Update frameworks

Signed-off-by: gearnode <bryan@frimin.fr>
This commit is contained in:
gearnode
2025-04-09 21:19:53 -07:00
parent 785ad28b9f
commit 336487f332
4 changed files with 37 additions and 777 deletions

View File

@@ -1,123 +1,125 @@
{
"name": "ISO 27001 (2022)",
"id": "ISO/IEC 27001:2022",
"name": "ISO 27001 (2022)",
"controls": [
{
"id": "C.4.1",
"id": "4.1",
"name": "Context of the organization - Understanding the organization and its context"
},
{
"id": "C.4.2",
"id": "4.2",
"name": "Context of the organization - Understanding the needs of interested parties"
},
{
"id": "C.4.3",
"id": "4.3",
"name": "Context of the organization - Determining the scope of the information security management system"
},
{
"id": "C.4.4",
"id": "4.4",
"name": "Context of the organization - Information security management system"
},
{
"id": "C.5.1",
"id": "5.1",
"name": "Leadership - Leadership and commitment"
},
{
"id": "C.5.2",
"id": "5.2",
"name": "Leadership - Policy"
},
{
"id": "C.5.3",
"id": "5.3",
"name": "Leadership - Organizational roles, responsibilities and authorities"
},
{
"id": "C.6.1.1",
"id": "6.1.1",
"name": "Planning - General actions to address risks and opportunities"
},
{
"id": "C.6.1.2",
"id": "6.1.2",
"name": "Planning - Information security risk assessment"
},
{
"id": "C.6.1.3",
"id": "6.1.3",
"name": "Planning - Information security risk treatment"
},
{
"id": "C.6.2",
"id": "6.2",
"name": "Planning - Information security objective and planning to achieve them"
},
{
"id": "C.6.3",
"id": "6.3",
"name": "Planning - Planning of Changes"
},
{
"id": "C.7.1",
"id": "7.1",
"name": "Support - Resources"
},
{
"id": "C.7.2",
"id": "7.2",
"name": "Support - Competence"
},
{
"id": "C.7.3",
"id": "7.3",
"name": "Support - Awareness"
},
{
"id": "C.7.4",
"id": "7.4",
"name": "Support - Communication"
},
{
"id": "C.7.5.1",
"id": "7.5.1",
"name": "Support - Documented information"
},
{
"id": "C.7.5.2",
"name": "Support - Creating and Updating",
"id": "C.7.5.3",
"id": "7.5.2",
"name": "Support - Creating and Updating"
},
{
"id": "7.5.3",
"name": "Support - Control of documented information"
},
{
"id": "C.8.1",
"id": "8.1",
"name": "Operation - Operation planning and control"
},
{
"id": "C.8.2",
"id": "8.2",
"name": "Operation - Information security risk assessment"
},
{
"id": "C.8.3",
"id": "8.3",
"name": "Operation - Information security risk treatment"
},
{
"id": "C.9.1",
"id": "9.1",
"name": "Performance evaluation - Monitoring, measurement, analysis, and evaluation"
},
{
"id": "C.9.2.1",
"id": "9.2.1",
"name": "Performance evaluation - Internal Audit - General"
},
{
"id": "C.9.2.2",
"id": "9.2.2",
"name": "Performance evaluation - Internal Audit Program"
},
{
"id": "C.9.3.1",
"id": "9.3.1",
"name": "Performance evaluation - Management review - General"
},
{
"id": "C.9.3.2",
"id": "9.3.2",
"name": "Performance evaluation - Management review inputs"
},
{
"id": "C.9.3.3",
"id": "9.3.3",
"name": "Performance evaluation - Management review results"
},
{
"id": "C.10.1",
"id": "10.1",
"name": "Improvement - Continual Improvement"
},
{
"id": "C.10.2",
"id": "10.2",
"name": "Improvement - Nonconformity and corrective action"
},
{
@@ -457,7 +459,8 @@
"name": "Technological - Secure development life cycle"
},
{
"id": "A.8.26"
"id": "A.8.26",
"name": "Technological - Application security requirements"
},
{
"id": "A.8.27",