🛡 DeterBot: ComplianceBot
Governance, Risk, and Compliance AI Assistant v0.1.3
Model Settings
Personas
ISSO
Information System Security Officer - security controls and compliance
ISSM
Information System Security Manager - risk management and oversight
Infrastructure Engineer
Technical implementation and system architecture
Chat Options
📋 Compliance
🏗 Under the Hood
💬 Chat
Compliance Management
Regulatory Controls in Scope
📋 Framework Status
✅ NIST/FedRAMP - Authoritative
✅ CMMC 2.0 - Authoritative DoD
✅ DISA IL2/IL4/IL5 - Maps to FedRAMP/NIST baselines (CC SRG parameters: PDF only — no OSCAL)
⚠ PCI-DSS v4.0 - Community-sourced
⚠ PSD2 - Community-sourced
⚠ SOC 2 - Community-sourced
⚠ HITRUST CSF v11 - Community-sourced (HIPAA)
🚧 NIST CSF 2.0 - Coming Soon
ISO 27001 - Not Available
🌎 Select Compliance Frameworks for This Workload
NIST & FedRAMP
FedRAMP 2026 (Class-Based)
DoD / Defense
Industry Standards
Canadian
➕ Add Controls to Baseline
Add controls beyond your selected baseline (e.g. workload-specific requirements). These are saved per-user per-framework.
Select one or more frameworks above and click Load Selected Frameworks.
Control Implementation Summary (CIS)
📊 Implementation Status Overview
Track control implementation progress and AWS inheritance status across your selected compliance framework.
0
Implemented
0
Partially Implemented
0
Planned
0
Not Applicable
0
To Be Determined
0
AWS Inherited
0
Customer Responsibility
0
Shared Responsibility
Control Framework Crosswalk
Determines AWS inheritance in Delta View
vs
NIST 800-53 Moderate
▼
Select one or more target frameworks
NIST / FedRAMP
Industry Standards
DoD / Defense
DISA Impact Levels
Canadian
| Framework 1 Control | Title | Framework 2 Control | Title | Delta Analysis | Details |
|---|---|---|---|---|---|
| Select frameworks above to generate crosswalk analysis | |||||
Framework Control Count Summary
| Framework | Low/Level 1 | Moderate/Level 2 | High/Level 3 |
|---|---|---|---|
| NIST SP 800-53 | 125 controls | 219 controls | 318 controls |
| FedRAMP | 125 controls | 253 controls | 386 controls |
| CMMC 2.0 | ~17 practices | ~110 practices | ~130 practices |
| DISA Impact Levels | IL2 = FedRAMP Moderate | IL4 = FedRAMP High | IL5 = NIST High + DoD |
| CCCS ITSP.30.031 | 219 controls (Medium baseline) | ||
| PCI-DSS v4.0 | 362 requirements | ||
| PSD2 | EU Payment Services Directive 2 | ||
| SOC 2 | 64 trust service criteria | ||
| ISO 27001:2022 | 114 controls (Annex A) | ||
Framework Notes
- FedRAMP baselines are based on NIST SP 800-53 with additional cloud-specific security controls. FISMA is the federal law that mandates NIST standards for federal agencies.
- FedRAMP Low is NIST Low plus extra cloud controls. Moderate and High follow the same pattern.
- CMMC Level 1 is a basic subset for public federal data, Level 2 aligns with NIST SP 800-171 (comparable to NIST Moderate and FedRAMP Moderate), Level 3 overlays additional critical security based on NIST SP 800-172 (comparable in scope to NIST/FedRAMP High).
- PCI-DSS v4.0 contains 12 high-level requirements with 362 sub-requirements for payment card data protection.
- SOC 2 Trust Services Criteria focus on Security, Availability, Processing Integrity, Confidentiality, and Privacy with 64 points of focus.
- ISO 27001:2022 Annex A provides 114 security controls across 4 themes and 14 categories.
- Direct one-to-one control matches are rare; equivalence is based on typical federal and DoD mapping guidelines.
📄 Upload Compliance Documents
Upload SSPs, policies, or OSCAL catalogs to enrich the ComplianceBot knowledge base. Supported: .docx, .pdf, .json
Notice: ComplianceBot does not provide legal guidance. Consult your compliance and legal teams for authoritative requirements.
DeterBot: ComplianceBot
🛡 ComplianceBot Ready
| Framework | Coverage | Status |
|---|---|---|
| NIST SP 800-53 | Low / Moderate / High baselines | ✅ Authoritative |
| FedRAMP 20x | Low / Moderate / High + SDR output | ✅ Authoritative |
| CMMC 2.0 | Level 1 / 2 / 3 | ✅ Authoritative |
| DISA IL2 / IL4 / IL5 | DoD Impact Levels | ✅ Authoritative |
| CCCS ITSP.30.031 | Canadian Medium baseline | ✅ Authoritative |
| PCI-DSS v4.0 / SOC 2 / HITRUST / PSD2 | Industry standards | ⚠ Community-sourced |
What I can help with
| Feature | Description |
|---|---|
| 📋 Control Assessment | Document controls, set implementation status, write narratives |
| 🔗 Semantic Crosswalk | Map controls across frameworks — answer once, satisfy many |
| ☁ Resource Discovery | Scan AWS accounts and tag-scoped resources into your workload |
| 📊 CIS Export | Control Implementation Summary with inheritance — export to CSV |
| 📄 FedRAMP SDR | Generate Security Decision Record (FedRAMP 20x requirement) |