Skip to content
SCA
Open-source · Free · Community-driven

Learn how technical controls map to compliance frameworks.

A free, open-source platform for learning cybersecurity frameworks, cloud security, AI security, and governance, risk & compliance — with hands-on labs and control-to-framework mapping.

Controls mapped to frameworks, not just standards restated
Accurate, cited, and production-quality content
Hands-on labs that turn theory into practice
Free and open-source, forever

Frameworks

Each framework page follows one template: overview, controls, cloud mapping, implementation guidance, labs, and interview questions.

Privacyin-progress

GDPR

The EU General Data Protection Regulation; Article 32 defines the security-of-processing obligations.

GRCin-progress

ISO/IEC 27001

The international standard for information security management systems (ISMS), with Annex A controls.

GRCin-progress

NIST CSF 2.0

A voluntary framework of cybersecurity outcomes across six functions: Govern, Identify, Protect, Detect, Respond, and Recover.

GRCin-progress

SOC 2

AICPA Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy.

GRCdraft

CIS Controls v8

A prioritized set of 18 safeguards, organized by Implementation Group, to mitigate the most common attacks.

Operational Resiliencedraft

DORA

The EU Digital Operational Resilience Act for ICT risk management in the financial sector.

AIdraft

ISO/IEC 42001

The management-system standard for responsible AI (AIMS).

Operational Resiliencedraft

NIS2

The EU directive raising the baseline for network and information system security across essential and important entities.

Built in the open. Contributions welcome.

This academy is a living, community-maintained resource. Follow a learning path or help shape what comes next.