Technical research mapped to security frameworks.
These reference pages show how research artifacts may relate to common framework provisions. Framework references describe evidence mapping and control alignment. SecHive is not presently certified or independently audited under these frameworks unless explicitly stated.
NIS 2 Directive
Cybersecurity risk-management measures for essential and important entities across the EU.
Open →DORA
Threat-led penetration testing for financial entities and ICT third parties.
Open →PCI DSS 4.0
Penetration testing of the cardholder-data environment, with segmentation evidence.
Open →SOC 2
Common criteria for vulnerability identification and threat detection.
Open →ISO/IEC 27001
Annex A controls for technical vulnerability management and security testing.
Open →HIPAA Security Rule
Periodic technical and non-technical evaluation evidence.
Open →Reference mapping, not certification.
Framework references describe evidence mapping and control alignment. SecHive is not presently certified or independently audited under these frameworks unless explicitly stated.
Research workflow
- Mode-labeled technical evidence.
- Per-finding artifact history.
- Replay scripts and artifact hashes.
- Reference matrices mapped to framework articles.
- Redaction manifests for handling sensitive material.
SecHive does not produce
- Compliance certification.
- Auditor opinion or attestation.
- Organizational control design.
- Risk acceptance decisions.
- Substitute for a qualified assessor.