Bridging Security & Privacy Standards: Harnessing OpenCRE for Effective Mapping - Dimitar Raichev @OWASPGLOBAL
Bridging Security & Privacy Standards: Harnessing OpenCRE for Effective Mapping - Dimitar Raichev  @OWASPGLOBAL
Uploaded March 2025 | Updated September 2026, 3 weeks ago
The complexity of the cybersecurity landscape, compounded by evolving frameworks and compliance regulations, necessitates a clear understanding of how different standards align and relate to each other. Mappings between standards have been our solution so far, but manual mappings are a slow, labour intensive process. The OWASP OpenCRE project aims to remediate this issue.

This presentation explores the current state of standard mappings, comparing traditional manual methods with the innovative OpenCRE solution. It highlights the benefits and limitations of each approach and shares insights from our experiences using OpenCRE. We also investigate a novel approach combining manual mappings with OpenCRE to extend mappings to standards outside OpenCRE.


Key concepts of mappings such as purpose, target audience, and relationship types are examined. We discuss how these elements help organisations align different guidelines and best practices. While OpenCRE supports various relationship types and offers a fast, automated alternative to manual mappings, it has limitations. This is illustrated by comparing the SAMM / SSDF mapping generated with OpenCRE to the direct manual mapping approved by NIST.


Proposed solutions include improving the quality of OpenCRE mappings by involving standards & regulations bodies (NIST, ISO, etc.) and using OpenCRE as a foundation for expert-reviewed and validated mappings. A specific example showcases how mappings can facilitate compliance efforts, by using SAMM to infer compliance with other frameworks.


In conclusion, mappings are crucial for aligning standards and frameworks, serving as guidelines rather than definitive proofs of compliance. Despite technological advancements, expert involvement remains essential for creating high-quality mappings. Investing in these mappings can streamline security and compliance efforts, making processes more robust and reducing the burden on security professionals.

-

Managed by the OWASP® Foundation
owasp.org
Bridging Security & Privacy Standards: Harnessing OpenCRE for Effective Mapping - Dimitar RaichevSherif Mansour - Donate Blood Today!202011 November 2020 Global Board MeetingThe Missing Link - How we collect and leverage SBOMs - Cassie CrossleyAutomating Threat Modeling - Challenges + AI SolutionsRethinking Threat Modeling for Dev Teams: A Scalable ApproachLearning from Past Security Breaches: Strengthening AppSec Efforts and Focus - Jon McCoy202005 May 2020 Global Board MeetingAppSec Meets Project Management: Hacking the Frameworks for Secure Software - Stefan BrätschOWASP Coraza - Web Application Firewall - Juan Pablo TossoBenchmarking Scanner Blind Spots: How Runtime Context Uncovers Hidden VulnsSecurity for Citizen Developers: Low-Code/No-Code Cybersecurity Threats
OWASP Foundation |

Bridging Security & Privacy Standards: Harnessing OpenCRE for Effective Mapping - Dimitar Raichev

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER