An API and client for managing STIG assessments
-
Updated
Jul 29, 2026 - JavaScript
An API and client for managing STIG assessments
compliance assessment and POA&M management for CMMC/NIST 800-171A
Crane POAM Automation Tool (C-PAT™)
Comprehensive NIST SP 800-171 Rev 3 compliance toolkit: 110 control checklists, System Security Plan (SSP) templates, POA&M tracking, and CMMC Level 2 mapping. By Petronella Technology Group.
This tool is one of eight free CMMC tools published by APT Security Management for the defense industrial base. All tools run entirely client-side with no signup and no tracking. Full list: https://github.com/Apt-Security-Management. Questions and issues welcome.
RampControl manages and tracks security compliance per FedRAMP requirements. It allows users to add new system security plans, manage POA&M entries, and export data in OSCAL format.
TenableTrawler (Cloud OR FedCloud) is a Python project that pulls scan results via the Tenable API, laying them into organized, POAM-ready outputs. It supports various scans and exports in formats like CSV, JSON, and YAML.
NIST SP 800-53 Rev 5 security control mapping, gap analysis, risk scoring, and POA&M development
This repository automates the collection and management of evidence from various tools and sources, committing the data for transparency and traceability. It's designed to gather evidence that tools like Vanta and others aren't built to collect.
Sanitized ATO and GRC authorization package demonstrating SSP development, NIST 800-53 control implementation, continuous monitoring, and audit readiness documentation. Policy documentation, POA&M samples, and compliance artifacts.
ديوان — The cybersecurity program office every company should have, in one file: risk register with live 5×5 heatmap, asset inventory, NIST CSF 2.0 maturity assessment, incident log, vendor register, POA&M, policy generator & executive reporting. Client-side, zero backend.
Synthetic cybersecurity incident reporting and remediation toolkit featuring executive reports, technical timelines, root-cause analysis, lessons learned, CAPA/POA&M tracking, effectiveness validation and Excel management dashboards.
15-section Container Vulnerability Remediation Plan (CVRP) template mapped to NIST 800-53 / ISO 27001 / FedRAMP — turns container scanner output into audit-ready, control-mapped evidence.
Complete GRC deliverable set for a fictional clinic - scored NIST CSF 2.0 maturity assessment, HIPAA Security Rule crosswalk, owned risk register, and phased POA&M
End-to-end vulnerability management program — policy development, credentialed Tenable scanning, PowerShell STIG remediations, and POA&M documentation aligned to NIST 800-53. 74% total vulnerability reduction in one remediation cycle.
Reference implementation and control mapping for tracking CMMC Level 1-2 / NIST SP-800-171 POA&M and evidence workflows in Jira and Confluence. Independent project, not affiliated with DoD or the Cyber-AB
Add a description, image, and links to the poam topic page so that developers can more easily learn about it.
To associate your repository with the poam topic, visit your repo's landing page and select "manage topics."