AWS Config
AWS service for recording resource configuration, relationships and compliance over time.
AWS service for recording resource configuration, relationships and compliance over time.
An open platform for building developer portals with a typed software catalogue, owners and relations.
A policy language for authorisation decisions over principals, actions, resources and context.
Continuous integration and continuous delivery—automated pipelines that validate change and promote it through environments.
Google Cloud inventory of assets and relationships across projects and services.
An open FINOS standard for technology-agnostic cloud security, resiliency and compliance controls with machine-verifiable assessments.
An OWASP standard for software bills of materials (SBOMs) and related supply-chain inventory formats.
OMG Decision Model and Notation for executable decision tables and decision requirements diagrams.
GitOps toolkit for Kubernetes that reconciles desired state and can gate changes with policy.
Kubernetes-native policy controller built on OPA, with admission enforcement and audit modes.
An activity-centred GRC model with typed, linkable governance artifacts across definition, activity and measurement layers.
GitHub feature that maps paths to required reviewers so changes have named owners.
A registry for publishing, distributing and installing governance artefacts such as control catalogues and related packages.
A framework for cryptographically verifying software supply-chain steps via link metadata and layouts.
Container orchestration platform whose admission controllers intercept API requests before persistence.
NIST SP 800-161 guidance on cyber supply-chain risk management for acquiring and using ICT products.
A general-purpose policy engine (Rego) that evaluates structured input and returns structured decisions.
Automated security health metrics for open-source projects, produced as machine-readable results.
NIST Open Security Controls Assessment Language for machine-readable controls, profiles and assessment results.
An enterprise configuration-management database for IT assets, CIs and relationship maps.
Supply-chain Levels for Software Artifacts—provenance requirements that show how an artefact was built.
OASIS standard for attribute-based access control with request/response evaluation and obligations.