Skip to content

This repository houses CyStack's security controls along with their mappings to industry standards such as SOC2, ISO 27001, and HIPAA.

License

Notifications You must be signed in to change notification settings

cystack/security-controls

 
 

Repository files navigation

CyStack Security Controls

Overview

CyStack stands out as one of the premier cybersecurity companies in Vietnam, dedicated to fortifying digital defenses and safeguarding businesses against evolving cyber threats. With a focus on providing cutting-edge cybersecurity services and innovative security platforms, CyStack empowers organizations to streamline their cybersecurity actions and bolster their resilience in the face of cyberattacks.

This repository contains a comprehensive set of security controls developed by CyStack to help organizations enhance their security posture and achieve compliance with industry standards. These controls are meticulously designed and aligned with popular frameworks such as SOC2, ISO 27001, and HIPAA.

Data Format

Security Controls

The main CyStack Security Controls - CSC file contains:

  • metadata: version and other information of the release
  • controls: a list of security controls

Mappings

We facilitate the mapping of our CSC with the most popular security frameworks today. These mappings are located in the mappings directory. Each mapping file contains:

  • name: The name of the framework, such as SOC2.
  • principles: Top-level sections/principles of the standard, including:
    • name: The name of the principle.
    • section: The corresponding section in the official standard.
    • requirements: Requirements of this principle, consisting of a list of security controls.

Additionally, JSON schemas describing these files are provided for reference.

Credits

The security controls in this repository are built on the base of Vanta Control Set. We extend our sincere thanks to Vanta for their work.

About

This repository houses CyStack's security controls along with their mappings to industry standards such as SOC2, ISO 27001, and HIPAA.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published