OSCAL
ISO/IEC 27001:2022 component definition
Projection of component-definition.json. How to read it: `USER-MANUAL`. Do not edit this file by hand; rebuild the baseline or re-run the pipeline step.
- Owner components: **24**. Policy components: **8**. Process components: **0**.
- Owner implemented requirements: **118** (each catalog control once).
- Owners come from ISOCL/SOA. Policies and processes come from companion isoAnchors (comparison a, HITL).
Owners
| Owner | Controls | ISO IDs |
|---|---|---|
| Asset Manager | 1 | A.5.9 |
| Business Continuity Manager | 1 | A.5.29 |
| Change Manager | 2 | 6.3, A.8.32 |
| Cloud Service Owner | 1 | A.5.23 |
| Communications Owner | 1 | 7.4 |
| Compliance Manager | 3 | 4.2, A.5.5, A.5.31 |
| Data Owner | 1 | A.8.10 |
| Document Owner | 3 | 7.5, A.5.13, A.5.33 |
| Engineering Lead | 9 | A.8.4, A.8.11, A.8.25, A.8.27, A.8.28, A.8.29, A.8.30, A.8.31, A.8.33 |
| Facilities Manager | 8 | A.7.1, A.7.2, A.7.3, A.7.4, A.7.5, A.7.6, A.7.11, A.7.12 |
| HR Manager | 9 | 7.2, A.5.10, A.5.11, A.6.1, A.6.2, A.6.3, A.6.4, A.6.5, A.7.7 |
| ISMS Manager | 13 | 4.1, 4.3, 4.4, 5.2, 5.3, 8.1, 10.1, 10.2, A.5.1, A.5.2, A.5.12, A.5.28, A.5.36 |
| IT Operations | 29 | A.5.3, A.5.14, A.5.15, A.5.16, A.5.17, A.5.18, A.5.30, A.6.7, A.7.8, A.7.9, A.7.10, A.7.13, A.7.14, A.8.1, A.8.2, A.8.3, A.8.5, A.8.6, A.8.7, A.8.9, A.8.13, A.8.14, A.8.17, A.8.18, A.8.19, A.8.20, A.8.21, A.8.22, A.8.23 |
| Incident Manager | 5 | A.5.24, A.5.25, A.5.26, A.5.27, A.6.8 |
| Internal Auditor | 3 | 9.2, A.5.35, A.8.34 |
| Legal Counsel | 2 | A.5.32, A.6.6 |
| Privacy Lead | 1 | A.5.34 |
| Process Owner | 1 | A.5.37 |
| Product Owner | 1 | A.8.26 |
| Project Manager | 1 | A.5.8 |
| Risk Manager | 5 | 6.1.1, 6.1.2, 6.1.3, 8.2, 8.3 |
| Security Lead | 9 | 7.3, 9.1, A.5.6, A.5.7, A.8.8, A.8.12, A.8.15, A.8.16, A.8.24 |
| Supplier Manager | 4 | A.5.19, A.5.20, A.5.21, A.5.22 |
| Top Management | 5 | 5.1, 6.2, 7.1, 9.3, A.5.4 |
Policies (comparison a)
| Policy | Controls | ISO IDs | Volume | Presence |
|---|---|---|---|---|
| HRSP | 5 | A.6.1, A.6.2, A.6.3, A.6.5, 7.2 | Vol. 1 · Vol. 2 | installed |
| PAP | 5 | A.5.15, A.5.16, A.5.17, A.5.18, A.8.5 | Vol. 3 | not installed |
| AMP | 5 | A.5.9, A.5.10, A.5.11, A.5.12, A.5.13 | Vol. 1 | installed |
| ICP | 2 | A.5.12, A.5.13 | Vol. 1 · Vol. 3 | installed |
| RASM | 3 | 6.1.1, 6.1.2, 6.1.3 | Vol. 1 · Vol. 2 | installed |
| SRP | 5 | A.5.19, A.5.20, A.5.21, A.5.22, A.5.23 | Vol. 1 · Vol. 5 | installed |
| ISP | 3 | 5.2, 5.1, 7.5 | Vol. 1 | installed |
| HRP | 6 | A.6.1, A.6.2, A.6.3, A.6.4, A.6.5, 7.2 | Vol. 1 | installed |
Asset Manager
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| A.5.9 | Inventory of information and other associated assets | applicable | linked |
Business Continuity Manager
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| A.5.29 | Information security during disruption | applicable | documented |
Change Manager
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| 6.3 | Planning of changes | applicable | linked |
| A.8.32 | Change management | applicable | documented |
Cloud Service Owner
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| A.5.23 | Information security for use of cloud services | applicable | documented |
Communications Owner
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| 7.4 | Communication | applicable | documented |
Compliance Manager
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| 4.2 | Understanding the needs and expectations of interested parties | applicable | linked |
| A.5.5 | Contact with authorities | applicable | documented |
| A.5.31 | Legal, statutory, regulatory and contractual requirements | applicable | documented |
Data Owner
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| A.8.10 | Information deletion | applicable | documented |
Document Owner
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| 7.5 | Documented information | applicable | linked |
| A.5.13 | Labelling of information | applicable | linked |
| A.5.33 | Protection of records | applicable | documented |
Engineering Lead
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| A.8.4 | Access to source code | applicable | documented |
| A.8.11 | Data masking | applicable | documented |
| A.8.25 | Secure development life cycle | applicable | documented |
| A.8.27 | Secure system architecture and engineering principles | applicable | documented |
| A.8.28 | Secure coding | applicable | documented |
| A.8.29 | Security testing in development and acceptance | applicable | documented |
| A.8.30 | Outsourced development | not-applicable | not-applicable |
| A.8.31 | Separation of development, test and production environments | applicable | documented |
| A.8.33 | Test information | applicable | documented |
Facilities Manager
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| A.7.1 | Physical security perimeters | applicable | documented |
| A.7.2 | Physical entry | applicable | documented |
| A.7.3 | Securing offices, rooms and facilities | applicable | documented |
| A.7.4 | Physical security monitoring | applicable | documented |
| A.7.5 | Protecting against physical and environmental threats | applicable | documented |
| A.7.6 | Working in secure areas | not-applicable | not-applicable |
| A.7.11 | Supporting utilities | not-applicable | not-applicable |
| A.7.12 | Cabling security | not-applicable | not-applicable |
HR Manager
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| 7.2 | Competence | applicable | linked |
| A.5.10 | Acceptable use of information and other associated assets | applicable | documented |
| A.5.11 | Return of assets | applicable | linked |
| A.6.1 | Screening | applicable | documented |
| A.6.2 | Terms and conditions of employment | applicable | documented |
| A.6.3 | Information security awareness, education and training | applicable | documented |
| A.6.4 | Disciplinary process | applicable | linked |
| A.6.5 | Responsibilities after termination or change of employment | applicable | linked |
| A.7.7 | Clear desk and clear screen | applicable | documented |
ISMS Manager
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| 4.1 | Understanding the organization and its context | applicable | linked |
| 4.3 | Determining the scope of the ISMS | applicable | linked |
| 4.4 | Information security management system | applicable | linked |
| 5.2 | Information security policy | applicable | linked |
| 5.3 | Organizational roles, responsibilities and authorities | applicable | linked |
| 8.1 | Operational planning and control | applicable | documented |
| 10.1 | Continual improvement | applicable | linked |
| 10.2 | Nonconformity and corrective action | applicable | linked |
| A.5.1 | Policies for information security | applicable | linked |
| A.5.2 | Information security roles and responsibilities | applicable | linked |
| A.5.12 | Classification of information | applicable | documented |
| A.5.28 | Collection of evidence | applicable | documented |
| A.5.36 | Compliance with policies, rules and standards for information security | applicable | documented |
IT Operations
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| A.5.3 | Segregation of duties | applicable | documented |
| A.5.14 | Information transfer | applicable | documented |
| A.5.15 | Access control | applicable | documented |
| A.5.16 | Identity management | applicable | documented |
| A.5.17 | Authentication information | applicable | documented |
| A.5.18 | Access rights | applicable | documented |
| A.5.30 | ICT readiness for business continuity | applicable | documented |
| A.6.7 | Remote working | applicable | documented |
| A.7.8 | Equipment siting and protection | applicable | linked |
| A.7.9 | Security of assets off-premises | applicable | documented |
| A.7.10 | Storage media | applicable | documented |
| A.7.13 | Equipment maintenance | applicable | documented |
| A.7.14 | Secure disposal or re-use of equipment | applicable | linked |
| A.8.1 | User endpoint devices | applicable | documented |
| A.8.2 | Privileged access rights | applicable | documented |
| A.8.3 | Information access restriction | applicable | documented |
| A.8.5 | Secure authentication | applicable | documented |
| A.8.6 | Capacity management | applicable | documented |
| A.8.7 | Protection against malware | applicable | documented |
| A.8.9 | Configuration management | applicable | documented |
| A.8.13 | Information backup | applicable | documented |
| A.8.14 | Redundancy of information processing facilities | applicable | linked |
| A.8.17 | Clock synchronization | applicable | documented |
| A.8.18 | Use of privileged utility programs | applicable | documented |
| A.8.19 | Installation of software on operational systems | applicable | documented |
| A.8.20 | Networks security | applicable | documented |
| A.8.21 | Security of network services | applicable | linked |
| A.8.22 | Segregation of networks | applicable | documented |
| A.8.23 | Web filtering | applicable | documented |
Incident Manager
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| A.5.24 | Information security incident management planning and preparation | applicable | documented |
| A.5.25 | Assessment and decision on information security events | applicable | documented |
| A.5.26 | Response to information security incidents | applicable | documented |
| A.5.27 | Learning from information security incidents | applicable | documented |
| A.6.8 | Information security event reporting | applicable | documented |
Internal Auditor
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| 9.2 | Internal audit | applicable | linked |
| A.5.35 | Independent review of information security | applicable | linked |
| A.8.34 | Protection of information systems during audit testing | applicable | linked |
Legal Counsel
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| A.5.32 | Intellectual property rights | applicable | linked |
| A.6.6 | Confidentiality or non-disclosure agreements | applicable | documented |
Privacy Lead
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| A.5.34 | Privacy and protection of PII | applicable | documented |
Process Owner
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| A.5.37 | Documented operating procedures | applicable | documented |
Product Owner
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| A.8.26 | Application security requirements | applicable | documented |
Project Manager
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| A.5.8 | Information security in project management | applicable | documented |
Risk Manager
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| 6.1.1 | Actions to address risks and opportunities | applicable | linked |
| 6.1.2 | Information security risk assessment | applicable | linked |
| 6.1.3 | Information security risk treatment | applicable | linked |
| 8.2 | Information security risk assessment | applicable | linked |
| 8.3 | Information security risk treatment | applicable | linked |
Security Lead
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| 7.3 | Awareness | applicable | linked |
| 9.1 | Monitoring, measurement, analysis and evaluation | applicable | linked |
| A.5.6 | Contact with special interest groups | applicable | documented |
| A.5.7 | Threat intelligence | applicable | documented |
| A.8.8 | Management of technical vulnerabilities | applicable | documented |
| A.8.12 | Data leakage prevention | applicable | documented |
| A.8.15 | Logging | applicable | documented |
| A.8.16 | Monitoring activities | applicable | documented |
| A.8.24 | Use of cryptography | applicable | documented |
Supplier Manager
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| A.5.19 | Information security in supplier relationships | applicable | linked |
| A.5.20 | Addressing information security within supplier agreements | applicable | documented |
| A.5.21 | Managing information security in the ICT supply chain | applicable | linked |
| A.5.22 | Monitoring, review and change management of supplier services | applicable | linked |
Top Management
| ISO ID | Title | Applicability | Layer |
|---|---|---|---|
| 5.1 | Leadership and commitment | applicable | linked |
| 6.2 | Information security objectives and planning to achieve them | applicable | linked |
| 7.1 | Resources | applicable | linked |
| 9.3 | Management review | applicable | linked |
| A.5.4 | Management responsibilities | applicable | documented |
