ExportableProof — Routines today. Proof tomorrow.

Evidence

ISMS Change Log

Define the required structure for planning, approving, implementing and reviewing changes to the ISMS as a management system, distinct from technical production change management.

Back to demo

OSCAL source · ISMS-CL

{
  "artifactId": "ISMS-CL",
  "iso": [
    "6.3",
    "7.5"
  ],
  "catalog": [
    {
      "iso": "6.3",
      "oscalId": "iso27001-6.3",
      "title": "Planning of changes",
      "className": "iso27001-clause",
      "group": "Planning"
    },
    {
      "iso": "7.5",
      "oscalId": "iso27001-7.5",
      "title": "Documented information",
      "className": "iso27001-clause",
      "group": "Support"
    }
  ],
  "profileAlters": [
    {
      "control-id": "iso27001-6.3",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
            },
            {
              "name": "implementation-status",
              "value": "always-in-scope"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-7.5",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
            },
            {
              "name": "implementation-status",
              "value": "always-in-scope"
            }
          ]
        }
      ]
    }
  ],
  "components": [],
  "sspImplementedRequirements": [
    {
      "control-id": "iso27001-6.3",
      "props": [
        {
          "name": "iso-id",
          "value": "6.3"
        },
        {
          "name": "applicability",
          "value": "applicable"
        },
        {
          "name": "evidence-layer",
          "value": "linked"
        },
        {
          "name": "implementation-status-raw",
          "value": "always-in-scope"
        },
        {
          "name": "control-owner",
          "value": "Change Manager"
        },
        {
          "name": "evidence-status",
          "value": "documented"
        },
        {
          "name": "unresolved-evidence",
          "value": "CMP; CR"
        }
      ],
      "links": [
        {
          "rel": "cites",
          "text": "ISMS-CL"
        },
        {
          "rel": "cites",
          "text": "ISOCL"
        }
      ]
    },
    {
      "control-id": "iso27001-8.2",
      "props": [
        {
          "name": "iso-id",
          "value": "8.2"
        },
        {
          "name": "applicability",
          "value": "applicable"
        },
        {
          "name": "evidence-layer",
          "value": "linked"
        },
        {
          "name": "implementation-status-raw",
          "value": "always-in-scope"
        },
        {
          "name": "control-owner",
          "value": "Risk Manager"
        },
        {
          "name": "evidence-status",
          "value": "documented"
        },
        {
          "name": "unresolved-evidence",
          "value": "RAM"
        }
      ],
      "links": [
        {
          "rel": "cites",
          "text": "RR"
        },
        {
          "rel": "cites",
          "text": "ISMS-CL"
        },
        {
          "rel": "cites",
          "text": "ISOCL"
        }
      ]
    }
  ]
}

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…