# ISO/IEC 27001:2022 system security plan

Projection of `system-security-plan.json`. How to read it: [`USER-MANUAL`](./oscal-guide.md). Do not edit this file by hand; rebuild the baseline or re-run the pipeline step.

- Implemented requirements: **118**.
- Layer A documented: **67**. Layer B linked: **47**. N/A: **4**.
- Unresolved evidence tokens: **88** (visible, not an abort). Layer C field scoring is not in this SSP.
- Policy components (comparison a): **7**. Process components: **0**. HITL citation; not a kernel score.
- Companion Example JSON is cited, not rewritten.

| ISO ID | Title | Layer | Owner | Linked artefacts | Unresolved | Status |
| --- | --- | --- | --- | --- | --- | --- |
| [4.1](control.html#4.1) | Understanding the organization and its context | linked | ISMS Manager | OS (cites), GS (cites), ERR (cites), ISOCL (cites) |  | implemented |
| [4.2](control.html#4.2) | Understanding the needs and expectations of interested parties | linked | Compliance Manager | ERR (cites), SRP (cites), ISOCL (cites) | SOC2-SD | implemented |
| [4.3](control.html#4.3) | Determining the scope of the ISMS | linked | ISMS Manager | ISS (cites), SAS (cites), SINV (cites), ISOCL (cites), AST-001 (field-ref), AST-005 (field-ref), AST-011 (field-ref), AST-014 (field-ref), AST-012 (field-ref), AST-013 (field-ref), AST-003 (field-ref) |  | implemented |
| [4.4](control.html#4.4) | Information security management system | linked | ISMS Manager | GS (cites), IMPL-WB (cites), ISOCL (cites) | WIR-S1 | implemented |
| [5.1](control.html#5.1) | Leadership and commitment | linked | Top Management | ISP (cites), MRART (cites), MRMT (cites), ISOCL (cites), DR (cites), AI (cites), SINV (cites) |  | implemented |
| [5.2](control.html#5.2) | Information security policy | linked | ISMS Manager | ISP (cites), TRC (cites), ISOCL (cites), DR (cites), AI (cites), SINV (cites) |  | implemented |
| [5.3](control.html#5.3) | Organizational roles, responsibilities and authorities | linked | ISMS Manager | RACI (cites), GS (cites), OS (cites), ISOCL (cites) |  | implemented |
| [6.1.1](control.html#6.1.1) | Actions to address risks and opportunities | linked | Risk Manager | RR (cites), RTP (cites), ISOCL (cites), RASM (cites), DR (cites), AI (cites), SINV (cites) | CIL | implemented |
| [6.1.2](control.html#6.1.2) | Information security risk assessment | linked | Risk Manager | RAM (cites), RAMT (cites), RASM (cites), RR (cites), ISOCL (cites), DR (cites), AI (cites), SINV (cites) |  | implemented |
| [6.1.3](control.html#6.1.3) | Information security risk treatment | linked | Risk Manager | RTP (cites), SOA (cites), ISOCTRL (cites), ISOCL (cites), RASM (cites), DR (cites), AI (cites), SINV (cites) |  | implemented |
| [6.2](control.html#6.2) | Information security objectives and planning to achieve them | linked | Top Management | ISP (cites), IMPL-WB (cites), MME (cites), ISOCL (cites) |  | implemented |
| [6.3](control.html#6.3) | Planning of changes | linked | Change Manager | CR (cites), ISOCL (cites) | CMP; ISMS-CL | implemented |
| [7.1](control.html#7.1) | Resources | linked | Top Management | MRART (cites), MRMT (cites), GS (cites), ISOCL (cites) |  | implemented |
| [7.2](control.html#7.2) | Competence | linked | HR Manager | TR (cites), TRC (cites), HRP (cites), ISOCL (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites) | CMTP | implemented |
| [7.3](control.html#7.3) | Awareness | linked | Security Lead | TRC (cites), HRSP (cites), ISOCL (cites) |  | implemented |
| [7.4](control.html#7.4) | Communication | documented | Communications Owner | ISOCL (cites) | COMM-P; SICT; IRP | implemented |
| [7.5](control.html#7.5) | Documented information | linked | Document Owner | DR (cites), ISOCL (cites), ISP (cites), AI (cites), SINV (cites) | DCP; WIR-S1 | implemented |
| [8.1](control.html#8.1) | Operational planning and control | documented | ISMS Manager | ISOCTRL (cites), ISOCL (cites) | WIR-S1; CMP | implemented |
| [8.2](control.html#8.2) | Information security risk assessment | linked | Risk Manager | RR (cites), RAM (cites), ISOCL (cites) | ISMS-CL | implemented |
| [8.3](control.html#8.3) | Information security risk treatment | linked | Risk Manager | RTP (cites), SOA (cites), CAR (cites), ISOCL (cites) |  | implemented |
| [9.1](control.html#9.1) | Monitoring, measurement, analysis and evaluation | linked | Security Lead | MME (cites), IMPL-WB (cites), MRART (cites), ISOCL (cites) |  | implemented |
| [9.2](control.html#9.2) | Internal audit | linked | Internal Auditor | IAP (cites), CAR (cites), MRMT (cites), ISOCL (cites) |  | implemented |
| [9.3](control.html#9.3) | Management review | linked | Top Management | MRART (cites), MRMT (cites), ISOCL (cites) |  | implemented |
| [10.1](control.html#10.1) | Continual improvement | linked | ISMS Manager | CAR (cites), ISOCL (cites) | CIL; WIR-S1 | implemented |
| [10.2](control.html#10.2) | Nonconformity and corrective action | linked | ISMS Manager | CAR (cites), IAP (cites), MRMT (cites), ISOCL (cites) |  | implemented |
| [A.5.1](control.html#A.5.1) | Policies for information security | linked | ISMS Manager | ISP (field-ref), SOA (cites), ISOCTRL (cites) |  | implemented |
| [A.5.2](control.html#A.5.2) | Information security roles and responsibilities | linked | ISMS Manager | RACI (field-ref), SOA (cites), ISOCTRL (cites) |  | implemented |
| [A.5.3](control.html#A.5.3) | Segregation of duties | documented | IT Operations | SOA (cites), ISOCTRL (cites) | SOD-CHK-2026-Q3 | partial |
| [A.5.4](control.html#A.5.4) | Management responsibilities | documented | Top Management | SOA (cites), ISOCTRL (cites) | MR-2026-Q3 | implemented |
| [A.5.5](control.html#A.5.5) | Contact with authorities | documented | Compliance Manager | SOA (cites), ISOCTRL (cites) | COMM-P | implemented |
| [A.5.6](control.html#A.5.6) | Contact with special interest groups | documented | Security Lead | SOA (cites), ISOCTRL (cites) | TI-SUB-2026 | implemented |
| [A.5.7](control.html#A.5.7) | Threat intelligence | documented | Security Lead | SOA (cites), ISOCTRL (cites) | TI-LOG-2026-Q3 | partial |
| [A.5.8](control.html#A.5.8) | Information security in project management | documented | Project Manager | SOA (cites), ISOCTRL (cites) | SSDLC | implemented |
| [A.5.9](control.html#A.5.9) | Inventory of information and other associated assets | linked | Asset Manager | AI (field-ref), SOA (cites), ISOCTRL (cites), AMP (cites), DR (cites), SINV (cites) |  | implemented |
| [A.5.10](control.html#A.5.10) | Acceptable use of information and other associated assets | linked | HR Manager | SOA (cites), ISOCTRL (cites), AMP (cites), DR (cites), AI (cites), SINV (cites) | AUP-ACK-2026-Q3 | implemented |
| [A.5.11](control.html#A.5.11) | Return of assets | linked | HR Manager | OFC (field-ref), SOA (cites), ISOCTRL (cites), AMP (cites), DR (cites), AI (cites), SINV (cites), LAP-047 (field-ref), BADGE-047 (field-ref) |  | implemented |
| [A.5.12](control.html#A.5.12) | Classification of information | linked | ISMS Manager | SOA (cites), ISOCTRL (cites), AMP (cites), DR (cites), AI (cites), SINV (cites), ICP (cites) | CLASS-STD-2026 | implemented |
| [A.5.13](control.html#A.5.13) | Labelling of information | linked | Document Owner | DR (field-ref), SOA (cites), ISOCTRL (cites), AMP (cites), AI (cites), SINV (cites), ICP (cites) |  | implemented |
| [A.5.14](control.html#A.5.14) | Information transfer | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ITR-2026-Q3 | implemented |
| [A.5.15](control.html#A.5.15) | Access control | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ACM | implemented |
| [A.5.16](control.html#A.5.16) | Identity management | documented | IT Operations | SOA (cites), ISOCTRL (cites) | IAM-CTRL-2026-Q3 | implemented |
| [A.5.17](control.html#A.5.17) | Authentication information | documented | IT Operations | SOA (cites), ISOCTRL (cites) | IAM-CTRL-2026-Q3 | implemented |
| [A.5.18](control.html#A.5.18) | Access rights | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ARR | implemented |
| [A.5.19](control.html#A.5.19) | Information security in supplier relationships | linked | Supplier Manager | SINV (field-ref), SOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites) |  | partial |
| [A.5.20](control.html#A.5.20) | Addressing information security within supplier agreements | linked | Supplier Manager | SOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites), SINV (cites) | CSS | partial |
| [A.5.21](control.html#A.5.21) | Managing information security in the ICT supply chain | linked | Supplier Manager | SINV (field-ref), SOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites) |  | planned |
| [A.5.22](control.html#A.5.22) | Monitoring, review and change management of supplier services | linked | Supplier Manager | SINV (field-ref), SOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites) |  | partial |
| [A.5.23](control.html#A.5.23) | Information security for use of cloud services | linked | Cloud Service Owner | SOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites), SINV (cites) | CLOUD-CTRL-2026-Q3 | partial |
| [A.5.24](control.html#A.5.24) | Information security incident management planning and preparation | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | IRP | implemented |
| [A.5.25](control.html#A.5.25) | Assessment and decision on information security events | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | SIR | implemented |
| [A.5.26](control.html#A.5.26) | Response to information security incidents | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | IR-RB | implemented |
| [A.5.27](control.html#A.5.27) | Learning from information security incidents | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | CIL | planned |
| [A.5.28](control.html#A.5.28) | Collection of evidence | documented | ISMS Manager | SOA (cites), ISOCTRL (cites) | ELAI | implemented |
| [A.5.29](control.html#A.5.29) | Information security during disruption | documented | Business Continuity Manager | SOA (cites), ISOCTRL (cites) | BCP | implemented |
| [A.5.30](control.html#A.5.30) | ICT readiness for business continuity | documented | IT Operations | SOA (cites), ISOCTRL (cites) | DRP | partial |
| [A.5.31](control.html#A.5.31) | Legal, statutory, regulatory and contractual requirements | documented | Compliance Manager | SOA (cites), ISOCTRL (cites) | LRR | implemented |
| [A.5.32](control.html#A.5.32) | Intellectual property rights | linked | Legal Counsel | IPR (field-ref), SOA (cites), ISOCTRL (cites) |  | planned |
| [A.5.33](control.html#A.5.33) | Protection of records | documented | Document Owner | SOA (cites), ISOCTRL (cites) | RRS | implemented |
| [A.5.34](control.html#A.5.34) | Privacy and protection of PII | documented | Privacy Lead | SOA (cites), ISOCTRL (cites) | DPAR | implemented |
| [A.5.35](control.html#A.5.35) | Independent review of information security | linked | Internal Auditor | IAP (field-ref), SOA (cites), ISOCTRL (cites) |  | implemented |
| [A.5.36](control.html#A.5.36) | Compliance with policies, rules and standards for information security | documented | ISMS Manager | SOA (cites), ISOCTRL (cites) | REQT | implemented |
| [A.5.37](control.html#A.5.37) | Documented operating procedures | documented | Process Owner | SOA (cites), ISOCTRL (cites) | DOP | partial |
| [A.6.1](control.html#A.6.1) | Screening | linked | HR Manager | SOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites) | HR-ONB-2026-023 | implemented |
| [A.6.2](control.html#A.6.2) | Terms and conditions of employment | linked | HR Manager | SOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites) | HR-ONB-2026-023 | implemented |
| [A.6.3](control.html#A.6.3) | Information security awareness, education and training | linked | HR Manager | SOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites) | TRAIN-REC-2026-188 | implemented |
| [A.6.4](control.html#A.6.4) | Disciplinary process | linked | HR Manager | HRP (field-ref), SOA (cites), ISOCTRL (cites), DR (cites), AI (cites), SINV (cites) |  | planned |
| [A.6.5](control.html#A.6.5) | Responsibilities after termination or change of employment | linked | HR Manager | OFC (field-ref), SOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites), LAP-047 (field-ref), BADGE-047 (field-ref) |  | implemented |
| [A.6.6](control.html#A.6.6) | Confidentiality or non-disclosure agreements | documented | Legal Counsel | SOA (cites), ISOCTRL (cites) | NDA-REG-2026 | implemented |
| [A.6.7](control.html#A.6.7) | Remote working | documented | IT Operations | SOA (cites), ISOCTRL (cites) | REMOTE-2026 | implemented |
| [A.6.8](control.html#A.6.8) | Information security event reporting | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | IRP | implemented |
| [A.7.1](control.html#A.7.1) | Physical security perimeters | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | PHY-SEC-2026 | implemented |
| [A.7.2](control.html#A.7.2) | Physical entry | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | PHY-ACCESS-2026 | implemented |
| [A.7.3](control.html#A.7.3) | Securing offices, rooms and facilities | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | PHY-OFFICE-2026 | implemented |
| [A.7.4](control.html#A.7.4) | Physical security monitoring | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | PHY-MON-2026-Q3 | partial |
| [A.7.5](control.html#A.7.5) | Protecting against physical and environmental threats | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | BCP | planned |
| [A.7.6](control.html#A.7.6) | Working in secure areas | not-applicable | Facilities Manager | SOA (field-ref), ISOCTRL (cites) |  | not-applicable |
| [A.7.7](control.html#A.7.7) | Clear desk and clear screen | documented | HR Manager | SOA (cites), ISOCTRL (cites) | AUP-ACK-2026-Q3 | implemented |
| [A.7.8](control.html#A.7.8) | Equipment siting and protection | linked | IT Operations | AI (field-ref), SOA (cites), ISOCTRL (cites) |  | implemented |
| [A.7.9](control.html#A.7.9) | Security of assets off-premises | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MDM-2026-Q3 | implemented |
| [A.7.10](control.html#A.7.10) | Storage media | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MDM-2026-Q3 | implemented |
| [A.7.11](control.html#A.7.11) | Supporting utilities | not-applicable | Facilities Manager | SINV (field-ref), SOA (cites), ISOCTRL (cites) |  | not-applicable |
| [A.7.12](control.html#A.7.12) | Cabling security | not-applicable | Facilities Manager | SOA (field-ref), ISOCTRL (cites) |  | not-applicable |
| [A.7.13](control.html#A.7.13) | Equipment maintenance | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MDM-2026-Q3 | implemented |
| [A.7.14](control.html#A.7.14) | Secure disposal or re-use of equipment | linked | IT Operations | OFC (field-ref), SOA (cites), ISOCTRL (cites), LAP-047 (field-ref), BADGE-047 (field-ref) |  | implemented |
| [A.8.1](control.html#A.8.1) | User endpoint devices | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MDM-2026-Q3 | implemented |
| [A.8.2](control.html#A.8.2) | Privileged access rights | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ACC-REV-2026-Q3 | partial |
| [A.8.3](control.html#A.8.3) | Information access restriction | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ACM | implemented |
| [A.8.4](control.html#A.8.4) | Access to source code | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | SI | implemented |
| [A.8.5](control.html#A.8.5) | Secure authentication | documented | IT Operations | SOA (cites), ISOCTRL (cites) | IAM-CTRL-2026-Q3 | implemented |
| [A.8.6](control.html#A.8.6) | Capacity management | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MON-2026-Q3 | planned |
| [A.8.7](control.html#A.8.7) | Protection against malware | documented | IT Operations | SOA (cites), ISOCTRL (cites) | EDR-2026-Q3 | implemented |
| [A.8.8](control.html#A.8.8) | Management of technical vulnerabilities | documented | Security Lead | SOA (cites), ISOCTRL (cites) | VULN-2026-Q3 | partial |
| [A.8.9](control.html#A.8.9) | Configuration management | documented | IT Operations | SOA (cites), ISOCTRL (cites) | CFG-BASE-2026 | partial |
| [A.8.10](control.html#A.8.10) | Information deletion | documented | Data Owner | SOA (cites), ISOCTRL (cites) | RRS | partial |
| [A.8.11](control.html#A.8.11) | Data masking | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | TBD-DMASK-2026 | planned |
| [A.8.12](control.html#A.8.12) | Data leakage prevention | documented | Security Lead | SOA (cites), ISOCTRL (cites) | DLP-PLAN-2026 | planned |
| [A.8.13](control.html#A.8.13) | Information backup | documented | IT Operations | SOA (cites), ISOCTRL (cites) | BKP-CRM-001 | implemented |
| [A.8.14](control.html#A.8.14) | Redundancy of information processing facilities | linked | IT Operations | SINV (field-ref), SOA (cites), ISOCTRL (cites) |  | implemented |
| [A.8.15](control.html#A.8.15) | Logging | documented | Security Lead | SOA (cites), ISOCTRL (cites) | LOG-2026-Q3 | implemented |
| [A.8.16](control.html#A.8.16) | Monitoring activities | documented | Security Lead | SOA (cites), ISOCTRL (cites) | MON-2026-Q3 | partial |
| [A.8.17](control.html#A.8.17) | Clock synchronization | documented | IT Operations | SOA (cites), ISOCTRL (cites) | CFG-BASE-2026 | implemented |
| [A.8.18](control.html#A.8.18) | Use of privileged utility programs | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ACC-REV-2026-Q3 | partial |
| [A.8.19](control.html#A.8.19) | Installation of software on operational systems | documented | IT Operations | SOA (cites), ISOCTRL (cites) | CMP | implemented |
| [A.8.20](control.html#A.8.20) | Networks security | documented | IT Operations | SOA (cites), ISOCTRL (cites) | NSP | implemented |
| [A.8.21](control.html#A.8.21) | Security of network services | linked | IT Operations | SINV (field-ref), SOA (cites), ISOCTRL (cites) |  | implemented |
| [A.8.22](control.html#A.8.22) | Segregation of networks | documented | IT Operations | SOA (cites), ISOCTRL (cites) | NET-SEG-2026 | partial |
| [A.8.23](control.html#A.8.23) | Web filtering | documented | IT Operations | SOA (cites), ISOCTRL (cites) | TBD-WEBFILTER-2026 | planned |
| [A.8.24](control.html#A.8.24) | Use of cryptography | documented | Security Lead | SOA (cites), ISOCTRL (cites) | CKMP | implemented |
| [A.8.25](control.html#A.8.25) | Secure development life cycle | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | SSDLC | implemented |
| [A.8.26](control.html#A.8.26) | Application security requirements | documented | Product Owner | SOA (cites), ISOCTRL (cites) | APPSEC-REQ-2026 | partial |
| [A.8.27](control.html#A.8.27) | Secure system architecture and engineering principles | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | ARCH-SEC-2026 | planned |
| [A.8.28](control.html#A.8.28) | Secure coding | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | SSDLC | implemented |
| [A.8.29](control.html#A.8.29) | Security testing in development and acceptance | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | TEST-SEC-2026 | partial |
| [A.8.30](control.html#A.8.30) | Outsourced development | not-applicable | Engineering Lead | SOA (field-ref), ISOCTRL (cites) |  | not-applicable |
| [A.8.31](control.html#A.8.31) | Separation of development, test and production environments | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | ENV-SEP-2026 | implemented |
| [A.8.32](control.html#A.8.32) | Change management | documented | Change Manager | SOA (cites), ISOCTRL (cites) | CMP | implemented |
| [A.8.33](control.html#A.8.33) | Test information | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | TBD-TESTDATA-2026 | planned |
| [A.8.34](control.html#A.8.34) | Protection of information systems during audit testing | linked | Internal Auditor | IAP (field-ref), SOA (cites), ISOCTRL (cites) |  | implemented |

## Not applicable

| ISO ID | Title | Layer | Owner | Linked artefacts | Unresolved | Status |
| --- | --- | --- | --- | --- | --- | --- |
| [A.7.6](control.html#A.7.6) | Working in secure areas | not-applicable | Facilities Manager | SOA (field-ref), ISOCTRL (cites) |  | not-applicable |
| [A.7.11](control.html#A.7.11) | Supporting utilities | not-applicable | Facilities Manager | SINV (field-ref), SOA (cites), ISOCTRL (cites) |  | not-applicable |
| [A.7.12](control.html#A.7.12) | Cabling security | not-applicable | Facilities Manager | SOA (field-ref), ISOCTRL (cites) |  | not-applicable |
| [A.8.30](control.html#A.8.30) | Outsourced development | not-applicable | Engineering Lead | SOA (field-ref), ISOCTRL (cites) |  | not-applicable |

## Unresolved evidence tokens

| ISO ID | Title | Layer | Owner | Linked artefacts | Unresolved | Status |
| --- | --- | --- | --- | --- | --- | --- |
| [4.2](control.html#4.2) | Understanding the needs and expectations of interested parties | linked | Compliance Manager | ERR (cites), SRP (cites), ISOCL (cites) | SOC2-SD | implemented |
| [4.4](control.html#4.4) | Information security management system | linked | ISMS Manager | GS (cites), IMPL-WB (cites), ISOCL (cites) | WIR-S1 | implemented |
| [6.1.1](control.html#6.1.1) | Actions to address risks and opportunities | linked | Risk Manager | RR (cites), RTP (cites), ISOCL (cites), RASM (cites), DR (cites), AI (cites), SINV (cites) | CIL | implemented |
| [6.3](control.html#6.3) | Planning of changes | linked | Change Manager | CR (cites), ISOCL (cites) | CMP; ISMS-CL | implemented |
| [7.2](control.html#7.2) | Competence | linked | HR Manager | TR (cites), TRC (cites), HRP (cites), ISOCL (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites) | CMTP | implemented |
| [7.4](control.html#7.4) | Communication | documented | Communications Owner | ISOCL (cites) | COMM-P; SICT; IRP | implemented |
| [7.5](control.html#7.5) | Documented information | linked | Document Owner | DR (cites), ISOCL (cites), ISP (cites), AI (cites), SINV (cites) | DCP; WIR-S1 | implemented |
| [8.1](control.html#8.1) | Operational planning and control | documented | ISMS Manager | ISOCTRL (cites), ISOCL (cites) | WIR-S1; CMP | implemented |
| [8.2](control.html#8.2) | Information security risk assessment | linked | Risk Manager | RR (cites), RAM (cites), ISOCL (cites) | ISMS-CL | implemented |
| [10.1](control.html#10.1) | Continual improvement | linked | ISMS Manager | CAR (cites), ISOCL (cites) | CIL; WIR-S1 | implemented |
| [A.5.3](control.html#A.5.3) | Segregation of duties | documented | IT Operations | SOA (cites), ISOCTRL (cites) | SOD-CHK-2026-Q3 | partial |
| [A.5.4](control.html#A.5.4) | Management responsibilities | documented | Top Management | SOA (cites), ISOCTRL (cites) | MR-2026-Q3 | implemented |
| [A.5.5](control.html#A.5.5) | Contact with authorities | documented | Compliance Manager | SOA (cites), ISOCTRL (cites) | COMM-P | implemented |
| [A.5.6](control.html#A.5.6) | Contact with special interest groups | documented | Security Lead | SOA (cites), ISOCTRL (cites) | TI-SUB-2026 | implemented |
| [A.5.7](control.html#A.5.7) | Threat intelligence | documented | Security Lead | SOA (cites), ISOCTRL (cites) | TI-LOG-2026-Q3 | partial |
| [A.5.8](control.html#A.5.8) | Information security in project management | documented | Project Manager | SOA (cites), ISOCTRL (cites) | SSDLC | implemented |
| [A.5.10](control.html#A.5.10) | Acceptable use of information and other associated assets | linked | HR Manager | SOA (cites), ISOCTRL (cites), AMP (cites), DR (cites), AI (cites), SINV (cites) | AUP-ACK-2026-Q3 | implemented |
| [A.5.12](control.html#A.5.12) | Classification of information | linked | ISMS Manager | SOA (cites), ISOCTRL (cites), AMP (cites), DR (cites), AI (cites), SINV (cites), ICP (cites) | CLASS-STD-2026 | implemented |
| [A.5.14](control.html#A.5.14) | Information transfer | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ITR-2026-Q3 | implemented |
| [A.5.15](control.html#A.5.15) | Access control | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ACM | implemented |
| [A.5.16](control.html#A.5.16) | Identity management | documented | IT Operations | SOA (cites), ISOCTRL (cites) | IAM-CTRL-2026-Q3 | implemented |
| [A.5.17](control.html#A.5.17) | Authentication information | documented | IT Operations | SOA (cites), ISOCTRL (cites) | IAM-CTRL-2026-Q3 | implemented |
| [A.5.18](control.html#A.5.18) | Access rights | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ARR | implemented |
| [A.5.20](control.html#A.5.20) | Addressing information security within supplier agreements | linked | Supplier Manager | SOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites), SINV (cites) | CSS | partial |
| [A.5.23](control.html#A.5.23) | Information security for use of cloud services | linked | Cloud Service Owner | SOA (cites), ISOCTRL (cites), SRP (cites), DR (cites), AI (cites), SINV (cites) | CLOUD-CTRL-2026-Q3 | partial |
| [A.5.24](control.html#A.5.24) | Information security incident management planning and preparation | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | IRP | implemented |
| [A.5.25](control.html#A.5.25) | Assessment and decision on information security events | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | SIR | implemented |
| [A.5.26](control.html#A.5.26) | Response to information security incidents | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | IR-RB | implemented |
| [A.5.27](control.html#A.5.27) | Learning from information security incidents | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | CIL | planned |
| [A.5.28](control.html#A.5.28) | Collection of evidence | documented | ISMS Manager | SOA (cites), ISOCTRL (cites) | ELAI | implemented |
| [A.5.29](control.html#A.5.29) | Information security during disruption | documented | Business Continuity Manager | SOA (cites), ISOCTRL (cites) | BCP | implemented |
| [A.5.30](control.html#A.5.30) | ICT readiness for business continuity | documented | IT Operations | SOA (cites), ISOCTRL (cites) | DRP | partial |
| [A.5.31](control.html#A.5.31) | Legal, statutory, regulatory and contractual requirements | documented | Compliance Manager | SOA (cites), ISOCTRL (cites) | LRR | implemented |
| [A.5.33](control.html#A.5.33) | Protection of records | documented | Document Owner | SOA (cites), ISOCTRL (cites) | RRS | implemented |
| [A.5.34](control.html#A.5.34) | Privacy and protection of PII | documented | Privacy Lead | SOA (cites), ISOCTRL (cites) | DPAR | implemented |
| [A.5.36](control.html#A.5.36) | Compliance with policies, rules and standards for information security | documented | ISMS Manager | SOA (cites), ISOCTRL (cites) | REQT | implemented |
| [A.5.37](control.html#A.5.37) | Documented operating procedures | documented | Process Owner | SOA (cites), ISOCTRL (cites) | DOP | partial |
| [A.6.1](control.html#A.6.1) | Screening | linked | HR Manager | SOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites) | HR-ONB-2026-023 | implemented |
| [A.6.2](control.html#A.6.2) | Terms and conditions of employment | linked | HR Manager | SOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites) | HR-ONB-2026-023 | implemented |
| [A.6.3](control.html#A.6.3) | Information security awareness, education and training | linked | HR Manager | SOA (cites), ISOCTRL (cites), HRP (cites), DR (cites), AI (cites), SINV (cites), HRSP (cites) | TRAIN-REC-2026-188 | implemented |
| [A.6.6](control.html#A.6.6) | Confidentiality or non-disclosure agreements | documented | Legal Counsel | SOA (cites), ISOCTRL (cites) | NDA-REG-2026 | implemented |
| [A.6.7](control.html#A.6.7) | Remote working | documented | IT Operations | SOA (cites), ISOCTRL (cites) | REMOTE-2026 | implemented |
| [A.6.8](control.html#A.6.8) | Information security event reporting | documented | Incident Manager | SOA (cites), ISOCTRL (cites) | IRP | implemented |
| [A.7.1](control.html#A.7.1) | Physical security perimeters | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | PHY-SEC-2026 | implemented |
| [A.7.2](control.html#A.7.2) | Physical entry | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | PHY-ACCESS-2026 | implemented |
| [A.7.3](control.html#A.7.3) | Securing offices, rooms and facilities | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | PHY-OFFICE-2026 | implemented |
| [A.7.4](control.html#A.7.4) | Physical security monitoring | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | PHY-MON-2026-Q3 | partial |
| [A.7.5](control.html#A.7.5) | Protecting against physical and environmental threats | documented | Facilities Manager | SOA (cites), ISOCTRL (cites) | BCP | planned |
| [A.7.7](control.html#A.7.7) | Clear desk and clear screen | documented | HR Manager | SOA (cites), ISOCTRL (cites) | AUP-ACK-2026-Q3 | implemented |
| [A.7.9](control.html#A.7.9) | Security of assets off-premises | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MDM-2026-Q3 | implemented |
| [A.7.10](control.html#A.7.10) | Storage media | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MDM-2026-Q3 | implemented |
| [A.7.13](control.html#A.7.13) | Equipment maintenance | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MDM-2026-Q3 | implemented |
| [A.8.1](control.html#A.8.1) | User endpoint devices | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MDM-2026-Q3 | implemented |
| [A.8.2](control.html#A.8.2) | Privileged access rights | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ACC-REV-2026-Q3 | partial |
| [A.8.3](control.html#A.8.3) | Information access restriction | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ACM | implemented |
| [A.8.4](control.html#A.8.4) | Access to source code | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | SI | implemented |
| [A.8.5](control.html#A.8.5) | Secure authentication | documented | IT Operations | SOA (cites), ISOCTRL (cites) | IAM-CTRL-2026-Q3 | implemented |
| [A.8.6](control.html#A.8.6) | Capacity management | documented | IT Operations | SOA (cites), ISOCTRL (cites) | MON-2026-Q3 | planned |
| [A.8.7](control.html#A.8.7) | Protection against malware | documented | IT Operations | SOA (cites), ISOCTRL (cites) | EDR-2026-Q3 | implemented |
| [A.8.8](control.html#A.8.8) | Management of technical vulnerabilities | documented | Security Lead | SOA (cites), ISOCTRL (cites) | VULN-2026-Q3 | partial |
| [A.8.9](control.html#A.8.9) | Configuration management | documented | IT Operations | SOA (cites), ISOCTRL (cites) | CFG-BASE-2026 | partial |
| [A.8.10](control.html#A.8.10) | Information deletion | documented | Data Owner | SOA (cites), ISOCTRL (cites) | RRS | partial |
| [A.8.11](control.html#A.8.11) | Data masking | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | TBD-DMASK-2026 | planned |
| [A.8.12](control.html#A.8.12) | Data leakage prevention | documented | Security Lead | SOA (cites), ISOCTRL (cites) | DLP-PLAN-2026 | planned |
| [A.8.13](control.html#A.8.13) | Information backup | documented | IT Operations | SOA (cites), ISOCTRL (cites) | BKP-CRM-001 | implemented |
| [A.8.15](control.html#A.8.15) | Logging | documented | Security Lead | SOA (cites), ISOCTRL (cites) | LOG-2026-Q3 | implemented |
| [A.8.16](control.html#A.8.16) | Monitoring activities | documented | Security Lead | SOA (cites), ISOCTRL (cites) | MON-2026-Q3 | partial |
| [A.8.17](control.html#A.8.17) | Clock synchronization | documented | IT Operations | SOA (cites), ISOCTRL (cites) | CFG-BASE-2026 | implemented |
| [A.8.18](control.html#A.8.18) | Use of privileged utility programs | documented | IT Operations | SOA (cites), ISOCTRL (cites) | ACC-REV-2026-Q3 | partial |
| [A.8.19](control.html#A.8.19) | Installation of software on operational systems | documented | IT Operations | SOA (cites), ISOCTRL (cites) | CMP | implemented |
| [A.8.20](control.html#A.8.20) | Networks security | documented | IT Operations | SOA (cites), ISOCTRL (cites) | NSP | implemented |
| [A.8.22](control.html#A.8.22) | Segregation of networks | documented | IT Operations | SOA (cites), ISOCTRL (cites) | NET-SEG-2026 | partial |
| [A.8.23](control.html#A.8.23) | Web filtering | documented | IT Operations | SOA (cites), ISOCTRL (cites) | TBD-WEBFILTER-2026 | planned |
| [A.8.24](control.html#A.8.24) | Use of cryptography | documented | Security Lead | SOA (cites), ISOCTRL (cites) | CKMP | implemented |
| [A.8.25](control.html#A.8.25) | Secure development life cycle | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | SSDLC | implemented |
| [A.8.26](control.html#A.8.26) | Application security requirements | documented | Product Owner | SOA (cites), ISOCTRL (cites) | APPSEC-REQ-2026 | partial |
| [A.8.27](control.html#A.8.27) | Secure system architecture and engineering principles | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | ARCH-SEC-2026 | planned |
| [A.8.28](control.html#A.8.28) | Secure coding | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | SSDLC | implemented |
| [A.8.29](control.html#A.8.29) | Security testing in development and acceptance | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | TEST-SEC-2026 | partial |
| [A.8.31](control.html#A.8.31) | Separation of development, test and production environments | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | ENV-SEP-2026 | implemented |
| [A.8.32](control.html#A.8.32) | Change management | documented | Change Manager | SOA (cites), ISOCTRL (cites) | CMP | implemented |
| [A.8.33](control.html#A.8.33) | Test information | documented | Engineering Lead | SOA (cites), ISOCTRL (cites) | TBD-TESTDATA-2026 | planned |

## Cited companion resources (carrier)

| Artifact | Object type | Carrier | Provenance | File |
| --- | --- | --- | --- | --- |
| AI | asset | companion | unknown | AI_Asset_Inventory_Example.json |
| AMP | policy | companion | unknown | AMP_Asset_Management_Policy_Example.json |
| CAR | evidence | companion | unknown | CAR_Corrective_Actions_Register_Example.json |
| CR | evidence | companion | unknown | CR_Context_Register_Example.json |
| CSSAQ | process | companion | unknown | CSSAQ_Critical_Supplier_Security_Assessment_Questionnaire_Example.json |
| DAL | evidence | companion | unknown | DAL_Decision_and_Action_Log_Example.json |
| DR | evidence | companion | unknown | DR_Document_Register_Example.json |
| ERR | process | companion | unknown | ERR_Executive_Risk_Report_Example.json |
| GS | policy | companion | unknown | GS_Gap_Statement_Example.json |
| HRP | policy | companion | unknown | HRP_Human_Resources_Policy_Example.json |
| HRSP | policy | companion | unknown | HRSP_Human_Resources_Security_Policy_Example.json |
| IAP | assessment | companion | unknown | IAP_Internal_Audit_Plan_Example.json |
| IAPC | assessment | companion | unknown | IAPC_Internal_Audit_Program_and_Checklist_Example.json |
| IAS | process | companion | unknown | IAS_Information_Asset_Standard_Example.json |
| ICL | evidence | companion | unknown | ICL_ISMS_Communication_Log_Example.json |
| ICP | policy | companion | unknown | ICP_Information_Classification_Policy_Example.json |
| ICVC | process | companion | unknown | ICVC_ISO_27001_Control_Owner_Control_Validation_Checklist_Example.json |
| IGC | process | companion | unknown | IGC_ISMS_Governance_Calendar_Example.json |
| IMPL-WB | dependency | companion | unknown | IMPL-WB_Operational_ISMS_Dashboard_Example.json |
| IPR | role | companion | unknown | IPR_Interested_Parties_Register_Example.json |
| IRAR | role | companion | unknown | IRAR_ISMS_Role_Appointment_Record_Example.json |
| ISO | evidence | companion | unknown | ISO_Information_Security_Objectives_Example.json |
| ISOCL | control | companion | unknown | ISOCL_ISO_27001_2022_Clauses_Example.json |
| ISOCTRL | control | companion | unknown | ISOCTRL_ISO_27001_2022_Controls_Example.json |
| ISP | policy | companion | unknown | ISP_Information_Security_Policy_Example.json |
| ISS | system | companion | unknown | ISS_ISMS_Scope_Statement_Example.json |
| MME | evidence | companion | unknown | MME_Monitoring_and_Measurement_Evidence_Example.json |
| MRART | process | companion | unknown | MRART_Management_Review_Agenda_and_Report_Example.json |
| MRMT | evidence | companion | unknown | MRMT_Management_Review_Minutes_Example.json |
| OFC | process | companion | unknown | OFC_Offboarding_Checklist_Example.json |
| ONC | process | companion | unknown | ONC_Onboarding_Checklist_Example.json |
| OPC | evidence | companion | unknown | OPC_Operational_Planning_and_Control_Evidence_Example.json |
| OS | role | companion | unknown | OS_Organization_Statement_Example.json |
| PARR | policy | companion | unknown | PARR_Policy_Approval_and_Review_Register_Example.json |
| RACI | role | companion | unknown | RACI_ISMS_RACI_Matrix_Example.json |
| RAE | evidence | companion | unknown | RAE_Resource_Allocation_Evidence_Example.json |
| RAM | process | companion | unknown | RAM_Risk_Assessment_Methodology_Example.json |
| RAMT | evidence | companion | unknown | RAMT_Risk_Acceptance_Minutes_Example.json |
| RASM | policy | companion | unknown | RASM_Risk_Analysis_Statement_according_to_Magerit_and_ISO_27005_Example.json |
| RMP | process | companion | unknown | RMP_Risk_Management_Plan_Example.json |
| RR | risk | companion | unknown | RR_Risk_Register_Example.json |
| RTP | poam | companion | unknown | RTP_Risk_Treatment_Plan_Example.json |
| SAS | system | companion | unknown | SAS_Systems_Architecture_Statement_Example.json |
| SINV | asset | companion | unknown | SINV_Supplier_Inventory_Example.json |
| SOA | control | companion | unknown | SOA_Statement_of_Applicability_SoA_Example.json |
| SOAVC | process | companion | unknown | SOAVC_Control_Owner_Statement_of_Applicability_Validation_Checklist_Example.json |
| SRP | policy | companion | unknown | SRP_Supplier_Relationships_Policy_Example.json |
| SSAQ | process | companion | unknown | SSAQ_Supplier_Security_Assessment_Questionnaire_Example.json |
| TR | evidence | companion | unknown | TR_Training_Register_Example.json |
| TRC | evidence | companion | unknown | TRC_Training_Records_Example.json |
| AST-001 | asset | companion | unknown | AI_Asset_Inventory_Example.json |
| AST-003 | asset | companion | unknown | AI_Asset_Inventory_Example.json |
| AST-005 | asset | companion | unknown | AI_Asset_Inventory_Example.json |
| AST-011 | asset | companion | unknown | AI_Asset_Inventory_Example.json |
| AST-012 | asset | companion | unknown | AI_Asset_Inventory_Example.json |
| AST-013 | asset | companion | unknown | AI_Asset_Inventory_Example.json |
| AST-014 | asset | companion | unknown | AI_Asset_Inventory_Example.json |
| BADGE-047 | asset | companion | unknown |  |
| LAP-047 | asset | companion | unknown |  |
