ExportableProof — Routines today. Proof tomorrow.

Evidence

Access Rights Register

Define the required structure for an auditable register of access rights, approvals, business justifications, review status, revocation evidence, and privileged access decisions.

Back to demo

OSCAL source · ARR

{
  "artifactId": "ARR",
  "iso": [
    "8.1",
    "7.5"
  ],
  "catalog": [
    {
      "iso": "8.1",
      "oscalId": "iso27001-8.1",
      "title": "Operational planning and control",
      "className": "iso27001-clause",
      "group": "Operation"
    },
    {
      "iso": "7.5",
      "oscalId": "iso27001-7.5",
      "title": "Documented information",
      "className": "iso27001-clause",
      "group": "Support"
    }
  ],
  "profileAlters": [
    {
      "control-id": "iso27001-7.5",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
            },
            {
              "name": "implementation-status",
              "value": "always-in-scope"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-8.1",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
            },
            {
              "name": "implementation-status",
              "value": "always-in-scope"
            }
          ]
        }
      ]
    }
  ],
  "components": [],
  "sspImplementedRequirements": [
    {
      "control-id": "iso27001-a.5.18",
      "props": [
        {
          "name": "iso-id",
          "value": "A.5.18"
        },
        {
          "name": "applicability",
          "value": "applicable"
        },
        {
          "name": "evidence-layer",
          "value": "linked"
        },
        {
          "name": "implementation-status-raw",
          "value": "Implemented"
        },
        {
          "name": "control-owner",
          "value": "IT Operations"
        },
        {
          "name": "evidence-status",
          "value": "Partial"
        }
      ],
      "links": [
        {
          "rel": "field-ref",
          "text": "ARR"
        },
        {
          "rel": "cites",
          "text": "SOA"
        },
        {
          "rel": "cites",
          "text": "ISOCTRL"
        },
        {
          "rel": "field-ref",
          "text": "AST-001"
        },
        {
          "rel": "field-ref",
          "text": "AST-003"
        },
        {
          "rel": "field-ref",
          "text": "AST-002"
        },
        {
          "rel": "field-ref",
          "text": "AST-009"
        },
        {
          "rel": "field-ref",
          "text": "AST-007"
        },
        {
          "rel": "field-ref",
          "text": "AST-005"
        }
      ]
    }
  ]
}

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…