• 0 Posts
  • 5 Comments
Joined 3 years ago
cake
Cake day: July 1st, 2023

help-circle



  • Whoever downvoted you probably doesn’t understand what you’re saying. This package doesn’t stipulate as to what regulations, frameworks, standards etc it is checking compliance against.

    If it doesn’t say what it’s checking it’s compliant against, how can it determine if you’re compliant to it or not?

    ISO 27001? SOC2? CIS Benchmarks? HIPAA? GDPR? NIST CSF? 800-53? PCI DSS? Cyber Essentials? Vendor guidance?

    This seems, at best, some general security checks but not mapped to any framework in particular.

    The Linux Security Audit Project is far more mature in this regard and maps checks to specific frameworks.