OpenSSF project
Gemara
Schemas, SDKs, and tooling implementing the Gemara GRC engineering model — machine-readable formats that bridge high-level compliance requirements and low-level technical evidence to enable automated risk assessment across security tooling.
How each persona uses Gemara
Open Source Professional (OSPO) OSPO
Expresses the organization's controls and compliance requirements in Gemara's shared model so they can be assessed consistently across projects.
Security Engineer / Architect Security
Maps threats, controls, and evidence onto Gemara's layered schema to drive automated, repeatable risk assessment.
CI/CD DevOps & Tooling Integrator DevOps
Consumes Gemara's machine-readable model to automate control evaluation and evidence collection inside the pipeline.
Executive / End-User Consumer Executive
Reads risk and compliance status rolled up through Gemara's model rather than from disconnected, hand-assembled spreadsheets.
Problems Gemara helps with
Policy & Compliance Enforcement Compliance
Encodes governance, risk, and compliance requirements as a shared data model so controls map cleanly between regulations and evidence.
Measuring Security Posture Posture
Standardizes how risk and control evidence are expressed so posture can be assessed automatically and compared across projects.
Relationships
Outgoing
- implementsGemara Whitepaperpublication