OSCAL source · ISS
{
"artifactId": "ISS",
"iso": [
"4.3",
"4.1",
"4.2"
],
"catalog": [
{
"iso": "4.3",
"oscalId": "iso27001-4.3",
"title": "Determining the scope of the ISMS",
"className": "iso27001-clause",
"group": "Context of the organization"
},
{
"iso": "4.1",
"oscalId": "iso27001-4.1",
"title": "Understanding the organization and its context",
"className": "iso27001-clause",
"group": "Context of the organization"
},
{
"iso": "4.2",
"oscalId": "iso27001-4.2",
"title": "Understanding the needs and expectations of interested parties",
"className": "iso27001-clause",
"group": "Context of the organization"
}
],
"profileAlters": [
{
"control-id": "iso27001-4.1",
"adds": [
{
"props": [
{
"name": "applicability",
"value": "applicable"
},
{
"name": "applicability-justification",
"value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
},
{
"name": "implementation-status",
"value": "always-in-scope"
}
]
}
]
},
{
"control-id": "iso27001-4.2",
"adds": [
{
"props": [
{
"name": "applicability",
"value": "applicable"
},
{
"name": "applicability-justification",
"value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
},
{
"name": "implementation-status",
"value": "always-in-scope"
}
]
}
]
},
{
"control-id": "iso27001-4.3",
"adds": [
{
"props": [
{
"name": "applicability",
"value": "applicable"
},
{
"name": "applicability-justification",
"value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
},
{
"name": "implementation-status",
"value": "always-in-scope"
}
]
}
]
}
],
"components": [],
"sspImplementedRequirements": []
}
Close