ExportableProof — Routines today. Proof tomorrow.

Dependency

Competence Matrix and Training Plan

Define the required structure for mapping ISMS roles to competence requirements, evidence held, gaps, training actions, owners, target dates and effectiveness verification.

Back to demo

OSCAL source · CMTP

{
  "artifactId": "CMTP",
  "iso": [
    "7.2",
    "7.5"
  ],
  "catalog": [
    {
      "iso": "7.2",
      "oscalId": "iso27001-7.2",
      "title": "Competence",
      "className": "iso27001-clause",
      "group": "Support"
    },
    {
      "iso": "7.5",
      "oscalId": "iso27001-7.5",
      "title": "Documented information",
      "className": "iso27001-clause",
      "group": "Support"
    }
  ],
  "profileAlters": [
    {
      "control-id": "iso27001-7.2",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
            },
            {
              "name": "implementation-status",
              "value": "always-in-scope"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-7.5",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
            },
            {
              "name": "implementation-status",
              "value": "always-in-scope"
            }
          ]
        }
      ]
    }
  ],
  "components": [],
  "sspImplementedRequirements": [
    {
      "control-id": "iso27001-7.2",
      "props": [
        {
          "name": "iso-id",
          "value": "7.2"
        },
        {
          "name": "applicability",
          "value": "applicable"
        },
        {
          "name": "evidence-layer",
          "value": "linked"
        },
        {
          "name": "implementation-status-raw",
          "value": "always-in-scope"
        },
        {
          "name": "control-owner",
          "value": "HR Manager"
        },
        {
          "name": "evidence-status",
          "value": "documented"
        },
        {
          "name": "unresolved-evidence",
          "value": "TR; TRC; HRP"
        }
      ],
      "links": [
        {
          "rel": "cites",
          "text": "CMTP"
        },
        {
          "rel": "cites",
          "text": "ISOCL"
        },
        {
          "rel": "cites",
          "text": "HRSP"
        },
        {
          "rel": "cites",
          "text": "MDR"
        },
        {
          "rel": "cites",
          "text": "DR"
        },
        {
          "rel": "cites",
          "text": "RRS"
        },
        {
          "rel": "cites",
          "text": "AI"
        },
        {
          "rel": "cites",
          "text": "UAI"
        }
      ]
    }
  ]
}

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…