Open-source GRC toolkit from the GRC Engineering Club. Claude Code plugins for evidence collection, SCF crosswalks, multi-framework gap reports, OSCAL workflows.
-
Updated
Aug 10, 2026 - JavaScript
Open-source GRC toolkit from the GRC Engineering Club. Claude Code plugins for evidence collection, SCF crosswalks, multi-framework gap reports, OSCAL workflows.
Security architecture patterns and NIST 800-53 controls from opensecurityarchitecture.org
Zero-Trust Cloud Modernization Framework for Federal and Enterprise Environments with IaC, Security Policies, and Monitoring Design
Agent-portable Compliance Trestle and OSCAL engineering toolkit: convert legacy SSPs to OSCAL, validate with Trestle and oscal-cli, FedRAMP Rev 5 and 20x KSI workflows. Claude Code plugin plus portable skills for Cursor, Codex, Gemini, and more.
Unified NIST + OWASP security framework MCP server — 36 tools, 3439+ records, live NVD/KEV, PDF reading, STRIDE threat modeling, compliance mapping
Centralized STIG & NIST 800-53 compliance knowledge, playbooks, and secure code templates for federal systems development.
☁️ Multi-cloud security configuration review for AWS, Azure, GCP, and OCI. Read-only audits mapped to CIS, SOC 2, PCI DSS, NIST 800-53, and HIPAA, with remediation tracking to verify fixes over time. ✅
Terraform provider for Technitium DNS Server with STIG-hardened defaults and CNSSI 1253 compliance support
NIST SP 800-171 controls matrix with all 110 requirements mapped to NIST 800-53, CMMC 2.0, CIS Controls, and ISO 27001.
Compliance-as-Code lab using AWS Config, EventBridge, and Lambda auto-remediation with CloudFormation.
Fledge: hardened macOS platform for autonomous AI agents. Security-first n8n orchestration from hello world to production.
Open-source multi-cloud compliance & security platform — scan AWS/Azure/GCP against 678 controls across 9 frameworks (SOC 2, ISO 27001, HIPAA, GDPR, PCI-DSS, NIST…) with tamper-evident evidence
Free, agentless SQL Server compliance audit - 500+ checks mapped to NIST, CIS, STIG, ISO 27001 & SOC 2. The open alternative to SQL Vulnerability Assessment.
Automated compliance as code for hybrid cloud hardening. NIST Hardening Suite converts NIST 800-53 controls into executable, auditable Ansible workflows that reduce drift and support SOC 2 and DORA evidence mapping.
Databricks lakehouse for GRC compliance automation — NIST 800-53 and SOC 2 controls, cross-framework mapping, rule engine, and ML risk prediction
Read-only, evidence-grade automation for FedRAMP 20x & Rev5: a TypeScript collector that captures AWS/GCP/Kubernetes config evidence for all 63 KSIs (223 requirements), benchmarks against NIST 800-53 at Low/Moderate/High, and signs it (Ed25519 + OSCAL) — plus a local multi-user tracker over the FRMR catalog.
Production security platform on DigitalOcean. SOAR, runtime detection, PAM, agentic AI with guardrails, full NIST 800-53 compliance documentation.
SSH 暴力破解深度防御:从攻击链到六层防御体系。一本关于 SSH 纵深加固与堡垒机架构的电子书。by LeisureLinux
DoD-aligned Kubernetes platform with STIG-gated CI/CD, NIST 800-53 controls, and Iron Bank-pattern container hardening
Open-source benchmark for adversarial evidence attacks on LLM-based cybersecurity auditors, targeting ACM AsiaCCS 2027.
Add a description, image, and links to the nist-800-53 topic page so that developers can more easily learn about it.
To associate your repository with the nist-800-53 topic, visit your repo's landing page and select "manage topics."