Under active development Content is continuously updated and improved
Home / Open License
Open License

Open License Resources

Frameworks and guidance released under open licenses (like Creative Commons). These resources are free to use but have specific license terms that must be followed. 3417 items across 11 resources.

v8.1.2 Open License 153 safeguards

CIS Controls

Critical Security Controls for Effective Cyber Defense

18 Controls Framework Official Source
v2014 Open License 922 controls

ITSG-33

IT Security Risk Management - Canadian Government Security Control Catalogue

17 Families Framework Official Source
v5 Open License 317 controls

Adobe CCF

Adobe Common Controls Framework - Open-source unified control framework mapping to 20+ compliance standards

25 Domains Framework Official Source
v3.2 Open License 30 requirements

Cyber Essentials

UK NCSC Cyber Essentials certification - 5 technical controls to protect against common cyber attacks

5 Controls Framework Official Source
v2020 Open License 121 criteria

BSI C5

Cloud Computing Compliance Criteria Catalogue - German Federal Office for Information Security

17 Areas Framework Official Source
v2025.4 Open License 1,451 controls

SCF

Secure Controls Framework - A comprehensive meta-framework harmonizing 100+ security standards

33 Domains Framework Official Source
vRev 5 Open License 419 controls

GovRAMP

Government Risk and Authorization Management Program - Security Baselines for State and Local Government Cloud Services

17 Families Framework Official Source
vTBD Open License 1 controls

CSA CCM

Cloud Security Alliance Cloud Controls Matrix - cloud security meta-framework with mappings to major standards

1 Domain Framework Official Source
vTBD Open License 1 classes

OCSF

Open Cybersecurity Schema Framework - open standard for security data normalization across tools and vendors

1 Category Framework Official Source
vTBD Open License 1 factors

FAIR

Factor Analysis of Information Risk - quantitative risk analysis framework for measuring and managing cyber risk

1 Stage Framework Official Source
vTBD Open License 1 techniques

MITRE ATT&CK

Adversarial Tactics, Techniques & Common Knowledge - attack taxonomy that maps across security frameworks

1 Tactic Framework Official Source

> About Open Licenses

Open license resources are freely available but released under specific license terms (typically Creative Commons). Unlike public domain works, these have some restrictions on use.

Common terms include:

  • Attribution (BY) - Credit the original creator
  • Non-Commercial (NC) - Free for non-commercial use only
  • No Derivatives (ND) - Cannot modify or create derivative works