-
Notifications
You must be signed in to change notification settings - Fork 1
Compliance
The compliance-tool differentiator section. What catalogs Evidentia ships, what conformance Evidentia itself claims, how to browse + use the framework crosswalks, and how to contribute a catalog.
-
Catalog inventory — 92 framework catalogs by region/standard family + version pin + last-update date + maintainer.
-
Framework conformance — standards Evidentia ITSELF conforms to (OSPS Baseline, NIST 800-53 self-assessment, OpenSSF Best Practices Silver, etc.).
-
Crosswalk index — browse + filter all 13 crosswalks.
-
OSPS Baseline mapping — OSPS Baseline v2026.02.19 walkthrough + Evidentia's conformance status per assessment-requirement + the 5 OSPS crosswalks + the 16 GitHub OSPS collector helpers.
-
OCSF mapping — NORMATIVE
SecurityFinding↔ OCSF field map (v0.10.0 + v0.10.5 ingestion + detection). -
Gemara mapping — NORMATIVE Evidentia ↔ OpenSSF Gemara taxonomy alignment (Catalogs / Logs / Documents / Entities / Collections).
-
Financial-sector overlay — composition pattern for federally-supervised banks, broker-dealers, insurers, credit unions (OCC + FRB + FDIC + NCUA + FFIEC + state insurance + SR 11-7 / SR 26-02 + OCC Bulletin 2026-13a).
-
Contributing a catalog — 3-file PR recipe + YAML-vs-JSON comparison + required schema + tier conventions.
This section is the answer to "does Evidentia cover [framework X]?" + "how do I use Evidentia's mapping outputs in [audit / compliance / SIEM workflow]?" The OSPS Baseline mapping page is the showcase of the v0.10.6 first-mover work.
Stub status: as of v0.10.7,
osps-baseline-mapping.mdis the only fully-detailed compliance page; others are stubs that consolidate existingdocs/<file>.mdcontent as the wiki migration progresses.
-
- AI Governance
- Air Gapped Install
- Ci Integration
- CONMON Deployment
- Emit Cyclonedx VEX
- Emit OCSF Detection
- Emit SARIF
- Explain Controls
- Generate And Quantify Risk
- Governance Metrics And Workflows
- Ingest OCSF
- Manage Model Risk
- Manage POAM
- Manage Third Party Risk
- MCP Client Setup
- OSPS Self Assessment
- Run Gap Analysis
- Serve The Web Ui
- Sign And Verify Evidence