compliance

There are 1067 repositories under compliance topic.

  • CISOfy/lynis

    Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.

    Language:Shell14.6k3489001.5k
  • wazuh/wazuh

    Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

    Language:C13.5k22619.8k2k
  • prowler

    prowler-cloud/prowler

    Prowler is the Open Cloud Security platform for AWS, Azure, GCP, Kubernetes, M365 and more. It helps for continuous monitoring, security assessments & audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, ENS and more

    Language:Python12.1k1241.2k1.8k
  • open-policy-agent/opa

    Open Policy Agent (OPA) is an open source, general-purpose policy engine.

    Language:Go10.7k1332.8k1.5k
  • immudb

    codenotary/immudb

    immudb - immutable database based on zero trust, SQL/Key-Value/Document model, tamperproof, data change history

    Language:Go8.8k76539351
  • bridgecrewio/checkov

    Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

    Language:Python7.9k562k1.2k
  • tfsec

    aquasecurity/tfsec

    Tfsec is now part of Trivy

    Language:Go6.9k700551
  • cloud-custodian

    cloud-custodian/cloud-custodian

    Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources

    Language:Python5.8k1674.4k1.6k
  • ThreatMapper

    deepfence/ThreatMapper

    Open Source Cloud Native Application Protection Platform (CNAPP)

    Language:TypeScript5.1k54606628
  • ossec/ossec-hids

    OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.

    Language:C4.8k3281k1.1k
  • ciso-assistant-community

    intuitem/ciso-assistant-community

    CISO Assistant is a one-stop-shop for GRC, covering Risk, AppSec, Compliance/Audit Management, Privacy and supporting +100 frameworks worldwide with auto-mapping: NIST CSF, ISO 27001, SOC2, CIS, PCI DSS, NIS2, CMMC, PSPF, GDPR, HIPAA, Essential Eight, NYDFS-500, DORA, NIST AI RMF, 800-53, CyFun, AirCyber, NCSC, ECC, SCF and so much more

    Language:Python3.2k38464474
  • inspec/inspec

    InSpec: Auditing and Testing Framework

    Language:Ruby3k1362.6k685
  • yannh/kubeconform

    A FAST Kubernetes manifests validator, with support for Custom Resources!

    Language:Go2.8k6163148
  • ComplianceAsCode/content

    Security automation content in SCAP, Bash, Ansible, and other formats

    Language:Shell2.5k1253.1k750
  • 0x6d69636b/windows_hardening

    HardeningKitty and Windows Hardening Settings

    Language:PowerShell2.5k7873329
  • bearer

    Bearer/bearer

    Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

    Language:Go2.4k23343128
  • ballerine

    ballerine-io/ballerine

    Open-source infrastructure and data orchestration platform for risk decisioning

    Language:TypeScript2.3k26471254
  • usnistgov/macos_security

    macOS Security Compliance Project

    Language:YAML2.1k141276256
  • ort

    oss-review-toolkit/ort

    A suite of tools to automate software compliance checks.

    Language:Kotlin1.8k371.4k349
  • bytedance/appshark

    Appshark is a static taint analysis platform to scan vulnerabilities in an Android app.

    Language:Kotlin1.7k1857178
  • nsacyber/Windows-Secure-Host-Baseline

    Configuration guidance for implementing the Windows 10 and Windows Server 2016 DoD Secure Host Baseline settings. #nsacyber

    Language:HTML1.6k20862289
  • OpenSCAP/openscap

    NIST Certified SCAP 1.2 toolkit

    Language:XSLT1.6k76680406
  • HummerRisk/HummerRisk

    HummerRisk 是云原生安全平台,包括混合云安全治理和云原生安全检测。

    Language:Java1.5k87216237
  • lunasec-io/lunasec

    LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/

    Language:TypeScript1.5k29290168
  • project-copacetic/copacetic

    🧵 CLI tool for directly patching container images!

    Language:Go1.4k1129397
  • strongdm/comply

    Compliance automation framework, focused on SOC2

    Language:Go1.4k7791260
  • terraform-compliance/cli

    a lightweight, security focused, BDD test framework against terraform.

    Language:Python1.4k35345153
  • aws-cloudformation/cloudformation-guard

    Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data such as CloudFormation Templates, K8s configurations, and Terraform JSON plans/configurations against those rules. Take this survey to provide feedback about cfn-guard: https://amazonmr.au1.qualtrics.com/jfe/form/SV_bpyzpfoYGGuuUl0

    Language:Rust1.4k42232188
  • databunker

    securitybunker/databunker

    Secure Vault for Customer PII/PHI/PCI/KYC Records

    Language:Go1.3k341485
  • cfn_nag

    stelligent/cfn_nag

    Linting tool for CloudFormation templates

    Language:Ruby1.3k31369210
  • square/sudo_pair

    Plugin for sudo that requires another human to approve and monitor privileged sudo sessions

    Language:Rust1.3k263447
  • owasp-dep-scan/dep-scan

    OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.

    Language:Python1.2k19195117
  • comp

    trycompai/comp

    The open source compliance platform - Drata & Vanta Alternative

    Language:TypeScript1.1k212164
  • ElectricEye

    jonrau1/ElectricEye

    ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks

    Language:Python1k3382135
  • Open-Source-Security-Guide

    mikeroyal/Open-Source-Security-Guide

    Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.

    Language:Go1k28391
  • tern-tools/tern

    Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.

    Language:Python99931529190