ExportableProof — Routines today. Proof tomorrow.

Evidence

Security Incident Register

Define the required structure for tracking security incidents from detection through triage, containment, investigation, communication, corrective action, lessons learned and closure evidence.

Back to demo

OSCAL source · SIR

{
  "artifactId": "SIR",
  "iso": [
    "8.1",
    "7.5"
  ],
  "catalog": [
    {
      "iso": "8.1",
      "oscalId": "iso27001-8.1",
      "title": "Operational planning and control",
      "className": "iso27001-clause",
      "group": "Operation"
    },
    {
      "iso": "7.5",
      "oscalId": "iso27001-7.5",
      "title": "Documented information",
      "className": "iso27001-clause",
      "group": "Support"
    }
  ],
  "profileAlters": [
    {
      "control-id": "iso27001-7.5",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
            },
            {
              "name": "implementation-status",
              "value": "always-in-scope"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-8.1",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
            },
            {
              "name": "implementation-status",
              "value": "always-in-scope"
            }
          ]
        }
      ]
    }
  ],
  "components": [],
  "sspImplementedRequirements": [
    {
      "control-id": "iso27001-a.5.25",
      "props": [
        {
          "name": "iso-id",
          "value": "A.5.25"
        },
        {
          "name": "applicability",
          "value": "applicable"
        },
        {
          "name": "evidence-layer",
          "value": "linked"
        },
        {
          "name": "implementation-status-raw",
          "value": "Implemented"
        },
        {
          "name": "control-owner",
          "value": "Incident Manager"
        },
        {
          "name": "evidence-status",
          "value": "Partial"
        },
        {
          "name": "unresolved-evidence",
          "value": "SIR"
        }
      ],
      "links": [
        {
          "rel": "cites",
          "text": "SOA"
        },
        {
          "rel": "cites",
          "text": "ISOCTRL"
        },
        {
          "rel": "cites",
          "text": "IMP"
        },
        {
          "rel": "cites",
          "text": "MDR"
        },
        {
          "rel": "cites",
          "text": "DR"
        },
        {
          "rel": "cites",
          "text": "RRS"
        },
        {
          "rel": "cites",
          "text": "AI"
        },
        {
          "rel": "cites",
          "text": "UAI"
        }
      ]
    }
  ]
}

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…