LAION-AI / LAION-AI/Open-Assistant

Information Security Standards, Frameworks, Controls Mapping

Open
#1,720 9 comments 1 reaction 1 assignee View on GitHub

@ascarola is already working on this.

Since Feb 20, 2023.

data
Dominant language
Python
Stars
37.4k
Forks
3.3k
PR merge metrics
No merged PRs in 30d

Description

Per a comment left for me on Discord by Huu Nguyen#6677, I would like to help with the project.

Here is the background, which I posted earlier today: "I'm an InfoSec pro and would like to have a means to create mappings between different InfoSec standard frameworks, such as NIST, ISO, and some financial regulatory frameworks such as the FFIEC Cybersecurity Assessment Tool, NCUA's ISE assessment, ISO 27000-series, etc. Most all of this data is publicly accessible, except for the ISO standards. I've asked ChatGPT to help me perform some simple mappings; however, it provided completely incorrect information - utterly hallucinating in the responses. How can I help support Open Assistant to get it to help support other information security professionals with this generally simple task using publicly available datasets? This could be very valuable assistance for my field."

When asked to create a dataset, I replied: "I could absolutely help with that, but I'm wondering if it would be possible for the engine to kick-off the help initially. For example, I could easily provide it with the standards (with assistance in formatting them) for multiple datasets, and it would be great if it could begin to perform some generic mapping based on the declarative statements. For example, given the following two statements, determine how similar the "controls" are: "the company installs firewalls at the perimeter of the network" and "the company has board-approved information security policies". The result of this operation then could then be reviewed by myself and other infosec pros to validate those responses. The datasets contain many declarative control statements, such as in the 250-500+ range each."

I'm not a developer, more of a technical manager, and would need to be walked through the processes.

How can I help?!

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.