ExportableProof — Routines today. Proof tomorrow.

Evidence

ISMS Communication Plan

Define the required structure for planning and tracking ISMS communications by audience, message, trigger, frequency, owner, channel, evidence and effectiveness.

Back to demo

OSCAL source · COMM-P

{
  "artifactId": "COMM-P",
  "iso": [
    "7.4",
    "7.5"
  ],
  "catalog": [
    {
      "iso": "7.4",
      "oscalId": "iso27001-7.4",
      "title": "Communication",
      "className": "iso27001-clause",
      "group": "Support"
    },
    {
      "iso": "7.5",
      "oscalId": "iso27001-7.5",
      "title": "Documented information",
      "className": "iso27001-clause",
      "group": "Support"
    }
  ],
  "profileAlters": [
    {
      "control-id": "iso27001-7.4",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
            },
            {
              "name": "implementation-status",
              "value": "always-in-scope"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-7.5",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
            },
            {
              "name": "implementation-status",
              "value": "always-in-scope"
            }
          ]
        }
      ]
    }
  ],
  "components": [],
  "sspImplementedRequirements": [
    {
      "control-id": "iso27001-7.4",
      "props": [
        {
          "name": "iso-id",
          "value": "7.4"
        },
        {
          "name": "applicability",
          "value": "applicable"
        },
        {
          "name": "evidence-layer",
          "value": "linked"
        },
        {
          "name": "implementation-status-raw",
          "value": "always-in-scope"
        },
        {
          "name": "control-owner",
          "value": "Communications Owner"
        },
        {
          "name": "evidence-status",
          "value": "documented"
        },
        {
          "name": "unresolved-evidence",
          "value": "SICT; IRP"
        }
      ],
      "links": [
        {
          "rel": "cites",
          "text": "COMM-P"
        },
        {
          "rel": "cites",
          "text": "ISOCL"
        }
      ]
    },
    {
      "control-id": "iso27001-a.5.5",
      "props": [
        {
          "name": "iso-id",
          "value": "A.5.5"
        },
        {
          "name": "applicability",
          "value": "applicable"
        },
        {
          "name": "evidence-layer",
          "value": "linked"
        },
        {
          "name": "implementation-status-raw",
          "value": "Implemented"
        },
        {
          "name": "control-owner",
          "value": "Compliance Manager"
        },
        {
          "name": "evidence-status",
          "value": "Partial"
        }
      ],
      "links": [
        {
          "rel": "field-ref",
          "text": "COMM-P"
        },
        {
          "rel": "cites",
          "text": "SOA"
        },
        {
          "rel": "cites",
          "text": "ISOCTRL"
        }
      ]
    }
  ]
}

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…