myctrl.tools
Home / Public Domain
Public Domain

Public Domain Resources

Frameworks and guidance published as public domain works, primarily from U.S. government agencies (NIST, FedRAMP, DoD) and open-source organizations (OWASP). These resources can be freely used, shared, and built upon. 5062 items across 22 resources.

v5.2.0 Federal Public Domain 1,196 controls

NIST SP 800-53

Security and Privacy Controls for Information Systems and Organizations

FedRAMP Rev 5

Federal Risk and Authorization Management Program Security Baselines

v0.9.0-beta Federal Public Domain 60 indicators

FedRAMP 20x KSI

Key Security Indicators for FedRAMP 20x authorization

vRev 5 Federal DoD Public Domain 622 controls

DoD SRG

DoD Cloud Computing Security Requirements Guide - FedRAMP+ controls by Impact Level

20 Families
v2.0 AI Public Domain 10 risks

OWASP Top 10 for LLMs

Security risks for Large Language Model applications

10 Risk Categories
v2025 Web Public Domain 10 risks

OWASP Top 10

The OWASP Top 10 is a standard awareness document for web application security risks

10 Risk Categories
v2023 API Public Domain 10 risks

OWASP API Security Top 10

The OWASP API Security Top 10 represents the most critical security risks to APIs

8 Risk Categories
v2024 Mobile Public Domain 10 risks

OWASP Mobile Top 10

The OWASP Mobile Top 10 represents the most critical security risks to mobile applications

10 Risk Categories
v2026 Public Domain 10 risks

OWASP Smart Contract Top 10

The most critical security risks in smart contract development, based on 2025 incident data

10 Risk Categories
v2.0 Public Domain 106 outcomes

NIST CSF

Cybersecurity Framework 2.0 for improving critical infrastructure security

6 Functions
vV2R4 Federal DoD Public Domain 94 findings

Kubernetes STIG

DoD Security Technical Implementation Guide for Kubernetes container orchestration

NIST AI RMF

AI Risk Management Framework Playbook - Suggested actions for trustworthy AI

4 Functions
v2024/1689 AI Public Domain 21 requirements

EU AI Act

European Union Artificial Intelligence Act - Risk-based regulatory framework for AI systems

NIST SSDF

Secure Software Development Framework - Practices for integrating security into SDLC

4 Groups
vRev 2 Federal Public Domain 110 requirements

NIST SP 800-171

Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

14 Families
v2.0 Federal DoD Public Domain 110 practices

CMMC

Cybersecurity Maturity Model Certification for DoD contractors

v2.0 Public Domain 223 controls

TX-RAMP

Texas Risk and Authorization Management Program - Security assessment and certification for cloud computing services used by Texas state agencies

v2024 Public Domain 131 requirements

HIPAA Security Rule

Health Insurance Portability and Accountability Act - Security safeguards for electronic protected health information (ePHI)

6 Sections
v2016/679 Public Domain 499 articles

GDPR

General Data Protection Regulation - EU regulation on data protection and privacy

12 Chapters
v2022/2555 Public Domain 473 requirements

NIS2 Directive

Network and Information Security Directive 2 - EU cybersecurity legislation

2 Chapters
v2026 Public Domain 825 requirements

CCPA

California Consumer Privacy Act - California state privacy regulation

11 Articles

CISA Secure by Design

Principles and pledge goals for building cybersecurity into product design — jointly published by CISA, FBI, NSA, and 17+ international partners

3 Categories

> About Public Domain

Public domain works are not restricted by copyright and can be freely used by anyone for any purpose.

Most U.S. government publications, including NIST standards and FedRAMP baselines, are automatically in the public domain under 17 U.S.C. § 105. OWASP content is released under open-source licenses (typically Creative Commons) that allow free redistribution.

This means you can reference, reproduce, and build upon these frameworks without permission or licensing fees.