compliance

There are 683 repositories under compliance topic.

  • CISOfy/lynis

    Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.

    Language:Shell12.6k3478201.4k
  • prowler

    prowler-cloud/prowler

    Prowler is an Open Source Security tool for AWS, Azure, GCP and Kubernetes to do security assessments, audits, incident response, compliance, continuous monitoring, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more

    Language:Python9.6k1188251.4k
  • wazuh/wazuh

    Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

    Language:C9.3k20815.7k1.5k
  • open-policy-agent/opa

    Open Policy Agent (OPA) is an open source, general-purpose policy engine.

    Language:Go9.2k1252.5k1.3k
  • immudb

    codenotary/immudb

    immudb - immutable database based on zero trust, SQL/Key-Value/Document model, tamperproof, data change history

    Language:Go8.5k79519338
  • tfsec

    aquasecurity/tfsec

    Security scanner for your Terraform code

    Language:Go6.6k710530
  • bridgecrewio/checkov

    Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

    Language:Python6.6k581.7k1.1k
  • cloud-custodian

    cloud-custodian/cloud-custodian

    Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources

    Language:Python5.2k1654k1.4k
  • ThreatMapper

    deepfence/ThreatMapper

    Open Source Cloud Native Application Protection Platform (CNAPP)

    Language:TypeScript4.7k58567571
  • ossec/ossec-hids

    OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.

    Language:C4.3k3331k1k
  • inspec/inspec

    InSpec: Auditing and Testing Framework

    Language:Ruby2.8k1352.6k679
  • 0x6d69636b/windows_hardening

    HardeningKitty and Windows Hardening settings and configurations

    Language:PowerShell2.2k6759301
  • ComplianceAsCode/content

    Security automation content in SCAP, Bash, Ansible, and other formats

    Language:Shell2.1k1242.9k668
  • yannh/kubeconform

    A FAST Kubernetes manifests validator, with support for Custom Resources!

    Language:Go2k5133113
  • ballerine

    ballerine-io/ballerine

    Open-source infrastructure and data orchestration platform for risk decisioning

    Language:TypeScript2k24449165
  • bearer

    Bearer/bearer

    Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

    Language:Go1.8k1932081
  • HummerRisk/HummerRisk

    HummerRisk 是云原生安全平台,包括混合云安全治理和云原生安全检测。

    Language:Java1.8k110213287
  • usnistgov/macos_security

    macOS Security Compliance Project

    Language:YAML1.6k132238184
  • nsacyber/Windows-Secure-Host-Baseline

    Configuration guidance for implementing the Windows 10 and Windows Server 2016 DoD Secure Host Baseline settings. #nsacyber

    Language:HTML1.5k21062286
  • ort

    oss-review-toolkit/ort

    A suite of tools to automate software compliance checks.

    Language:Kotlin1.5k411.2k293
  • bytedance/appshark

    Appshark is a static taint analysis platform to scan vulnerabilities in an Android app.

    Language:Kotlin1.4k1952157
  • lunasec-io/lunasec

    LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/

    Language:TypeScript1.4k30290162
  • terraform-compliance/cli

    a lightweight, security focused, BDD test framework against terraform.

    Language:Python1.3k38338150
  • OpenSCAP/openscap

    NIST Certified SCAP 1.2 toolkit

    Language:XSLT1.3k74647360
  • strongdm/comply

    Compliance automation framework, focused on SOC2

    Language:Go1.2k7490237
  • aws-cloudformation/cloudformation-guard

    Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data such as CloudFormation Templates, K8s configurations, and Terraform JSON plans/configurations against those rules. Take this survey to provide feedback about cfn-guard: https://amazonmr.au1.qualtrics.com/jfe/form/SV_bpyzpfoYGGuuUl0

    Language:Rust1.2k38209176
  • square/sudo_pair

    Plugin for sudo that requires another human to approve and monitor privileged sudo sessions

    Language:Rust1.2k273251
  • cfn_nag

    stelligent/cfn_nag

    Linting tool for CloudFormation templates

    Language:Ruby1.2k34363207
  • databunker

    securitybunker/databunker

    Secure SDK/vault for personal records/PII built to comply with GDPR

    Language:Go1.2k331170
  • tern-tools/tern

    Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.

    Language:Python93831528185
  • ElectricEye

    jonrau1/ElectricEye

    ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks

    Language:Python8673473118
  • Open-Source-Security-Guide

    mikeroyal/Open-Source-Security-Guide

    Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.

    Language:Go85829377
  • project-copacetic/copacetic

    🧵 CLI tool for directly patching container images using reports from vulnerability scanners

    Language:Go802712754
  • fossology/fossology

    FOSSology is an open source license compliance software system and toolkit. As a toolkit you can run license, copyright and export control scans from the command line. As a system, a database and web ui are provided to give you a compliance workflow. License, copyright and export scanners are tools used in the workflow.

    Language:PHP753631.3k401
  • privacyradius/gdpr-checklist

    The GDPR Checklist

    Language:JavaScript7503515104
  • owasp-dep-scan/dep-scan

    OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.

    Language:Python7271313985