Skip to content

api-evangelist/cybersecurity-standards

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

9 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Cybersecurity Standards (cybersecurity-standards)

Cybersecurity Standards captures the public, machine-readable, and reference frameworks that establish best practices for protecting information systems, networks, software, and data from cyber threats. The landscape is anchored by NIST publications (CSF 2.0, SP 800-53, 800-171, 800-218 SSDF, RMF), ISO/IEC 27001 / 27002, the CIS Critical Security Controls and Benchmarks, OWASP Top 10 and ASVS, PCI DSS, HITRUST CSF, SOC 2 Trust Services Criteria, and FedRAMP / StateRAMP cloud authorizations.

URL: Visit APIs.json URL

Scope

  • Type: Index
  • Position: Reference
  • Access: 3rd-Party
  • x-type: topic

Tags

  • CIS Controls, Compliance, CSF, Cybersecurity, FedRAMP, Frameworks, HIPAA, HITRUST, Information Security, ISO 27001, ISO 27002, NIST, NIST 800-171, NIST 800-218, NIST 800-53, OSCAL, OWASP, PCI DSS, Risk Management, SOC 2, SSDF, Standards

Timestamps

  • Created: 2025-01-01
  • Modified: 2026-04-28

APIs / Standards

NIST Cybersecurity Framework (CSF) 2.0

Voluntary risk-based framework organizing cybersecurity activities into six core functions (Govern, Identify, Protect, Detect, Respond, Recover).

NIST SP 800-53 Security and Privacy Controls (Rev. 5)

Catalog of security and privacy controls used as the basis of FedRAMP and RMF. Available in machine-readable OSCAL.

NIST SP 800-171 Protecting CUI

Requirements for protecting Controlled Unclassified Information in non-federal systems. Foundation of CMMC.

NIST SP 800-218 SSDF

Secure Software Development Framework referenced by EO 14028 procurement attestations.

ISO/IEC 27001

International standard for information security management systems (ISMS). 2022 revision aligns with ISO/IEC 27002:2022 controls.

CIS Critical Security Controls and Benchmarks

Prescriptive controls (v8.1) and benchmarks for OSes, cloud platforms, and applications.

OWASP Top 10 and ASVS

Web application and API risk lists plus the Application Security Verification Standard.

PCI DSS 4.0.1

Payment Card Industry Data Security Standard for cardholder data environments.

SOC 2 Trust Services Criteria

AICPA reporting framework against Security, Availability, Processing Integrity, Confidentiality, Privacy.

FedRAMP

Standardized approach for U.S. federal agencies to authorize cloud services, anchored on NIST 800-53 baselines.

Capabilities

  • Map organizational controls to multiple frameworks (NIST, ISO, CIS, SOC 2)
  • Author and exchange machine-readable controls via OSCAL
  • Demonstrate FedRAMP, PCI DSS, SOC 2, ISO 27001 compliance
  • Reference OWASP Top 10 in application security reviews
  • Track CMMC alignment via NIST 800-171 implementation

Use Cases

  • Building a unified compliance program across cloud customers
  • Procurement attestations for federal contracts (EO 14028, FedRAMP)
  • Vendor risk assessments using SOC 2 / ISO 27001 reports
  • Application security baselines using OWASP ASVS
  • Translating CSF outcomes to control implementations in 800-53 / ISO 27002

Common Resources

Maintainers

FN: Kin Lane

Email: kin@apievangelist.com

About

Cybersecurity Standards captures the public, machine-readable, and reference frameworks that establish best practices for protecting information systems, networks, software, and data from cyber threats. The landscape is anchored by U.S.

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors