feat: add AI Governance, UAE/Regional frameworks & Open-Source GRC To… - #34
Open
Ankit-Uniyal wants to merge 2 commits into
Open
feat: add AI Governance, UAE/Regional frameworks & Open-Source GRC To…#34Ankit-Uniyal wants to merge 2 commits into
Ankit-Uniyal wants to merge 2 commits into
Conversation
…ols sections Added a comprehensive section on AI governance, risk management frameworks, and tools for GRC professionals. Included regional frameworks and open-source GRC tools to enhance the resourcefulness of the document.
Open
Added three major new sections to the GRC knowledge base: 1. TPRM: ISO 28000, NIST SP 800-161, SIG questionnaire, vendor tiering lifecycle, DORA/NIS2/PCI DSS/HIPAA regulatory requirements, and commercial tools. 2. Incident Response and Business Continuity: NIST SP 800-61, SANS 6-step process, ISO/IEC 27035, ISO 22301, and open-source IR tools (TheHive, MISP, Velociraptor, GRR). 3. GRC Metrics and KPIs: Governance, risk, and compliance metrics with formulas and targets. References CIS Controls v8, ISACA COBIT 2019, and NIST CSF measurement guidance. Contributed by Ankit Uniyal - GRC Lead, PureHealth Group
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR adds three new sections that are currently missing from the awesome-security-GRC list, covering rapidly growing areas in the GRC field:
🤖 AI Governance & Emerging Technology Risk (NEW)
As AI adoption accelerates in enterprises, GRC professionals need dedicated resources. This section adds:
🌍 Regional & Emerging Frameworks (NEW)
The current list is heavily US/EU focused. This section adds critical frameworks for MENA, India, and emerging EU regulations:
🧰 Open-Source GRC Tools Table (NEW)
A structured comparison table of the best open-source GRC platforms (CISO Assistant, GigaChad GRC, Unicis Platform CE, Comply, riskquant, OpenRMF) including frameworks supported.
About the contributor: I'm a GRC Lead at PureHealth Group (UAE's largest healthcare platform) with 10+ years in GRC across PwC, Deloitte, Equifax, and Oman Arab Bank. I hold ISO 42001 Lead Auditor, CISM, CISA, CRISC and 15+ other certifications. These sections reflect real practitioner experience, especially working in the UAE/GCC region where regional frameworks are often overlooked in US-centric resources.