Frameworks / Sigstore - Software Artifact Signing and Verification / SIGSTORE-2 Sigstore - Software Artifact Signing and Verification
Transparency Log
Sigstore - Software Artifact Signing and Verification SIGSTORE-2: Transparency Log (Rekor) and Verification Per Sigstore: Rekor transparency log. Requirements include (a) record signing events to Rekor + (b) verify signatures + Rekor entries + (c) implement verification policy + (d) integrate with consumers.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 185 controls across 67 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ISO27043-06 Asset inventory and ownership ISO27043-08 Information classification and labeling ISO27043-10 Media management and disposal ISO27043-11 Access control policy and enforcement ISO27043-12 User access management and provisioning ISO27043-13 Authentication and password management ISO27043-14 Privileged access management ISO27043-15 Access review and recertification ISO21434-07 Acceptable use of assets ISO21434-08 Information classification and labeling ISO21434-09 Asset handling procedures ISO21434-12 User access management and provisioning ISO21434-13 Authentication and password management ISO21434-14 Privileged access management ISO21434-15 Access review and recertification AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management AWWA-2.2 Authentication Mechanisms AWWA-2.3 Account Management AWWA-2.4 Physical Access Controls BSI-01 Account management and provisioning BSI-02 Access enforcement and least privilege BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions ISO27799-01 ePHI access controls and authorization ISO27799-08 Information access management ISO27799-12 Unique user identification and authentication ISO27799-17 Facility access controls ISMSP-AC-01 Access Control Policy ISMSP-AC-02 User Account Management ISMSP-AC-03 Authentication Mechanisms ISMSP-AC-04 Network Access Control API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) CAT-D3-1 Preventative controls CAT-D4-3 Third-party access controls CAT-IRP-4 Organizational characteristics IEC62443-07 Personnel risk assessment IEC62443-08 Electronic access perimeter management IEC62443-10 Revocation of access procedures 27010-8.1 Membership Onboarding 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources ISO27019-07 Personnel risk assessment ISO27019-08 Electronic access perimeter management ISO27019-10 Revocation of access procedures 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties OB-CX.3 Strong Customer Authentication OB-DIR.1 Open Banking Directory OB-SEC.4 Certificate Management DSO-2 Data Security DSO-3 Data Access Management FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) ISO-19650-1-5 Delivery team and task team concepts ISO-19650-2-5.7 Information model delivery 27011-5.3 Segregation of duties 27011-8.1 User Endpoint Devices BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition SAM-1 Customer Information Confidentiality (Section 48) SAM-6 Legal Authorization Requirements AMLCTF-35 Identity Verification Standard APPI-A26 Report of Leakage to the Commission and Notification to the Person CA-ITSG33-SC-01 Security Control Catalogue FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) 62351-8 Role-based access control (RBAC) ISO28001-PS-01 Facility Security ISO20000-15 Access management for services 23837-1.7.3 Authentication and classical post-processing 27400-6.1 Secure Device Design ITIL4-15 Access management for services QRCM-1.1 Cryptographic Asset Inventory RCEPEC-1 Online Personal Information Protection (12.13) SA-PDPL-15 Access control for personal data TEFCAREC-1 Common Agreement Conformance and Onboarding TSAPIPE-2 OT/IT Network Segmentation and Access Control TURKEYKVKK-2 Information Notice and Data Subject Rights UKGAMBLE-4 Resilience and Incident Response SEMD-PS-2 Site Security Measures ACE-CR-4 Cargo Release Authorization CPSC-CS.2 Authentication and Access Controls USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) CYB-2 Account Security Measures USMCADIGITAL-2 Personal Information Protection and Consumer Protection VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency VIETNAMPDP-2 Consent and Notice W3CVCDM-4 Accessibility, Internationalization, Security Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 185 it maps to, and the evidence behind each claim, over MCP and REST.