awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoAcerca deCómo clasificamosPrensaServidor MCP
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
intuitem avatar

intuitem/ciso-assistant-community

0
View on GitHub↗
4,162 estrellas·749 forks·Python·11 vistasintuitem.com↗

Ciso Assistant Community

Este proyecto es una plataforma de gobernanza, riesgo y cumplimiento diseñada para centralizar las actividades de gobernanza de seguridad, gestión de riesgos y cumplimiento normativo. Funciona como un gestor de framework de ciberseguridad y un sistema de gestión de riesgos cuantitativos, permitiendo a las organizaciones rastrear su postura de seguridad a través de un centro centralizado.

La plataforma se distingue por su capacidad para desacoplar los requisitos normativos de los controles de seguridad técnicos, permitiendo a los usuarios mapear una única implementación a través de múltiples frameworks globales para reducir la duplicación de auditorías. Se diferencia aún más a través de una capa de integración que conecta agentes de modelos de lenguaje a datos de gobernanza para la interacción conversacional y un bus de mensajes para la orquestación de seguridad basada en eventos.

Las capacidades amplias cubren la orquestación de auditorías de seguridad, gestión de riesgos de terceros y simulación de riesgos cuantitativos para modelar escenarios de amenazas. El sistema también incluye herramientas para la catalogación de activos, control de acceso basado en roles con autenticación multifactor y seguimiento de métricas de rendimiento a través de dashboards de gestión.

La aplicación puede desplegarse en infraestructura privada, servidores privados virtuales o clústeres de Kubernetes utilizando Docker y Helm charts.

Features

  • Governance, Risk, and Compliance Platforms - Centralizes security governance, risk management, and regulatory compliance activities in a single integrated hub.
  • Cyber Risk Simulations - Simulates security threat scenarios and loss bounds to calculate quantitative risk scores and residual risk.
  • Compliance Frameworks - Manages the import and creation of security frameworks to define organizational security benchmarks.
  • GRC Hubs - Consolidates all governance, risk, and compliance activities into a centralized security tracking hub.
  • GRC Workflow Management - Centralizes governance, risk, and compliance activities to decouple requirements from technical implementations.
  • Security Assessments - Evaluates external entities by distributing compliance frameworks and questionnaires to assess security posture.
  • Vendor Security Questionnaires - Distributes security assessments and risk management questionnaires to external vendors via direct email links.
  • Framework Synchronization Associations - Generates associations between different framework libraries to synchronize and align compliance requirements.
  • Compliance Tracking - Monitors adherence to regulatory frameworks and security controls via a centralized governance hub.
  • Security Risk Assessments - Models security threats and simulates loss scenarios to calculate quantitative risk scores and mitigation strategies.
  • Risk Mitigations - Assigns security controls to risk scenarios to reduce risk levels and determine residual risk.
  • Risk Scenarios - Enables the creation of specific risk scenarios associated with threats to analyze their potential impacts.
  • Compliance & Audit Tools - Establishes security audit baselines aligned with international standards to evaluate security posture.
  • Assessment Progress Monitoring - Monitors compliance assessment progress by linking applied controls and evidence to status indicators.
  • Audit Progress Tracking - Tracks the completion state and advancement of security audit requirements.
  • Evidence Collection and Assignment - Orchestrates security audits by collecting evidence and assigning requirements to stakeholders for validation.
  • Status Assessments - Evaluates adherence to security requirements by assigning specific status levels to individual controls.
  • Compliance-Driven Security Controls - Defines reference control templates and tracks their technical implementation through applied controls.
  • Control Definitions - Creates reference templates and applied controls to manage security remediation and standardization across domains.
  • Control Management - Enumerates existing security capabilities and defines baselines of selected controls to maintain the organizational security posture.
  • Cybersecurity Frameworks - Imports and links global security standards to reduce audit duplication and identify control gaps.
  • Compliance Evidence Preparation - Links descriptions, files, and URLs to requirements to provide evidence for implemented security measures.
  • Domain-Scoped Permissions - Assigns user access by linking roles and permissions to specific organizational scopes and domains.
  • Audit and Compliance - Conducts structured reviews of security practices to verify adherence to industry and legal standards.
  • Compliance Frameworks - Evaluates programs or products against cybersecurity frameworks to identify and address posture gaps.
  • Framework Mapping - Provides the ability to create relationships between different regulatory libraries to evaluate a scope against multiple standards.
  • Regulatory Compliance - Maps security controls to specific regulations and monitors compliance progress through evidence and audits.
  • Control-Requirement Decoupling - Separates regulatory requirements from technical security controls to allow for independent management and lifecycle tracking.
  • Versioned Governance Libraries - Bundles security frameworks and risk matrices into versioned portable files that can be updated without data loss.
  • Global Framework Mappings - Tracks adherence to global frameworks by decoupling regulatory requirements from technical security implementations.
  • Domain-Based Data Isolation - Segments organizational data into hierarchical folders to enforce access control and administrative boundaries.
  • Role-Based Access Control - Assigns users to groups that link roles and permissions to specific organizational scopes.
  • Security Posture Checklists - Evaluates the organizational security configuration against predefined best practices and standard frameworks.
  • Vendor Compliance Questionnaires - Evaluates vendor security posture through distributed compliance questionnaires and audits.
  • User Account Management - Manages user accounts, identities, and group assignments with integrated SSO and MFA support.
  • Security Control Mappings - Decouples regulatory requirements from technical security controls through a directional relationship mapping system.
  • GRC Risk Scoring - Determines organizational risk levels by applying impact factors and standardized GRC methodologies.
  • Control Implementation Separation - Decouples the technical implementation of security controls from reporting to streamline remediation efforts.
  • Hierarchical Domain Organization - Structures cybersecurity data into a hierarchical tree of folders to delimit administrative and work areas.
  • Security Control Mapping - Assigns specific security controls to mitigate identified risks and calculate residual risk across frameworks.
  • LLM Model Integrations - Interfaces tool-capable language models to create conversational experiences for interacting with governance data.
  • LLM GRC Orchestration - Connects language model agents to governance data to enable conversational interfaces for risk and compliance management.
  • LLM Integration Layers - Interfaces tool-capable language models with domain-specific governance data via a standardized communication protocol.
  • Governance Perimeters - Provides logical boundaries to isolate business units for administrative governance and risk scoping.
  • Governance Dashboards - Provides visual interfaces to monitor the status of applied security controls and risk priorities across perimeters.
  • Risk Matrix Visualizations - Maps current and residual risk scenarios onto a matrix to identify risk clusters and trends.
  • Governance AI Integrations - Provides protocols for connecting AI assistants to governance-specific data via a standardized communication protocol.
  • Container Deployment Orchestrations - Configures the environment using Docker Compose or Helm charts to orchestrate containerized deployment targets.
  • Software Asset Catalogs - Lists physical and digital resources to distinguish core assets from supporting infrastructure.
  • Automated Control Mapping - Suggests appropriate technical security controls for audit requirements based on a reference catalog.
  • Docker Deployments - Orchestrates the application using Docker containers for consistent environment isolation.
  • Helm Chart Deployment - Installs and configures the platform on Kubernetes clusters using standardized Helm chart packages.
  • Private Infrastructure Management - Installs the platform on self-managed hardware using Docker or Kubernetes for maximum data control.
  • Kafka Event Streaming - Listens to a Kafka message bus to execute specific actions based on incoming data streams.
  • Security Event Orchestrators - Uses a Kafka message bus to trigger security orchestration actions based on external data streams.
  • Risk Acceptance Workflows - Implements a formal approval workflow for management to review and consciously tolerate identified security risks.
  • Residual Risk Analysis - Analyzes the remaining risk levels after applying specific security controls to a threat scenario.
  • Risk Analysis Matrices - Evaluates risk scenarios based on probability and impact coordinates using an analysis matrix.
  • Permission Bundling - Assigns permission bundles through roles to control data management and validation processes.
  • Custom Framework Definitions - Enables the definition of tailored security frameworks using a simplified language to track specific organizational requirements.
  • Security Requirement Reviews - Tracks and updates management system items to ensure continuous alignment with organizational and regulatory standards.
  • Assessment Perimeter Segmentation - Organizes assets and governance scopes into named perimeters to isolate business units for analysis.
  • Governance Library Versioning - Applies non-destructive updates to security frameworks and risk matrices without erasing user progress.
  • Requirement Delegation - Assigns specific compliance requirements to users or teams for collaborative validation.
  • Requirement Filtering - Groups framework requirements into selectable sets to tailor audits to specific needs.
  • Custom Definitions - Enables the creation of tailored security standards using a domain-specific language to track unique organizational requirements.
  • Cross-Framework Result Projections - Projects the results of a completed audit from one security standard to another equivalent framework.
  • Organizational Structure Management - Defines internal user groups and hierarchical access permissions to organize the security program.
  • Implementation Group Scoping - Creates subsets of security frameworks to adapt compliance questionnaires to specific organizational contexts.
  • Multi-Factor Authentication - Implements identity verification using a second factor via authenticator apps and recovery codes.
  • Personal Access Tokens - Generates named authentication tokens with expiration periods for secure programmatic API access.
  • Protected Asset Tracking - Identifies and catalogs specific critical assets that require protection within the organizational environment.
  • Security Finding Management - Tracks security issues and monitors the implementation of controls to resolve findings.
  • Operations and Incident Response - Manages periodic tasks, incident responses, and security findings through operational workflows.
  • Single Sign-On Integrations - Integrates with external identity providers to centralize user authentication and access management.
  • Threat Modeling - Provides methodologies for identifying and prioritizing security threats to clarify requirements and control applications.
  • Mandatory MFA Enforcement - Mandates multi-factor authentication by redirecting users to setup pages until completion.
  • Folder-Based Access Restrictions - Controls user permissions and roles across all objects within specific organizational folders.
  • Event Bus Architectures - Utilizes an event-driven message bus with Kafka to trigger actions and synchronize data.
  • Governance Performance Definitions - Creates standardized definitions for measuring the effectiveness of security programs across various domains.
  • Governance Performance Metrics - Provides templates for quantitative and qualitative metrics to standardize security tracking across different organizational domains.
  • Metric Collection - Records periodic data samples through manual entry or integrations to track changes in security posture.
  • Custom Metric Dashboards - Provides custom dashboards with charts and widgets to monitor key performance and risk indicators.

Historial de estrellas

Gráfico del historial de estrellas de intuitem/ciso-assistant-communityGráfico del historial de estrellas de intuitem/ciso-assistant-community

Búsqueda con IA

Explora más repositorios increíbles

Describe lo que necesitas en lenguaje sencillo: la IA clasifica miles de proyectos open-source curados por relevancia.

Start searching with AI

Alternativas open-source a Ciso Assistant Community

Proyectos open-source similares, clasificados según cuántas características comparten con Ciso Assistant Community.
  • aws/aws-cdkAvatar de aws

    aws/aws-cdk

    12,817Ver en GitHub↗

    The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision cloud resources using familiar programming languages. By utilizing construct-based synthesis, it translates high-level, object-oriented code into declarative templates, allowing for the automated management of complex cloud environments through a centralized, code-driven control plane. The framework distinguishes itself through its ability to model infrastructure as a dependency-aware resource graph, ensuring that components are provisioned and updated in the correct order. It

    TypeScriptawscloud-infrastructurehacktoberfest
    Ver en GitHub↗12,817
  • forter/security-101-for-saas-startupsAvatar de forter

    forter/security-101-for-saas-startups

    4,643Ver en GitHub↗

    This project is a comprehensive set of guides and frameworks designed to secure software-as-a-service infrastructure and company operations. It provides a collection of technical checklists, architectural patterns, and best practices for hardening cloud applications against cyber attacks. The project differentiates itself by providing specialized manuals for risk management and compliance readiness. It offers structured approaches to threat modeling, incident response planning, and the preparation of audit evidence required to meet industry security certifications and enterprise customer requ

    chinesesecuritysecurity-considerations
    Ver en GitHub↗4,643
  • alfresco/prowlerAvatar de Alfresco

    Alfresco/prowler

    14,005Ver en GitHub↗

    Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for automating security audits, evaluating cloud infrastructure against regulatory compliance frameworks, and managing security assessments through a dedicated analysis dashboard. The project distinguishes itself by providing an AI-driven security context server that feeds structured data to AI assistants for automated risk analysis. It also employs graph-based attack path mapping to visualize potential lateral movement and exploitation routes across cloud inventories. The platform cove

    Python
    Ver en GitHub↗14,005
  • owasp/top10Avatar de OWASP

    OWASP/Top10

    5,273Ver en GitHub↗

    This project is a web application security standard and vulnerability framework. It provides a comprehensive list of the most critical security risks facing web applications, paired with technical guidance and a structured methodology for identifying and mitigating these flaws. The framework functions as a secure coding guide and a risk assessment methodology, offering a standardized approach to prioritizing vulnerabilities based on their potential impact and likelihood of exploitation. It defines architectural patterns and technical recommendations to help developers implement defense in dep

    HTML
    Ver en GitHub↗5,273
Ver las 30 alternativas a Ciso Assistant Community→

Preguntas frecuentes

¿Qué hace intuitem/ciso-assistant-community?

Este proyecto es una plataforma de gobernanza, riesgo y cumplimiento diseñada para centralizar las actividades de gobernanza de seguridad, gestión de riesgos y cumplimiento normativo. Funciona como un gestor de framework de ciberseguridad y un sistema de gestión de riesgos cuantitativos, permitiendo a las organizaciones rastrear su postura de seguridad a través de un centro centralizado.

¿Cuáles son las características principales de intuitem/ciso-assistant-community?

Las características principales de intuitem/ciso-assistant-community son: Governance, Risk, and Compliance Platforms, Cyber Risk Simulations, Compliance Frameworks, GRC Hubs, GRC Workflow Management, Security Assessments, Vendor Security Questionnaires, Framework Synchronization Associations.

¿Qué alternativas de código abierto existen para intuitem/ciso-assistant-community?

Las alternativas de código abierto para intuitem/ciso-assistant-community incluyen: aws/aws-cdk — The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision… forter/security-101-for-saas-startups — This project is a comprehensive set of guides and frameworks designed to secure software-as-a-service infrastructure… alfresco/prowler — Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for… owasp/top10 — This project is a web application security standard and vulnerability framework. It provides a comprehensive list of… staart/api — This project is a comprehensive backend framework built on NestJS, designed to accelerate the development of… bitwarden/clients — This project is a comprehensive zero-knowledge security suite designed for enterprise credential management, secrets…