Skip to main content

SIROS ID Compliance Dashboard

Security controls and compliance framework mappings.

  • Controls — 90 security controls
  • Frameworks — Mappings against EUDI Security Requirements, FitCEM Wallet Instance, ISO 27001 Annex A, GDPR Checklist, OWASP ASVS 4.0.3 Level 3, STRIDE Threat Model, NOBCCS Certification Scheme
  • CSF Functions — NIST Cybersecurity Framework function overview

How It Fits Together

Compliance frameworks define requirements that are mapped to platform controls. Each control is categorized under a NIST CSF 2.0 function so that coverage can be reviewed at every level of abstraction.

Frameworks Controls CSF 2.0 Functions EUDI Security Requirements FitCEM Wallet Instance ISO 27001 Annex A GDPR Checklist OWASP ASVS 4.0.3 Level 3 STRIDE Threat Model NOBCCS Certification Scheme 63 Technical 27 Organizational 90 Controls Govern (GV) · 8 Identify (ID) · 8 Protect (PR) · 58 Detect (DE) · 7 Respond (RS) · 1 Recover (RC) · 2 requirements categorized

Platform vs Operator

Each control is labeled platform or operator:

  • Platform controls apply to the open-source SIROS ID codebase itself — they are satisfied by the software and verified through code, tests, and audits.
  • Operator controls apply to the organization running the platform — policies, processes, and infrastructure that each deployment must provide independently.

This separation reflects the fact that SIROS ID is designed to be operated not only by the SIROS Foundation but by any organization independently.