ExportableProof — Routines today. Proof tomorrow.

OSCAL

ISO/IEC 27001:2022 SoA profile

Projection of profile.json. How to read it: `USER-MANUAL`. Do not edit this file by hand; rebuild the baseline or re-run the pipeline step.

ISO IDTitleApplicabilityImplementationJustification
4.1Understanding the organization and its contextapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
4.2Understanding the needs and expectations of interested partiesapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
4.3Determining the scope of the ISMSapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
4.4Information security management systemapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
5.1Leadership and commitmentapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
5.2Information security policyapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
5.3Organizational roles, responsibilities and authoritiesapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
6.1.1Actions to address risks and opportunitiesapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
6.1.2Information security risk assessmentapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
6.1.3Information security risk treatmentapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
6.2Information security objectives and planning to achieve themapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
6.3Planning of changesapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
7.1Resourcesapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
7.2Competenceapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
7.3Awarenessapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
7.4Communicationapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
7.5Documented informationapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
8.1Operational planning and controlapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
8.2Information security risk assessmentapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
8.3Information security risk treatmentapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
9.1Monitoring, measurement, analysis and evaluationapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
9.2Internal auditapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
9.3Management reviewapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
10.1Continual improvementapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
10.2Nonconformity and corrective actionapplicablealways-in-scopeISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion.
A.5.1Policies for information securityapplicableImplementedRequired for ISMS governance and policy direction.
A.5.2Information security roles and responsibilitiesapplicableImplementedRequired for assigning ISMS accountability.
A.5.3Segregation of dutiesapplicableIn progressRelevant to privileged administration and approval workflows.
A.5.4Management responsibilitiesapplicableImplementedRequired for management commitment and oversight.
A.5.5Contact with authoritiesapplicableImplementedRequired for incident and regulatory escalation.
A.5.6Contact with special interest groupsapplicableImplementedRelevant for threat intelligence and software security updates.
A.5.7Threat intelligenceapplicableIn progressRequired for software and cloud threat awareness.
A.5.8Information security in project managementapplicableImplementedRequired for product and ISMS implementation projects.
A.5.9Inventory of information and other associated assetsapplicableImplementedRequired because in-scope assets support customer, HR, code, identity and evidence processes.
A.5.10Acceptable use of information and other associated assetsapplicableImplementedRequired for user obligations on company assets and services.
A.5.11Return of assetsapplicableImplementedRequired during offboarding and role changes.
A.5.12Classification of informationapplicableImplementedRequired for handling and protection decisions.
A.5.13Labelling of informationapplicableImplementedRequired to communicate classification handling.
A.5.14Information transferapplicableImplementedRequired for customer, supplier and audit information transfer.
A.5.15Access controlapplicableImplementedRequired to protect production, identity, HR and evidence systems.
A.5.16Identity managementapplicableImplementedRequired for lifecycle management of user identities.
A.5.17Authentication informationapplicableImplementedRequired for authentication secrets and recovery.
A.5.18Access rightsapplicableImplementedRequired to grant, review and revoke access rights.
A.5.19Information security in supplier relationshipsapplicableIn progressRequired for cloud and SaaS supplier dependencies.
A.5.20Addressing information security within supplier agreementsapplicableIn progressRequired for supplier security terms.
A.5.21Managing information security in the ICT supply chainapplicablePlannedRequired for SaaS, repository, identity and hosting chain.
A.5.22Monitoring, review and change management of supplier servicesapplicableIn progressRequired for supplier performance and changes.
A.5.23Information security for use of cloud servicesapplicableIn progressRequired because core services are cloud and SaaS based.
A.5.24Information security incident management planning and preparationapplicableImplementedRequired for incident readiness.
A.5.25Assessment and decision on information security eventsapplicableImplementedRequired for event triage.
A.5.26Response to information security incidentsapplicableImplementedRequired for incident handling.
A.5.27Learning from information security incidentsapplicablePlannedRequired for improvement after incidents.
A.5.28Collection of evidenceapplicableImplementedRequired for audit and incident evidence.
A.5.29Information security during disruptionapplicableImplementedRequired for continuity of critical services.
A.5.30ICT readiness for business continuityapplicableIn progressRequired for ICT continuity readiness.
A.5.31Legal, statutory, regulatory and contractual requirementsapplicableImplementedRequired for legal and contractual obligations.
A.5.32Intellectual property rightsapplicablePlannedRequired for software, content and third-party licenses.
A.5.33Protection of recordsapplicableImplementedRequired to protect ISMS and operational records.
A.5.34Privacy and protection of PIIapplicableImplementedRequired because HR and customer personal data are processed.
A.5.35Independent review of information securityapplicableImplementedRequired to review ISMS effectiveness independently.
A.5.36Compliance with policies, rules and standards for information securityapplicableImplementedRequired to verify compliance with ISMS requirements.
A.5.37Documented operating proceduresapplicableIn progressRequired for repeatable ISMS and IT operations.
A.6.1ScreeningapplicableImplementedRequired for relevant roles before employment.
A.6.2Terms and conditions of employmentapplicableImplementedRequired for contractual security obligations.
A.6.3Information security awareness, education and trainingapplicableImplementedRequired for staff and contractors.
A.6.4Disciplinary processapplicablePlannedRequired for security policy violations.
A.6.5Responsibilities after termination or change of employmentapplicableImplementedRequired for offboarding and role changes.
A.6.6Confidentiality or non-disclosure agreementsapplicableImplementedRequired for personnel, contractors and suppliers.
A.6.7Remote workingapplicableImplementedRequired because staff work remotely.
A.6.8Information security event reportingapplicableImplementedRequired so personnel report security events.
A.7.1Physical security perimetersapplicableImplementedRelevant for office and equipment storage.
A.7.2Physical entryapplicableImplementedRelevant for controlled office access.
A.7.3Securing offices, rooms and facilitiesapplicableImplementedRelevant for office workspaces and records.
A.7.4Physical security monitoringapplicableIn progressRelevant to office and equipment monitoring.
A.7.5Protecting against physical and environmental threatsapplicablePlannedRelevant to equipment and office availability.
A.7.6Working in secure areasnot-applicableNot applicableExcluded because the ISMS scope has no dedicated secure area, laboratory, datacenter, or restricted physical processing room operated by Arcfield.
A.7.7Clear desk and clear screenapplicableImplementedRelevant for office and remote working.
A.7.8Equipment siting and protectionapplicableImplementedRelevant for endpoint and office equipment.
A.7.9Security of assets off-premisesapplicableImplementedRequired for laptops and remote work.
A.7.10Storage mediaapplicableImplementedRelevant to endpoint media and backups.
A.7.11Supporting utilitiesnot-applicableNot applicableExcluded because Arcfield does not operate datacenter or server-room utilities in the ISMS scope; production processing relies on cloud-provider facilities covered by supplier assurance.
A.7.12Cabling securitynot-applicableNot applicableExcluded because Arcfield does not operate managed cabling infrastructure for in-scope production systems; office network cabling is not used for hosting customer services.
A.7.13Equipment maintenanceapplicableImplementedRelevant to managed endpoint fleet.
A.7.14Secure disposal or re-use of equipmentapplicableImplementedRequired for endpoint disposal and reuse.
A.8.1User endpoint devicesapplicableImplementedRequired for managed laptop fleet.
A.8.2Privileged access rightsapplicableIn progressRequired for production and identity administration.
A.8.3Information access restrictionapplicableImplementedRequired for restricted repositories and production data.
A.8.4Access to source codeapplicableImplementedRequired for source repositories.
A.8.5Secure authenticationapplicableImplementedRequired for cloud, SaaS and repository access.
A.8.6Capacity managementapplicablePlannedRequired for service availability.
A.8.7Protection against malwareapplicableImplementedRequired for endpoints and repositories.
A.8.8Management of technical vulnerabilitiesapplicableIn progressRequired for software and cloud services.
A.8.9Configuration managementapplicableIn progressRequired for identity, cloud, endpoint and application configuration.
A.8.10Information deletionapplicableIn progressRequired for retention and offboarding.
A.8.11Data maskingapplicablePlannedRelevant to test data and support access.
A.8.12Data leakage preventionapplicablePlannedRelevant to customer and HR data transfer.
A.8.13Information backupapplicableImplementedRequired for availability and evidence integrity.
A.8.14Redundancy of information processing facilitiesapplicableImplementedRequired where supplier redundancy is relied on.
A.8.15LoggingapplicableImplementedRequired for security monitoring and investigation.
A.8.16Monitoring activitiesapplicableIn progressRequired for detecting security events.
A.8.17Clock synchronizationapplicableImplementedRequired for reliable logging and investigations.
A.8.18Use of privileged utility programsapplicableIn progressRelevant to administrative tooling.
A.8.19Installation of software on operational systemsapplicableImplementedRequired for production and endpoint change control.
A.8.20Networks securityapplicableImplementedRequired for cloud and office connectivity.
A.8.21Security of network servicesapplicableImplementedRelevant to supplier and cloud network services.
A.8.22Segregation of networksapplicableIn progressRequired for production and management separation.
A.8.23Web filteringapplicablePlannedRelevant to endpoint protection and acceptable use.
A.8.24Use of cryptographyapplicableImplementedRequired for confidentiality and integrity.
A.8.25Secure development life cycleapplicableImplementedRequired for customer portal software development.
A.8.26Application security requirementsapplicableIn progressRequired for customer portal requirements.
A.8.27Secure system architecture and engineering principlesapplicablePlannedRequired for architecture of in-scope systems.
A.8.28Secure codingapplicableImplementedRequired for developed software.
A.8.29Security testing in development and acceptanceapplicableIn progressRequired before software release.
A.8.30Outsourced developmentnot-applicableNot applicableExcluded because Arcfield does not outsource software development within the current ISMS scope; all in-scope development is performed by internal engineering staff.
A.8.31Separation of development, test and production environmentsapplicableImplementedRequired for safe software delivery.
A.8.32Change managementapplicableImplementedRequired for changes to systems and services.
A.8.33Test informationapplicablePlannedRequired to protect production data in testing.
A.8.34Protection of information systems during audit testingapplicableImplementedRequired to protect systems during internal and external audit testing.

Not applicable (stay visible)

ISO IDTitleApplicabilityImplementationJustification
A.7.6Working in secure areasnot-applicableNot applicableExcluded because the ISMS scope has no dedicated secure area, laboratory, datacenter, or restricted physical processing room operated by Arcfield.
A.7.11Supporting utilitiesnot-applicableNot applicableExcluded because Arcfield does not operate datacenter or server-room utilities in the ISMS scope; production processing relies on cloud-provider facilities covered by supplier assurance.
A.7.12Cabling securitynot-applicableNot applicableExcluded because Arcfield does not operate managed cabling infrastructure for in-scope production systems; office network cabling is not used for hosting customer services.
A.8.30Outsourced developmentnot-applicableNot applicableExcluded because Arcfield does not outsource software development within the current ISMS scope; all in-scope development is performed by internal engineering staff.

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…