Skip to content

feat: add AI Governance, UAE/Regional frameworks & Open-Source GRC To… - #34

Open
Ankit-Uniyal wants to merge 2 commits into
GRC-Engineer:mainfrom
Ankit-Uniyal:main
Open

feat: add AI Governance, UAE/Regional frameworks & Open-Source GRC To…#34
Ankit-Uniyal wants to merge 2 commits into
GRC-Engineer:mainfrom
Ankit-Uniyal:main

Conversation

@Ankit-Uniyal

Copy link
Copy Markdown

Summary

This PR adds three new sections that are currently missing from the awesome-security-GRC list, covering rapidly growing areas in the GRC field:

🤖 AI Governance & Emerging Technology Risk (NEW)

As AI adoption accelerates in enterprises, GRC professionals need dedicated resources. This section adds:

  • Key AI governance frameworks: ISO 42001, NIST AI RMF, EU AI Act, OWASP Top 10 for LLMs, MITRE ATLAS
    • AI security testing tools: Garak (LLM vulnerability scanner), Microsoft PyRIT
    • Practical AI Governance checklist for GRC practitioners
    • AI Risk Navigator tool (free, covers 15+ frameworks)

🌍 Regional & Emerging Frameworks (NEW)

The current list is heavily US/EU focused. This section adds critical frameworks for MENA, India, and emerging EU regulations:

  • UAE/Middle East: NCA ECC, UAE IAS, UAE AI Strategy 2031, DIFC DPL, ADGM regulations
    • India: DPDP Act 2023, RBI IT Framework, SEBI Cybersecurity Framework
    • Europe (Emerging): DORA (effective Jan 2025), NIS2 Directive

🧰 Open-Source GRC Tools Table (NEW)

A structured comparison table of the best open-source GRC platforms (CISO Assistant, GigaChad GRC, Unicis Platform CE, Comply, riskquant, OpenRMF) including frameworks supported.


About the contributor: I'm a GRC Lead at PureHealth Group (UAE's largest healthcare platform) with 10+ years in GRC across PwC, Deloitte, Equifax, and Oman Arab Bank. I hold ISO 42001 Lead Auditor, CISM, CISA, CRISC and 15+ other certifications. These sections reflect real practitioner experience, especially working in the UAE/GCC region where regional frameworks are often overlooked in US-centric resources.

…ols sections

Added a comprehensive section on AI governance, risk management frameworks, and tools for GRC professionals. Included regional frameworks and open-source GRC tools to enhance the resourcefulness of the document.
@Ankit-Uniyal Ankit-Uniyal mentioned this pull request Apr 10, 2026
Added three major new sections to the GRC knowledge base:

1. TPRM: ISO 28000, NIST SP 800-161, SIG questionnaire, vendor tiering lifecycle, DORA/NIS2/PCI DSS/HIPAA regulatory requirements, and commercial tools.

2. Incident Response and Business Continuity: NIST SP 800-61, SANS 6-step process, ISO/IEC 27035, ISO 22301, and open-source IR tools (TheHive, MISP, Velociraptor, GRR).

3. GRC Metrics and KPIs: Governance, risk, and compliance metrics with formulas and targets. References CIS Controls v8, ISACA COBIT 2019, and NIST CSF measurement guidance.

Contributed by Ankit Uniyal - GRC Lead, PureHealth Group
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant