An API and client for managing STIG assessments
-
Updated
Sep 23, 2026 - JavaScript
An API and client for managing STIG assessments
compliance assessment and POA&M management for CMMC/NIST 800-171A
Crane POAM Automation Tool (C-PAT™)
Comprehensive NIST SP 800-171 Rev 3 compliance toolkit: 110 control checklists, System Security Plan (SSP) templates, POA&M tracking, and CMMC Level 2 mapping. By Petronella Technology Group.
This tool is one of eight free CMMC tools published by APT Security Management for the defense industrial base. All tools run entirely client-side with no signup and no tracking. Full list: https://github.com/Apt-Security-Management. Questions and issues welcome.
RampControl manages and tracks security compliance per FedRAMP requirements. It allows users to add new system security plans, manage POA&M entries, and export data in OSCAL format.
Full stack FedRAMP Continuous Monitoring (ConMon) SaaS: vulnerability and POA&M management, OSCAL deliverables, multi-tenant RLS, CI/CD. Showcase with demo video.
TenableTrawler (Cloud OR FedCloud) is a Python project that pulls scan results via the Tenable API, laying them into organized, POAM-ready outputs. It supports various scans and exports in formats like CSV, JSON, and YAML.
NIST SP 800-53 Rev 5 security control mapping, gap analysis, risk scoring, and POA&M development
Local OSCAL converter for NIST control implementation and continuous control monitoring. Convert CSV, Excel and documents to OSCAL JSON, YAML and XML, with optional Gemini, Azure OpenAI and Snowflake.
ديوان — The cybersecurity program office every company should have, in one file: risk register with live 5×5 heatmap, asset inventory, NIST CSF 2.0 maturity assessment, incident log, vendor register, POA&M, policy generator & executive reporting. Client-side, zero backend.
Beta. Deterministic, offline structural validator for OSCAL documents: checks structure, identifier format and uniqueness, and whether references resolve, against NIST's published JSON Schema and Metaschema constraint layer, citing the rule behind every finding. Structural conformance only; it does not assess whether a control is implemented.
This repository automates the collection and management of evidence from various tools and sources, committing the data for transparency and traceability. It's designed to gather evidence that tools like Vanta and others aren't built to collect.
Sanitized ATO and GRC authorization package demonstrating SSP development, NIST 800-53 control implementation, continuous monitoring, and audit readiness documentation. Policy documentation, POA&M samples, and compliance artifacts.
Complete GRC deliverable set for a fictional clinic - scored NIST CSF 2.0 maturity assessment, HIPAA Security Rule crosswalk, owned risk register, and phased POA&M
FedRAMP-aligned RMF compliance lab: DISA STIG hardening via Ansible, OpenSCAP/SCAP scanning, POA&M, SSP, FedRAMP control mapping, and SOX/COSO access certification on Ubuntu 24.04.
To associate your repository with the poam topic, visit your repo's landing page and select "manage topics."