Cybersecurity Guidelines
GovRAMP
Government Risk and Authorization Management Program - Security Baselines for State and Local Government Cloud Services
Data Privacy Management Principles
Data Privacy Management Principles
NY DFS 23 NYCRR 500
NY Department of Financial Services Cybersecurity Regulation
Unified Compliance
The "Rosetta Stone" of compliance - harmonizes hundreds of regulatory requirements into a unified control framework
HITRUST CSF
Health Information Trust Alliance Common Security Framework - comprehensive framework mapping to HIPAA, PCI, NIST, and more
CSA CCM
Cloud Security Alliance Cloud Controls Matrix - cloud security meta-framework with mappings to major standards
COBIT
ISACA Control Objectives for Information Technologies - IT governance framework with extensive cross-mappings
OCSF
Open Cybersecurity Schema Framework - open standard for security data normalization across tools and vendors
FAIR
Factor Analysis of Information Risk - quantitative risk analysis framework for measuring and managing cyber risk
MITRE ATT&CK
Adversarial Tactics, Techniques & Common Knowledge - attack taxonomy that maps across security frameworks
> Risk Lists (4)
OWASP Top 10
The OWASP Top 10 is a standard awareness document for web application security risks
OWASP API Security Top 10
The OWASP API Security Top 10 represents the most critical security risks to APIs
OWASP Mobile Top 10
The OWASP Mobile Top 10 represents the most critical security risks to mobile applications