It’s a modular ruleset for aligning [Wazuh](https://wazuh.com) (open-source SIEM) with the FBI’s CJIS Security Policy — with mappings to NIST 800-53 baked in. Built for public sector security teams, analysts, and any org handling CJIS-regulated data.
In less than 48 hours:
- 349 clones, 178 unique cloners
- 822+ repo views, 101 unique visitors
- Interest from multiple orgs including use for CMMC control scanning
- Community engagement on LinkedIn and GitHub already kicking off
What’s included so far:
- Rule creation for CJIS Areas 1–6 (in progress)
- Modular, Git-managed XML rules
- Inline control mappings + assumptions
- Project roadmap and contributor-friendly structure
Up next:
- Compliance dashboards
- Trigger validation in Wazuh test environment
- SCA policies + reporting scripts
This is a build-in-public project — I’m keeping it transparent, open to feedback, and focused on real-world use. If CJIS, NIST, or Wazuh is in your world, I’d love input or collaboration.
BestDev•3h ago
I've released a new open-source project that's gaining real momentum in the security compliance space:
https://github.com/TristanGNS/wazuh-cjis-rules
It’s a modular ruleset for aligning [Wazuh](https://wazuh.com) (open-source SIEM) with the FBI’s CJIS Security Policy — with mappings to NIST 800-53 baked in. Built for public sector security teams, analysts, and any org handling CJIS-regulated data.
In less than 48 hours: - 349 clones, 178 unique cloners - 822+ repo views, 101 unique visitors - Interest from multiple orgs including use for CMMC control scanning - Community engagement on LinkedIn and GitHub already kicking off
What’s included so far: - Rule creation for CJIS Areas 1–6 (in progress) - Modular, Git-managed XML rules - Inline control mappings + assumptions - Project roadmap and contributor-friendly structure
Up next: - Compliance dashboards - Trigger validation in Wazuh test environment - SCA policies + reporting scripts
This is a build-in-public project — I’m keeping it transparent, open to feedback, and focused on real-world use. If CJIS, NIST, or Wazuh is in your world, I’d love input or collaboration.
GitHub: https://github.com/TristanGNS/wazuh-cjis-rules
Thanks for reading!