Security Frameworks and Standards

How to enable compliance framework mappings on Settings → Organization.

Security Frameworks and Standards

This is the second section on Settings → Organization. Section copy: Enable compliance framework mappings for risk assessments.

Each framework is its own card with a switch. Toggles require manage-settings. Enabled ids are stored as the compliance_frameworks setting.

NameIdUI description
NIST CSF 2.0nist_csfNIST Cybersecurity Framework — risk-based subcategory mappings derived from SP 800-53 controls
PCI DSS 4.0pci_dssPayment Card Industry Data Security Standard — requirement-level mappings for cardholder data protection
HIPAA Security RulehipaaHealth Insurance Portability and Accountability Act — technical safeguard mappings for protected health information
SOC 2 Type IIsoc2Service Organization Control — Trust Services Criteria mappings for service providers
CIS Controls v8cisCenter for Internet Security Critical Security Controls — implementation-focused control mappings

Turning a switch on adds that id to the list; turning it off removes it.