diff --git a/apps/console/public/data/frameworks/ISO27701-2025.json b/apps/console/public/data/frameworks/ISO27701-2025.json new file mode 100644 index 000000000..f55c3a892 --- /dev/null +++ b/apps/console/public/data/frameworks/ISO27701-2025.json @@ -0,0 +1,438 @@ +{ + "id": "ISO/IEC 27701:2025", + "name": "ISO 27701 (2025)", + "controls": [ + { + "id": "4.1", + "name": "Context of the organization - Understanding the organization and its context" + }, + { + "id": "4.2", + "name": "Context of the organization - Understanding the needs and expectations of interested parties" + }, + { + "id": "4.3", + "name": "Context of the organization - Determining the scope of the privacy information management system" + }, + { + "id": "4.4", + "name": "Context of the organization - Privacy information management system" + }, + { + "id": "5.1", + "name": "Leadership - Leadership and commitment" + }, + { + "id": "5.2", + "name": "Leadership - Privacy Policy" + }, + { + "id": "5.3", + "name": "Leadership - Roles, responsibilities and authorities" + }, + { + "id": "6.1.1", + "name": "Planning - General actions to address risks and opportunities" + }, + { + "id": "6.1.2", + "name": "Planning - Privacy risk assessment" + }, + { + "id": "6.1.3", + "name": "Planning - Privacy risk treatment" + }, + { + "id": "6.2", + "name": "Planning - Privacy objectives and planning to achieve them" + }, + { + "id": "6.3", + "name": "Planning - Planning of changes" + }, + { + "id": "7.1", + "name": "Support - Resources" + }, + { + "id": "7.2", + "name": "Support - Competence" + }, + { + "id": "7.3", + "name": "Support - Awareness" + }, + { + "id": "7.4", + "name": "Support - Communication" + }, + { + "id": "7.5.1", + "name": "Support - Documented information - General" + }, + { + "id": "7.5.2", + "name": "Support - Documented information - Creating and updating documented information" + }, + { + "id": "7.5.3", + "name": "Support - Documented information - Control of documented information" + }, + { + "id": "8.1", + "name": "Operation - Operational planning and control" + }, + { + "id": "8.2", + "name": "Operation - Privacy risk assessment" + }, + { + "id": "8.3", + "name": "Operation - Privacy risk treatment" + }, + { + "id": "9.1", + "name": "Performance evaluation - Monitoring, measurement, analysis and evaluation" + }, + { + "id": "9.2.1", + "name": "Performance evaluation - Internal audit - General" + }, + { + "id": "9.2.2", + "name": "Performance evaluation - Internal audit - Internal audit programme" + }, + { + "id": "9.3.1", + "name": "Performance evaluation - Management review - General" + }, + { + "id": "9.3.2", + "name": "Performance evaluation - Management review - Management review inputs" + }, + { + "id": "9.3.3", + "name": "Performance evaluation - Management review - Management review results" + }, + { + "id": "10.1", + "name": "Improvement - Continual improvement" + }, + { + "id": "10.2", + "name": "Improvement - Nonconformity and corrective action" + }, + { + "id": "A.1.2.2", + "name": "Conditions for collection and processing - Identify and document purpose" + }, + { + "id": "A.1.2.3", + "name": "Conditions for collection and processing - Identify lawful basis" + }, + { + "id": "A.1.2.4", + "name": "Conditions for collection and processing - Determine when and how consent is to be obtained" + }, + { + "id": "A.1.2.5", + "name": "Conditions for collection and processing - Obtain and record consent" + }, + { + "id": "A.1.2.6", + "name": "Conditions for collection and processing - Privacy impact assessment" + }, + { + "id": "A.1.2.7", + "name": "Conditions for collection and processing - Contracts with PII processors" + }, + { + "id": "A.1.2.8", + "name": "Conditions for collection and processing - Joint PII controller" + }, + { + "id": "A.1.2.9", + "name": "Conditions for collection and processing - Records related to processing PII" + }, + { + "id": "A.1.3.2", + "name": "Obligations to PII principals - Determining and fulfilling obligations to PII principals" + }, + { + "id": "A.1.3.3", + "name": "Obligations to PII principals - Determining information for PII principals" + }, + { + "id": "A.1.3.4", + "name": "Obligations to PII principals - Providing information to PII principals" + }, + { + "id": "A.1.3.5", + "name": "Obligations to PII principals - Providing mechanism to modify or withdraw consent" + }, + { + "id": "A.1.3.6", + "name": "Obligations to PII principals - Providing mechanism to object to PII processing" + }, + { + "id": "A.1.3.7", + "name": "Obligations to PII principals - Access, correction or erasure" + }, + { + "id": "A.1.3.8", + "name": "Obligations to PII principals - PII controllers' obligations to inform third parties" + }, + { + "id": "A.1.3.9", + "name": "Obligations to PII principals - Providing copy of PII processed" + }, + { + "id": "A.1.3.10", + "name": "Obligations to PII principals - Handling requests" + }, + { + "id": "A.1.3.11", + "name": "Obligations to PII principals - Automated decision making" + }, + { + "id": "A.1.4.2", + "name": "Privacy by design and privacy by default - Limit collection" + }, + { + "id": "A.1.4.3", + "name": "Privacy by design and privacy by default - Limit processing" + }, + { + "id": "A.1.4.4", + "name": "Privacy by design and privacy by default - Accuracy and quality" + }, + { + "id": "A.1.4.5", + "name": "Privacy by design and privacy by default - PII minimization objectives" + }, + { + "id": "A.1.4.6", + "name": "Privacy by design and privacy by default - PII de-identification and deletion at the end of processing" + }, + { + "id": "A.1.4.7", + "name": "Privacy by design and privacy by default - Temporary files" + }, + { + "id": "A.1.4.8", + "name": "Privacy by design and privacy by default - Retention" + }, + { + "id": "A.1.4.9", + "name": "Privacy by design and privacy by default - Disposal" + }, + { + "id": "A.1.4.10", + "name": "Privacy by design and privacy by default - PII transmission controls" + }, + { + "id": "A.1.5.2", + "name": "PII sharing, transfer and disclosure - Identify basis for PII transfer between jurisdictions" + }, + { + "id": "A.1.5.3", + "name": "PII sharing, transfer and disclosure - Countries and international organizations to which PII can be transferred" + }, + { + "id": "A.1.5.4", + "name": "PII sharing, transfer and disclosure - Records of transfer of PII" + }, + { + "id": "A.1.5.5", + "name": "PII sharing, transfer and disclosure - Records of PII disclosures to third parties" + }, + { + "id": "A.2.2.2", + "name": "Conditions for collection and processing - Customer agreement" + }, + { + "id": "A.2.2.3", + "name": "Conditions for collection and processing - Organization's purposes" + }, + { + "id": "A.2.2.4", + "name": "Conditions for collection and processing - Marketing and advertising use" + }, + { + "id": "A.2.2.5", + "name": "Conditions for collection and processing - Infringing instruction" + }, + { + "id": "A.2.2.6", + "name": "Conditions for collection and processing - Customer obligations" + }, + { + "id": "A.2.2.7", + "name": "Conditions for collection and processing - Records related to processing PII" + }, + { + "id": "A.2.3.2", + "name": "Obligations to PII principals - Comply with obligations to PII principals" + }, + { + "id": "A.2.4.2", + "name": "Privacy by design and privacy by default - Temporary files" + }, + { + "id": "A.2.4.3", + "name": "Privacy by design and privacy by default - Return, transfer or disposal of PII" + }, + { + "id": "A.2.4.4", + "name": "Privacy by design and privacy by default - PII transmission controls" + }, + { + "id": "A.2.5.2", + "name": "PII sharing, transfer and disclosure - Basis for PII transfer between jurisdictions" + }, + { + "id": "A.2.5.3", + "name": "PII sharing, transfer and disclosure - Countries and international organizations to which PII can be transferred" + }, + { + "id": "A.2.5.4", + "name": "PII sharing, transfer and disclosure - Records of PII disclosures to third parties" + }, + { + "id": "A.2.5.5", + "name": "PII sharing, transfer and disclosure - Notification of PII disclosure requests" + }, + { + "id": "A.2.5.6", + "name": "PII sharing, transfer and disclosure - Legally binding PII disclosures" + }, + { + "id": "A.2.5.7", + "name": "PII sharing, transfer and disclosure - Disclosure of subcontractors used to process PII" + }, + { + "id": "A.2.5.8", + "name": "PII sharing, transfer and disclosure - Engagement of a subcontractor to process PII" + }, + { + "id": "A.2.5.9", + "name": "PII sharing, transfer and disclosure - Change of subcontractor to process PII" + }, + { + "id": "A.3.3", + "name": "Information security - Policies for information security" + }, + { + "id": "A.3.4", + "name": "Information security - Information security roles and responsibilities" + }, + { + "id": "A.3.5", + "name": "Information security - Classification of information" + }, + { + "id": "A.3.6", + "name": "Information security - Labelling of information" + }, + { + "id": "A.3.7", + "name": "Information security - Information transfer" + }, + { + "id": "A.3.8", + "name": "Information security - Identity management" + }, + { + "id": "A.3.9", + "name": "Information security - Access rights" + }, + { + "id": "A.3.10", + "name": "Information security - Addressing information security within supplier agreements" + }, + { + "id": "A.3.11", + "name": "Information security - Information security incident management planning and preparation" + }, + { + "id": "A.3.12", + "name": "Information security - Response to information security incidents" + }, + { + "id": "A.3.13", + "name": "Information security - Legal, statutory, regulatory and contractual requirements" + }, + { + "id": "A.3.14", + "name": "Information security - Protection of records" + }, + { + "id": "A.3.15", + "name": "Information security - Independent review of information security" + }, + { + "id": "A.3.16", + "name": "Information security - Compliance with policies, rules and standards for information security" + }, + { + "id": "A.3.17", + "name": "Information security - Information security awareness, education and training" + }, + { + "id": "A.3.18", + "name": "Information security - Confidentiality or non-disclosure agreements" + }, + { + "id": "A.3.19", + "name": "Information security - Clear desk and clear screen" + }, + { + "id": "A.3.20", + "name": "Information security - Storage media" + }, + { + "id": "A.3.21", + "name": "Information security - Secure disposal or re-use of equipment" + }, + { + "id": "A.3.22", + "name": "Information security - User endpoint devices" + }, + { + "id": "A.3.23", + "name": "Information security - Secure authentication" + }, + { + "id": "A.3.24", + "name": "Information security - Information backup" + }, + { + "id": "A.3.25", + "name": "Information security - Logging" + }, + { + "id": "A.3.26", + "name": "Information security - Use of cryptography" + }, + { + "id": "A.3.27", + "name": "Information security - Secure development life cycle" + }, + { + "id": "A.3.28", + "name": "Information security - Application security requirements" + }, + { + "id": "A.3.29", + "name": "Information security - Secure system architecture and engineering principles" + }, + { + "id": "A.3.30", + "name": "Information security - Outsourced development" + }, + { + "id": "A.3.31", + "name": "Information security - Test information" + } + ]} + \ No newline at end of file diff --git a/apps/console/public/data/frameworks/ISO42001.json b/apps/console/public/data/frameworks/ISO42001.json new file mode 100644 index 000000000..a2524fb72 --- /dev/null +++ b/apps/console/public/data/frameworks/ISO42001.json @@ -0,0 +1,285 @@ +{ + "id": "ISO/IEC 27701:2025", + "name": "ISO 27701 (2025)", + "controls": [ + { + "id": "4.1", + "name": "Context of the organization - Understanding the organization and its context" + }, + { + "id": "4.2", + "name": "Context of the organization - Understanding the needs and expectations of interested parties" + }, + { + "id": "4.3", + "name": "Context of the organization - Determining the scope of the AI management system" + }, + { + "id": "4.4", + "name": "Context of the organization - AI management system" + }, + { + "id": "5.1", + "name": "Leadership - Leadership and commitment" + }, + { + "id": "5.2", + "name": "Leadership - AI policy" + }, + { + "id": "5.3", + "name": "Leadership - Roles, responsibilities and authorities" + }, + { + "id": "6.1.1", + "name": "Planning - Actions to address risks and opportunities - General" + }, + { + "id": "6.1.2", + "name": "Planning - Actions to address risks and opportunities - AI risk assessment" + }, + { + "id": "6.1.3", + "name": "Planning - Actions to address risks and opportunities - AI risk treatment" + }, + { + "id": "6.1.4", + "name": "Planning - Actions to address risks and opportunities - AI system impact assessment" + }, + { + "id": "6.2", + "name": "Planning - AI objectives and planning to achieve them" + }, + { + "id": "6.3", + "name": "Planning - Planning of changes" + }, + { + "id": "7.1", + "name": "Support - Resources" + }, + { + "id": "7.2", + "name": "Support - Competence" + }, + { + "id": "7.3", + "name": "Support - Awareness" + }, + { + "id": "7.4", + "name": "Support - Communication" + }, + { + "id": "7.5.1", + "name": "Support - Documented information - General" + }, + { + "id": "7.5.2", + "name": "Support - Documented information - Creating and updating documented information" + }, + { + "id": "7.5.3", + "name": "Support - Documented information - Control of documented information" + }, + { + "id": "8.1", + "name": "Operation - Operational planning and control" + }, + { + "id": "8.2", + "name": "Operation - AI risk assessment" + }, + { + "id": "8.3", + "name": "Operation - AI risk treatment" + }, + { + "id": "8.4", + "name": "Operation - AI system impact assessment" + }, + { + "id": "9.1", + "name": "Performance evaluation - Monitoring, measurement, analysis and evaluation" + }, + { + "id": "9.2.1", + "name": "Performance evaluation - Internal audit - General" + }, + { + "id": "9.2.2", + "name": "Performance evaluation - Internal audit - Internal audit programme" + }, + { + "id": "9.3.1", + "name": "Performance evaluation - Management review - General" + }, + { + "id": "9.3.2", + "name": "Performance evaluation - Management review - Management review inputs" + }, + { + "id": "9.3.3", + "name": "Performance evaluation - Management review - Management review results" + }, + { + "id": "10.1", + "name": "Improvement - Continual improvement" + }, + { + "id": "10.2", + "name": "Improvement - Nonconformity and corrective action" + }, + { + "id": "A.2.2", + "name": "Policies related to AI - AI policy" + }, + { + "id": "A.2.3", + "name": "Policies related to AI - Alignment with other organizational policies" + }, + { + "id": "A.2.4", + "name": "Policies related to AI - Review of the AI policy" + }, + { + "id": "A.3.2", + "name": "Internal organization - AI roles and responsibilities" + }, + { + "id": "A.3.3", + "name": "Internal organization - Reporting of concerns" + }, + { + "id": "A.4.2", + "name": "Resources for AI systems - Resource documentation" + }, + { + "id": "A.4.3", + "name": "Resources for AI systems - Data resources" + }, + { + "id": "A.4.4", + "name": "Resources for AI systems - Tooling resources" + }, + { + "id": "A.4.5", + "name": "Resources for AI systems - System and computing resources" + }, + { + "id": "A.4.6", + "name": "Resources for AI systems - Human resources" + }, + { + "id": "A.5.2", + "name": "Assessing impacts of AI systems - AI system impact assessment process" + }, + { + "id": "A.5.3", + "name": "Assessing impacts of AI systems - Documentation of AI system impact assessments" + }, + { + "id": "A.5.4", + "name": "Assessing impacts of AI systems - Assessing AI system impact on individuals or groups of individuals" + }, + { + "id": "A.5.5", + "name": "Assessing impacts of AI systems - Assessing societal impacts of AI systems" + }, + { + "id": "A.6.1.2", + "name": "AI system life cycle - Management guidance for AI system development - Objectives for responsible development of AI system" + }, + { + "id": "A.6.1.3", + "name": "AI system life cycle - Management guidance for AI system development - Processes for responsible AI system design and development" + }, + { + "id": "A.6.2.2", + "name": "AI system life cycle - AI system requirements and specification" + }, + { + "id": "A.6.2.3", + "name": "AI system life cycle - Documentation of AI system design and development" + }, + { + "id": "A.6.2.4", + "name": "AI system life cycle - AI system verification and validation" + }, + { + "id": "A.6.2.5", + "name": "AI system life cycle - AI system deployment" + }, + { + "id": "A.6.2.6", + "name": "AI system life cycle - AI system operation and monitoring" + }, + { + "id": "A.6.2.7", + "name": "AI system life cycle - AI system technical documentation" + }, + { + "id": "A.6.2.8", + "name": "AI system life cycle - AI system recording of event logs" + }, + { + "id": "A.7.2", + "name": "Data for AI systems - Data for development and enhancement of AI system" + }, + { + "id": "A.7.3", + "name": "Data for AI systems - Acquisition of data" + }, + { + "id": "A.7.4", + "name": "Data for AI systems - Quality of data for AI systems" + }, + { + "id": "A.7.5", + "name": "Data for AI systems - Data provenance" + }, + { + "id": "A.7.6", + "name": "Data for AI systems - Data preparation" + }, + { + "id": "A.8.2", + "name": "Information for interested parties of AI systems - System documentation and information for users" + }, + { + "id": "A.8.3", + "name": "Information for interested parties of AI systems - External reporting" + }, + { + "id": "A.8.4", + "name": "Information for interested parties of AI systems - Communication of incidents" + }, + { + "id": "A.8.5", + "name": "Information for interested parties of AI systems - Information for interested parties" + }, + { + "id": "A.9.2", + "name": "Use of AI systems - Processes for responsible use of AI systems" + }, + { + "id": "A.9.3", + "name": "Use of AI systems - Objectives for responsible use of AI system" + }, + { + "id": "A.9.4", + "name": "Use of AI systems - Intended use of the AI system" + }, + { + "id": "A.10.2", + "name": "Third-party and customer relationships - Allocating responsibilities" + }, + { + "id": "A.10.3", + "name": "Third-party and customer relationships - Suppliers" + }, + { + "id": "A.10.4", + "name": "Third-party and customer relationships - Customers" + } + ]} \ No newline at end of file