Security Frameworks and Standards

How to enable compliance framework mappings on Settings → Organization.

Security Frameworks and Standards

Security Frameworks and Standards is the second section on Settings → Organization. Section copy: Enable compliance framework mappings for risk assessments.

Each framework is its own card with a switch. Toggles require manage-settings. Enabled ids are stored as the compliance_frameworks setting (an array).

Name

Id

UI description

NIST CSF 2.0

nist_csf

NIST Cybersecurity Framework — risk-based subcategory mappings derived from SP 800-53 controls

PCI DSS 4.0

pci_dss

Payment Card Industry Data Security Standard — requirement-level mappings for cardholder data protection

HIPAA Security Rule

hipaa

Health Insurance Portability and Accountability Act — technical safeguard mappings for protected health information

SOC 2 Type II

soc2

Service Organization Control — Trust Services Criteria mappings for service providers

CIS Controls v8

cis

Center for Internet Security Critical Security Controls — implementation-focused control mappings

Turning a switch on adds that id to the list; turning it off removes it. These toggles do not configure SSO or scan policy.