GRC OBSERVABILITY
2 REPOS
CMPL54% NIST67% AI SYS2 THREATS5 LEAKS0
AI INVENTORY →
← REPOS
shipstuff/AOBuddy main · cca0580 · 13D AGO
  • MACHINE-READABLE
  • JSON (full state)
  • SARIF (code scanning)
  • OSCAL (assessment)
  • CSV
  • NIST CSF controls
  • EU AI Act articles
  • Risk register
  • Vulnerabilities
COMPLIANCE
13%
██░░░░░░░░░░░░ 13%
NIST CSF 2.0
44%
██████░░░░░░░░ 44%

NIST CSF 2.0 // 44% COMPLIANT

NIST ███████████░░░░░░░░░░░░░░ 44%
GOVERN
GOV ████░░░░░░░░░░░░ 25%
0P 1A 1F
IDENTIFY
IDE █████████░░░░░░░ 58%
3P 1A 2F
PROTECT
PRO ████████░░░░░░░░ 50%
2P 0A 2F
DETECT
DET ████████████████ 100%
1P 0A 0F
RESPOND
RES ░░░░░░░░░░░░░░░░ 0%
0P 0A 2F
RECOVER
REC ░░░░░░░░░░░░░░░░ 0%
0P 0A 1F

CONTROL DETAILS

IDCONTROLSTATUSSOC 2ISO 27001
GV.PO-01Governance and security policy documents exist[XX] FAILCC1.1, CC1.2, CC5.3A.5.1
GV.SC-01Third-party dependencies and services are inventoried and tracked[!!] PARTIALCC9.2A.5.19, A.5.20, A.5.21, A.5.22
ID.AM-01Infrastructure hosting is documented[XX] FAILCC6.1A.5.9
ID.AM-02Dependencies and third-party services are tracked[OK] PASSCC6.1A.5.9, A.8.19
ID.RA-01Dependency vulnerabilities are scanned[!!] PARTIALCC3.2, CC7.1A.8.8
ID.RA-02Known vulnerability databases are checked (npm audit, GitHub Advisory Database)[OK] PASSCC3.2A.5.6
ID.RA-08Vulnerability disclosure process + security contact published[XX] FAILCC7.3A.5.24, A.6.8
ID.IM-02Automated scanning runs on code changes[OK] PASSCC4.1, CC8.1A.8.8
PR.AA-01No secrets/credentials in source code[OK] PASSCC6.1, CC6.2A.5.16, A.5.17
PR.AA-05Branch protection and code review requirements[XX] FAILCC6.1, CC6.3A.5.15, A.8.3
PR.DS-01Data collection points are documented with retention policies[XX] FAILCC6.1, CC6.7A.5.10, A.8.24
PR.DS-02HTTPS enforced with valid certificate and HSTS[--] NOT-APPLICABLECC6.1, CC6.7A.8.24, A.8.20
PR.DS-10Security headers mitigate in-browser data leakage and tampering[--] NOT-APPLICABLECC6.1A.8.20, A.8.22, A.8.23
PR.PS-01Security configuration baseline is documented and scannable[OK] PASSCC7.1, CC8.1A.8.9
DE.CM-09Secrets scanning + dependency monitoring on every push/PR[OK] PASSCC7.1A.8.7, A.8.16
RS.MA-01Incident Response Plan exists[XX] FAILCC7.3, CC7.4A.5.24, A.5.26
RS.CO-02Vulnerability disclosure and security contact are published[XX] FAILCC7.3A.5.25, A.6.8
RC.RP-01IRP includes recovery procedures[XX] FAILCC7.5A.5.29, A.5.30

GAPS // 10 CONTROLS

IDSTATUSEVIDENCE
GV.PO-01[XX] FAILPrivacy Policy: missing, ToS: missing, security.txt: missing, Vuln Disclosure: missing, IRP: missing
GV.SC-01[!!] PARTIAL1 third-party services identified, 0 open advisories tracked. A supply-chain program additionally requires supplier agreements, risk tiering, and periodic review (not scanner-verifiable).
ID.AM-01[XX] FAILNo live site URL provided
ID.RA-01[!!] PARTIALCritical: 0, High: 1, Medium: 3
ID.RA-08[XX] FAILsecurity.txt: missing, Vulnerability Disclosure: missing
PR.AA-05[XX] FAILBranch protection: disabled, Required reviews: none
PR.DS-01[XX] FAIL10 data collection points. 10 with undefined retention.
RS.MA-01[XX] FAILIRP status: missing
RS.CO-02[XX] FAILsecurity.txt: missing, Vulnerability Disclosure: missing
RC.RP-01[XX] FAILIRP includes recovery section: no