ExportableProof — Routines today. Proof tomorrow.

Evidence

Monitoring and Measurement Evidence

Define the required structure for tracking ISMS monitoring and measurement evidence, including metrics, targets, actual results, owners, review cadence, evidence references and follow-up actions.

Back to demo

OSCAL source · MME

{
  "artifactId": "MME",
  "iso": [
    "9.1",
    "7.5"
  ],
  "catalog": [
    {
      "iso": "9.1",
      "oscalId": "iso27001-9.1",
      "title": "Monitoring, measurement, analysis and evaluation",
      "className": "iso27001-clause",
      "group": "Performance evaluation"
    },
    {
      "iso": "7.5",
      "oscalId": "iso27001-7.5",
      "title": "Documented information",
      "className": "iso27001-clause",
      "group": "Support"
    }
  ],
  "profileAlters": [
    {
      "control-id": "iso27001-7.5",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
            },
            {
              "name": "implementation-status",
              "value": "always-in-scope"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-9.1",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
            },
            {
              "name": "implementation-status",
              "value": "always-in-scope"
            }
          ]
        }
      ]
    }
  ],
  "components": [],
  "sspImplementedRequirements": [
    {
      "control-id": "iso27001-9.1",
      "props": [
        {
          "name": "iso-id",
          "value": "9.1"
        },
        {
          "name": "applicability",
          "value": "applicable"
        },
        {
          "name": "evidence-layer",
          "value": "linked"
        },
        {
          "name": "implementation-status-raw",
          "value": "always-in-scope"
        },
        {
          "name": "control-owner",
          "value": "Security Lead"
        },
        {
          "name": "evidence-status",
          "value": "documented"
        },
        {
          "name": "unresolved-evidence",
          "value": "MME"
        }
      ],
      "links": [
        {
          "rel": "cites",
          "text": "IMPL-WB"
        },
        {
          "rel": "cites",
          "text": "MRART"
        },
        {
          "rel": "cites",
          "text": "ISOCL"
        }
      ]
    }
  ]
}

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…