Portfolio

cybersecurity

Concord

A hypothetical bank compliance framework (SBP/ISO 27001/PCI DSS/NIST CSF), plus grcmap: a cross-framework GRC mapping and gap-analysis engine grounded in the real current versions of all four frameworks.

completedPythonPyYAMLNIST CPRTpytestRuffGitHub Actions

53/53

grcmap: automated tests passing

0

grcmap: Ruff lint issues

ISO 27001:2022 (93), PCI DSS 4.0.1 (12), NIST CSF 2.0 (106 active), SBP ETGRM (6)

grcmap: real current framework requirements modeled

100 across 33 internal controls

grcmap: cross-framework mappings in the example inventory

A hypothetical contingency-planning framework originally using Habib Bank Limited (HBL) as a reference organization for a hypothetical, illustrative analysis — explicitly not a representation of HBL's actual confidential systems, controls, or compliance status. Covers a compliance-framework mapping (SBP, ISO/IEC 27001, PCI DSS, NIST CSF), a risk register, illustrative RTO/RPO tables, an incident-response procedure, and a 5-phase implementation roadmap. Added grcmap: a cross-framework compliance-mapping and gap-analysis engine modeling the real current ISO/IEC 27001:2022, PCI DSS v4.0.1, NIST CSF 2.0 (parsed directly from NIST's own official data export), and Pakistan's real SBP ETGRM framework, using NIST IR 8477/OSCAL -inspired directed set-theory relationships instead of a static mapping table. Genericized the example organization to a fictional bank (Meridian Bank) since the new tool computes readiness/gap results, not just a one-time hypothetical narrative.