Tools · Category 05

Risk & GRC

Score vulnerabilities, model risk, map your controls to a framework and check where you stand against ISO, NIST and privacy law. The governance and compliance side of the work.

14 tools Governance and compliance Browser based
📊

CVSS v3.1 Calculator

Score a vulnerability with the CVSS v3.1 base, temporal and environmental metrics and read the severity.

Open →
🎯

CVSS v4.0 Calculator

Score a vulnerability with the official CVSS v4.0 metrics and get the score and severity from a vetted engine.

Open →
📐

Risk Matrix Calculator

Plot likelihood against impact on a five by five matrix and build a ranked risk register you can export.

Open →
📚

ISO 27001 Annex A Reference

Browse all 93 Annex A controls from ISO 27001:2022 and track your statement of applicability.

Open →
📑

NIST CSF 2.0 Reference

Work through the six functions and 22 categories of the NIST Cybersecurity Framework 2.0 and profile your tiers.

Open →
🔗

Compliance Framework Mapper

Cross map NIST CSF 2.0 and ISO 27001:2022 controls to see where the two frameworks line up.

Open →

GDPR and India DPDP Readiness Checklist

Check your readiness against GDPR and the India DPDP rules with a scored, exportable checklist.

Open →
🔑

Password Policy Generator

Generate a password policy aligned to current NIST SP 800-63B guidance, ready to drop into a document.

Open →
📝

Security Policy Template Generator

Assemble policy documents from selectable templates with ISO and NIST alignment notes.

Open →
🔎

Cyber Risk Assessment

Run a guided risk assessment across your environment and surface the gaps that matter most.

Open →
🛡

STRIDE Threat Model

Model threats against a system using the STRIDE categories and capture a mitigation for each one.

Open →

Cloud Security Checklist

Check your cloud setup against a practical security baseline across identity, network and data.

Open →
💰

Incident Cost Calculator

Estimate the financial impact of a security incident from downtime, response and recovery costs.

Open →

Security Awareness Quiz

Test and reinforce staff security awareness with a quick interactive quiz.

Open →

Framework references track the published standards, including NIST CSF 2.0 and ISO 27001:2022. Last reviewed June 2026.