Smart contracts — Volume 1
Every artefact is four layers: Contract, Example, Office, and OSCAL. List them, check they sit together, trace a control, or open the review. This page does not re-score the review.
SIMULATION · 51/51 closed sets · 7 of 7 OSCAL models · 105 artefacts from another book, cited not merged
List
Artefacts in this book. Items from another book stay listed, not merged.
| ID | Title | Type | Role | Contract | Example | Office | OSCAL |
|---|---|---|---|---|---|---|---|
27003-27004-MAP | ISO 27003 / 27004 Conformance Matrix | dependency | other-book | — | — | Acquire | — |
ACM | Access Control Matrix | operational-target | other-book | — | — | Acquire | — |
AI | Asset Inventory | asset | in-pack | Contract | Example | Office | OSCAL |
AISGF | AI System Governance File | evidence | other-book | — | — | Acquire | — |
AMP | Asset Management Policy | policy | in-pack | Contract | Example | Office | OSCAL |
AOAVC | Asset Owner Asset Validation Checklist | process | other-book | — | — | Acquire | — |
AORVC | Asset Owner Risk Validation Checklist | process | other-book | — | — | Acquire | — |
ARA | Access Request and Approval | process | other-book | — | — | Acquire | — |
ARR | Access Rights Register | evidence | other-book | — | — | Acquire | — |
ASTR | Application Security Testing Register | evidence | other-book | — | — | Acquire | — |
AUD-ER | Auditor Evidence Request Log | evidence | other-book | — | — | Acquire | — |
BCP | Business Continuity Plan (BCP) | process | other-book | — | — | Acquire | — |
BCPOL | Business Continuity Policy | policy | other-book | — | — | Acquire | — |
BIA | Business Impact Analysis (BIA) Statement | business-impact | other-book | — | — | Acquire | — |
BRP | Backup & Recovery Policy | process | other-book | — | — | Acquire | — |
BRPROC | Backup & Recovery Procedure | process | other-book | — | — | Acquire | — |
BRT-R | Backup Restore Test Record | evidence | other-book | — | — | Acquire | — |
C5-CM | BSI C5 Criteria Mapping | dependency | other-book | — | — | Acquire | — |
CAR | Corrective Actions Register | evidence | in-pack | Contract | Example | Office | OSCAL |
CB-SEL | Certification Body Selection and Evaluation | dependency | other-book | — | — | Acquire | — |
CE-SA | UK Cyber Essentials Self-Assessment | process | other-book | — | — | Acquire | — |
CERT-DR | Certification Audit Dry-Run Workbook | evidence | other-book | — | — | Acquire | — |
CERT-P | Certification Project Plan | evidence | other-book | — | — | Acquire | — |
CFE-X | Cross-Framework Evidence Crosswalk | dependency | other-book | — | — | Acquire | — |
CICD-H | CI/CD Security Hardening Checklist | assessment | other-book | — | — | Acquire | — |
CIL | Continual Improvement Log | evidence | other-book | — | — | Acquire | — |
CKMP | Cryptography & Key Management Policy | policy | other-book | — | — | Acquire | — |
CLD-BL | Cloud Security Baseline Checklist | assessment | other-book | — | — | Acquire | — |
CMP | Change Management Policy & Procedure | process | other-book | — | — | Acquire | — |
CMTP | Competence Matrix and Training Plan | dependency | other-book | — | — | Acquire | — |
CNI | Companion Navigation Index | dependency | in-pack | Contract | Example | Office | OSCAL |
COMM-P | ISMS Communication Plan | evidence | other-book | — | — | Acquire | — |
CP | Cryptography Policy | policy | other-book | — | — | Acquire | — |
CR | Context Register | evidence | in-pack | Contract | Example | Office | OSCAL |
CRA-PSF | CRA Product Security File | process | other-book | — | — | Acquire | — |
CSP | Cloud Security Policy | policy | other-book | — | — | Acquire | — |
CSR | Critical Services Register | evidence | other-book | — | — | Acquire | — |
CSRM | Cloud Shared Responsibility Matrix | dependency | other-book | — | — | Acquire | — |
CSS | Contract Security Schedule | policy | other-book | — | — | Acquire | — |
CSSAQ | Critical Supplier Security Assessment Questionnaire | process | in-pack | Contract | Example | Office | OSCAL |
DAL | Decision and Action Log | evidence | in-pack | Contract | Example | Office | OSCAL |
DCP | Document Control Procedure | process | other-book | — | — | Acquire | — |
DEP-RISK | Dependency Risk Assessment | process | other-book | — | — | Acquire | — |
DOP | Documented Operating Procedure Template | process | other-book | — | — | Acquire | — |
DPAR | Data Processing Activities Register (GDPR) | evidence | other-book | — | — | Acquire | — |
DPIA | Data Protection Impact Assessment | business-impact | other-book | — | — | Acquire | — |
DPR | Data Processors Register (GDPR) | evidence | other-book | — | — | Acquire | — |
DR | Document Register | evidence | in-pack | Contract | Example | Office | OSCAL |
DRP | Disaster Recovery Plan (DRP) | process | other-book | — | — | Acquire | — |
DSAR | Data Subject Request Case File | process | other-book | — | — | Acquire | — |
ELAI | Evidence Log / Audit Pack Index | dependency | other-book | — | — | Acquire | — |
ENS-CAT | ENS Categorization Decision Record | process | other-book | — | — | Acquire | — |
ENS-MI | ENS Measure-to-Evidence Index | dependency | other-book | — | — | Acquire | — |
ENV-LOG | Environmental Monitoring and Alert Log | evidence | other-book | — | — | Acquire | — |
EP | Evacuation Plan | process | other-book | — | — | Acquire | — |
ERR | Executive Risk Report | process | in-pack | Contract | Example | Office | OSCAL |
EVAC-DR | Evacuation Drill Record | evidence | other-book | — | — | Acquire | — |
EXR | Exceptions Register | hybrid | other-book | — | — | Acquire | — |
FAC-RV | Facility Access Review Checklist | assessment | other-book | — | — | Acquire | — |
FDB | Framework Delta Backlog | evidence | other-book | — | — | Acquire | — |
FMI | Framework Mapping Index | dependency | other-book | — | — | Acquire | — |
GBDR | GDPR Breach Decision Record | process | other-book | — | — | Acquire | — |
GS | Gap Statement | policy | in-pack | Contract | Example | Office | OSCAL |
HRP | Human Resources Policy | policy | in-pack | Contract | Example | Office | OSCAL |
HRSP | Human Resources Security Policy | policy | in-pack | Contract | Example | Office | OSCAL |
IAP | Internal Audit Plan | assessment | in-pack | Contract | Example | Office | OSCAL |
IAPC | Internal Audit Program & Checklist | assessment | in-pack | Contract | Example | Office | OSCAL |
IAS | Information Assets Statement | process | in-pack | Contract | Example | Office | OSCAL |
ICL | ISMS Communication Log | evidence | in-pack | Contract | Example | Office | OSCAL |
ICP | Information Classification Policy | policy | in-pack | Contract | Example | Office | OSCAL |
ICVC | ISO 27001 Control Owner Control Validation Checklist | process | in-pack | Contract | Example | Office | OSCAL |
IGC | ISMS Governance Calendar | process | in-pack | Contract | Example | Office | OSCAL |
IL | Incident Log | evidence | other-book | — | — | Acquire | — |
IMP | Incident Management Policy | policy | other-book | — | — | Acquire | — |
IMPL-P | Phased ISMS Implementation Plan | evidence | other-book | — | — | Acquire | — |
IMPL-WB | Operational ISMS Dashboard | dependency | in-pack | Contract | Example | Office | OSCAL |
IPR | Interested Parties Register | role | in-pack | Contract | Example | Office | OSCAL |
IR-RB | Incident Response Runbooks | process | other-book | — | — | Acquire | — |
IRAR | ISMS Role Appointment Record | role | in-pack | Contract | Example | Office | OSCAL |
IRP | Incident Response Policy | policy | other-book | — | — | Acquire | — |
IRPROC | Incident Response Procedure | process | other-book | — | — | Acquire | — |
IRRT | Incident Register and Reporting Template | evidence | other-book | — | — | Acquire | — |
ISMS-CL | ISMS Change Log | evidence | other-book | — | — | Acquire | — |
ISO | Information Security Objectives | evidence | in-pack | Contract | Example | Office | OSCAL |
ISOCL | ISO 27001:2022 Clauses | control | in-pack | Contract | Example | Office | OSCAL |
ISOCTRL | ISO 27001:2022 Controls | control | in-pack | Contract | Example | Office | OSCAL |
ISP | Information Security Policy | policy | in-pack | Contract | Example | Office | OSCAL |
ISS | ISMS Scope Statement | system | in-pack | Contract | Example | Office | OSCAL |
ITG-MM | BSI IT-Grundschutz Module Mapping | dependency | other-book | — | — | Acquire | — |
KEY-R | Cryptographic Key Register | evidence | other-book | — | — | Acquire | — |
LMP | Logging and Monitoring Policy | policy | other-book | — | — | Acquire | — |
LRR | Legal, Regulatory and Contractual Requirements Register | evidence | other-book | — | — | Acquire | — |
MDR | Mandatory Documents and Records Register | evidence | other-book | — | — | Acquire | — |
MFAR | Multi-Framework Assurance Report | evidence | other-book | — | — | Acquire | — |
MME | Monitoring and Measurement Evidence | evidence | in-pack | Contract | Example | Office | OSCAL |
MRART | Management Review Agenda & Report Template | process | in-pack | Contract | Example | Office | OSCAL |
MRMT | Management Review Minutes Template | evidence | in-pack | Contract | Example | Office | OSCAL |
NC-RP | Nonconformity Response and Corrective Action Pack | poam | other-book | — | — | Acquire | — |
NFR-R | Network Firewall Rule Review Register | evidence | other-book | — | — | Acquire | — |
NIS2-RD | NIS2 First-Hours Reporting Drill | process | other-book | — | — | Acquire | — |
NSP | Network Security Policy | policy | other-book | — | — | Acquire | — |
OBL-CAL | Compliance Obligations Calendar | process | other-book | — | — | Acquire | — |
OER | Operations Evidence Register | evidence | other-book | — | — | Acquire | — |
OFC | Offboarding Checklist | process | in-pack | Contract | Example | Office | OSCAL |
ONC | Onboarding Checklist | process | in-pack | Contract | Example | Office | OSCAL |
OPC | Operational Planning and Control Evidence | evidence | in-pack | Contract | Example | Office | OSCAL |
OPI | Operational Procedures Index | dependency | other-book | — | — | Acquire | — |
OS | Organization Statement | role | in-pack | Contract | Example | Office | OSCAL |
PAP | Password & Authentication Policy | policy | other-book | — | — | Acquire | — |
PAR | Physical Access Register | evidence | other-book | — | — | Acquire | — |
PARR | Policy Approval and Review Register | policy | in-pack | Contract | Example | Office | OSCAL |
PBIVC | Process Owner Business Impact Validation Checklist | process | other-book | — | — | Acquire | — |
PCI-CDE | PCI DSS CDE Scope and Control Matrix | dependency | other-book | — | — | Acquire | — |
PESP | Physical and Environmental Security Policy | policy | other-book | — | — | Acquire | — |
RACI | ISMS RACI Matrix | role | in-pack | Contract | Example | Office | OSCAL |
RAE | Resource Allocation Evidence | evidence | in-pack | Contract | Example | Office | OSCAL |
RAM | Risk Assessment Methodology | process | in-pack | Contract | Example | Office | OSCAL |
RAMT | Risk Acceptance Minutes Template | evidence | in-pack | Contract | Example | Office | OSCAL |
RASM | Risk Analysis Statement according to Magerit and ISO 27005 | policy | in-pack | Contract | Example | Office | OSCAL |
RCIA | Regulatory Change Impact Assessment | evidence | other-book | — | — | Acquire | — |
REL-GATE | Security Release Gate Record | evidence | other-book | — | — | Acquire | — |
REQT | ISO 27001 Clauses 4-10 Requirements Tracker | control | other-book | — | — | Acquire | — |
RMP | Risk Management Plan | process | in-pack | Contract | Example | Office | OSCAL |
ROAR | ISMS Risks and Opportunities Register | risk | other-book | — | — | Acquire | — |
RPIT | Response Procedure by Incident Type | process | other-book | — | — | Acquire | — |
RR | Risk Register | risk | in-pack | Contract | Example | Office | OSCAL |
RRS | Records Retention Schedule | evidence | other-book | — | — | Acquire | — |
RTP | Risk Treatment Plan | poam | in-pack | Contract | Example | Office | OSCAL |
S1-RDY | Stage 1 Readiness Assessment | assessment | other-book | — | — | Acquire | — |
S2-RDY | Stage 2 Readiness and Sampling Assessment | assessment | other-book | — | — | Acquire | — |
SAS | Systems Architecture Statement | system | in-pack | Contract | Example | Office | OSCAL |
SBOM-R | SBOM and Component Inventory Register | asset | other-book | — | — | Acquire | — |
SCR-C | Secure Code Review Checklist | assessment | other-book | — | — | Acquire | — |
SEC-REQ | Security Requirements Register | evidence | other-book | — | — | Acquire | — |
SECR | Secrets Management Register | evidence | other-book | — | — | Acquire | — |
SI | Software Inventory | system | other-book | — | — | Acquire | — |
SICT | Security Incident Communication Template | process | other-book | — | — | Acquire | — |
SINV | Supplier Inventory | asset | in-pack | Contract | Example | Office | OSCAL |
SIR | Security Incident Register | evidence | other-book | — | — | Acquire | — |
SOA | Statement of Applicability (SoA) | control | in-pack | Contract | Example | Office | OSCAL |
SOAVC | Control Owner Statement of Applicability Validation Checklist | process | in-pack | Contract | Example | Office | OSCAL |
SOC2-EC | SOC 2 Evidence Calendar | process | other-book | — | — | Acquire | — |
SOC2-SD | SOC 2 System Description | policy | other-book | — | — | Acquire | — |
SRP | Supplier Relationships Policy | policy | in-pack | Contract | Example | Office | OSCAL |
SSAQ | Supplier Security Assessment Questionnaire | process | in-pack | Contract | Example | Office | OSCAL |
SSDLC | S-SDLC Implementation Requirements Checklist | process | other-book | — | — | Acquire | — |
SSDP | Secure Software Development Policy | policy | other-book | — | — | Acquire | — |
STD-SUP | Current Standard Supplement | policy | other-book | — | — | Acquire | — |
TISAX-AS | TISAX Assessment Scope and ISA Mapping | dependency | other-book | — | — | Acquire | — |
TMM | Threat Modeling Worksheet | evidence | other-book | — | — | Acquire | — |
TR | Training Register | evidence | in-pack | Contract | Example | Office | OSCAL |
TRC | Training Records | evidence | in-pack | Contract | Example | Office | OSCAL |
UAI | Users and Access Inventory | evidence | other-book | — | — | Acquire | — |
VULN-SLA | Vulnerability Remediation SLA Matrix | dependency | other-book | — | — | Acquire | — |
WIR-S1 | Weekly Report | process | other-book | — | — | Acquire | — |
XFA-R | Cross-Framework Applicability Register | control | other-book | — | — | Acquire | — |
Validate
Whether Contract, Example, Office, and OSCAL sit together, and that nothing was silently merged from another book.
Models are present, the office snapshot matches this book, and nothing was silently merged.
8 schema files are present for the OSCAL models.
OSCAL 1.1.2 models
| Model | Path | Status |
|---|---|---|
| catalog | oscal/catalog.json | present |
| profile | oscal/profile.json | present |
| component-definition | oscal/component-definition.json | present |
| system-security-plan | oscal/system-security-plan.json | present |
| assessment-plan | oscal/assessment-plan.json | present |
| assessment-results | oscal/assessment-results.json | present |
| plan-of-action-and-milestones | oscal/plan-of-action-and-milestones.json | present |
In-pack / factory-source triples
| ID | Title | Contract · Example · Office · OSCAL |
|---|---|---|
AI | Asset Inventory | closed |
AMP | Asset Management Policy | closed |
CAR | Corrective Actions Register | closed |
CNI | Companion Navigation Index | closed |
CR | Context Register | closed |
CSSAQ | Critical Supplier Security Assessment Questionnaire | closed |
DAL | Decision and Action Log | closed |
DR | Document Register | closed |
ERR | Executive Risk Report | closed |
GS | Gap Statement | closed |
HRP | Human Resources Policy | closed |
HRSP | Human Resources Security Policy | closed |
IAP | Internal Audit Plan | closed |
IAPC | Internal Audit Program & Checklist | closed |
IAS | Information Assets Statement | closed |
ICL | ISMS Communication Log | closed |
ICP | Information Classification Policy | closed |
ICVC | ISO 27001 Control Owner Control Validation Checklist | closed |
IGC | ISMS Governance Calendar | closed |
IMPL-WB | Operational ISMS Dashboard | closed |
IPR | Interested Parties Register | closed |
IRAR | ISMS Role Appointment Record | closed |
ISO | Information Security Objectives | closed |
ISOCL | ISO 27001:2022 Clauses | closed |
ISOCTRL | ISO 27001:2022 Controls | closed |
ISP | Information Security Policy | closed |
ISS | ISMS Scope Statement | closed |
MME | Monitoring and Measurement Evidence | closed |
MRART | Management Review Agenda & Report Template | closed |
MRMT | Management Review Minutes Template | closed |
OFC | Offboarding Checklist | closed |
ONC | Onboarding Checklist | closed |
OPC | Operational Planning and Control Evidence | closed |
OS | Organization Statement | closed |
PARR | Policy Approval and Review Register | closed |
RACI | ISMS RACI Matrix | closed |
RAE | Resource Allocation Evidence | closed |
RAM | Risk Assessment Methodology | closed |
RAMT | Risk Acceptance Minutes Template | closed |
RASM | Risk Analysis Statement according to Magerit and ISO 27005 | closed |
RMP | Risk Management Plan | closed |
RR | Risk Register | closed |
RTP | Risk Treatment Plan | closed |
SAS | Systems Architecture Statement | closed |
SINV | Supplier Inventory | closed |
SOA | Statement of Applicability (SoA) | closed |
SOAVC | Control Owner Statement of Applicability Validation Checklist | closed |
SRP | Supplier Relationships Policy | closed |
SSAQ | Supplier Security Assessment Questionnaire | closed |
TR | Training Register | closed |
TRC | Training Records | closed |
Office MANIFEST
| Tier | Path | Volume / language |
|---|---|---|
| Basic | source/volume-1/basic/MANIFEST.json | matches |
| Premium | source/volume-1/premium/MANIFEST.json | matches |
Silent joins
Nothing was silently merged from another book.
Trace
Start from a control, an artefact, or a finding. The chain is catalogue identity → Contract → Example → Office → assessment result.
Artefacts
| ID | Title | isoAnchors | cites | Open |
|---|---|---|---|---|
27003-27004-MAP | ISO 27003 / 27004 Conformance Matrix | — | — | open |
ACM | Access Control Matrix | — | — | open |
AI | Asset Inventory | 8.1, 7.5 | — | open |
AISGF | AI System Governance File | — | — | open |
AMP | Asset Management Policy | A.5.9, A.5.10, A.5.11, A.5.12, A.5.13 | MDR, DR, RRS, AI, SINV, UAI | open |
AOAVC | Asset Owner Asset Validation Checklist | — | — | open |
AORVC | Asset Owner Risk Validation Checklist | — | — | open |
ARA | Access Request and Approval | — | — | open |
ARR | Access Rights Register | — | — | open |
ASTR | Application Security Testing Register | — | — | open |
AUD-ER | Auditor Evidence Request Log | — | — | open |
BCP | Business Continuity Plan (BCP) | — | — | open |
BCPOL | Business Continuity Policy | — | — | open |
BIA | Business Impact Analysis (BIA) Statement | — | — | open |
BRP | Backup & Recovery Policy | — | — | open |
BRPROC | Backup & Recovery Procedure | — | — | open |
BRT-R | Backup Restore Test Record | — | — | open |
C5-CM | BSI C5 Criteria Mapping | — | — | open |
CAR | Corrective Actions Register | 7.5 | — | open |
CB-SEL | Certification Body Selection and Evaluation | — | — | open |
CE-SA | UK Cyber Essentials Self-Assessment | — | — | open |
CERT-DR | Certification Audit Dry-Run Workbook | — | — | open |
CERT-P | Certification Project Plan | — | — | open |
CFE-X | Cross-Framework Evidence Crosswalk | — | — | open |
CICD-H | CI/CD Security Hardening Checklist | — | — | open |
CIL | Continual Improvement Log | — | — | open |
CKMP | Cryptography & Key Management Policy | — | — | open |
CLD-BL | Cloud Security Baseline Checklist | — | — | open |
CMP | Change Management Policy & Procedure | — | — | open |
CMTP | Competence Matrix and Training Plan | — | — | open |
CNI | Companion Navigation Index | 8.1, 7.5 | — | open |
COMM-P | ISMS Communication Plan | — | — | open |
CP | Cryptography Policy | — | — | open |
CR | Context Register | 4.1, 7.5 | — | open |
CRA-PSF | CRA Product Security File | — | — | open |
CSP | Cloud Security Policy | — | — | open |
CSR | Critical Services Register | — | — | open |
CSRM | Cloud Shared Responsibility Matrix | — | — | open |
CSS | Contract Security Schedule | — | — | open |
CSSAQ | Critical Supplier Security Assessment Questionnaire | A.5.19, A.5.20, A.5.21, A.5.22 | — | open |
DAL | Decision and Action Log | 8.1, 7.5 | — | open |
DCP | Document Control Procedure | — | — | open |
DEP-RISK | Dependency Risk Assessment | — | — | open |
DOP | Documented Operating Procedure Template | — | — | open |
DPAR | Data Processing Activities Register (GDPR) | — | — | open |
DPIA | Data Protection Impact Assessment | — | — | open |
DPR | Data Processors Register (GDPR) | — | — | open |
DR | Document Register | 7.5 | — | open |
DRP | Disaster Recovery Plan (DRP) | — | — | open |
DSAR | Data Subject Request Case File | — | — | open |
ELAI | Evidence Log / Audit Pack Index | — | — | open |
ENS-CAT | ENS Categorization Decision Record | — | — | open |
ENS-MI | ENS Measure-to-Evidence Index | — | — | open |
ENV-LOG | Environmental Monitoring and Alert Log | — | — | open |
EP | Evacuation Plan | — | — | open |
ERR | Executive Risk Report | 7.5 | MDR, DR, RRS | open |
EVAC-DR | Evacuation Drill Record | — | — | open |
EXR | Exceptions Register | — | — | open |
FAC-RV | Facility Access Review Checklist | — | — | open |
FDB | Framework Delta Backlog | — | — | open |
FMI | Framework Mapping Index | — | — | open |
GBDR | GDPR Breach Decision Record | — | — | open |
GS | Gap Statement | 7.5 | MDR, DR, RRS, AI, SINV, UAI | open |
HRP | Human Resources Policy | A.6.1, A.6.2, A.6.3, A.6.4, A.6.5, 7.2 | MDR, DR, RRS, AI, SINV, UAI | open |
HRSP | Human Resources Security Policy | A.6.1, A.6.2, A.6.3, A.6.5, 7.2 | MDR, DR, RRS, AI, SINV, UAI | open |
IAP | Internal Audit Plan | 9.2, 9.2.2 | AUD-ER, MDR | open |
IAPC | Internal Audit Program & Checklist | 7.5 | — | open |
IAS | Information Assets Statement | A.5.9, A.5.12, A.5.15 | MDR, DR, RRS | open |
ICL | ISMS Communication Log | 7.4, 7.5 | — | open |
ICP | Information Classification Policy | A.5.12, A.5.13 | MDR, DR, RRS, AI, SINV, UAI | open |
ICVC | ISO 27001 Control Owner Control Validation Checklist | 7.5 | — | open |
IGC | ISMS Governance Calendar | 8.1, 7.5 | — | open |
IL | Incident Log | — | — | open |
IMP | Incident Management Policy | — | — | open |
IMPL-P | Phased ISMS Implementation Plan | — | — | open |
IMPL-WB | Operational ISMS Dashboard | 8.1, 7.5 | REQT, SOA, MDR, RR, MME, CAR, IMPL-P, IAP, OS, ISS, ISP, RAM, DCP, ICP, IRPROC, MRMT, NC-RP, CIL, S1-RDY, IL, SIR | open |
IPR | Interested Parties Register | 4.2, 7.5 | — | open |
IR-RB | Incident Response Runbooks | — | — | open |
IRAR | ISMS Role Appointment Record | 5.3, 7.5 | — | open |
IRP | Incident Response Policy | — | — | open |
IRPROC | Incident Response Procedure | — | — | open |
IRRT | Incident Register and Reporting Template | — | — | open |
ISMS-CL | ISMS Change Log | — | — | open |
ISO | Information Security Objectives | 6.2, 7.5 | — | open |
ISOCL | ISO 27001:2022 Clauses | 8.1, 7.5 | — | open |
ISOCTRL | ISO 27001:2022 Controls | 8.1, 7.5 | — | open |
ISP | Information Security Policy | 5.2, 5.1, 7.5 | MDR, DR, AI, SINV, UAI | open |
ISS | ISMS Scope Statement | 4.3, 4.1, 4.2 | MDR, DR, RRS, AI, SINV, UAI | open |
ITG-MM | BSI IT-Grundschutz Module Mapping | — | — | open |
KEY-R | Cryptographic Key Register | — | — | open |
LMP | Logging and Monitoring Policy | — | — | open |
LRR | Legal, Regulatory and Contractual Requirements Register | — | — | open |
MDR | Mandatory Documents and Records Register | — | — | open |
MFAR | Multi-Framework Assurance Report | — | — | open |
MME | Monitoring and Measurement Evidence | 9.1, 7.5 | — | open |
MRART | Management Review Agenda & Report Template | 9.3 | MDR, DR, RRS | open |
MRMT | Management Review Minutes Template | 9.3 | — | open |
NC-RP | Nonconformity Response and Corrective Action Pack | — | — | open |
NFR-R | Network Firewall Rule Review Register | — | — | open |
NIS2-RD | NIS2 First-Hours Reporting Drill | — | — | open |
NSP | Network Security Policy | — | — | open |
OBL-CAL | Compliance Obligations Calendar | — | — | open |
OER | Operations Evidence Register | — | — | open |
OFC | Offboarding Checklist | 7.5 | — | open |
ONC | Onboarding Checklist | 7.5 | — | open |
OPC | Operational Planning and Control Evidence | 8.1, 7.5 | — | open |
OPI | Operational Procedures Index | — | — | open |
OS | Organization Statement | 5.3, 5.1, 4.1 | MDR, DR, UAI, AI, SINV | open |
PAP | Password & Authentication Policy | — | — | open |
PAR | Physical Access Register | — | — | open |
PARR | Policy Approval and Review Register | 8.1, 7.5 | — | open |
PBIVC | Process Owner Business Impact Validation Checklist | — | — | open |
PCI-CDE | PCI DSS CDE Scope and Control Matrix | — | — | open |
PESP | Physical and Environmental Security Policy | — | — | open |
RACI | ISMS RACI Matrix | 5.3, 7.5 | — | open |
RAE | Resource Allocation Evidence | 7.1, 7.5 | — | open |
RAM | Risk Assessment Methodology | 6.1.2, 6.1.3 | RR, RTP, MDR | open |
RAMT | Risk Acceptance Minutes Template | 9.3, 7.5 | — | open |
RASM | Risk Analysis Statement according to Magerit and ISO 27005 | 6.1 | MDR, DR, RRS, AI, SINV, UAI | open |
RCIA | Regulatory Change Impact Assessment | — | — | open |
REL-GATE | Security Release Gate Record | — | — | open |
REQT | ISO 27001 Clauses 4-10 Requirements Tracker | — | — | open |
RMP | Risk Management Plan | A.5.36, A.8.8, 6.1 | MDR, DR, RRS | open |
ROAR | ISMS Risks and Opportunities Register | — | — | open |
RPIT | Response Procedure by Incident Type | — | — | open |
RR | Risk Register | 8.1, 7.5 | — | open |
RRS | Records Retention Schedule | — | — | open |
RTP | Risk Treatment Plan | 8.1, 7.5 | — | open |
S1-RDY | Stage 1 Readiness Assessment | — | — | open |
S2-RDY | Stage 2 Readiness and Sampling Assessment | — | — | open |
SAS | Systems Architecture Statement | 4.1, 8.1, A.8 | MDR, DR, RRS | open |
SBOM-R | SBOM and Component Inventory Register | — | — | open |
SCR-C | Secure Code Review Checklist | — | — | open |
SEC-REQ | Security Requirements Register | — | — | open |
SECR | Secrets Management Register | — | — | open |
SI | Software Inventory | — | — | open |
SICT | Security Incident Communication Template | — | — | open |
SINV | Supplier Inventory | 8.1, 7.5 | — | open |
SIR | Security Incident Register | — | — | open |
SOA | Statement of Applicability (SoA) | 6.1, 7.5 | — | open |
SOAVC | Control Owner Statement of Applicability Validation Checklist | 7.5 | — | open |
SOC2-EC | SOC 2 Evidence Calendar | — | — | open |
SOC2-SD | SOC 2 System Description | — | — | open |
SRP | Supplier Relationships Policy | A.5.19, A.5.20, A.5.21, A.5.22, A.5.23 | MDR, DR, RRS, AI, SINV, UAI | open |
SSAQ | Supplier Security Assessment Questionnaire | A.5.19, A.5.20, A.5.21, A.5.22 | — | open |
SSDLC | S-SDLC Implementation Requirements Checklist | — | — | open |
SSDP | Secure Software Development Policy | — | — | open |
STD-SUP | Current Standard Supplement | — | — | open |
TISAX-AS | TISAX Assessment Scope and ISA Mapping | — | — | open |
TMM | Threat Modeling Worksheet | — | — | open |
TR | Training Register | 7.2, 7.5 | — | open |
TRC | Training Records | 7.2, 7.5 | — | open |
UAI | Users and Access Inventory | — | — | open |
VULN-SLA | Vulnerability Remediation SLA Matrix | — | — | open |
WIR-S1 | Weekly Report | — | — | open |
XFA-R | Cross-Framework Applicability Register | — | — | open |
Findings
| UUID | Title | Subject | Control | Verdict | OSCAL |
|---|---|---|---|---|---|
8a2b3b8c-900e-55db-9516-9b3dd16ea22c | No ACM/UAI enablement join REVIEW_REQUIRED | PACK | iso27001-a.8.5_ptr | REVIEW_REQUIRED | AR |
Catalog: oscal/catalog.html
· SSP: oscal/system-security-plan.html
· AR: oscal/assessment-results.html
· POA&M: oscal/plan-of-action-and-milestones.html
Render
The management review — operational, ISO, and nonconformity views. Jump back here to trace a row.
