ExportableProof — Routines today. Proof tomorrow.

OSCAL

ISO/IEC 27001:2022 system security plan

Projection of system-security-plan.json. How to read it: `USER-MANUAL`. Do not edit this file by hand; rebuild the baseline or re-run the pipeline step.

ISO IDTitleLayerOwnerLinked artefactsUnresolvedStatus
4.1Understanding the organization and its contextlinkedISMS ManagerOS (cites), GS (cites), ERR (cites), ISOCL (cites)implemented
4.2Understanding the needs and expectations of interested partieslinkedCompliance ManagerERR (cites), SRP (cites), ISOCL (cites)SOC2-SDimplemented
4.3Determining the scope of the ISMSlinkedISMS ManagerISS (cites), SAS (cites), SINV (cites), ISOCL (cites), AST-001 (field-ref), AST-005 (field-ref), AST-011 (field-ref), AST-014 (field-ref), AST-012 (field-ref), AST-013 (field-ref), AST-003 (field-ref)implemented
4.4Information security management systemlinkedISMS ManagerGS (cites), IMPL-WB (cites), ISOCL (cites)WIR-S1implemented
5.1Leadership and commitmentlinkedTop ManagementISP (cites), MRART (cites), MRMT (cites), ISOCL (cites), DR (cites), AI (cites), SINV (cites)implemented
5.2Information security policylinkedISMS ManagerISP (cites), TRC (cites), ISOCL (cites), DR (cites), AI (cites), SINV (cites)implemented
5.3Organizational roles, responsibilities and authoritieslinkedISMS ManagerRACI (cites), GS (cites), OS (cites), ISOCL (cites)implemented
6.1.1Actions to address risks and opportunitieslinkedRisk ManagerRR (cites), RTP (cites), ISOCL (cites), RASM (cites), DR (cites), AI (cites), SINV (cites)CILimplemented
6.1.2Information security risk assessmentlinkedRisk ManagerRAM (cites), RAMT (cites), RASM (cites), RR (cites), ISOCL (cites), DR (cites), AI (cites), SINV (cites)implemented
6.1.3Information security risk treatmentlinkedRisk ManagerRTP (cites), SOA (cites), ISOCTRL (cites), ISOCL (cites), RASM (cites), DR (cites), AI (cites), SINV (cites)implemented
6.2Information security objectives and planning to achieve themlinkedTop ManagementISP (cites), IMPL-WB (cites), MME (cites), ISOCL (cites)implemented
6.3Planning of changeslinkedChange ManagerCR (cites), ISOCL (cites)CMP; ISMS-CLimplemented
7.1ResourceslinkedTop ManagementMRART (cites), MRMT (cites), GS (cites), ISOCL (cites)implemented
7.2CompetencelinkedHR ManagerTR (cites), TRC (cites), HRP (cites), ISOCL (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites)CMTPimplemented
7.3AwarenesslinkedSecurity LeadTRC (cites), HRSP (cites), ISOCL (cites)implemented
7.4CommunicationdocumentedCommunications OwnerISOCL (cites)COMM-P; SICT; IRPimplemented
7.5Documented informationlinkedDocument OwnerDR (cites), ISOCL (cites), ISP (cites), AI (cites), SINV (cites)DCP; WIR-S1implemented
8.1Operational planning and controldocumentedISMS ManagerISOCTRL (cites), ISOCL (cites)WIR-S1; CMPimplemented
8.2Information security risk assessmentlinkedRisk ManagerRR (cites), RAM (cites), ISOCL (cites)ISMS-CLimplemented
8.3Information security risk treatmentlinkedRisk ManagerRTP (cites), SOA (cites), CAR (cites), ISOCL (cites)implemented
9.1Monitoring, measurement, analysis and evaluationlinkedSecurity LeadMME (cites), IMPL-WB (cites), MRART (cites), ISOCL (cites)implemented
9.2Internal auditlinkedInternal AuditorIAP (cites), CAR (cites), MRMT (cites), ISOCL (cites)implemented
9.3Management reviewlinkedTop ManagementMRART (cites), MRMT (cites), ISOCL (cites)implemented
10.1Continual improvementlinkedISMS ManagerCAR (cites), ISOCL (cites)CIL; WIR-S1implemented
10.2Nonconformity and corrective actionlinkedISMS ManagerCAR (cites), IAP (cites), MRMT (cites), ISOCL (cites)implemented
A.5.1Policies for information securitylinkedISMS ManagerISP (field-ref), SOA (cites), ISOCTRL (cites)implemented
A.5.2Information security roles and responsibilitieslinkedISMS ManagerRACI (field-ref), SOA (cites), ISOCTRL (cites)implemented
A.5.3Segregation of dutiesdocumentedIT OperationsSOA (cites), ISOCTRL (cites)SOD-CHK-2026-Q3partial
A.5.4Management responsibilitiesdocumentedTop ManagementSOA (cites), ISOCTRL (cites)MR-2026-Q3implemented
A.5.5Contact with authoritiesdocumentedCompliance ManagerSOA (cites), ISOCTRL (cites)COMM-Pimplemented
A.5.6Contact with special interest groupsdocumentedSecurity LeadSOA (cites), ISOCTRL (cites)TI-SUB-2026implemented
A.5.7Threat intelligencedocumentedSecurity LeadSOA (cites), ISOCTRL (cites)TI-LOG-2026-Q3partial
A.5.8Information security in project managementdocumentedProject ManagerSOA (cites), ISOCTRL (cites)SSDLCimplemented
A.5.9Inventory of information and other associated assetslinkedAsset ManagerAI (field-ref), SOA (cites), ISOCTRL (cites), AMP (cites), DR (cites), SINV (cites)implemented
A.5.10Acceptable use of information and other associated assetslinkedHR ManagerSOA (cites), ISOCTRL (cites), AMP (cites), DR (cites), AI (cites), SINV (cites)AUP-ACK-2026-Q3implemented
A.5.11Return of assetslinkedHR ManagerOFC (field-ref), SOA (cites), ISOCTRL (cites), AMP (cites), DR (cites), AI (cites), SINV (cites), LAP-047 (field-ref), BADGE-047 (field-ref)implemented
A.5.12Classification of informationlinkedISMS ManagerSOA (cites), ISOCTRL (cites), AMP (cites), DR (cites), AI (cites), SINV (cites), ICP (cites)CLASS-STD-2026implemented
A.5.13Labelling of informationlinkedDocument OwnerDR (field-ref), SOA (cites), ISOCTRL (cites), AMP (cites), AI (cites), SINV (cites), ICP (cites)implemented
A.5.14Information transferdocumentedIT OperationsSOA (cites), ISOCTRL (cites)ITR-2026-Q3implemented
A.5.15Access controldocumentedIT OperationsSOA (cites), ISOCTRL (cites)ACMimplemented
A.5.16Identity managementdocumentedIT OperationsSOA (cites), ISOCTRL (cites)IAM-CTRL-2026-Q3implemented
A.5.17Authentication informationdocumentedIT OperationsSOA (cites), ISOCTRL (cites)IAM-CTRL-2026-Q3implemented
A.5.18Access rightsdocumentedIT OperationsSOA (cites), ISOCTRL (cites)ARRimplemented
A.5.19Information security in supplier relationshipslinkedSupplier ManagerSINV (field-ref), SOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites)partial
A.5.20Addressing information security within supplier agreementslinkedSupplier ManagerSOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites), SINV (cites)CSSpartial
A.5.21Managing information security in the ICT supply chainlinkedSupplier ManagerSINV (field-ref), SOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites)planned
A.5.22Monitoring, review and change management of supplier serviceslinkedSupplier ManagerSINV (field-ref), SOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites)partial
A.5.23Information security for use of cloud serviceslinkedCloud Service OwnerSOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites), SINV (cites)CLOUD-CTRL-2026-Q3partial
A.5.24Information security incident management planning and preparationdocumentedIncident ManagerSOA (cites), ISOCTRL (cites)IRPimplemented
A.5.25Assessment and decision on information security eventsdocumentedIncident ManagerSOA (cites), ISOCTRL (cites)SIRimplemented
A.5.26Response to information security incidentsdocumentedIncident ManagerSOA (cites), ISOCTRL (cites)IR-RBimplemented
A.5.27Learning from information security incidentsdocumentedIncident ManagerSOA (cites), ISOCTRL (cites)CILplanned
A.5.28Collection of evidencedocumentedISMS ManagerSOA (cites), ISOCTRL (cites)ELAIimplemented
A.5.29Information security during disruptiondocumentedBusiness Continuity ManagerSOA (cites), ISOCTRL (cites)BCPimplemented
A.5.30ICT readiness for business continuitydocumentedIT OperationsSOA (cites), ISOCTRL (cites)DRPpartial
A.5.31Legal, statutory, regulatory and contractual requirementsdocumentedCompliance ManagerSOA (cites), ISOCTRL (cites)LRRimplemented
A.5.32Intellectual property rightslinkedLegal CounselIPR (field-ref), SOA (cites), ISOCTRL (cites)planned
A.5.33Protection of recordsdocumentedDocument OwnerSOA (cites), ISOCTRL (cites)RRSimplemented
A.5.34Privacy and protection of PIIdocumentedPrivacy LeadSOA (cites), ISOCTRL (cites)DPARimplemented
A.5.35Independent review of information securitylinkedInternal AuditorIAP (field-ref), SOA (cites), ISOCTRL (cites)implemented
A.5.36Compliance with policies, rules and standards for information securitydocumentedISMS ManagerSOA (cites), ISOCTRL (cites)REQTimplemented
A.5.37Documented operating proceduresdocumentedProcess OwnerSOA (cites), ISOCTRL (cites)DOPpartial
A.6.1ScreeninglinkedHR ManagerSOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites)HR-ONB-2026-023implemented
A.6.2Terms and conditions of employmentlinkedHR ManagerSOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites)HR-ONB-2026-023implemented
A.6.3Information security awareness, education and traininglinkedHR ManagerSOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites)TRAIN-REC-2026-188implemented
A.6.4Disciplinary processlinkedHR ManagerHRP (field-ref), SOA (cites), ISOCTRL (cites), DR (cites), AI (cites), SINV (cites)planned
A.6.5Responsibilities after termination or change of employmentlinkedHR ManagerOFC (field-ref), SOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites), LAP-047 (field-ref), BADGE-047 (field-ref)implemented
A.6.6Confidentiality or non-disclosure agreementsdocumentedLegal CounselSOA (cites), ISOCTRL (cites)NDA-REG-2026implemented
A.6.7Remote workingdocumentedIT OperationsSOA (cites), ISOCTRL (cites)REMOTE-2026implemented
A.6.8Information security event reportingdocumentedIncident ManagerSOA (cites), ISOCTRL (cites)IRPimplemented
A.7.1Physical security perimetersdocumentedFacilities ManagerSOA (cites), ISOCTRL (cites)PHY-SEC-2026implemented
A.7.2Physical entrydocumentedFacilities ManagerSOA (cites), ISOCTRL (cites)PHY-ACCESS-2026implemented
A.7.3Securing offices, rooms and facilitiesdocumentedFacilities ManagerSOA (cites), ISOCTRL (cites)PHY-OFFICE-2026implemented
A.7.4Physical security monitoringdocumentedFacilities ManagerSOA (cites), ISOCTRL (cites)PHY-MON-2026-Q3partial
A.7.5Protecting against physical and environmental threatsdocumentedFacilities ManagerSOA (cites), ISOCTRL (cites)BCPplanned
A.7.6Working in secure areasnot-applicableFacilities ManagerSOA (field-ref), ISOCTRL (cites)not-applicable
A.7.7Clear desk and clear screendocumentedHR ManagerSOA (cites), ISOCTRL (cites)AUP-ACK-2026-Q3implemented
A.7.8Equipment siting and protectionlinkedIT OperationsAI (field-ref), SOA (cites), ISOCTRL (cites)implemented
A.7.9Security of assets off-premisesdocumentedIT OperationsSOA (cites), ISOCTRL (cites)MDM-2026-Q3implemented
A.7.10Storage mediadocumentedIT OperationsSOA (cites), ISOCTRL (cites)MDM-2026-Q3implemented
A.7.11Supporting utilitiesnot-applicableFacilities ManagerSINV (field-ref), SOA (cites), ISOCTRL (cites)not-applicable
A.7.12Cabling securitynot-applicableFacilities ManagerSOA (field-ref), ISOCTRL (cites)not-applicable
A.7.13Equipment maintenancedocumentedIT OperationsSOA (cites), ISOCTRL (cites)MDM-2026-Q3implemented
A.7.14Secure disposal or re-use of equipmentlinkedIT OperationsOFC (field-ref), SOA (cites), ISOCTRL (cites), LAP-047 (field-ref), BADGE-047 (field-ref)implemented
A.8.1User endpoint devicesdocumentedIT OperationsSOA (cites), ISOCTRL (cites)MDM-2026-Q3implemented
A.8.2Privileged access rightsdocumentedIT OperationsSOA (cites), ISOCTRL (cites)ACC-REV-2026-Q3partial
A.8.3Information access restrictiondocumentedIT OperationsSOA (cites), ISOCTRL (cites)ACMimplemented
A.8.4Access to source codedocumentedEngineering LeadSOA (cites), ISOCTRL (cites)SIimplemented
A.8.5Secure authenticationdocumentedIT OperationsSOA (cites), ISOCTRL (cites)IAM-CTRL-2026-Q3implemented
A.8.6Capacity managementdocumentedIT OperationsSOA (cites), ISOCTRL (cites)MON-2026-Q3planned
A.8.7Protection against malwaredocumentedIT OperationsSOA (cites), ISOCTRL (cites)EDR-2026-Q3implemented
A.8.8Management of technical vulnerabilitiesdocumentedSecurity LeadSOA (cites), ISOCTRL (cites)VULN-2026-Q3partial
A.8.9Configuration managementdocumentedIT OperationsSOA (cites), ISOCTRL (cites)CFG-BASE-2026partial
A.8.10Information deletiondocumentedData OwnerSOA (cites), ISOCTRL (cites)RRSpartial
A.8.11Data maskingdocumentedEngineering LeadSOA (cites), ISOCTRL (cites)TBD-DMASK-2026planned
A.8.12Data leakage preventiondocumentedSecurity LeadSOA (cites), ISOCTRL (cites)DLP-PLAN-2026planned
A.8.13Information backupdocumentedIT OperationsSOA (cites), ISOCTRL (cites)BKP-CRM-001implemented
A.8.14Redundancy of information processing facilitieslinkedIT OperationsSINV (field-ref), SOA (cites), ISOCTRL (cites)implemented
A.8.15LoggingdocumentedSecurity LeadSOA (cites), ISOCTRL (cites)LOG-2026-Q3implemented
A.8.16Monitoring activitiesdocumentedSecurity LeadSOA (cites), ISOCTRL (cites)MON-2026-Q3partial
A.8.17Clock synchronizationdocumentedIT OperationsSOA (cites), ISOCTRL (cites)CFG-BASE-2026implemented
A.8.18Use of privileged utility programsdocumentedIT OperationsSOA (cites), ISOCTRL (cites)ACC-REV-2026-Q3partial
A.8.19Installation of software on operational systemsdocumentedIT OperationsSOA (cites), ISOCTRL (cites)CMPimplemented
A.8.20Networks securitydocumentedIT OperationsSOA (cites), ISOCTRL (cites)NSPimplemented
A.8.21Security of network serviceslinkedIT OperationsSINV (field-ref), SOA (cites), ISOCTRL (cites)implemented
A.8.22Segregation of networksdocumentedIT OperationsSOA (cites), ISOCTRL (cites)NET-SEG-2026partial
A.8.23Web filteringdocumentedIT OperationsSOA (cites), ISOCTRL (cites)TBD-WEBFILTER-2026planned
A.8.24Use of cryptographydocumentedSecurity LeadSOA (cites), ISOCTRL (cites)CKMPimplemented
A.8.25Secure development life cycledocumentedEngineering LeadSOA (cites), ISOCTRL (cites)SSDLCimplemented
A.8.26Application security requirementsdocumentedProduct OwnerSOA (cites), ISOCTRL (cites)APPSEC-REQ-2026partial
A.8.27Secure system architecture and engineering principlesdocumentedEngineering LeadSOA (cites), ISOCTRL (cites)ARCH-SEC-2026planned
A.8.28Secure codingdocumentedEngineering LeadSOA (cites), ISOCTRL (cites)SSDLCimplemented
A.8.29Security testing in development and acceptancedocumentedEngineering LeadSOA (cites), ISOCTRL (cites)TEST-SEC-2026partial
A.8.30Outsourced developmentnot-applicableEngineering LeadSOA (field-ref), ISOCTRL (cites)not-applicable
A.8.31Separation of development, test and production environmentsdocumentedEngineering LeadSOA (cites), ISOCTRL (cites)ENV-SEP-2026implemented
A.8.32Change managementdocumentedChange ManagerSOA (cites), ISOCTRL (cites)CMPimplemented
A.8.33Test informationdocumentedEngineering LeadSOA (cites), ISOCTRL (cites)TBD-TESTDATA-2026planned
A.8.34Protection of information systems during audit testinglinkedInternal AuditorIAP (field-ref), SOA (cites), ISOCTRL (cites)implemented

Not applicable

ISO IDTitleLayerOwnerLinked artefactsUnresolvedStatus
A.7.6Working in secure areasnot-applicableFacilities ManagerSOA (field-ref), ISOCTRL (cites)not-applicable
A.7.11Supporting utilitiesnot-applicableFacilities ManagerSINV (field-ref), SOA (cites), ISOCTRL (cites)not-applicable
A.7.12Cabling securitynot-applicableFacilities ManagerSOA (field-ref), ISOCTRL (cites)not-applicable
A.8.30Outsourced developmentnot-applicableEngineering LeadSOA (field-ref), ISOCTRL (cites)not-applicable

Unresolved evidence tokens

ISO IDTitleLayerOwnerLinked artefactsUnresolvedStatus
4.2Understanding the needs and expectations of interested partieslinkedCompliance ManagerERR (cites), SRP (cites), ISOCL (cites)SOC2-SDimplemented
4.4Information security management systemlinkedISMS ManagerGS (cites), IMPL-WB (cites), ISOCL (cites)WIR-S1implemented
6.1.1Actions to address risks and opportunitieslinkedRisk ManagerRR (cites), RTP (cites), ISOCL (cites), RASM (cites), DR (cites), AI (cites), SINV (cites)CILimplemented
6.3Planning of changeslinkedChange ManagerCR (cites), ISOCL (cites)CMP; ISMS-CLimplemented
7.2CompetencelinkedHR ManagerTR (cites), TRC (cites), HRP (cites), ISOCL (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites)CMTPimplemented
7.4CommunicationdocumentedCommunications OwnerISOCL (cites)COMM-P; SICT; IRPimplemented
7.5Documented informationlinkedDocument OwnerDR (cites), ISOCL (cites), ISP (cites), AI (cites), SINV (cites)DCP; WIR-S1implemented
8.1Operational planning and controldocumentedISMS ManagerISOCTRL (cites), ISOCL (cites)WIR-S1; CMPimplemented
8.2Information security risk assessmentlinkedRisk ManagerRR (cites), RAM (cites), ISOCL (cites)ISMS-CLimplemented
10.1Continual improvementlinkedISMS ManagerCAR (cites), ISOCL (cites)CIL; WIR-S1implemented
A.5.3Segregation of dutiesdocumentedIT OperationsSOA (cites), ISOCTRL (cites)SOD-CHK-2026-Q3partial
A.5.4Management responsibilitiesdocumentedTop ManagementSOA (cites), ISOCTRL (cites)MR-2026-Q3implemented
A.5.5Contact with authoritiesdocumentedCompliance ManagerSOA (cites), ISOCTRL (cites)COMM-Pimplemented
A.5.6Contact with special interest groupsdocumentedSecurity LeadSOA (cites), ISOCTRL (cites)TI-SUB-2026implemented
A.5.7Threat intelligencedocumentedSecurity LeadSOA (cites), ISOCTRL (cites)TI-LOG-2026-Q3partial
A.5.8Information security in project managementdocumentedProject ManagerSOA (cites), ISOCTRL (cites)SSDLCimplemented
A.5.10Acceptable use of information and other associated assetslinkedHR ManagerSOA (cites), ISOCTRL (cites), AMP (cites), DR (cites), AI (cites), SINV (cites)AUP-ACK-2026-Q3implemented
A.5.12Classification of informationlinkedISMS ManagerSOA (cites), ISOCTRL (cites), AMP (cites), DR (cites), AI (cites), SINV (cites), ICP (cites)CLASS-STD-2026implemented
A.5.14Information transferdocumentedIT OperationsSOA (cites), ISOCTRL (cites)ITR-2026-Q3implemented
A.5.15Access controldocumentedIT OperationsSOA (cites), ISOCTRL (cites)ACMimplemented
A.5.16Identity managementdocumentedIT OperationsSOA (cites), ISOCTRL (cites)IAM-CTRL-2026-Q3implemented
A.5.17Authentication informationdocumentedIT OperationsSOA (cites), ISOCTRL (cites)IAM-CTRL-2026-Q3implemented
A.5.18Access rightsdocumentedIT OperationsSOA (cites), ISOCTRL (cites)ARRimplemented
A.5.20Addressing information security within supplier agreementslinkedSupplier ManagerSOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites), SINV (cites)CSSpartial
A.5.23Information security for use of cloud serviceslinkedCloud Service OwnerSOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites), SINV (cites)CLOUD-CTRL-2026-Q3partial
A.5.24Information security incident management planning and preparationdocumentedIncident ManagerSOA (cites), ISOCTRL (cites)IRPimplemented
A.5.25Assessment and decision on information security eventsdocumentedIncident ManagerSOA (cites), ISOCTRL (cites)SIRimplemented
A.5.26Response to information security incidentsdocumentedIncident ManagerSOA (cites), ISOCTRL (cites)IR-RBimplemented
A.5.27Learning from information security incidentsdocumentedIncident ManagerSOA (cites), ISOCTRL (cites)CILplanned
A.5.28Collection of evidencedocumentedISMS ManagerSOA (cites), ISOCTRL (cites)ELAIimplemented
A.5.29Information security during disruptiondocumentedBusiness Continuity ManagerSOA (cites), ISOCTRL (cites)BCPimplemented
A.5.30ICT readiness for business continuitydocumentedIT OperationsSOA (cites), ISOCTRL (cites)DRPpartial
A.5.31Legal, statutory, regulatory and contractual requirementsdocumentedCompliance ManagerSOA (cites), ISOCTRL (cites)LRRimplemented
A.5.33Protection of recordsdocumentedDocument OwnerSOA (cites), ISOCTRL (cites)RRSimplemented
A.5.34Privacy and protection of PIIdocumentedPrivacy LeadSOA (cites), ISOCTRL (cites)DPARimplemented
A.5.36Compliance with policies, rules and standards for information securitydocumentedISMS ManagerSOA (cites), ISOCTRL (cites)REQTimplemented
A.5.37Documented operating proceduresdocumentedProcess OwnerSOA (cites), ISOCTRL (cites)DOPpartial
A.6.1ScreeninglinkedHR ManagerSOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites)HR-ONB-2026-023implemented
A.6.2Terms and conditions of employmentlinkedHR ManagerSOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites)HR-ONB-2026-023implemented
A.6.3Information security awareness, education and traininglinkedHR ManagerSOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites)TRAIN-REC-2026-188implemented
A.6.6Confidentiality or non-disclosure agreementsdocumentedLegal CounselSOA (cites), ISOCTRL (cites)NDA-REG-2026implemented
A.6.7Remote workingdocumentedIT OperationsSOA (cites), ISOCTRL (cites)REMOTE-2026implemented
A.6.8Information security event reportingdocumentedIncident ManagerSOA (cites), ISOCTRL (cites)IRPimplemented
A.7.1Physical security perimetersdocumentedFacilities ManagerSOA (cites), ISOCTRL (cites)PHY-SEC-2026implemented
A.7.2Physical entrydocumentedFacilities ManagerSOA (cites), ISOCTRL (cites)PHY-ACCESS-2026implemented
A.7.3Securing offices, rooms and facilitiesdocumentedFacilities ManagerSOA (cites), ISOCTRL (cites)PHY-OFFICE-2026implemented
A.7.4Physical security monitoringdocumentedFacilities ManagerSOA (cites), ISOCTRL (cites)PHY-MON-2026-Q3partial
A.7.5Protecting against physical and environmental threatsdocumentedFacilities ManagerSOA (cites), ISOCTRL (cites)BCPplanned
A.7.7Clear desk and clear screendocumentedHR ManagerSOA (cites), ISOCTRL (cites)AUP-ACK-2026-Q3implemented
A.7.9Security of assets off-premisesdocumentedIT OperationsSOA (cites), ISOCTRL (cites)MDM-2026-Q3implemented
A.7.10Storage mediadocumentedIT OperationsSOA (cites), ISOCTRL (cites)MDM-2026-Q3implemented
A.7.13Equipment maintenancedocumentedIT OperationsSOA (cites), ISOCTRL (cites)MDM-2026-Q3implemented
A.8.1User endpoint devicesdocumentedIT OperationsSOA (cites), ISOCTRL (cites)MDM-2026-Q3implemented
A.8.2Privileged access rightsdocumentedIT OperationsSOA (cites), ISOCTRL (cites)ACC-REV-2026-Q3partial
A.8.3Information access restrictiondocumentedIT OperationsSOA (cites), ISOCTRL (cites)ACMimplemented
A.8.4Access to source codedocumentedEngineering LeadSOA (cites), ISOCTRL (cites)SIimplemented
A.8.5Secure authenticationdocumentedIT OperationsSOA (cites), ISOCTRL (cites)IAM-CTRL-2026-Q3implemented
A.8.6Capacity managementdocumentedIT OperationsSOA (cites), ISOCTRL (cites)MON-2026-Q3planned
A.8.7Protection against malwaredocumentedIT OperationsSOA (cites), ISOCTRL (cites)EDR-2026-Q3implemented
A.8.8Management of technical vulnerabilitiesdocumentedSecurity LeadSOA (cites), ISOCTRL (cites)VULN-2026-Q3partial
A.8.9Configuration managementdocumentedIT OperationsSOA (cites), ISOCTRL (cites)CFG-BASE-2026partial
A.8.10Information deletiondocumentedData OwnerSOA (cites), ISOCTRL (cites)RRSpartial
A.8.11Data maskingdocumentedEngineering LeadSOA (cites), ISOCTRL (cites)TBD-DMASK-2026planned
A.8.12Data leakage preventiondocumentedSecurity LeadSOA (cites), ISOCTRL (cites)DLP-PLAN-2026planned
A.8.13Information backupdocumentedIT OperationsSOA (cites), ISOCTRL (cites)BKP-CRM-001implemented
A.8.15LoggingdocumentedSecurity LeadSOA (cites), ISOCTRL (cites)LOG-2026-Q3implemented
A.8.16Monitoring activitiesdocumentedSecurity LeadSOA (cites), ISOCTRL (cites)MON-2026-Q3partial
A.8.17Clock synchronizationdocumentedIT OperationsSOA (cites), ISOCTRL (cites)CFG-BASE-2026implemented
A.8.18Use of privileged utility programsdocumentedIT OperationsSOA (cites), ISOCTRL (cites)ACC-REV-2026-Q3partial
A.8.19Installation of software on operational systemsdocumentedIT OperationsSOA (cites), ISOCTRL (cites)CMPimplemented
A.8.20Networks securitydocumentedIT OperationsSOA (cites), ISOCTRL (cites)NSPimplemented
A.8.22Segregation of networksdocumentedIT OperationsSOA (cites), ISOCTRL (cites)NET-SEG-2026partial
A.8.23Web filteringdocumentedIT OperationsSOA (cites), ISOCTRL (cites)TBD-WEBFILTER-2026planned
A.8.24Use of cryptographydocumentedSecurity LeadSOA (cites), ISOCTRL (cites)CKMPimplemented
A.8.25Secure development life cycledocumentedEngineering LeadSOA (cites), ISOCTRL (cites)SSDLCimplemented
A.8.26Application security requirementsdocumentedProduct OwnerSOA (cites), ISOCTRL (cites)APPSEC-REQ-2026partial
A.8.27Secure system architecture and engineering principlesdocumentedEngineering LeadSOA (cites), ISOCTRL (cites)ARCH-SEC-2026planned
A.8.28Secure codingdocumentedEngineering LeadSOA (cites), ISOCTRL (cites)SSDLCimplemented
A.8.29Security testing in development and acceptancedocumentedEngineering LeadSOA (cites), ISOCTRL (cites)TEST-SEC-2026partial
A.8.31Separation of development, test and production environmentsdocumentedEngineering LeadSOA (cites), ISOCTRL (cites)ENV-SEP-2026implemented
A.8.32Change managementdocumentedChange ManagerSOA (cites), ISOCTRL (cites)CMPimplemented
A.8.33Test informationdocumentedEngineering LeadSOA (cites), ISOCTRL (cites)TBD-TESTDATA-2026planned

Cited companion resources (carrier)

ArtifactObject typeCarrierProvenanceFile
AIassetcompanionunknownAI_Asset_Inventory_Example.json
AMPpolicycompanionunknownAMP_Asset_Management_Policy_Example.json
CARevidencecompanionunknownCAR_Corrective_Actions_Register_Example.json
CRevidencecompanionunknownCR_Context_Register_Example.json
CSSAQprocesscompanionunknownCSSAQ_Critical_Supplier_Security_Assessment_Questionnaire_Example.json
DALevidencecompanionunknownDAL_Decision_and_Action_Log_Example.json
DRevidencecompanionunknownDR_Document_Register_Example.json
ERRprocesscompanionunknownERR_Executive_Risk_Report_Example.json
GSpolicycompanionunknownGS_Gap_Statement_Example.json
HRPpolicycompanionunknownHRP_Human_Resources_Policy_Example.json
HRSPpolicycompanionunknownHRSP_Human_Resources_Security_Policy_Example.json
IAPassessmentcompanionunknownIAP_Internal_Audit_Plan_Example.json
IAPCassessmentcompanionunknownIAPC_Internal_Audit_Program_and_Checklist_Example.json
IASprocesscompanionunknownIAS_Information_Asset_Standard_Example.json
ICLevidencecompanionunknownICL_ISMS_Communication_Log_Example.json
ICPpolicycompanionunknownICP_Information_Classification_Policy_Example.json
ICVCprocesscompanionunknownICVC_ISO_27001_Control_Owner_Control_Validation_Checklist_Example.json
IGCprocesscompanionunknownIGC_ISMS_Governance_Calendar_Example.json
IMPL-WBdependencycompanionunknownIMPL-WB_Operational_ISMS_Dashboard_Example.json
IPRrolecompanionunknownIPR_Interested_Parties_Register_Example.json
IRARrolecompanionunknownIRAR_ISMS_Role_Appointment_Record_Example.json
ISOevidencecompanionunknownISO_Information_Security_Objectives_Example.json
ISOCLcontrolcompanionunknownISOCL_ISO_27001_2022_Clauses_Example.json
ISOCTRLcontrolcompanionunknownISOCTRL_ISO_27001_2022_Controls_Example.json
ISPpolicycompanionunknownISP_Information_Security_Policy_Example.json
ISSsystemcompanionunknownISS_ISMS_Scope_Statement_Example.json
MMEevidencecompanionunknownMME_Monitoring_and_Measurement_Evidence_Example.json
MRARTprocesscompanionunknownMRART_Management_Review_Agenda_and_Report_Example.json
MRMTevidencecompanionunknownMRMT_Management_Review_Minutes_Example.json
OFCprocesscompanionunknownOFC_Offboarding_Checklist_Example.json
ONCprocesscompanionunknownONC_Onboarding_Checklist_Example.json
OPCevidencecompanionunknownOPC_Operational_Planning_and_Control_Evidence_Example.json
OSrolecompanionunknownOS_Organization_Statement_Example.json
PARRpolicycompanionunknownPARR_Policy_Approval_and_Review_Register_Example.json
RACIrolecompanionunknownRACI_ISMS_RACI_Matrix_Example.json
RAEevidencecompanionunknownRAE_Resource_Allocation_Evidence_Example.json
RAMprocesscompanionunknownRAM_Risk_Assessment_Methodology_Example.json
RAMTevidencecompanionunknownRAMT_Risk_Acceptance_Minutes_Example.json
RASMpolicycompanionunknownRASM_Risk_Analysis_Statement_according_to_Magerit_and_ISO_27005_Example.json
RMPprocesscompanionunknownRMP_Risk_Management_Plan_Example.json
RRriskcompanionunknownRR_Risk_Register_Example.json
RTPpoamcompanionunknownRTP_Risk_Treatment_Plan_Example.json
SASsystemcompanionunknownSAS_Systems_Architecture_Statement_Example.json
SINVassetcompanionunknownSINV_Supplier_Inventory_Example.json
SOAcontrolcompanionunknownSOA_Statement_of_Applicability_SoA_Example.json
SOAVCprocesscompanionunknownSOAVC_Control_Owner_Statement_of_Applicability_Validation_Checklist_Example.json
SRPpolicycompanionunknownSRP_Supplier_Relationships_Policy_Example.json
SSAQprocesscompanionunknownSSAQ_Supplier_Security_Assessment_Questionnaire_Example.json
TRevidencecompanionunknownTR_Training_Register_Example.json
TRCevidencecompanionunknownTRC_Training_Records_Example.json
AST-001assetcompanionunknownAI_Asset_Inventory_Example.json
AST-003assetcompanionunknownAI_Asset_Inventory_Example.json
AST-005assetcompanionunknownAI_Asset_Inventory_Example.json
AST-011assetcompanionunknownAI_Asset_Inventory_Example.json
AST-012assetcompanionunknownAI_Asset_Inventory_Example.json
AST-013assetcompanionunknownAI_Asset_Inventory_Example.json
AST-014assetcompanionunknownAI_Asset_Inventory_Example.json
BADGE-047assetcompanionunknown
LAP-047assetcompanionunknown

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…