diff --git a/apps/console/public/data/frameworks/CCPA.json b/apps/console/public/data/frameworks/CCPA.json
index acd05696d..f9de31560 100644
--- a/apps/console/public/data/frameworks/CCPA.json
+++ b/apps/console/public/data/frameworks/CCPA.json
@@ -1,7 +1,11 @@
{
- "id": "CCPA",
- "name": "CCPA",
- "controls": [
+ "id": "CCPA",
+ "name": "CCPA",
+ "logo": {
+ "light": "",
+ "dark": ""
+ },
+ "controls": [
{
"id": "1798.100(a)",
"name": "Notice at collection"
@@ -94,4 +98,5 @@
"id": "1798.135(c)(4)",
"name": "Waiting period after opt-out"
}
- ]}
\ No newline at end of file
+ ]
+}
diff --git a/apps/console/public/data/frameworks/DORA.json b/apps/console/public/data/frameworks/DORA.json
index c06a76ad7..572e9e1c1 100644
--- a/apps/console/public/data/frameworks/DORA.json
+++ b/apps/console/public/data/frameworks/DORA.json
@@ -1,265 +1,270 @@
{
- "id": "DORA",
- "name": "DORA",
- "controls":[
- {
- "id": "Art. 5(1)",
- "name": "Internal governance and control framework"
- },
- {
- "id": "Art. 5(2)",
- "name": "Management body responsibility for ICT risk management"
- },
- {
- "id": "Art. 5(3)",
- "name": "Senior management role for ICT third-party risk"
- },
- {
- "id": "Art. 5(4)",
- "name": "ICT training for management body"
- },
- {
- "id": "Art. 6(1)",
- "name": "ICT risk management framework"
- },
- {
- "id": "Art. 6(4)",
- "name": "Independence of control functions"
- },
- {
- "id": "Art. 6(5)",
- "name": "Review of ICT risk management framework"
- },
- {
- "id": "Art. 6(6)",
- "name": "ICT internal audits"
- },
- {
- "id": "Art. 6(8)",
- "name": "Digital operational resilience strategy"
- },
- {
- "id": "Art. 7",
- "name": "ICT systems protocols and tools"
- },
- {
- "id": "Art. 8(1)",
- "name": "Identification and classification of ICT assets"
- },
- {
- "id": "Art. 8(2)",
- "name": "Identification of ICT risks and cyber threats"
- },
- {
- "id": "Art. 8(4)",
- "name": "Mapping of critical assets and dependencies"
- },
- {
- "id": "Art. 8(5)",
- "name": "Identification of third-party dependencies"
- },
- {
- "id": "Art. 8(7)",
- "name": "Risk assessment on legacy ICT systems"
- },
- {
- "id": "Art. 9(1)",
- "name": "Monitoring and control of ICT security"
- },
- {
- "id": "Art. 9(2)",
- "name": "ICT security policies and procedures"
- },
- {
- "id": "Art. 9(4)(a)",
- "name": "Information security policy"
- },
- {
- "id": "Art. 9(4)(b)",
- "name": "Network and infrastructure management"
- },
- {
- "id": "Art. 9(4)(c)",
- "name": "Access control policies"
- },
- {
- "id": "Art. 9(4)(d)",
- "name": "Authentication and encryption protocols"
- },
- {
- "id": "Art. 9(4)(e)",
- "name": "ICT change management policies"
- },
- {
- "id": "Art. 9(4)(f)",
- "name": "Patch management and updates"
- },
- {
- "id": "Art. 10(1)",
- "name": "Detection of anomalous activities"
- },
- {
- "id": "Art. 10(2)",
- "name": "Alert thresholds and control layers"
- },
- {
- "id": "Art. 11(1)",
- "name": "ICT business continuity policy"
- },
- {
- "id": "Art. 11(3)",
- "name": "ICT response and recovery plans"
- },
- {
- "id": "Art. 11(5)",
- "name": "Business impact analysis (BIA)"
- },
- {
- "id": "Art. 11(6)",
- "name": "Testing of business continuity plans"
- },
- {
- "id": "Art. 11(7)",
- "name": "Crisis management function"
- },
- {
- "id": "Art. 12(1)",
- "name": "Backup policies and procedures"
- },
- {
- "id": "Art. 12(4)",
- "name": "Redundant ICT capacities"
- },
- {
- "id": "Art. 13(1)",
- "name": "Capabilities to gather threat information"
- },
- {
- "id": "Art. 13(2)",
- "name": "Post-incident reviews"
- },
- {
- "id": "Art. 13(6)",
- "name": "ICT security awareness and training"
- },
- {
- "id": "Art. 14(1)",
- "name": "Crisis communication plans"
- },
- {
- "id": "Art. 14(2)",
- "name": "Internal and external communication policies"
- },
- {
- "id": "Art. 16(1)",
- "name": "Simplified ICT risk management framework"
- },
- {
- "id": "Art. 17(1)",
- "name": "ICT-related incident management process"
- },
- {
- "id": "Art. 17(2)",
- "name": "Recording of incidents and cyber threats"
- },
- {
- "id": "Art. 17(3)",
- "name": "Classification and reporting procedures"
- },
- {
- "id": "Art. 18(1)",
- "name": "Classification of ICT-related incidents"
- },
- {
- "id": "Art. 19(1)",
- "name": "Reporting of major ICT-related incidents"
- },
- {
- "id": "Art. 19(3)",
- "name": "Client notification of major incidents"
- },
- {
- "id": "Art. 23",
- "name": "Operational or security payment-related incidents"
- },
- {
- "id": "Art. 24(1)",
- "name": "Digital operational resilience testing programme"
- },
- {
- "id": "Art. 25(1)",
- "name": "Execution of appropriate tests (vulnerability scans)"
- },
- {
- "id": "Art. 26(1)",
- "name": "Advanced threat-led penetration testing (TLPT)"
- },
- {
- "id": "Art. 28(1)",
- "name": "Management of ICT third-party risk"
- },
- {
- "id": "Art. 28(2)",
- "name": "Strategy on ICT third-party risk"
- },
- {
- "id": "Art. 28(3)",
- "name": "Register of information on contractual arrangements"
- },
- {
- "id": "Art. 28(4)",
- "name": "Assessment before entering contractual arrangements"
- },
- {
- "id": "Art. 28(8)",
- "name": "Exit strategies for critical services"
- },
- {
- "id": "Art. 29",
- "name": "Assessment of ICT concentration risk"
- },
- {
- "id": "Art. 30(1)",
- "name": "Documentation of contractual arrangements"
- },
- {
- "id": "Art. 30(2)",
- "name": "Key contractual provisions (general)"
- },
- {
- "id": "Art. 30(3)",
- "name": "Key contractual provisions (critical functions)"
- },
- {
- "id": "Art. 31(12)",
- "name": "Establishment of subsidiary in the Union"
- },
- {
- "id": "Art. 35(5)",
- "name": "Cooperation with Lead Overseer"
- },
- {
- "id": "Art. 37",
- "name": "Response to requests for information"
- },
- {
- "id": "Art. 38",
- "name": "Submission to general investigations"
- },
- {
- "id": "Art. 39",
- "name": "Submission to on-site inspections"
- },
- {
- "id": "Art. 42(1)",
- "name": "Notification of intent to follow recommendations"
- },
- {
- "id": "Art. 43",
- "name": "Payment of oversight fees"
- },
- {
- "id": "Art. 45",
- "name": "Information-sharing arrangements"
- }
- ]}
\ No newline at end of file
+ "id": "DORA",
+ "name": "DORA",
+ "logo": {
+ "light": "",
+ "dark": ""
+ },
+ "controls": [
+ {
+ "id": "Art. 5(1)",
+ "name": "Internal governance and control framework"
+ },
+ {
+ "id": "Art. 5(2)",
+ "name": "Management body responsibility for ICT risk management"
+ },
+ {
+ "id": "Art. 5(3)",
+ "name": "Senior management role for ICT third-party risk"
+ },
+ {
+ "id": "Art. 5(4)",
+ "name": "ICT training for management body"
+ },
+ {
+ "id": "Art. 6(1)",
+ "name": "ICT risk management framework"
+ },
+ {
+ "id": "Art. 6(4)",
+ "name": "Independence of control functions"
+ },
+ {
+ "id": "Art. 6(5)",
+ "name": "Review of ICT risk management framework"
+ },
+ {
+ "id": "Art. 6(6)",
+ "name": "ICT internal audits"
+ },
+ {
+ "id": "Art. 6(8)",
+ "name": "Digital operational resilience strategy"
+ },
+ {
+ "id": "Art. 7",
+ "name": "ICT systems protocols and tools"
+ },
+ {
+ "id": "Art. 8(1)",
+ "name": "Identification and classification of ICT assets"
+ },
+ {
+ "id": "Art. 8(2)",
+ "name": "Identification of ICT risks and cyber threats"
+ },
+ {
+ "id": "Art. 8(4)",
+ "name": "Mapping of critical assets and dependencies"
+ },
+ {
+ "id": "Art. 8(5)",
+ "name": "Identification of third-party dependencies"
+ },
+ {
+ "id": "Art. 8(7)",
+ "name": "Risk assessment on legacy ICT systems"
+ },
+ {
+ "id": "Art. 9(1)",
+ "name": "Monitoring and control of ICT security"
+ },
+ {
+ "id": "Art. 9(2)",
+ "name": "ICT security policies and procedures"
+ },
+ {
+ "id": "Art. 9(4)(a)",
+ "name": "Information security policy"
+ },
+ {
+ "id": "Art. 9(4)(b)",
+ "name": "Network and infrastructure management"
+ },
+ {
+ "id": "Art. 9(4)(c)",
+ "name": "Access control policies"
+ },
+ {
+ "id": "Art. 9(4)(d)",
+ "name": "Authentication and encryption protocols"
+ },
+ {
+ "id": "Art. 9(4)(e)",
+ "name": "ICT change management policies"
+ },
+ {
+ "id": "Art. 9(4)(f)",
+ "name": "Patch management and updates"
+ },
+ {
+ "id": "Art. 10(1)",
+ "name": "Detection of anomalous activities"
+ },
+ {
+ "id": "Art. 10(2)",
+ "name": "Alert thresholds and control layers"
+ },
+ {
+ "id": "Art. 11(1)",
+ "name": "ICT business continuity policy"
+ },
+ {
+ "id": "Art. 11(3)",
+ "name": "ICT response and recovery plans"
+ },
+ {
+ "id": "Art. 11(5)",
+ "name": "Business impact analysis (BIA)"
+ },
+ {
+ "id": "Art. 11(6)",
+ "name": "Testing of business continuity plans"
+ },
+ {
+ "id": "Art. 11(7)",
+ "name": "Crisis management function"
+ },
+ {
+ "id": "Art. 12(1)",
+ "name": "Backup policies and procedures"
+ },
+ {
+ "id": "Art. 12(4)",
+ "name": "Redundant ICT capacities"
+ },
+ {
+ "id": "Art. 13(1)",
+ "name": "Capabilities to gather threat information"
+ },
+ {
+ "id": "Art. 13(2)",
+ "name": "Post-incident reviews"
+ },
+ {
+ "id": "Art. 13(6)",
+ "name": "ICT security awareness and training"
+ },
+ {
+ "id": "Art. 14(1)",
+ "name": "Crisis communication plans"
+ },
+ {
+ "id": "Art. 14(2)",
+ "name": "Internal and external communication policies"
+ },
+ {
+ "id": "Art. 16(1)",
+ "name": "Simplified ICT risk management framework"
+ },
+ {
+ "id": "Art. 17(1)",
+ "name": "ICT-related incident management process"
+ },
+ {
+ "id": "Art. 17(2)",
+ "name": "Recording of incidents and cyber threats"
+ },
+ {
+ "id": "Art. 17(3)",
+ "name": "Classification and reporting procedures"
+ },
+ {
+ "id": "Art. 18(1)",
+ "name": "Classification of ICT-related incidents"
+ },
+ {
+ "id": "Art. 19(1)",
+ "name": "Reporting of major ICT-related incidents"
+ },
+ {
+ "id": "Art. 19(3)",
+ "name": "Client notification of major incidents"
+ },
+ {
+ "id": "Art. 23",
+ "name": "Operational or security payment-related incidents"
+ },
+ {
+ "id": "Art. 24(1)",
+ "name": "Digital operational resilience testing programme"
+ },
+ {
+ "id": "Art. 25(1)",
+ "name": "Execution of appropriate tests (vulnerability scans)"
+ },
+ {
+ "id": "Art. 26(1)",
+ "name": "Advanced threat-led penetration testing (TLPT)"
+ },
+ {
+ "id": "Art. 28(1)",
+ "name": "Management of ICT third-party risk"
+ },
+ {
+ "id": "Art. 28(2)",
+ "name": "Strategy on ICT third-party risk"
+ },
+ {
+ "id": "Art. 28(3)",
+ "name": "Register of information on contractual arrangements"
+ },
+ {
+ "id": "Art. 28(4)",
+ "name": "Assessment before entering contractual arrangements"
+ },
+ {
+ "id": "Art. 28(8)",
+ "name": "Exit strategies for critical services"
+ },
+ {
+ "id": "Art. 29",
+ "name": "Assessment of ICT concentration risk"
+ },
+ {
+ "id": "Art. 30(1)",
+ "name": "Documentation of contractual arrangements"
+ },
+ {
+ "id": "Art. 30(2)",
+ "name": "Key contractual provisions (general)"
+ },
+ {
+ "id": "Art. 30(3)",
+ "name": "Key contractual provisions (critical functions)"
+ },
+ {
+ "id": "Art. 31(12)",
+ "name": "Establishment of subsidiary in the Union"
+ },
+ {
+ "id": "Art. 35(5)",
+ "name": "Cooperation with Lead Overseer"
+ },
+ {
+ "id": "Art. 37",
+ "name": "Response to requests for information"
+ },
+ {
+ "id": "Art. 38",
+ "name": "Submission to general investigations"
+ },
+ {
+ "id": "Art. 39",
+ "name": "Submission to on-site inspections"
+ },
+ {
+ "id": "Art. 42(1)",
+ "name": "Notification of intent to follow recommendations"
+ },
+ {
+ "id": "Art. 43",
+ "name": "Payment of oversight fees"
+ },
+ {
+ "id": "Art. 45",
+ "name": "Information-sharing arrangements"
+ }
+ ]
+}
diff --git a/apps/console/public/data/frameworks/GDPR.json b/apps/console/public/data/frameworks/GDPR.json
index 93072fcac..d483062bb 100644
--- a/apps/console/public/data/frameworks/GDPR.json
+++ b/apps/console/public/data/frameworks/GDPR.json
@@ -1,7 +1,11 @@
{
- "id": "GDPR",
- "name": "GDPR",
- "controls": [
+ "id": "GDPR",
+ "name": "GDPR",
+ "logo": {
+ "light": "",
+ "dark": ""
+ },
+ "controls": [
{
"id": "Art. 5(1)(a)",
"name": "Lawfulness, fairness and transparency"
@@ -250,4 +254,5 @@
"id": "Art. 50",
"name": "International cooperation"
}
- ]}
\ No newline at end of file
+ ]
+}
diff --git a/apps/console/public/data/frameworks/NIS2.json b/apps/console/public/data/frameworks/NIS2.json
index bba0cc42c..68a85818b 100644
--- a/apps/console/public/data/frameworks/NIS2.json
+++ b/apps/console/public/data/frameworks/NIS2.json
@@ -1,73 +1,78 @@
{
- "id": "NIS2",
- "name": "NIS 2",
- "controls":[
- {
- "id": "Art. 3(4)",
- "name": "Submission of entity registration data"
- },
- {
- "id": "Art. 20(1)",
- "name": "Management body oversight and approval"
- },
- {
- "id": "Art. 20(2)",
- "name": "Cybersecurity training for management bodies"
- },
- {
- "id": "Art. 21(2)(a)",
- "name": "Policies on risk analysis and information system security"
- },
- {
- "id": "Art. 21(2)(b)",
- "name": "Incident handling"
- },
- {
- "id": "Art. 21(2)(c)",
- "name": "Business continuity and crisis management"
- },
- {
- "id": "Art. 21(2)(d)",
- "name": "Supply chain security"
- },
- {
- "id": "Art. 21(2)(e)",
- "name": "Security in system acquisition, development and maintenance"
- },
- {
- "id": "Art. 21(2)(f)",
- "name": "Assessment of security measure effectiveness"
- },
- {
- "id": "Art. 21(2)(g)",
- "name": "Cyber hygiene practices and training"
- },
- {
- "id": "Art. 21(2)(h)",
- "name": "Cryptography and encryption policies"
- },
- {
- "id": "Art. 21(2)(i)",
- "name": "Human resources security and asset management"
- },
- {
- "id": "Art. 21(2)(j)",
- "name": "Multi-factor authentication and secure communications"
- },
- {
- "id": "Art. 23(1)",
- "name": "Reporting significant incidents to authorities"
- },
- {
- "id": "Art. 23(2)",
- "name": "Notifying service recipients of significant cyber threats"
- },
- {
- "id": "Art. 26(3)",
- "name": "Designation of Union representative (non-EU entities)"
- },
- {
- "id": "Art. 28(1)",
- "name": "Maintenance of domain name registration data (TLDs/registrars)"
- }
- ]}
\ No newline at end of file
+ "id": "NIS2",
+ "name": "NIS 2",
+ "logo": {
+ "light": "",
+ "dark": ""
+ },
+ "controls": [
+ {
+ "id": "Art. 3(4)",
+ "name": "Submission of entity registration data"
+ },
+ {
+ "id": "Art. 20(1)",
+ "name": "Management body oversight and approval"
+ },
+ {
+ "id": "Art. 20(2)",
+ "name": "Cybersecurity training for management bodies"
+ },
+ {
+ "id": "Art. 21(2)(a)",
+ "name": "Policies on risk analysis and information system security"
+ },
+ {
+ "id": "Art. 21(2)(b)",
+ "name": "Incident handling"
+ },
+ {
+ "id": "Art. 21(2)(c)",
+ "name": "Business continuity and crisis management"
+ },
+ {
+ "id": "Art. 21(2)(d)",
+ "name": "Supply chain security"
+ },
+ {
+ "id": "Art. 21(2)(e)",
+ "name": "Security in system acquisition, development and maintenance"
+ },
+ {
+ "id": "Art. 21(2)(f)",
+ "name": "Assessment of security measure effectiveness"
+ },
+ {
+ "id": "Art. 21(2)(g)",
+ "name": "Cyber hygiene practices and training"
+ },
+ {
+ "id": "Art. 21(2)(h)",
+ "name": "Cryptography and encryption policies"
+ },
+ {
+ "id": "Art. 21(2)(i)",
+ "name": "Human resources security and asset management"
+ },
+ {
+ "id": "Art. 21(2)(j)",
+ "name": "Multi-factor authentication and secure communications"
+ },
+ {
+ "id": "Art. 23(1)",
+ "name": "Reporting significant incidents to authorities"
+ },
+ {
+ "id": "Art. 23(2)",
+ "name": "Notifying service recipients of significant cyber threats"
+ },
+ {
+ "id": "Art. 26(3)",
+ "name": "Designation of Union representative (non-EU entities)"
+ },
+ {
+ "id": "Art. 28(1)",
+ "name": "Maintenance of domain name registration data (TLDs/registrars)"
+ }
+ ]
+}