diff --git a/docs/FRAMEWORK-COVERAGE.md b/docs/FRAMEWORK-COVERAGE.md index 3144716..2f10041 100644 --- a/docs/FRAMEWORK-COVERAGE.md +++ b/docs/FRAMEWORK-COVERAGE.md @@ -2,7 +2,7 @@ > **Auto-generated.** Regenerated by `node plugins/grc-engineer/scripts/generate-coverage.js`. Do not hand-edit — your changes will be overwritten on the next release. -Last generated: 2026-04-18 +Last generated: 2026-07-19 This page tracks which of the 249 frameworks in the [Secure Controls Framework](https://securecontrolsframework.com) crosswalk have a dedicated plugin in this repo. Frameworks without a dedicated plugin are **already usable today** via `/grc-engineer:gap-assessment ` through the SCF crosswalk. @@ -11,8 +11,8 @@ This page tracks which of the 249 frameworks in the [Secure Controls Framework]( | | | |---|---| | Total SCF-mapped frameworks | 249 | -| With dedicated plugin | **15** (6.0%) | -| Crosswalk-only (no plugin yet) | 234 | +| With dedicated plugin | **28** (11.2%) | +| Crosswalk-only (no plugin yet) | 221 | | Shipped plugins without SCF mapping | 6 | ### By depth @@ -20,8 +20,8 @@ This page tracks which of the 249 frameworks in the [Secure Controls Framework]( | Depth | Count | Description | |---|---|---| | Full | 0 | Framework-native workflow commands + Reference content | -| Reference | 15 | Scope + evidence checklist + framework-specific SKILL | -| Stub | 0 | Scaffolded delegation to `/grc-engineer:gap-assessment` | +| Reference | 26 | Scope + evidence checklist + framework-specific SKILL | +| Stub | 2 | Scaffolded delegation to `/grc-engineer:gap-assessment` | See [Framework Plugin Guide](FRAMEWORK-PLUGIN-GUIDE.md) for depth definitions and level-up checklists. @@ -29,21 +29,34 @@ See [Framework Plugin Guide](FRAMEWORK-PLUGIN-GUIDE.md) for depth definitions an | Namespace | Depth | SCF framework ID | Display name | |---|---|---|---| +| `/au-apra-cps-234:` | reference | `apac-aus-ps-cps-234-2019` | Australia - Prudential Standard CPS 234 (2019) | +| `/ch-fadp:` | stub | `emea-che-fadp-2025` | Switzerland - FADP | | `/cis-controls:` | reference | `general-cis-csc-8-1` | Critical Security Controls (CSC) (v8.1) | | `/cmmc:` | reference | `usa-federal-dow-cmmc-2-level-2` | Cybersecurity Maturity Model Certification (CMMC) 2.0 - Level 2 | | `/csa-ccm:` | reference | `general-csa-cmm-4-1-0` | Cloud Controls Matrix (CCM) (v4.1.0) | +| `/cyber-essentials-plus:` | reference | `emea-gbr-ce-2021` | UK NCSC Cyber Essentials Plus (CE+) v3.3 Danzell | | `/dora:` | reference | `emea-eu-dora-2023` | EU Digital Operational Resilience Act (DORA) (2023) | | `/essential8:` | reference | `apac-aus-essential-8-2024` | Australia - Essential Eight (2024) | +| `/eu-nis2:` | reference | `emea-eu-nis2-2022` | EU NIS2 Directive (2022) | | `/fedramp-rev5:` | reference | `usa-federal-gsa-fedramp-5-mod` | FedRAMP R5 - Moderate Baseline | | `/gdpr:` | reference | `emea-eu-gdpr-2016` | EU General Data Protection Regulation (GDPR) (2016) | | `/glba:` | reference | `usa-federal-law-glba-cfr-314-2023` | Gramm Leach Bliley Act (GLBA) (2023) | +| `/ind-dpdpa:` | reference | `apac-ind-dpdpa-2023` | India - DPDPA (2023) | | `/ismap:` | reference | `apac-jpn-ismap` | Japan - Information System Security Management and Assessment Program (ISMAP) | | `/iso27001:` | reference | `general-iso-27001-2022` | ISO 27001 (2022) | +| `/jp-appi:` | reference | `apac-jpn-ppi-2020` | Japan - Act on the Protection of Personal Information (2020) | | `/nist-800-53:` | reference | `general-nist-800-53-r5-2` | NIST SP 800-53 R5 | +| `/nist-csf-20:` | reference | `general-nist-csf-2-0` | NIST Cybersecurity Framework (v2.0) | | `/nydfs:` | reference | `usa-state-ny-dfs-23-nycrr500-2023-amd2` | New York Department of Financial Services 23NYCRR Part 500 (2023 Amendment 2) | | `/pci-dss:` | reference | `general-pci-dss-4-0-1` | Payment Card Industry Data Security Standard (PCI DSS) (v4.01) | +| `/sg-mas-trm:` | reference | `apac-sgp-mas-trm-2021` | Singapore - Monitory Authority of Singapore (MAS) Technology Risk Management (TRM) Guidelines (2021) | | `/singapore-pdpa:` | reference | `apac-sgp-pdpa-2012` | Singapore - Personal Data Protection Ac (PDPA) (2012) | | `/soc2:` | reference | `general-aicpa-tsc-2017` | Trust Services Criteria (TSC) (2017) | +| `/us-ccpa:` | reference | `usa-state-ca-ccpa-cpra-2026` | California Consumer Privacy Act (CCPA) (2026) | +| `/us-finra:` | stub | `usa-federal-sro-finra` | FINRA Cybersecurity Rules | +| `/us-hipaa-security:` | reference | `US-HIPAA-Security` | US HIPAA Security Rule (45 CFR Part 164, Subpart C) | +| `/us-nerc-cip:` | reference | `usa-federal-nerc-cip-2024` | NERC Critical Infrastructure Protection (CIP) (2024) | +| `/us-sox:` | reference | `usa-federal-law-sox-2002` | SOX (2002) | ### Shipped without SCF mapping @@ -60,7 +73,7 @@ These plugins exist in the marketplace but do not have a `framework_metadata.scf ## Not started -234 frameworks are supported today via the SCF crosswalk but have no dedicated plugin. To adopt one: +221 frameworks are supported today via the SCF crosswalk but have no dedicated plugin. To adopt one: ```bash node plugins/grc-engineer/scripts/scaffold-framework.js @@ -72,7 +85,7 @@ Or keep using the crosswalk directly: /grc-engineer:gap-assessment "" ``` -### Americas — 73 frameworks +### Americas — 70 frameworks
Expand @@ -83,11 +96,11 @@ Or keep using the crosswalk directly: | `americas-bhs-dpa-2003` | Bahamas - DPA (2003) | 18 → 5 | | `americas-bmu-mba-coc-2020` | Bermuda - Bermuda Monetary Authority Code of Conduct (2020) | 61 → 37 | | `americas-bra-lgpd-2018` | Brazil - General Data Protection Law (LGPD) (2018) | 33 → 55 | -| `usa-state-ca-ccpa-cpra-2026` | California Consumer Privacy Act (CCPA) (2026) | 258 → 623 | | `usa-state-ca-sb1386-2002` | California SB1386 (2002) | 4 → 6 | | `usa-state-ca-sb327-2018` | California SB327 (2018) | 3 → 7 | | `americas-can-itsp-10-171-2025` | Canada - ITSP.10.171 (2025) | 407 → 275 | | `americas-can-osfi-b13-2022` | Canada - OSFI B-13 (2022) | 150 → 77 | +| `amaericas-can-osfi-self-assessment` | Canada - OSFI Cyber Security Self-Assessment Guidance | 141 → 88 | | `americas-can-pipeda-2000` | Canada - Personal Information Protection and Electronic Documents Act (PIPEDA) (2000) | 28 → 17 | | `usa-federal-dow-cert-rmm-1-2` | CERT-RMM (v1.2) | 85 → 753 | | `usa-federal-law-coppa-2024` | Children's Online Privacy Protection Act (COPPA) (2024) | 10 → 8 | @@ -117,7 +130,6 @@ Or keep using the crosswalk directly: | `usa-federal-gsa-fedramp-5-high` | FedRAMP R5 - High Baseline | 561 → 490 | | `usa-federal-gsa-fedramp-5-li-saas` | FedRAMP R5 - Li-SAAS Baseline | 383 → 269 | | `usa-federal-gsa-fedramp-5-low` | FedRAMP R5 - Low Baseline | 383 → 269 | -| `usa-federal-sro-finra` | FINRA Cybersecurity Rules | 17 → 39 | | `usa-federal-fda-21-cfr-part-11-2025` | Food & Drug Administration (FDA) 21 CFR Part 11 (2025) | 62 → 28 | | `usa-federal-hhs-45-cfr-155-260-2016` | HHS § 155.260 (2016) | 36 → 44 | | `usa-federal-law-hipaa-simplification-2013` | HIPAA Administrative Simplification (2013) | 170 → 576 | @@ -130,7 +142,6 @@ Or keep using the crosswalk directly: | `usa-state-ma-201-cmr-17-2008` | Massachusetts 201 CMR 17.00 (2008) | 53 → 37 | | `americas-mex-fdpa-2010` | Mexico - Federal Law on Protection of Personal Data held by Private Parties (2010) | 23 → 25 | | `usa-federal-nispom-2020` | National Industrial Security Program Operating Manual (NISPOM) (2020) | 35 → 226 | -| `usa-federal-nerc-cip-2024` | NERC Critical Infrastructure Protection (CIP) (2024) | 122 → 204 | | `usa-state-nv-regulation-5-2024` | Nevada Operation of Gaming Establishment (NOGE) Regulation 5.260 (2024) | 20 → 11 | | `usa-state-nv-sb220-2019` | Nevada SB220 (2019) | 3 → 4 | | `usa-state-ny-shield-act-2019` | New York SHIELD Act (SB S5575B) (2019) | 28 → 45 | @@ -138,7 +149,6 @@ Or keep using the crosswalk directly: | `usa-state-or-cpa-2023` | Oregon Consumer Privacy Act (SB 619) (2023) | 34 → 75 | | `usa-federal-dow-safeguarding-nnpi-2010` | Safeguarding of NNPI (2010) | 32 → 68 | | `usa-federal-sec-cybersecurity-rule-2023` | SEC Cybersecurity Rule (2023) | 40 → 15 | -| `usa-federal-law-sox-2002` | SOX (2002) | 4 → 17 | | `usa-state-tn-tipa-2025` | Tennessee Information Protection Act (TIPA) (2025) | 29 → 76 | | `usa-state-tx-cdpa-2025` | Texas Consumer Data Protection Act (2025) | 28 → 89 | | `usa-state-tx-dir-security-control-standards-catalog-2-2` | Texas DIR Security Control Standards Catalog (v2.2) | 238 → 228 | @@ -154,7 +164,7 @@ Or keep using the crosswalk directly:
-### APAC — 26 frameworks +### APAC — 22 frameworks
Expand @@ -165,16 +175,13 @@ Or keep using the crosswalk directly: | `apac-aus-privacy-act-1998` | Australia - Privacy Act of 1998 | 23 → 12 | | `apac-aus-privacy-principles-2026` | Australia - Privacy Principles (2026) | 26 → 13 | | `apac-aus-ps-cps-230-2023` | Australia - Prudential Standard CPS 230 (2023) | 41 → 98 | -| `apac-aus-ps-cps-234-2019` | Australia - Prudential Standard CPS 234 (2019) | 52 → 38 | | `apac-chn-cybersecurity-law-2017` | China - Cybersecurity Law (2017) | 27 → 34 | | `apac-chn-data-security-law-2021` | China - Data Security Law (2021) | 15 → 24 | | `apac-chn-csnip-2012` | China - Decision on Strengthening Network Information Protection (2012) | 10 → 4 | | `apac-chn-pipl-2021` | China - Personal Information Protection Law (2021) | 79 → 100 | | `apac-hkg-pdo-2022` | Hong Kong - Personal Data Ordinance (2022) | 14 → 14 | -| `apac-ind-dpdpa-2023` | India - DPDPA (2023) | 41 → 96 | | `apac-ind-privacy-rules-2011` | India - Privacy Rules (2011) | 12 → 5 | | `apac-ind-sebi-2024` | India - SEBI CSCRF (2024) | 170 → 129 | -| `apac-jpn-ppi-2020` | Japan - Act on the Protection of Personal Information (2020) | 58 → 134 | | `apac-mys-pdpa-2010` | Malaysia - Personal Data Protection Act (PDPA) (2010) | 25 → 12 | | `apac-nzl-hisf-suppliers-2023` | New Zealand - HISF Guidance for Suppliers (2023) | 101 → 68 | | `apac-nzl-hisf-microsmall-2023` | New Zealand - HISF MicroSmall (2023) | 32 → 21 | @@ -183,13 +190,12 @@ Or keep using the crosswalk directly: | `apac-nzl-privacy-act-2020` | New Zealand - Privacy Act (2020) | 20 → 121 | | `apac-phl-dpa-2012` | Philippines - Data Privacy Act (DPA) (2012) | 30 → 16 | | `apac-sgp-cyber-hygiene-practice-2019` | Singapore - Cyber Hygiene Practice (2019) | 21 → 13 | -| `apac-sgp-mas-trm-2021` | Singapore - Monitory Authority of Singapore (MAS) Technology Risk Management (TRM) Guidelines (2021) | 214 → 280 | | `apac-kor-pipa-2011` | South Korea - Personal Information Protection Act (PIPA) (2011) | 37 → 22 | | `apac-twn-pdpa-2025` | Taiwan - Personal Data Protection Act (PDPA) (2025) | 23 → 8 |
-### EMEA — 49 frameworks +### EMEA — 47 frameworks
Expand @@ -202,7 +208,6 @@ Or keep using the crosswalk directly: | `emea-eu-cyber-resilience-act-annexes-2022` | EU Cyber Resilience Act Annexes (CRA Annexes) (2022) | 23 → 117 | | `emea-eu-eba-ict-srm-2025` | EU EBA Guidelines on ICT and Security Risk Management (2025) | 148 → 150 | | `emea-eu-nis2-annex-2024` | EU NIS2 Annex (2024) | 223 → 351 | -| `emea-eu-nis2-2022` | EU NIS2 Directive (2022) | 68 → 30 | | `emea-us-psd2-2015` | EU Second Payment Services Directive (PSD2) (2015) | 30 → 10 | | `emea-deu-bsrit-2017` | Germany - Banking Supervisory Requirements for IT (2017) | 91 → 93 | | `emea-deu-c5-2020` | Germany - Cloud Computing Compliance Controls Catalogue (C5) (2020) | 239 → 121 | @@ -232,7 +237,6 @@ Or keep using the crosswalk directly: | `emea-esp-ccn-stic-825-2023` | Spain - ICT Security Guide CCN-STIC 825 (2023) | 99 → 75 | | `emea-esp-decree-1720-2007` | Spain - Royal Decree 1720/2007 | 17 → 16 | | `emea-esp-decree-311-2022` | Spain - Royal Decree 311/2022 | 73 → 128 | -| `emea-che-fadp-2025` | Switzerland - FADP | 16 → 9 | | `emea-tur-lppd-2016` | Turkey - Law on the Protection of Personal Data (LPPD) (2016) | 17 → 10 | | `emea-uae-niaf-2023` | UAE - National Information Assurance Framework (NIAF) (2023) | 20 → 15 | | `emea-gbr-caf-4-0` | UK - Cyber Assessment Framework (CAF) (v4.0) | 66 → 66 | @@ -247,7 +251,7 @@ Or keep using the crosswalk directly:
-### Global — 86 frameworks +### Global — 84 frameworks
Expand @@ -255,7 +259,6 @@ Or keep using the crosswalk directly: |---|---|---| | `general-aicpa-pmf-2020` | AICPA Privacy Management Framework (PMF) (2020) | 109 → 123 | | `general-apec-privacy-framework-2015` | APEC Privacy Framework (2015) | 14 → 25 | -| `amaericas-can-osfi-self-assessment` | Canada - OSFI Cyber Security Self-Assessment Guidance | 141 → 88 | | `general-coso-2013` | Committee of Sponsoring Organizations (COSO) (2013) | 104 → 17 | | `general-mpa-csbp-5-3-1` | Content Security Best Practices Common Guidelines (v5.3.1) | 232 → 81 | | `general-cobit-2019` | Control Objectives for Information and Related Technologies (COBIT) (2019) | 190 → 230 | @@ -291,7 +294,6 @@ Or keep using the crosswalk directly: | `general-mitre-att&ck-16-1` | MITRE ATT&CK (v16.1) | 108 → 511 | | `general-nist-100-1-ai-rmf` | NIST AI 100-1 (AI RMF 1.0) | 158 → 91 | | `general-nist-600-1-gen-ai-profile` | NIST AI 600-1 | 139 → 250 | -| `general-nist-csf-2-0` | NIST Cybersecurity Framework (v2.0) | 250 → 134 | | `general-nist-privacy-framework-1-0` | NIST Privacy Framework (v1.0) | 152 → 122 | | `general-nist-800-160-vol-2-r1` | NIST SP 800-160 (Vol 2, Rev 1) | 204 → 196 | | `general-nist-800-161-r1` | NIST SP 800-161 R1 UDP1 | 341 → 308 |