OSCAL source · OS
{
"artifactId": "OS",
"iso": [
"5.3",
"5.1",
"4.1"
],
"catalog": [
{
"iso": "5.3",
"oscalId": "iso27001-5.3",
"title": "Organizational roles, responsibilities and authorities",
"className": "iso27001-clause",
"group": "Leadership"
},
{
"iso": "5.1",
"oscalId": "iso27001-5.1",
"title": "Leadership and commitment",
"className": "iso27001-clause",
"group": "Leadership"
},
{
"iso": "4.1",
"oscalId": "iso27001-4.1",
"title": "Understanding the organization and its context",
"className": "iso27001-clause",
"group": "Context of the organization"
}
],
"profileAlters": [
{
"control-id": "iso27001-4.1",
"adds": [
{
"props": [
{
"name": "applicability",
"value": "applicable"
},
{
"name": "applicability-justification",
"value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
},
{
"name": "implementation-status",
"value": "always-in-scope"
}
]
}
]
},
{
"control-id": "iso27001-5.1",
"adds": [
{
"props": [
{
"name": "applicability",
"value": "applicable"
},
{
"name": "applicability-justification",
"value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
},
{
"name": "implementation-status",
"value": "always-in-scope"
}
]
}
]
},
{
"control-id": "iso27001-5.3",
"adds": [
{
"props": [
{
"name": "applicability",
"value": "applicable"
},
{
"name": "applicability-justification",
"value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
},
{
"name": "implementation-status",
"value": "always-in-scope"
}
]
}
]
}
],
"components": [],
"sspImplementedRequirements": []
}
Close