Skip to content
🚧 Early alpha — building the foundation. See the roadmap →

Security & GRC framework corpus

Updated

This is the directory of security & GRC frameworks worth crosswalking — scoped to Crosswalker’s launch problem domains: cybersecurity, information security, GRC, risk management, internal audit, and regulatory compliance. Each entry links to a durable home/landing page (not a download URL — those rot), notes its license, and whether usable source data is in hand.

The landscape — frameworks worth crosswalking

Section titled “The landscape — frameworks worth crosswalking”

Status = whether usable source data is in hand: ✅ acquired · ⚠️ partial (a crosswalk or subset) · 📥 still to source. (Whether a framework has been ingested and tested through Crosswalker is a separate status that comes online as we run the ingestion → mapping pipeline — see “Using these in practice” above.) License: 🟢 public / free · 🟡 registration / restrictive-CC · 🔴 purchase / copyrighted. Source links go to durable landing pages, not download URLs.

Threat-informed & adversary frameworks (MITRE family + friends)

Section titled “Threat-informed & adversary frameworks (MITRE family + friends)”
FrameworkWhat it isLicStatusSource
MITRE ATT&CK (Enterprise/Mobile/ICS)Adversary tactics & techniques🟢attack.mitre.org
MITRE D3FENDDefensive countermeasures ontology🟢d3fend.mitre.org
MITRE EngageAdversary engagement / cyber deception & denial (ex-Shield)🟢engage.mitre.org
MITRE CAPECCommon Attack Pattern Enumeration🟢capec.mitre.org
MITRE CWECommon Weakness Enumeration🟢cwe.mitre.org
CVE / NVD + CISA KEVKnown + exploited vulnerabilities🟢⚠️ ATT&CK↔CVE + KEV↔ATT&CKnvd.nist.gov
MITRE ATLASAdversarial AI/ML threat matrix🟢atlas.mitre.org
MITRE CARCyber Analytics Repository (detections)🟢car.mitre.org
MITRE VERISIncident classification taxonomy🟢verisframework.org
CTID resource packsATT&CK mappings + threat-informed-defense projects (Sightings, Summiting the Pyramid, M3TID, …)🟢ctid.mitre.org
Lockheed Cyber Kill Chain7-stage intrusion model🟡lockheedmartin.com
Diamond ModelIntrusion analysis model🟢activeresponse.org
FrameworkWhat it isLicStatusSource
NIST CSF 2.0Functions / categories / subcategories🟢nist.gov/cyberframework
NIST 800-53 r5Control catalog + assessment🟢csrc.nist.gov
NIST 800-171CUI protection (→ CMMC)🟢csrc.nist.gov
NIST SSDF (800-218)Secure software development🟢csrc.nist.gov/projects/ssdf
NIST 800-207Zero Trust Architecture🟢csrc.nist.gov
NIST Privacy FrameworkPrivacy risk (CSF-shaped)🟢📥nist.gov/privacy-framework
CIS Controls v8.118 controls / 153 safeguards🟡cisecurity.org/controls
CIS Benchmarks (~20)Per-technology hardening (AWS, Azure, GCP, K8s, M365, SQL Server, …)🟡cisecurity.org
ISO/IEC 27001 + 27002ISMS requirements + Annex A control catalog🔴✅ 27001:2022 (+Amd 1:2024) + 27002:2022iso.org
ISO 27701 / 27017 / 27018Privacy (PIMS) / cloud / PII ISMS extensions🔴⚠️ have 27701:2025; 27017/27018 missingiso.org
Secure Controls Framework175+ framework hub via STRM (+ maturity & risk models)🟡securecontrolsframework.com
CSA Cloud Controls MatrixCloud control framework🟡✅ CCM 4.1 (via CTID pack)cloudsecurityalliance.org
AICPA SOC 2 / TSCTrust Services Criteria🔴aicpa-cima.com
FrameworkWhat it isLicStatusSource
CRI Profile (v2.0–2.2)Financial-sector spine + mappings catalog + DORA / 800-53 / ATT&CK crosswalks + FS-AI-RMF🔴cyberriskinstitute.org
FFIEC IT HandbookUS FI examination booklets🟢ithandbook.ffiec.gov
FedRAMPUS gov cloud authorization🟢fedramp.gov
PCI DSS v4.0.1Payment card security🔴pcisecuritystandards.org
HIPAA Security RuleUS healthcare PHI🟢hhs.gov/hipaa
CMMCUS DoD contractor maturity🟢dodcio.defense.gov/CMMC
CISA CPGCross-sector performance goals🟢cisa.gov
HITRUST CSF v11.8Healthcare-centric certifiable framework🔴hitrustalliance.net
NERC CIPEnergy / grid critical infrastructure🟢📥nerc.com
SWIFT CSPFinancial messaging security🔴📥swift.com
Section titled “Regulatory & legal obligations (obligation-centric)”
RegulationJurisdictionLicStatusSource
DORAEU financial digital resilience🟢EUR-Lex (ELI 2022/2554)
NIS2EU critical-entity security🟢📥EUR-Lex (ELI 2022/2555)
GDPREU data protection🟢⚠️ TSC→GDPR crosswalkEUR-Lex (ELI 2016/679)
NYDFS Part 500US (NY) financial cyber🟢📥dfs.ny.gov
SEC cyber disclosure (33-11216)US public-company disclosure (8-K Item 1.05 + Reg S-K Item 106)🟢Federal Register (2023-16194)
FrameworkWhat it isLicStatusSource
NIST 800-30 / 800-39Risk assessment + risk-mgmt process🟢📥csrc.nist.gov
ISO 31000 / 27005Risk mgmt principles / infosec risk🔴⚠️ have 31000:2018; 27005 missingiso.org
FAIR / Open FAIRQuantitative cyber-risk taxonomy🟡📥fairinstitute.org
NIST AI RMFAI risk management (AI 100-1)🟢nist.gov
CRI FS-AI-RMFFinancial-services AI risk & control matrix (stages 1–3 + tier 4)🔴cyberriskinstitute.org
ISO 42001AI management system🔴📥iso.org

Application, product & supply-chain security

Section titled “Application, product & supply-chain security”
FrameworkWhat it isLicStatusSource
OWASP Top 10Web app risk list (Top 10 ↔ CWE via OSIB YAML export)🟢owasp.org · GitHub
OWASP ASVS v5.0App security verification standard🟢owasp.org
OWASP SAMM v2Software assurance maturity🟢owaspsamm.org
OWASP MASVSMobile app security🟢mas.owasp.org
SLSASupply-chain integrity levels🟢slsa.dev
BSIMMSoftware security maturity (descriptive)🟡📥bsimm.com
FrameworkWhat it isLicStatusSource
IIA Global Internal Audit Standards (2024)Internal-audit profession standards — 5 domains / 15 principles / 52 standards (PDF only, no structured file)🔴theiia.org/standards
IIA Topical RequirementsMandatory audit requirement sets — Cybersecurity, Third-Party, Org Resilience (crosswalk to NIST/CRI/DORA)🔴theiia.org
COSO Internal Control + ERMGovernance / internal-control / ERM🔴📥coso.org
COBIT 2019IT governance & management (objectives/practices/activities XLSX in the toolkit)🔴isaca.org/cobit
IIA Three Lines ModelRisk governance roles🟢theiia.org
Section titled “Licensing & copyright — what Crosswalker can share”

Raw framework sources split three ways for handling:

TierFrameworksHandling
🟢 Public domain / freeNIST, MITRE, FedRAMP, FFIEC, HIPAA, CMMC, CISA, DORA + EU lawcommit-safe
🟡 Registration / restrictive CCCIS (Controls + Benchmarks), Secure Controls Frameworklocal only
🔴 CopyrightedCRI, ISO, AICPA / SOC 2, PCI, HITRUST, COBIT, COSO, IIAlocal only

The raw corpus lives at repo-root Frameworks/local-by-default (fail-closed gitignore); copyrighted source files go in Frameworks/_licensed/ and are never committed.

The part that matters for using them: Crosswalker stores the transform logic (the import recipes + crosswalk mappings) and your derived output (paraphrased concept notes + crosswalk junction notes) — not the raw copyrighted text. So the mapping logic stays shareable even when the source standard isn’t, which is how copyrighted inputs (CRI, ISO, PCI) can feed a crosswalk graph you can still publish. That’s the schema-as-primitive idea.