Open-source GRC toolkit from the GRC Engineering Club. Claude Code plugins for evidence collection, SCF crosswalks, multi-framework gap reports, OSCAL workflows.
-
Updated
Aug 30, 2026 - JavaScript
Open-source GRC toolkit from the GRC Engineering Club. Claude Code plugins for evidence collection, SCF crosswalks, multi-framework gap reports, OSCAL workflows.
Self-hosted Information Security Management System — ISO 27001, NIS2, GDPR/DSGVO, BSI IT-Grundschutz
The most comprehensive open-source mapping of OWASP GenAI risks to industry frameworks - 70 mapping files, 25 frameworks, 1,016 controls, 125 incidents, ML classifier pipeline. Source lists: LLM Top 10, Agentic Top 10, DSGAI 2026. EU AI Act, NIST, ISO, SOC 2, FedRAMP, DORA, OT/ICS, MITRE ATLAS.
Seven-expert security decision Gen-AI council plus red, blue, and incident-response teams for EU SMEs.
Web-based diagnostic and self-assessment tool for evaluating ISO/IEC 27001 compliance and ISMS readiness.
Adds an AI-powered ChatGPT copilot to verinice.veo
Automated compliance auditing for Google Workspace using Claude's MCP. Performs 19 security checks covering access control, authentication, and system protection. Maps findings to CMMC, NIST 800-171, NIST CSF, ISO 27001, HIPAA, and FTC Safeguards frameworks. Built for MSPs and Workspace Admins to streamline security assessments.
ServiceNow security check pack — NIS2/DORA/ISO 27001 aligned, open methodology, Apache-2.0
A self-hosted control plane for orchestrating and governing AI agent fleets. Built on pure Node.js with zero external dependencies. Features tamper-evident audit logging, role-based access control with MFA, behavioral drift detection, real-time event streaming, and exportable compliance evidence mapped to SOC 2, ISO 27001, and NIST CSF.
Markdown ISO 27001 Annex A control library with SoA and risk treatment templates.
78 Cedar policies and 369 rules governing AI coding agents. Every rule traces to a real incident, published CVE, or compliance framework requirement (SOC 2, NIST, ISO 27001, EU AI Act, OWASP).
GRC Risk & Compliance Dashboard | Risk Heatmap, Control Tracking, and Compliance Monitoring (ISO 27001, GDPR, NIST)
Custodia — a CISO's working fork-and-extension of GRCEngClub/claude-grc-engineering. Stitches statutory baseline (DPDPA / GDPR / SOC 2 / NIST / FedRAMP / PCI / HITRUST) + sectoral overlay (RBI / SEBI / IRDAI / TRAI / CERT-In) + engineering reality into one Claude Code workbook. By Devam Shah.
Cybersecurity Consultant Portfolio | ISO 27001 | IT Audit | Risk Assessment | Vulnerability Assessment | React + Tailwind CSS
Security and compliance blueprints as code. Draw a trust zoned reference architecture from a short text source, then review it for control gaps. Eight frameworks: PCI DSS, SWIFT CSP, Zero Trust, HIPAA, GDPR, SOC 2, ISO 27001, IEC 62443. Zero dependencies.
Interactive Mission Control Engineering Portfolio of Heri Riski Anto — Senior DBA, Fullstack & Mobile Architect.
Open-source cloud misconfiguration detection with ML risk scoring, compliance automation, and Terraform remediation. Built with FastAPI + React.
Build and manage a self-hosted information security management system that operates without cloud dependencies and supports compliance efforts.
To associate your repository with the iso27001 topic, visit your repo's landing page and select "manage topics."