Skip to content

MyOpenCRE: allow for mapping CREs to a standard automatically #585

@northdpole

Description

@northdpole

MyOpenCRE is a nifty addition to the project that allows users to add their own mappings.
Using MyOpenCRE, users can download a CSV of all existing CREs, then map their own standard sections/subsections and finally re-upload for processing.

Mapping standards to CREs is a time consuming process. Instead we could use a bit of generative AI to do the mapping ourselves.
This feature would use a combination of AI techniques to derive highly accurate mappings between a CRE and the described information of the control of a Standard.

Stretch goal: If a mapping is not possible automatically or if a CRE does not exist for that mapping, the application should identify the controls for which a mapping could not be produced

Example Outcome: MyOpenCRE can map automatically the following standards:

  • PCI-DSS
  • DORA
  • SOC2

Stretch goal example outcome: MyOpenCRE can partially map the OWASP AI Exchange and the top 10 for LLMs while identifying the controls that require human intervention or the release of new CREs.

Metadata

Metadata

Assignees

No one assigned

    Labels

    GSOCthis feature is a potential Google Summer of Code candidateenhancementNew feature or request

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions