Compliance Norms define Control Groups and Tasks, which can be used to quickly set up new Pentests and Pentest Templates using standard Checklists and Norms. Cyver Core Compliance Norms function as pre-defined checklists of Control Groups with attached Tasks. You can create as many as you like and you can add as many as you like to a Pentest Template or Pentest.
Tasks from Compliance Norms will automatically populate in the Pentester’s backlog at Pentest start. In addition, all Findings are linked to Control Groups from Compliance Norms.
Supported Norms
You can always build your own Compliance Norm with your own Control Groups. However, Cyver Core offers a large list of pre-defined Compliance Norms for common pentests, cybersecurity standards, and vulnerability assessments.
These are useful for pentests performed using standardized checklists for compliance or audit purposes, where it doesn't make sense to build your own each time. Cyver offers a library of common Norms complete with linked Control Groups and Checklists. You can customize and edit any of these to create your own version of the Compliance Norm.
You can download the XLS for any of these compliance norms from our GitHub repository. You can then upload the full Compliance Norm, complete with Control Groups and Checklists, from the Compliance Norm dashboard in your Cyver Core portal.
- ASVS 4.0 L1
- ASVS 4.0 L2
- ASVS 4.0 L3
- ASVS IoT L3
- Cyber Essentials Plus
- Cyber Essentials Plus 2
- DigiD 2.0 Pentest Only
- DigiD 2.0
- ISO 27001
- ISO 27001 Norm
- MAS VS 1.2 L1
- MAS VS 1.2 L2
- MITRE ATT&CK
- MSTG L1 Android
- MSTG L1 iOS
- MSTG L2 Android
- MSTG L2 IOS
- MSTG L3 Android
- MSTG L3 iOS
- NIST Privacy Framework 1.0
- OTG v4
- OWASP API Security Top 10 2019
- OWASP Mobile Security Top 10 2023
- OWASP IOT Top 10 2018
- OWASP Top10 2017
- OWASP Top 10 2021
- OWASP Top 10 LLM V1
- PCI DSS 3.2.1 Norm
- PTES
- SANS Top 20
Cyver Core strives to offer out-of-the-box solutions for as many types of Pentesters as possible. For that reason, we will continue to add to this list. Check Draft Compliance Norms to see updates or download directly from our GitHub repository.
See more on setting up Compliance Norms
See more on Customizing Compliance Norms