Learn how technical controls map to compliance frameworks.
A free, open-source platform for learning cybersecurity frameworks, cloud security, AI security, and governance, risk & compliance — with hands-on labs and control-to-framework mapping.
Explore the academy
Everything you need to learn, map, and implement security and compliance.
Framework Explorer
Deep dives into ISO 27001, NIST CSF, SOC 2, GDPR, DORA, NIS2 and more — each with controls, architecture, and labs.
OpenCompliance Comparison
Side-by-side comparison of frameworks by scope, controls, and audit model.
OpenControl Mapping
Map one control (e.g. Access Control) across ISO 27001, NIST CSF, SOC 2, GDPR Art. 32, CIS, and cloud IAM.
OpenCloud Security
AWS, Azure, GCP, and Kubernetes security patterns tied back to compliance controls.
OpenAI Security
OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, EU AI Act, prompt injection, RAG, MCP & agent security.
OpenThreat Modeling
STRIDE, attack trees, and data-flow diagrams with worked examples.
OpenSecure SDLC
Build security into every phase — from design review to DevSecOps pipelines.
OpenLabs
Hands-on, guided labs that turn controls and standards into practice.
OpenQuizzes
Short, interactive quizzes with instant feedback across the frameworks.
OpenInterview Prep
Curated questions, model answers, and an interview simulator.
OpenCareer Roadmaps
Structured paths for GRC, cloud security, AppSec, and AI security roles.
OpenResources
Authoritative references, standards, and reading lists.
OpenBlog
Updates, deep dives, and analysis of the evolving compliance landscape.
OpenFrameworks
Each framework page follows one template: overview, controls, cloud mapping, implementation guidance, labs, and interview questions.
GDPR
The EU General Data Protection Regulation; Article 32 defines the security-of-processing obligations.
ISO/IEC 27001
The international standard for information security management systems (ISMS), with Annex A controls.
NIST CSF 2.0
A voluntary framework of cybersecurity outcomes across six functions: Govern, Identify, Protect, Detect, Respond, and Recover.
SOC 2
AICPA Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy.
CIS Controls v8
A prioritized set of 18 safeguards, organized by Implementation Group, to mitigate the most common attacks.
DORA
The EU Digital Operational Resilience Act for ICT risk management in the financial sector.
ISO/IEC 42001
The management-system standard for responsible AI (AIMS).
NIS2
The EU directive raising the baseline for network and information system security across essential and important entities.
Built in the open. Contributions welcome.
This academy is a living, community-maintained resource. Follow a learning path or help shape what comes next.