Robuta

https://pages.nist.gov/OSCAL/ OSCAL - Open Security Controls Assessment Language open securityoscalcontrolsassessmentlanguage https://www.opensecurityarchitecture.org/blog/5/ Blog - Page 5 | Open Security Architecture Updates and insights from the Open Security Architecture community. blog pageopen securityarchitecture https://opensecurityarchitecture.org/foundations/policy-templates/ Policy Templates | Open Security Architecture Free NIST-mapped Information Security Policy and Acceptable Use Policy templates from Open Security Architecture. policy templatesopen securityarchitecture https://www.opensecurityarchitecture.org/patterns/sp-014/ Awareness and Training Pattern | Open Security Architecture Security architecture for building and sustaining an effective security awareness and training program. Covers role-based training, phishing simulation,... open securityawarenesstrainingpatternarchitecture https://opensecurityarchitecture.org/frameworks/fips-140/ FIPS 140-3 Mappings | Open Security Architecture FIPS 140-3 Security Requirements for Cryptographic Modules clause-to-control mappings. 11 clauses mapped to SP 800-53 controls. open securityfipsmappingsarchitecture https://opensecurityarchitecture.org/controls/si-17/ SI-17 - Fail-safe Procedures | Open Security Architecture Implement the indicated fail-safe procedures when the indicated failures occur: [Assignment: organization-defined parameters]. fail safeopen securitysiproceduresarchitecture https://www.opensecurityarchitecture.org/controls/ia-03/ IA-03 - Device Identification And Authentication | Open Security Architecture The information system identifies and authenticates specific devices before establishing a connection. device identificationopen securityiaauthenticationarchitecture https://www.opensecurityarchitecture.org/controls/pt-05/ PT-05 - Privacy Notice | Open Security Architecture privacy noticeopen securityptarchitecture https://opensecurityarchitecture.org/controls/ac-17/ AC-17 - Remote Access | Open Security Architecture The organization authorizes, monitors, and controls all methods of remote access to the information system. remote accessopen securityarchitecture https://www.elastic.co/blog/open-security-impact-elastic-ai-assistant Open Security impact: Elastic AI Assistant | Elastic Blog Learn how Elastic's commitment to Open Security increases accuracy, efficiency, and usability in the Elastic AI Assistant.... open securityai assistantimpactelasticblog https://opensecurityarchitecture.org/controls/ma-07/ MA-07 - Field Maintenance | Open Security Architecture Restrict or prohibit field maintenance on [Assignment: organization-defined parameters] to [Assignment: organization-defined parameters]. field maintenanceopen securityarchitecture https://www.opensecurityarchitecture.org/controls/pl-10/ PL-10 - Baseline Selection | Open Security Architecture Select a control baseline for the system. open securityplbaselineselectionarchitecture https://opensecurityarchitecture.org/foundations/links/231-security-metrics Home | Open Security Architecture Open Security Architecture - Reusable security patterns, control mappings, and capability models for proportionate, consistent, and traceable security... home opensecurityarchitecture https://opensecurityarchitecture.org/controls/au-05/ AU-05 - Response To Audit Processing Failures | Open Security Architecture The information system alerts appropriate organizational officials in the event of an audit processing failure and takes the following additional actions:... open securityauresponseprocessingfailures https://opensecurityarchitecture.org/controls/sc-39/ SC-39 - Process Isolation | Open Security Architecture Maintain a separate execution domain for each executing system process. open securityscprocessisolationarchitecture https://securitybrief.co.uk/story/cisco-mcafee-collaborate-open-security-platform Cisco & McAfee collaborate on open security platform A collaboration between Cisco and McAfee will share security incident and contextual information in real time in an effort to detect and stop threats. open securityciscomcafeecollaborateplatform https://opensecurityarchitecture.org/controls/sa-10/ SA-10 - Developer Configuration Management | Open Security Architecture The organization requires that information system developers create and implement a configuration management plan that controls changes to the system during... configuration managementopen securitysadeveloperarchitecture https://opensecurityarchitecture.org/controls/cp-04/ CP-04 - Contingency Plan Testing And Exercises | Open Security Architecture The organization: (i) tests and/or exercises the contingency plan for the information system [Assignment: organization-defined frequency, at least annually]... contingency planopen securitycptestingexercises https://www.opensecurityarchitecture.org/controls/ia-12/ IA-12 - Identity Proofing | Open Security Architecture a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in... identity proofingopen securityiaarchitecture https://opensecurityarchitecture.org/about/privacy-policy/ Privacy Policy | Open Security Architecture How we handle your data -- we collect very little and respect your privacy. privacy policyopen securityarchitecture https://www.opensecurityarchitecture.org/controls/ac-11/ AC-11 - Session Lock | Open Security Architecture The information system prevents further access to the system by initiating a session lock after [Assignment: organization-defined time period] of inactivity,... open securityacsessionlockarchitecture https://www.opensecurityarchitecture.org/controls/sa-23/ SA-23 - Specialization | Open Security Architecture Employ [Assignment: organization-defined parameters] on [Assignment: organization-defined parameters] supporting mission essential services or functions to... open securitysaspecializationarchitecture https://blog.radicallyopensecurity.com/ Radically Open Security Blog // Radically Open Security Blog, radically open securityblog https://www.opensecurityarchitecture.org/controls/sc-35/ SC-35 - External Malicious Code Identification | Open Security Architecture Include system components that proactively seek to identify network-based malicious code or malicious websites. malicious codeopen securityscexternalidentification https://www.opensecurityarchitecture.org/frameworks/cmmc-2/ CMMC 2.0 Mappings | Open Security Architecture Cybersecurity Maturity Model Certification 2.0 Level 2 clause-to-control mappings. 14 clauses mapped to SP 800-53 controls. open securitycmmcmappingsarchitecture https://www.opensecurityarchitecture.org/controls/ir-08/ IR-08 - Incident Response Plan | Open Security Architecture a. Develop an incident response plan that: 1. Provides the organization with a roadmap for implementing its incident response capability; 2. Describes the... incident response planopen securityirarchitecture https://www.opensecurityarchitecture.org/controls/sc-13/ SC-13 - Use Of Cryptography | Open Security Architecture For information requiring cryptographic protection, the information system implements cryptographic mechanisms that comply with applicable laws, Executive... open securityscusecryptographyarchitecture https://opensecurityarchitecture.org/controls/ac-18/ AC-18 - Wireless Access Restrictions | Open Security Architecture The organization: (i) establishes usage restrictions and implementation guidance for wireless technologies; and (ii) authorizes, monitors, controls wireless... wireless accessopen securityrestrictionsarchitecture https://stenciltown.omnigroup.com/stencils/open-security-architecture/ Stenciltown - Open Security Architecture A collection of free-forever stencils for OmniGraffle with creative commons licenses. Share your own and bookmark your favorites. open securitystenciltownarchitecture https://opensecurityconference.org/support/sponsorship/ Open Security Conference - Sponsorship Welcome to the Open Security Conference (osco), the people-centred international gathering for everyone interested in cybersecurity. Join us 5-8 November 2026... open securityconferencesponsorship https://www.opensecurityarchitecture.org/controls/si-02/ SI-02 - Flaw Remediation | Open Security Architecture The organization identifies, reports, and corrects information system flaws. open securitysiflawremediationarchitecture https://www.opensecurityarchitecture.org/blog/secure-scrum/ Secure Scrum | Open Security Architecture For 10 years agile development has been finding more and more followers and practitioners. It seems like a sure bet that SCRUM will be the leading process... open securitysecurescrumarchitecture https://www.opensecurityarchitecture.org/controls/sc-07/ SC-07 - Boundary Protection | Open Security Architecture The information system monitors and controls communications at the external boundary of the information system and at key internal boundaries within the system. open securityscboundaryprotectionarchitecture https://www.opensecurityarchitecture.org/blog/4/ Blog - Page 4 | Open Security Architecture Updates and insights from the Open Security Architecture community. blog pageopen securityarchitecture https://opensecurityarchitecture.org/patterns/sp-015/ Secure Remote Working | Open Security Architecture Comprehensive remote and hybrid working security pattern covering endpoint hardening, ZTNA and VPN architectures, BYOD and corporate device management, split... secure remoteopen securityworkingarchitecture https://www.opensecurityarchitecture.org/frameworks/mas-trm/ MAS TRM Mappings | Open Security Architecture MAS Technology Risk Management Guidelines clause-to-control mappings. 14 clauses mapped to SP 800-53 controls. open securitymastrmmappingsarchitecture https://opensecurityarchitecture.org/controls/sc-09/ SC-09 - Transmission Confidentiality | Open Security Architecture The information system protects the confidentiality of transmitted information. open securitysctransmissionconfidentialityarchitecture https://www.opensecurityarchitecture.org/controls/cm-02/ CM-02 - Baseline Configuration | Open Security Architecture The organization develops, documents, and maintains a current baseline configuration of the information system. open securitycmbaselineconfigurationarchitecture https://www.deepwatch.com/deepwatch-unlocks-new-capabilities-and-increased-flexibility-with-its-open-security-data-architecture/ Deepwatch Introduces its Open Security Data Architecture Mar 5, 2024 - Deepwatch introduces its Open Security Data Architecture to unlock new capabilities and flexibility, delivering optimal outcomes for cyber resilience. open securitydeepwatchintroducesdataarchitecture https://opensecurityarchitecture.org/patterns/sp-034/ Cyber Resilience | Open Security Architecture Enterprise architecture pattern for designing systems that survive cyber attacks, maintain critical operations under degraded conditions, and recover rapidly.... cyber resilienceopen securityarchitecture https://www.opensecurityarchitecture.org/patterns/sp-032/ Modern Authentication | Open Security Architecture Enterprise authentication architecture pattern covering directory services, federation, and token-based authentication using OIDC, OAuth 2.0, and JWT. Provides... open securitymodernauthenticationarchitecture https://opensecuritycontroller.org/ Open Security Controller open securitycontroller https://www.opensecurityarchitecture.org/controls/pl-11/ PL-11 - Baseline Tailoring | Open Security Architecture Tailor the selected control baseline by applying specified tailoring actions. open securityplbaselinetailoringarchitecture https://www.opensecurityarchitecture.org/controls/pt-01/ PT-01 - Policy and Procedures | Open Security Architecture policy and proceduresopen securityptarchitecture https://opensecurityarchitecture.org/controls/sc-37/ SC-37 - Out-of-band Channels | Open Security Architecture Employ the following out-of-band channels for the physical delivery or electronic transmission of [Assignment: organization-defined parameters] to [Assignment:... out of bandopen securityscchannelsarchitecture https://www.opensecurityarchitecture.org/controls/au-14/ AU-14 - Session Audit | Open Security Architecture a. Provide and implement the capability for [Assignment: organization-defined users or roles] to [Selection (one or more): record; view; hear; log] the content... open securityausessionarchitecture https://opensecurityarchitecture.org/patterns/sp-042/ Third Party Risk Management | Open Security Architecture Architecture pattern for managing security risk from third party vendors, service providers, and supply chain dependencies. Covers vendor security assessment... third party risk managementopen securityarchitecture https://opensecurityarchitecture.org/controls/ac-24/ AC-24 - Access Control Decisions | Open Security Architecture Establish procedures to ensure [Assignment: organization-defined access control decisions] are applied to each access request prior to access enforcement. access controlopen securitydecisionsarchitecture https://2025.opensecurityconference.org/coc Open Security Conference - Code of Conduct Welcome to the Open Security Conference (osco), the people-centred international gathering for everyone interested in cybersecurity. Join us 2-5 October 2025... open securityconferencecodeconduct https://www.opensecurityarchitecture.org/patterns/sp-011/ Cloud Computing Pattern | Open Security Architecture Security architecture for organisations consuming or providing cloud services, addressing the shared responsibility model, data sovereignty, identity... cloud computingopen securitypatternarchitecture https://www.opensecurityarchitecture.org/about/who-uses-osa/ Who uses OSA? | Open Security Architecture Security professionals, consultants, students, and academics worldwide rely on OSA patterns and controls. open securityusesosaarchitecture https://www.opensecurityarchitecture.org/attack/ MITRE ATT&CK Coverage Matrix | Open Security Architecture open securitymitreattckcoverage https://opensecurityarchitecture.org/controls/cp-01/ CP-01 - Contingency Planning Policy And Procedures | Open Security Architecture The organization develops, disseminates, and periodically reviews/updates: (i) a formal, documented, contingency planning policy that addresses purpose, scope,... policy and procedurescontingency planningopen securitycparchitecture https://cdnapisec.kaltura.com/html5/html5lib/v2.101/mwEmbedFrame.php/p/684682/uiconf_id/31013851/entry_id/1_e861yoyu?wid=_684682&iframeembed=true&playerId=kaltura_player_1684176576&entry_id=1_e861yoyu&flashvars%5BstreamerType%5D=auto Open Security Controls Assessment Language 4th Annual OSCAL Conference and Workshop open securitycontrolsassessmentlanguage https://www.opensecurityarchitecture.org/controls/pm-28/ PM-28 - Risk Framing | Open Security Architecture a. Identify and document: 1. Assumptions affecting risk assessments, risk responses, and risk monitoring; 2. Constraints affecting risk assessments, risk... open securitypmriskframingarchitecture https://www.opensecurityarchitecture.org/blog/declassified-1970-us-dod-cybersecurity-document-still-relevant/ Declassified 1970 US DoD cybersecurity document still relevant | Open Security Architecture Just read a great article on Ars Technica covering a 1970 DoD analysis of computer system vulnerabilities... us dodopen securitycybersecurity https://www.opensecurityarchitecture.org/controls/ac-15/ AC-15 - Automated Marking | Open Security Architecture The information system marks output using standard naming conventions to identify any special dissemination, handling, or distribution instructions. open securityacautomatedmarkingarchitecture https://opensecurityarchitecture.org/controls/si-10/ SI-10 - Information Accuracy, Completeness, Validity, And Authenticity | Open Security Architecture The information system checks information for accuracy, completeness, validity, and authenticity. open securitysiinformationaccuracycompleteness https://opensecurityarchitecture.org/library/0802control-catalogue/32-08-02-ac-10 Home | Open Security Architecture Open Security Architecture - Reusable security patterns, control mappings, and capability models for proportionate, consistent, and traceable security... home opensecurityarchitecture https://www.opensecurityarchitecture.org/controls/pe-12/ PE-12 - Emergency Lighting | Open Security Architecture The organization employs and maintains automatic emergency lighting that activates in the event of a power outage or disruption and that covers emergency exits... emergency lightingopen securityarchitecture https://www.opensecurityarchitecture.org/controls/pe-21/ PE-21 - Electromagnetic Pulse Protection | Open Security Architecture Employ [Assignment: organization-defined parameters] against electromagnetic pulse damage for [Assignment: organization-defined parameters]. electromagnetic pulseopen securityprotectionarchitecture https://www.opensecurityarchitecture.org/frameworks/apra-cps-234/coverage/ APRA CPS 234 Coverage Analysis | Open Security Architecture SP 800-53 coverage analysis for APRA Prudential Standard CPS 234 Information Security. 11 clauses analysed, 79% average coverage. coverage analysisopen securityapracpsarchitecture https://2024.opensecurityconference.org/support/ Open Security Conference - Support Us Welcome to the Open Security Conference (osco), the people-centred international gathering for everyone interested in cybersecurity. Join us 4-6 October 2024... open securityconference supportus https://www.opensecurityarchitecture.org/frameworks/bot-cyber/coverage/ BOT Cyber Resilience Coverage Analysis | Open Security Architecture SP 800-53 coverage analysis for Bank of Thailand Cyber Resilience Guidelines for Financial Institutions. 26 clauses analysed, 77% average coverage. cyber resiliencecoverage analysisopen securitybotarchitecture https://www.opensecurityarchitecture.org/controls/sc-43/ SC-43 - Usage Restrictions | Open Security Architecture Establish usage restrictions and implementation guidelines for the following system components: [Assignment: organization-defined parameters] ; and Authorize,... usage restrictionsopen securityscarchitecture https://www.opensecurityarchitecture.org/blog/cloud-computing-research/ Cloud Computing research | Open Security Architecture I've been spending time researching the Cloud Computing pattern in the last week or so and I must say I am learning a lot. I've been a big fan of Nick Carr... cloud computingopen securityresearcharchitecture https://opensecurityarchitecture.org/attack/?pattern=SP-035 MITRE ATT&CK Coverage Matrix | Open Security Architecture open securitymitreattckcoverage https://www.amd.com/en/blogs/2024/amd-s-commitment-to-open-security-technologies-in-.html The AMD Commitment to Open Security Technologies in the Data Center Expanding the Horizon of Data Center Security In recent years, the complexity of data center security has surged, presenting new challenges and opportunities.... open securityin dataamdcommitmenttechnologies https://www.opensecurityarchitecture.org/controls/cm-13/ CM-13 - Data Action Mapping | Open Security Architecture Develop and document a map of system data actions. action mappingopen securitycmdataarchitecture https://opensecurityarchitecture.org/foundations/ Foundations | Open Security Architecture Core concepts and principles underlying the Open Security Architecture framework. open securityfoundationsarchitecture https://opensecurityarchitecture.org/library/0802control-catalogue/64-08-02-sc-04 Home | Open Security Architecture Open Security Architecture - Reusable security patterns, control mappings, and capability models for proportionate, consistent, and traceable security... home opensecurityarchitecture https://www.opensecurityarchitecture.org/controls/cp-09/ CP-09 - Information System Backup | Open Security Architecture The organization conducts backups of user-level and system-level information (including system state information) contained in the information system... information systemopen securitycpbackuparchitecture https://www.uml.edu/news/press-releases/2025/socrelease100725.aspx UMass Lowell to Open Security Operations Center | News security operations centerumass lowellopennews https://www.opensecurityarchitecture.org/controls/ Control Catalogue | Open Security Architecture NIST 800-53 Rev 5 control catalogue with mappings to ISO 27001, CIS Controls, NIST CSF, and more. open securitycontrolcataloguearchitecture https://www.opensecurityarchitecture.org/controls/ac-25/ AC-25 - Reference Monitor | Open Security Architecture Implement a reference monitor for [Assignment: organization-defined access control policies] that is tamperproof, always invoked, and small enough to be... open securityacreferencemonitorarchitecture https://opensecurityarchitecture.org/controls/sc-13/ SC-13 - Use Of Cryptography | Open Security Architecture For information requiring cryptographic protection, the information system implements cryptographic mechanisms that comply with applicable laws, Executive... open securityscusecryptographyarchitecture https://www.opensecurityarchitecture.org/frameworks/ferc-cip/coverage/ FERC CIP Orders Coverage Analysis | Open Security Architecture SP 800-53 coverage analysis for FERC Orders Directing NERC CIP Standard Development. 8 clauses analysed, 70% average coverage. coverage analysisopen securityfercciporders https://www.opensecurityarchitecture.org/controls/pm-23/ PM-23 - Data Governance Body | Open Security Architecture Establish a Data Governance Body consisting of [Assignment: organization-defined roles] with [Assignment: organization-defined responsibilities]. data governanceopen securitypmbodyarchitecture https://noxsystems.com/tag/open-security-architecture-2/ Open Security Architecture Archive - NOX SYSTEMS | Security beyond limits open securityarchitecturearchivenoxsystems https://www.opensecurityarchitecture.org/controls/pm-06/ PM-06 - Measures of Performance | Open Security Architecture Develop, monitor, and report on the results of information security and privacy measures of performance. open securitypmmeasuresperformancearchitecture https://www.opensecurityarchitecture.org/controls/sr-12/ SR-12 - Component Disposal | Open Security Architecture open securitysrcomponentdisposalarchitecture https://www.prosegur.co.uk/security/events/mutua-madrid-open Mutua Madrid Open | Security Events | Prosegur UK Discover our security solutions at the Mutua Madrid Open, Prosegur UK. mutua madrid opensecurity eventsproseguruk https://www.opensecurityarchitecture.org/controls/si-11/ SI-11 - Error Handling | Open Security Architecture The information system identifies and handles error conditions in an expeditious manner without providing information that could be exploited by adversaries. error handlingopen securitysiarchitecture https://opensecurityarchitecture.org/frameworks/doe-c2m2/ DOE C2M2 v2.1 Mappings | Open Security Architecture DOE Cybersecurity Capability Maturity Model v2.1 clause-to-control mappings. 10 clauses mapped to SP 800-53 controls. open securitydoemappingsarchitecture https://www.opensecurityarchitecture.org/controls/ac-13/ AC-13 - Supervision And Review -- Access Control | Open Security Architecture The organization supervises and reviews the activities of users with respect to the enforcement and usage of information system access controls. access controlopen securitysupervisionreviewarchitecture https://www.opensecurityarchitecture.org/blog/updated-icon-pack/ Updated icon pack | Open Security Architecture There is a new icon pack available (11.02) that includes the icons created for the Industrial Control Systems pattern. icon packopen securityupdatedarchitecture https://opensecurityarchitecture.org/ Home | Open Security Architecture Open Security Architecture - Reusable security patterns, control mappings, and capability models for proportionate, consistent, and traceable security... home opensecurityarchitecture https://www.opensecurityarchitecture.org/controls/pe-11/ PE-11 - Emergency Power | Open Security Architecture The organization provides a short-term uninterruptible power supply to facilitate an orderly shutdown of the information system in the event of a primary power... emergency poweropen securityarchitecture https://www.opensecurityarchitecture.org/frameworks/cbn-csf/ CBN CSF Mappings | Open Security Architecture CBN Risk-Based Cybersecurity Framework for DMBs and PSBs clause-to-control mappings. 25 clauses mapped to SP 800-53 controls. open securitycbncsfmappingsarchitecture https://www.opensecurityarchitecture.org/controls/ca-03/ CA-03 - Information System Connections | Open Security Architecture The organization authorizes all connections from the information system to other information systems outside of the accreditation boundary through the use of... information systemopen securitycaconnectionsarchitecture https://2024.opensecurityconference.org/open-space/ Open Security Conference - Open Space Welcome to the Open Security Conference (osco), the people-centred international gathering for everyone interested in cybersecurity. Join us 4-6 October 2024... open securityconferencespace https://www.opensecurityarchitecture.org/api/ API Documentation | Open Security Architecture REST API for accessing OSA security patterns, NIST 800-53 controls, and compliance framework mappings api documentationopen securityarchitecture https://www.opensecurityarchitecture.org/controls/sa-02/ SA-02 - Allocation Of Resources | Open Security Architecture The organization determines, documents, and allocates as part of its capital planning and investment control process, the resources required to adequately... open securitysaallocationresourcesarchitecture https://crosscon.eu/ Cross-platform Open Security Stack for Connected Devices | Crosscon cross platformopen securityconnected devicesstack https://www.opensecurityarchitecture.org/controls/au-01/ AU-01 - Audit And Accountability Policy And Procedures | Open Security Architecture The organization develops, disseminates, and periodically reviews/updates: (i) a formal, documented, audit and accountability policy that addresses purpose,... accountability policyopen securityauproceduresarchitecture https://opensecurityconference.org/location/ Open Security Conference - Location Welcome to the Open Security Conference (osco), the people-centred international gathering for everyone interested in cybersecurity. Join us 5-8 November 2026... open securityconferencelocation https://www.opensecurityarchitecture.org/controls/pm-20/ PM-20 - Dissemination of Privacy Program Information | Open Security Architecture Maintain a central resource page on the organization's principal public website that serves as a central source of information for the organization's privacy... privacy programopen securitypmdisseminationinformation https://www.opensecurityarchitecture.org/patterns/sp-046/ External Attack Surface Management | Open Security Architecture Comprehensive pattern for discovering, monitoring, and managing an organisation's internet-facing digital assets. Covers automated asset discovery, DNS and... external attack surfaceopen securitymanagementarchitecture https://www.opensecurityarchitecture.org/controls/pe-18/ PE-18 - Location Of Information System Components | Open Security Architecture The organization positions information system components within the facility to minimize potential damage from physical and environmental hazards and to... information systemopen securitylocationcomponentsarchitecture https://www.opensecurityarchitecture.org/controls/sa-04/ SA-04 - Acquisitions | Open Security Architecture The organization includes security requirements and/or security specifications, either explicitly or by reference, in information system acquisition contracts... open securitysaacquisitionsarchitecture