ExportableProof — Routines today. Proof tomorrow.

Role

ISMS RACI Matrix

Define the required structure for assigning ISMS responsibilities and authorities with exactly one accountable role per activity, clear responsible roles, consulted and informed stakeholders, named confirmation and evidence.

Back to demo

OSCAL source · RACI

{
  "artifactId": "RACI",
  "iso": [
    "5.3",
    "7.5"
  ],
  "catalog": [
    {
      "iso": "5.3",
      "oscalId": "iso27001-5.3",
      "title": "Organizational roles, responsibilities and authorities",
      "className": "iso27001-clause",
      "group": "Leadership"
    },
    {
      "iso": "7.5",
      "oscalId": "iso27001-7.5",
      "title": "Documented information",
      "className": "iso27001-clause",
      "group": "Support"
    }
  ],
  "profileAlters": [
    {
      "control-id": "iso27001-5.3",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
            },
            {
              "name": "implementation-status",
              "value": "always-in-scope"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-7.5",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
            },
            {
              "name": "implementation-status",
              "value": "always-in-scope"
            }
          ]
        }
      ]
    }
  ],
  "components": [],
  "sspImplementedRequirements": [
    {
      "control-id": "iso27001-a.5.2",
      "props": [
        {
          "name": "iso-id",
          "value": "A.5.2"
        },
        {
          "name": "applicability",
          "value": "applicable"
        },
        {
          "name": "evidence-layer",
          "value": "documented"
        },
        {
          "name": "implementation-status-raw",
          "value": "Implemented"
        },
        {
          "name": "control-owner",
          "value": "ISMS Manager"
        },
        {
          "name": "evidence-status",
          "value": "Complete"
        },
        {
          "name": "unresolved-evidence",
          "value": "RACI"
        }
      ],
      "links": [
        {
          "rel": "cites",
          "text": "SOA"
        },
        {
          "rel": "cites",
          "text": "ISOCTRL"
        }
      ]
    }
  ]
}

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…