Under active development Content is continuously updated and improved
Home / Public Domain
Public Domain

Public Domain Resources

Frameworks and guidance published as public domain works, primarily from U.S. government agencies (NIST, FedRAMP, DoD) and open-source organizations (OWASP). These resources can be freely used, shared, and built upon. 5034 items across 20 resources.

v5.2.0 Public Domain 1,196 controls

NIST SP 800-53

Security and Privacy Controls for Information Systems and Organizations

20 Families Framework
v5 Public Domain 410 controls

FedRAMP Rev 5

Federal Risk and Authorization Management Program Security Baselines

18 Families Framework
v0.9.0-beta Public Domain 60 indicators

FedRAMP 20x KSI

Key Security Indicators for FedRAMP 20x authorization

11 Categories Framework
vRev 5 Public Domain 622 controls

DoD SRG

DoD Cloud Computing Security Requirements Guide - FedRAMP+ controls by Impact Level

20 Families Framework
v2.0 Public Domain 10 risks

OWASP Top 10 for LLMs

Security risks for Large Language Model applications

10 Risk Categories Risk List
v2025 Public Domain 10 risks

OWASP Top 10

The OWASP Top 10 is a standard awareness document for web application security risks

10 Risk Categories Risk List
v2023 Public Domain 10 risks

OWASP API Security Top 10

The OWASP API Security Top 10 represents the most critical security risks to APIs

8 Risk Categories Risk List
v2024 Public Domain 10 risks

OWASP Mobile Top 10

The OWASP Mobile Top 10 represents the most critical security risks to mobile applications

10 Risk Categories Risk List
v2.0 Public Domain 106 outcomes

NIST CSF

Cybersecurity Framework 2.0 for improving critical infrastructure security

6 Functions Framework
vV2R4 Public Domain 94 findings

Kubernetes STIG

DoD Security Technical Implementation Guide for Kubernetes container orchestration

9 Components Framework
v1.0 Public Domain 72 actions

NIST AI RMF

AI Risk Management Framework Playbook - Suggested actions for trustworthy AI

4 Functions Framework
v2024/1689 Public Domain 21 requirements

EU AI Act

European Union Artificial Intelligence Act - Risk-based regulatory framework for AI systems

8 Chapters Framework
v1.1 Public Domain 42 tasks

NIST SSDF

Secure Software Development Framework - Practices for integrating security into SDLC

4 Groups Framework
vRev 2 Public Domain 110 requirements

NIST SP 800-171

Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

14 Families Framework
v2.0 Public Domain 110 practices

CMMC

Cybersecurity Maturity Model Certification for DoD contractors

14 Domains Framework
v2.0 Public Domain 223 controls

TX-RAMP

Texas Risk and Authorization Management Program - Security assessment and certification for cloud computing services used by Texas state agencies

17 Families Framework
v2024 Public Domain 131 requirements

HIPAA Security Rule

Health Insurance Portability and Accountability Act - Security safeguards for electronic protected health information (ePHI)

6 Sections Framework
v2016/679 Public Domain 499 articles

GDPR

General Data Protection Regulation - EU regulation on data protection and privacy

12 Chapters Framework
v2022/2555 Public Domain 473 requirements

NIS2 Directive

Network and Information Security Directive 2 - EU cybersecurity legislation

2 Chapters Framework
v2026 Public Domain 825 requirements

CCPA

California Consumer Privacy Act - California state privacy regulation

11 Articles Framework

> About Public Domain

Public domain works are not restricted by copyright and can be freely used by anyone for any purpose.

Most U.S. government publications, including NIST standards and FedRAMP baselines, are automatically in the public domain under 17 U.S.C. § 105. OWASP content is released under open-source licenses (typically Creative Commons) that allow free redistribution.

This means you can reference, reproduce, and build upon these frameworks without permission or licensing fees.