Domain
Cybersecurity
Security operations, governance, risk and compliance knowledge packages, including framework crosswalks between CMMC, NIST, FedRAMP, ISO 27001, SOC 2 and PCI DSS.
15 packages in this domain
MITRE ATT&CK Enterprise (STIX 2.1)
v17.1mitre.attack.enterprise
Adversary tactics, techniques and mitigations as a threat knowledge graph.
MITRE · Ontology Mapping, Instance Dataset, Reference Dataset
Cybersecurity Core Ontology
v1.1.0nimble.cyber.core
Shared security vocabulary: controls, assets, threats, vulnerabilities, risks and evidence.
Nimble · Ontology, Validation Rules
NIST SP 800-53 Rev 5 Control Catalog (OSCAL)
v5.1.1nist.800-53r5.oscal
The full NIST security and privacy control catalog in machine-readable OSCAL form.
NIST · Instance Dataset, Reference Dataset, Compliance Mapping
NIST SP 800-171 Rev 3 Requirement Set
v3.0.0nist.800-171r3
CUI protection requirements as structured, queryable instances.
NIST · Instance Dataset, Reference Dataset
CMMC Level 2 to NIST SP 800-171 Crosswalk
v2.1.0cmmc.l2.crosswalk
Practice-by-practice mapping from CMMC Level 2 to the underlying 800-171 requirements.
DoD CIO · Compliance Mapping, Crosswalk
NVD CVE Reference Dataset (sample)
v2026.02nvd.cve.reference
Sample CVE and CVSS records for vulnerability-management twins.
NIST · Analysis Notebook, Reference Dataset
MITRE D3FEND Countermeasure Ontology
v1.3.0mitre.d3fend
Defensive technique ontology that pairs with offensive ATT&CK knowledge.
MITRE · Ontology
FedRAMP Rev 5 Baselines (OSCAL)
v5.0.2fedramp.r5.baselines
Low, Moderate and High baselines as OSCAL profiles over 800-53 Rev 5.
GSA / FedRAMP PMO · Instance Dataset, Compliance Mapping
UAV Cybersecurity Pack
v1.0.0nimble.uav.cyber
Threats, controls and validation rules for uncrewed platforms.
Nimble · Ontology Extension, Validation Rules, Compliance Mapping
CISA Zero Trust Maturity Model 2.0
v2.0.0cisa.zero-trust.maturity
Pillars, functions and maturity stages as an assessable model.
CISA · Ontology, Inference Rules
STIX 2.1 Threat Intelligence Alignment
v2.1.0oasis.stix21.alignment
Maps STIX 2.1 domain objects onto Nimble threat concepts.
OASIS Open · Ontology Alignment, Example Instances
Water Infrastructure Cybersecurity Pack
v1.0.0nimble.water.ics.cyber
Cross-domain pack: OT/ICS security for water and wastewater utilities.
Nimble · Ontology Extension, Validation Rules, Compliance Mapping
ISO/IEC 27001:2022 Annex A Control Structure
v2022.1iso.27001.annexa
Link-only entry: obtain the standard from ISO, then load the structure locally.
ISO · Standards Mapping
PCI DSS v4.0.1 Requirement Structure
v4.0.1pci.dss4.structure
Link-only entry for PCI DSS requirements and testing procedures.
PCI Security Standards Council · Standards Mapping
SOC 2 Trust Services Criteria Structure
v2017.3soc2.tsc
Link-only entry for the AICPA Trust Services Criteria.
AICPA · Standards Mapping
