ExportableProof — Routines today. Proof tomorrow.

OSCAL

ISO/IEC 27001:2022 component definition

Projection of component-definition.json. How to read it: `USER-MANUAL`. Do not edit this file by hand; rebuild the baseline or re-run the pipeline step.

Owners

OwnerControlsISO IDs
Asset Manager1A.5.9
Business Continuity Manager1A.5.29
Change Manager26.3, A.8.32
Cloud Service Owner1A.5.23
Communications Owner17.4
Compliance Manager34.2, A.5.5, A.5.31
Data Owner1A.8.10
Document Owner37.5, A.5.13, A.5.33
Engineering Lead9A.8.4, A.8.11, A.8.25, A.8.27, A.8.28, A.8.29, A.8.30, A.8.31, A.8.33
Facilities Manager8A.7.1, A.7.2, A.7.3, A.7.4, A.7.5, A.7.6, A.7.11, A.7.12
HR Manager97.2, A.5.10, A.5.11, A.6.1, A.6.2, A.6.3, A.6.4, A.6.5, A.7.7
ISMS Manager134.1, 4.3, 4.4, 5.2, 5.3, 8.1, 10.1, 10.2, A.5.1, A.5.2, A.5.12, A.5.28, A.5.36
IT Operations29A.5.3, A.5.14, A.5.15, A.5.16, A.5.17, A.5.18, A.5.30, A.6.7, A.7.8, A.7.9, A.7.10, A.7.13, A.7.14, A.8.1, A.8.2, A.8.3, A.8.5, A.8.6, A.8.7, A.8.9, A.8.13, A.8.14, A.8.17, A.8.18, A.8.19, A.8.20, A.8.21, A.8.22, A.8.23
Incident Manager5A.5.24, A.5.25, A.5.26, A.5.27, A.6.8
Internal Auditor39.2, A.5.35, A.8.34
Legal Counsel2A.5.32, A.6.6
Privacy Lead1A.5.34
Process Owner1A.5.37
Product Owner1A.8.26
Project Manager1A.5.8
Risk Manager56.1.1, 6.1.2, 6.1.3, 8.2, 8.3
Security Lead97.3, 9.1, A.5.6, A.5.7, A.8.8, A.8.12, A.8.15, A.8.16, A.8.24
Supplier Manager4A.5.19, A.5.20, A.5.21, A.5.22
Top Management55.1, 6.2, 7.1, 9.3, A.5.4

Policies (comparison a)

PolicyControlsISO IDsVolumePresence
HRSP5A.6.1, A.6.2, A.6.3, A.6.5, 7.2Vol. 1 · Vol. 2installed
PAP5A.5.15, A.5.16, A.5.17, A.5.18, A.8.5Vol. 3not installed
AMP5A.5.9, A.5.10, A.5.11, A.5.12, A.5.13Vol. 1installed
ICP2A.5.12, A.5.13Vol. 1 · Vol. 3installed
RASM36.1.1, 6.1.2, 6.1.3Vol. 1 · Vol. 2installed
SRP5A.5.19, A.5.20, A.5.21, A.5.22, A.5.23Vol. 1 · Vol. 5installed
ISP35.2, 5.1, 7.5Vol. 1installed
HRP6A.6.1, A.6.2, A.6.3, A.6.4, A.6.5, 7.2Vol. 1installed

Asset Manager

ISO IDTitleApplicabilityLayer
A.5.9Inventory of information and other associated assetsapplicablelinked

Business Continuity Manager

ISO IDTitleApplicabilityLayer
A.5.29Information security during disruptionapplicabledocumented

Change Manager

ISO IDTitleApplicabilityLayer
6.3Planning of changesapplicablelinked
A.8.32Change managementapplicabledocumented

Cloud Service Owner

ISO IDTitleApplicabilityLayer
A.5.23Information security for use of cloud servicesapplicabledocumented

Communications Owner

ISO IDTitleApplicabilityLayer
7.4Communicationapplicabledocumented

Compliance Manager

ISO IDTitleApplicabilityLayer
4.2Understanding the needs and expectations of interested partiesapplicablelinked
A.5.5Contact with authoritiesapplicabledocumented
A.5.31Legal, statutory, regulatory and contractual requirementsapplicabledocumented

Data Owner

ISO IDTitleApplicabilityLayer
A.8.10Information deletionapplicabledocumented

Document Owner

ISO IDTitleApplicabilityLayer
7.5Documented informationapplicablelinked
A.5.13Labelling of informationapplicablelinked
A.5.33Protection of recordsapplicabledocumented

Engineering Lead

ISO IDTitleApplicabilityLayer
A.8.4Access to source codeapplicabledocumented
A.8.11Data maskingapplicabledocumented
A.8.25Secure development life cycleapplicabledocumented
A.8.27Secure system architecture and engineering principlesapplicabledocumented
A.8.28Secure codingapplicabledocumented
A.8.29Security testing in development and acceptanceapplicabledocumented
A.8.30Outsourced developmentnot-applicablenot-applicable
A.8.31Separation of development, test and production environmentsapplicabledocumented
A.8.33Test informationapplicabledocumented

Facilities Manager

ISO IDTitleApplicabilityLayer
A.7.1Physical security perimetersapplicabledocumented
A.7.2Physical entryapplicabledocumented
A.7.3Securing offices, rooms and facilitiesapplicabledocumented
A.7.4Physical security monitoringapplicabledocumented
A.7.5Protecting against physical and environmental threatsapplicabledocumented
A.7.6Working in secure areasnot-applicablenot-applicable
A.7.11Supporting utilitiesnot-applicablenot-applicable
A.7.12Cabling securitynot-applicablenot-applicable

HR Manager

ISO IDTitleApplicabilityLayer
7.2Competenceapplicablelinked
A.5.10Acceptable use of information and other associated assetsapplicabledocumented
A.5.11Return of assetsapplicablelinked
A.6.1Screeningapplicabledocumented
A.6.2Terms and conditions of employmentapplicabledocumented
A.6.3Information security awareness, education and trainingapplicabledocumented
A.6.4Disciplinary processapplicablelinked
A.6.5Responsibilities after termination or change of employmentapplicablelinked
A.7.7Clear desk and clear screenapplicabledocumented

ISMS Manager

ISO IDTitleApplicabilityLayer
4.1Understanding the organization and its contextapplicablelinked
4.3Determining the scope of the ISMSapplicablelinked
4.4Information security management systemapplicablelinked
5.2Information security policyapplicablelinked
5.3Organizational roles, responsibilities and authoritiesapplicablelinked
8.1Operational planning and controlapplicabledocumented
10.1Continual improvementapplicablelinked
10.2Nonconformity and corrective actionapplicablelinked
A.5.1Policies for information securityapplicablelinked
A.5.2Information security roles and responsibilitiesapplicablelinked
A.5.12Classification of informationapplicabledocumented
A.5.28Collection of evidenceapplicabledocumented
A.5.36Compliance with policies, rules and standards for information securityapplicabledocumented

IT Operations

ISO IDTitleApplicabilityLayer
A.5.3Segregation of dutiesapplicabledocumented
A.5.14Information transferapplicabledocumented
A.5.15Access controlapplicabledocumented
A.5.16Identity managementapplicabledocumented
A.5.17Authentication informationapplicabledocumented
A.5.18Access rightsapplicabledocumented
A.5.30ICT readiness for business continuityapplicabledocumented
A.6.7Remote workingapplicabledocumented
A.7.8Equipment siting and protectionapplicablelinked
A.7.9Security of assets off-premisesapplicabledocumented
A.7.10Storage mediaapplicabledocumented
A.7.13Equipment maintenanceapplicabledocumented
A.7.14Secure disposal or re-use of equipmentapplicablelinked
A.8.1User endpoint devicesapplicabledocumented
A.8.2Privileged access rightsapplicabledocumented
A.8.3Information access restrictionapplicabledocumented
A.8.5Secure authenticationapplicabledocumented
A.8.6Capacity managementapplicabledocumented
A.8.7Protection against malwareapplicabledocumented
A.8.9Configuration managementapplicabledocumented
A.8.13Information backupapplicabledocumented
A.8.14Redundancy of information processing facilitiesapplicablelinked
A.8.17Clock synchronizationapplicabledocumented
A.8.18Use of privileged utility programsapplicabledocumented
A.8.19Installation of software on operational systemsapplicabledocumented
A.8.20Networks securityapplicabledocumented
A.8.21Security of network servicesapplicablelinked
A.8.22Segregation of networksapplicabledocumented
A.8.23Web filteringapplicabledocumented

Incident Manager

ISO IDTitleApplicabilityLayer
A.5.24Information security incident management planning and preparationapplicabledocumented
A.5.25Assessment and decision on information security eventsapplicabledocumented
A.5.26Response to information security incidentsapplicabledocumented
A.5.27Learning from information security incidentsapplicabledocumented
A.6.8Information security event reportingapplicabledocumented

Internal Auditor

ISO IDTitleApplicabilityLayer
9.2Internal auditapplicablelinked
A.5.35Independent review of information securityapplicablelinked
A.8.34Protection of information systems during audit testingapplicablelinked

Legal Counsel

ISO IDTitleApplicabilityLayer
A.5.32Intellectual property rightsapplicablelinked
A.6.6Confidentiality or non-disclosure agreementsapplicabledocumented

Privacy Lead

ISO IDTitleApplicabilityLayer
A.5.34Privacy and protection of PIIapplicabledocumented

Process Owner

ISO IDTitleApplicabilityLayer
A.5.37Documented operating proceduresapplicabledocumented

Product Owner

ISO IDTitleApplicabilityLayer
A.8.26Application security requirementsapplicabledocumented

Project Manager

ISO IDTitleApplicabilityLayer
A.5.8Information security in project managementapplicabledocumented

Risk Manager

ISO IDTitleApplicabilityLayer
6.1.1Actions to address risks and opportunitiesapplicablelinked
6.1.2Information security risk assessmentapplicablelinked
6.1.3Information security risk treatmentapplicablelinked
8.2Information security risk assessmentapplicablelinked
8.3Information security risk treatmentapplicablelinked

Security Lead

ISO IDTitleApplicabilityLayer
7.3Awarenessapplicablelinked
9.1Monitoring, measurement, analysis and evaluationapplicablelinked
A.5.6Contact with special interest groupsapplicabledocumented
A.5.7Threat intelligenceapplicabledocumented
A.8.8Management of technical vulnerabilitiesapplicabledocumented
A.8.12Data leakage preventionapplicabledocumented
A.8.15Loggingapplicabledocumented
A.8.16Monitoring activitiesapplicabledocumented
A.8.24Use of cryptographyapplicabledocumented

Supplier Manager

ISO IDTitleApplicabilityLayer
A.5.19Information security in supplier relationshipsapplicablelinked
A.5.20Addressing information security within supplier agreementsapplicabledocumented
A.5.21Managing information security in the ICT supply chainapplicablelinked
A.5.22Monitoring, review and change management of supplier servicesapplicablelinked

Top Management

ISO IDTitleApplicabilityLayer
5.1Leadership and commitmentapplicablelinked
6.2Information security objectives and planning to achieve themapplicablelinked
7.1Resourcesapplicablelinked
9.3Management reviewapplicablelinked
A.5.4Management responsibilitiesapplicabledocumented

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…