ExportableProof — Routines today. Proof tomorrow.

OSCAL

ISO/IEC 27001:2022 catalog

Projection of catalog.json. How to read it: `USER-MANUAL`. Do not edit this file by hand; rebuild the baseline or re-run the pipeline step.

ISO/IEC 27001:2022 management system clauses

Context of the organization

ISO IDTitle
4.1Understanding the organization and its context
4.2Understanding the needs and expectations of interested parties
4.3Determining the scope of the ISMS
4.4Information security management system

Leadership

ISO IDTitle
5.1Leadership and commitment
5.2Information security policy
5.3Organizational roles, responsibilities and authorities

Planning

ISO IDTitle
6.1.1Actions to address risks and opportunities
6.1.2Information security risk assessment
6.1.3Information security risk treatment
6.2Information security objectives and planning to achieve them
6.3Planning of changes

Support

ISO IDTitle
7.1Resources
7.2Competence
7.3Awareness
7.4Communication
7.5Documented information

Operation

ISO IDTitle
8.1Operational planning and control
8.2Information security risk assessment
8.3Information security risk treatment

Performance evaluation

ISO IDTitle
9.1Monitoring, measurement, analysis and evaluation
9.2Internal audit
9.3Management review

Improvement

ISO IDTitle
10.1Continual improvement
10.2Nonconformity and corrective action

ISO/IEC 27001:2022 Annex A

Organizational controls (Annex A.5)

ISO IDTitle
A.5.1Policies for information security
A.5.2Information security roles and responsibilities
A.5.3Segregation of duties
A.5.4Management responsibilities
A.5.5Contact with authorities
A.5.6Contact with special interest groups
A.5.7Threat intelligence
A.5.8Information security in project management
A.5.9Inventory of information and other associated assets
A.5.10Acceptable use of information and other associated assets
A.5.11Return of assets
A.5.12Classification of information
A.5.13Labelling of information
A.5.14Information transfer
A.5.15Access control
A.5.16Identity management
A.5.17Authentication information
A.5.18Access rights
A.5.19Information security in supplier relationships
A.5.20Addressing information security within supplier agreements
A.5.21Managing information security in the ICT supply chain
A.5.22Monitoring, review and change management of supplier services
A.5.23Information security for use of cloud services
A.5.24Information security incident management planning and preparation
A.5.25Assessment and decision on information security events
A.5.26Response to information security incidents
A.5.27Learning from information security incidents
A.5.28Collection of evidence
A.5.29Information security during disruption
A.5.30ICT readiness for business continuity
A.5.31Legal, statutory, regulatory and contractual requirements
A.5.32Intellectual property rights
A.5.33Protection of records
A.5.34Privacy and protection of PII
A.5.35Independent review of information security
A.5.36Compliance with policies, rules and standards for information security
A.5.37Documented operating procedures

People controls (Annex A.6)

ISO IDTitle
A.6.1Screening
A.6.2Terms and conditions of employment
A.6.3Information security awareness, education and training
A.6.4Disciplinary process
A.6.5Responsibilities after termination or change of employment
A.6.6Confidentiality or non-disclosure agreements
A.6.7Remote working
A.6.8Information security event reporting

Physical controls (Annex A.7)

ISO IDTitle
A.7.1Physical security perimeters
A.7.2Physical entry
A.7.3Securing offices, rooms and facilities
A.7.4Physical security monitoring
A.7.5Protecting against physical and environmental threats
A.7.6Working in secure areas
A.7.7Clear desk and clear screen
A.7.8Equipment siting and protection
A.7.9Security of assets off-premises
A.7.10Storage media
A.7.11Supporting utilities
A.7.12Cabling security
A.7.13Equipment maintenance
A.7.14Secure disposal or re-use of equipment

Technological controls (Annex A.8)

ISO IDTitle
A.8.1User endpoint devices
A.8.2Privileged access rights
A.8.3Information access restriction
A.8.4Access to source code
A.8.5Secure authentication
A.8.6Capacity management
A.8.7Protection against malware
A.8.8Management of technical vulnerabilities
A.8.9Configuration management
A.8.10Information deletion
A.8.11Data masking
A.8.12Data leakage prevention
A.8.13Information backup
A.8.14Redundancy of information processing facilities
A.8.15Logging
A.8.16Monitoring activities
A.8.17Clock synchronization
A.8.18Use of privileged utility programs
A.8.19Installation of software on operational systems
A.8.20Networks security
A.8.21Security of network services
A.8.22Segregation of networks
A.8.23Web filtering
A.8.24Use of cryptography
A.8.25Secure development life cycle
A.8.26Application security requirements
A.8.27Secure system architecture and engineering principles
A.8.28Secure coding
A.8.29Security testing in development and acceptance
A.8.30Outsourced development
A.8.31Separation of development, test and production environments
A.8.32Change management
A.8.33Test information
A.8.34Protection of information systems during audit testing

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…