@@ -1,123 +1,125 @@
|
||||
{
|
||||
"name": "ISO 27001 (2022)",
|
||||
"id": "ISO/IEC 27001:2022",
|
||||
"name": "ISO 27001 (2022)",
|
||||
"controls": [
|
||||
{
|
||||
"id": "C.4.1",
|
||||
"id": "4.1",
|
||||
"name": "Context of the organization - Understanding the organization and its context"
|
||||
},
|
||||
{
|
||||
"id": "C.4.2",
|
||||
"id": "4.2",
|
||||
"name": "Context of the organization - Understanding the needs of interested parties"
|
||||
},
|
||||
{
|
||||
"id": "C.4.3",
|
||||
"id": "4.3",
|
||||
"name": "Context of the organization - Determining the scope of the information security management system"
|
||||
},
|
||||
{
|
||||
"id": "C.4.4",
|
||||
"id": "4.4",
|
||||
"name": "Context of the organization - Information security management system"
|
||||
},
|
||||
{
|
||||
"id": "C.5.1",
|
||||
"id": "5.1",
|
||||
"name": "Leadership - Leadership and commitment"
|
||||
},
|
||||
{
|
||||
"id": "C.5.2",
|
||||
"id": "5.2",
|
||||
"name": "Leadership - Policy"
|
||||
},
|
||||
{
|
||||
"id": "C.5.3",
|
||||
"id": "5.3",
|
||||
"name": "Leadership - Organizational roles, responsibilities and authorities"
|
||||
},
|
||||
{
|
||||
"id": "C.6.1.1",
|
||||
"id": "6.1.1",
|
||||
"name": "Planning - General actions to address risks and opportunities"
|
||||
},
|
||||
{
|
||||
"id": "C.6.1.2",
|
||||
"id": "6.1.2",
|
||||
"name": "Planning - Information security risk assessment"
|
||||
},
|
||||
{
|
||||
"id": "C.6.1.3",
|
||||
"id": "6.1.3",
|
||||
"name": "Planning - Information security risk treatment"
|
||||
},
|
||||
{
|
||||
"id": "C.6.2",
|
||||
"id": "6.2",
|
||||
"name": "Planning - Information security objective and planning to achieve them"
|
||||
},
|
||||
{
|
||||
"id": "C.6.3",
|
||||
"id": "6.3",
|
||||
"name": "Planning - Planning of Changes"
|
||||
},
|
||||
{
|
||||
"id": "C.7.1",
|
||||
"id": "7.1",
|
||||
"name": "Support - Resources"
|
||||
},
|
||||
{
|
||||
"id": "C.7.2",
|
||||
"id": "7.2",
|
||||
"name": "Support - Competence"
|
||||
},
|
||||
{
|
||||
"id": "C.7.3",
|
||||
"id": "7.3",
|
||||
"name": "Support - Awareness"
|
||||
},
|
||||
{
|
||||
"id": "C.7.4",
|
||||
"id": "7.4",
|
||||
"name": "Support - Communication"
|
||||
},
|
||||
{
|
||||
"id": "C.7.5.1",
|
||||
"id": "7.5.1",
|
||||
"name": "Support - Documented information"
|
||||
},
|
||||
{
|
||||
"id": "C.7.5.2",
|
||||
"name": "Support - Creating and Updating",
|
||||
"id": "C.7.5.3",
|
||||
"id": "7.5.2",
|
||||
"name": "Support - Creating and Updating"
|
||||
},
|
||||
{
|
||||
"id": "7.5.3",
|
||||
"name": "Support - Control of documented information"
|
||||
},
|
||||
{
|
||||
"id": "C.8.1",
|
||||
"id": "8.1",
|
||||
"name": "Operation - Operation planning and control"
|
||||
},
|
||||
{
|
||||
"id": "C.8.2",
|
||||
"id": "8.2",
|
||||
"name": "Operation - Information security risk assessment"
|
||||
},
|
||||
{
|
||||
"id": "C.8.3",
|
||||
"id": "8.3",
|
||||
"name": "Operation - Information security risk treatment"
|
||||
},
|
||||
{
|
||||
"id": "C.9.1",
|
||||
"id": "9.1",
|
||||
"name": "Performance evaluation - Monitoring, measurement, analysis, and evaluation"
|
||||
},
|
||||
{
|
||||
"id": "C.9.2.1",
|
||||
"id": "9.2.1",
|
||||
"name": "Performance evaluation - Internal Audit - General"
|
||||
},
|
||||
{
|
||||
"id": "C.9.2.2",
|
||||
"id": "9.2.2",
|
||||
"name": "Performance evaluation - Internal Audit Program"
|
||||
},
|
||||
{
|
||||
"id": "C.9.3.1",
|
||||
"id": "9.3.1",
|
||||
"name": "Performance evaluation - Management review - General"
|
||||
},
|
||||
{
|
||||
"id": "C.9.3.2",
|
||||
"id": "9.3.2",
|
||||
"name": "Performance evaluation - Management review inputs"
|
||||
},
|
||||
{
|
||||
"id": "C.9.3.3",
|
||||
"id": "9.3.3",
|
||||
"name": "Performance evaluation - Management review results"
|
||||
},
|
||||
{
|
||||
"id": "C.10.1",
|
||||
"id": "10.1",
|
||||
"name": "Improvement - Continual Improvement"
|
||||
},
|
||||
{
|
||||
"id": "C.10.2",
|
||||
"id": "10.2",
|
||||
"name": "Improvement - Nonconformity and corrective action"
|
||||
},
|
||||
{
|
||||
@@ -457,7 +459,8 @@
|
||||
"name": "Technological - Secure development life cycle"
|
||||
},
|
||||
{
|
||||
"id": "A.8.26"
|
||||
"id": "A.8.26",
|
||||
"name": "Technological - Application security requirements"
|
||||
},
|
||||
{
|
||||
"id": "A.8.27",
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"name": "SOC2",
|
||||
"name": "SOC 2",
|
||||
"id": "SOC2",
|
||||
"controls": [
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user