Skip to content

Commit d97054c

Browse files
committed
ISO 27001:2022 Mapping for Implementation
1 parent 1166f78 commit d97054c

3 files changed

Lines changed: 76 additions & 46 deletions

File tree

src/assets/YAML/default/Implementation/ApplicationHardening.yaml

Lines changed: 12 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -23,10 +23,11 @@ Implementation:
2323
samm2:
2424
- D-SR-2-A
2525
iso27001-2017:
26-
- hardening is not explicitly covered by ISO 27001 - too specific
26+
- Hardening is not explicitly covered by ISO 27001 - too specific
2727
- 13.1.3
2828
iso27001-2022:
29-
- ISO 27001:2022 mapping is missing
29+
- Hardening is not explicitly covered by ISO 27001 - too specific
30+
- 8.22
3031
isImplemented: false
3132
evidence: ""
3233
comments: ""
@@ -53,10 +54,11 @@ Implementation:
5354
samm2:
5455
- D-SR-3-A
5556
iso27001-2017:
56-
- hardening is not explicitly covered by ISO 27001 - too specific
57+
- Hardening is not explicitly covered by ISO 27001 - too specific
5758
- 13.1.3
5859
iso27001-2022:
59-
- ISO 27001:2022 mapping is missing
60+
- Hardening is not explicitly covered by ISO 27001 - too specific
61+
- 8.22
6062
isImplemented: false
6163
evidence: ""
6264
comments: ""
@@ -102,10 +104,11 @@ Implementation:
102104
samm2:
103105
- D-SR-1-A
104106
iso27001-2017:
105-
- hardening is not explicitly covered by ISO 27001 - too specific
107+
- Hardening is not explicitly covered by ISO 27001 - too specific
106108
- 13.1.3
107109
iso27001-2022:
108-
- ISO 27001:2022 mapping is missing
110+
- Hardening is not explicitly covered by ISO 27001 - too specific
111+
- 8.22
109112
isImplemented: false
110113
evidence: ""
111114
comments: ""
@@ -132,10 +135,11 @@ Implementation:
132135
samm2:
133136
- D-SR-3-A
134137
iso27001-2017:
135-
- hardening is not explicitly covered by ISO 27001 - too specific
138+
- Hardening is not explicitly covered by ISO 27001 - too specific
136139
- 13.1.3
137140
iso27001-2022:
138-
- ISO 27001:2022 mapping is missing
141+
- Hardening is not explicitly covered by ISO 27001 - too specific
142+
- 8.22
139143
isImplemented: false
140144
evidence: ""
141145
comments: ""

src/assets/YAML/default/Implementation/DevelopmentAndSourceControl.yaml

Lines changed: 15 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -68,11 +68,12 @@ Implementation:
6868
samm2:
6969
- V-ST-1-A
7070
iso27001-2017:
71+
- 14.2.1
72+
- 14.2.5
73+
iso27001-2022:
7174
- 8.25 # Secure development lifecycle
7275
- 8.27 # Secure system architecture and engineering principles
7376
- 8.28 # Secure coding
74-
iso27001-2022:
75-
- ISO 27001:2022 mapping is missing
7677
isImplemented: false
7778
evidence: ""
7879
comments: ""
@@ -98,11 +99,13 @@ Implementation:
9899
samm2:
99100
- O-EM-1-A
100101
iso27001-2017:
101-
- peer review - four eyes principle is not explicitly required by ISO 27001
102+
- Peer review - four eyes principle is not explicitly required by ISO 27001
102103
- 6.1.2
103104
- 14.2.1
104105
iso27001-2022:
105-
- ISO 27001:2022 mapping is missing
106+
- Peer review - four eyes principle is not explicitly required by ISO 27001
107+
- 5.3
108+
- 8.25
106109
isImplemented: false
107110
evidence: ""
108111
comments: ""
@@ -124,12 +127,14 @@ Implementation:
124127
samm2:
125128
- O-EM-1-A
126129
iso27001-2017:
127-
- not explicitly covered by ISO 27001 - too specific
130+
- Not explicitly covered by ISO 27001 - too specific
128131
- 12.1.1
129132
- 12.1.2
130133
- 14.2.2
131134
iso27001-2022:
132-
- ISO 27001:2022 mapping is missing
135+
- Not explicitly covered by ISO 27001 - too specific
136+
- 5.37
137+
- 8.32
133138
isImplemented: false
134139
evidence: ""
135140
comments: ""
@@ -153,11 +158,13 @@ Implementation:
153158
samm2:
154159
- O-EM-1-A
155160
iso27001-2017:
156-
- 5.17 # Authentication information
161+
- 9.2.4
157162
- 6.1.2 # Segregation of duties.
158163
- 14.2.1 # Secure development policies.
159164
iso27001-2022:
160-
- ISO 27001:2022 mapping is missing
165+
- 5.17 # Authentication information
166+
- 5.3
167+
- 8.25
161168
d3f:
162169
- Multi-factorAuthentication
163170
isImplemented: false

src/assets/YAML/default/Implementation/InfrastructureHardening.yaml

Lines changed: 49 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -21,12 +21,15 @@ Implementation:
2121
samm2:
2222
- TODO
2323
iso27001-2017:
24-
- not explicitly covered by ISO 27001 - too specific
24+
- Not explicitly covered by ISO 27001 - too specific
2525
- 9.1.1
2626
- 9.4.2
2727
- 14.2.5
2828
iso27001-2022:
29-
- ISO 27001:2022 mapping is missing
29+
- Not explicitly covered by ISO 27001 - too specific
30+
- 5.15
31+
- 8.5
32+
- 8.27
3033
isImplemented: false
3134
evidence: ""
3235
comments: ""
@@ -45,10 +48,11 @@ Implementation:
4548
samm2:
4649
- O-EM-1-A
4750
iso27001-2017:
48-
- virtual environments are not explicitly covered by ISO 27001 - too specific
51+
- Virtual environments are not explicitly covered by ISO 27001 - too specific
4952
- 13.1.3
5053
iso27001-2022:
51-
- ISO 27001:2022 mapping is missing
54+
- Virtual environments are not explicitly covered by ISO 27001 - too specific
55+
- 8.22
5256
isImplemented: false
5357
evidence: ""
5458
comments: ""
@@ -72,10 +76,11 @@ Implementation:
7276
samm2:
7377
- TODO
7478
iso27001-2017:
75-
- "12.3"
79+
- 12.3
7680
- 14.2.6
7781
iso27001-2022:
78-
- ISO 27001:2022 mapping is missing
82+
- 8.13
83+
- 8.31
7984
isImplemented: false
8085
evidence: ""
8186
comments: ""
@@ -94,11 +99,13 @@ Implementation:
9499
samm2:
95100
- O-EM-1-A
96101
iso27001-2017:
97-
- not explicitly covered by ISO 27001 - too specific
102+
- Not explicitly covered by ISO 27001 - too specific
98103
- 14.2.1
99104
- 14.2.5
100105
iso27001-2022:
101-
- ISO 27001:2022 mapping is missing
106+
- Not explicitly covered by ISO 27001 - too specific
107+
- 8.25
108+
- 8.27
102109
isImplemented: false
103110
evidence: ""
104111
comments: ""
@@ -120,10 +127,11 @@ Implementation:
120127
samm2:
121128
- O-EM-1-A
122129
iso27001-2017:
123-
- virtual environments are not explicitly covered by ISO 27001 - too specific
130+
- Virtual environments are not explicitly covered by ISO 27001 - too specific
124131
- 13.1.3
125132
iso27001-2022:
126-
- ISO 27001:2022 mapping is missing
133+
- Virtual environments are not explicitly covered by ISO 27001 - too specific
134+
- 8.22
127135
isImplemented: false
128136
evidence: ""
129137
comments: ""
@@ -144,10 +152,11 @@ Implementation:
144152
samm2:
145153
- O-EM-1-A
146154
iso27001-2017:
147-
- not explicitly covered by ISO 27001 - too specific
155+
- Not explicitly covered by ISO 27001 - too specific
148156
- 17.2.1
149157
iso27001-2022:
150-
- ISO 27001:2022 mapping is missing
158+
- Not explicitly covered by ISO 27001 - too specific
159+
- 8.14
151160
isImplemented: false
152161
evidence: ""
153162
comments: ""
@@ -173,11 +182,13 @@ Implementation:
173182
samm2:
174183
- O-EM-1-A
175184
iso27001-2017:
176-
- not explicitly covered by ISO 27001 - too specific
185+
- Not explicitly covered by ISO 27001 - too specific
177186
- 12.1.1
178187
- 12.1.2
179188
iso27001-2022:
180-
- ISO 27001:2022 mapping is missing
189+
- Not explicitly covered by ISO 27001 - too specific
190+
- 5.37
191+
- 8.32
181192
isImplemented: false
182193
evidence: ""
183194
comments: ""
@@ -203,10 +214,11 @@ Implementation:
203214
samm2:
204215
- O-EM-1-A
205216
iso27001-2017:
206-
- virtual environments are not explicitly covered by ISO 27001 - too specific
217+
- Virtual environments are not explicitly covered by ISO 27001 - too specific
207218
- 13.1.3
208219
iso27001-2022:
209-
- ISO 27001:2022 mapping is missing
220+
- Virtual environments are not explicitly covered by ISO 27001 - too specific
221+
- 8.22
210222
isImplemented: false
211223
evidence: ""
212224
comments: ""
@@ -230,7 +242,7 @@ Implementation:
230242
samm2:
231243
- O-EM-1-A
232244
iso27001-2017:
233-
- system hardening is not explicitly covered by ISO 27001 - too specific
245+
- System hardening is not explicitly covered by ISO 27001 - too specific
234246
iso27001-2022:
235247
- ISO 27001:2022 mapping is missing
236248
isImplemented: false
@@ -251,7 +263,7 @@ Implementation:
251263
samm2:
252264
- O-EM-1-A
253265
iso27001-2017:
254-
- not explicitly covered by ISO 27001
266+
- Not explicitly covered by ISO 27001
255267
iso27001-2022:
256268
- ISO 27001:2022 mapping is missing
257269
isImplemented: false
@@ -282,7 +294,8 @@ Implementation:
282294
- 12.1.4
283295
- 17.2.1
284296
iso27001-2022:
285-
- ISO 27001:2022 mapping is missing
297+
- 8.31
298+
- 8.14
286299
isImplemented: false
287300
evidence: ""
288301
comments: ""
@@ -309,7 +322,7 @@ Implementation:
309322
iso27001-2017:
310323
- 9.4.1
311324
iso27001-2022:
312-
- ISO 27001:2022 mapping is missing
325+
- 8.3
313326
isImplemented: false
314327
evidence: ""
315328
comments: ""
@@ -333,7 +346,7 @@ Implementation:
333346
iso27001-2017:
334347
- 9.4.1
335348
iso27001-2022:
336-
- ISO 27001:2022 mapping is missing
349+
- 8.3
337350
isImplemented: false
338351
evidence: ""
339352
comments: ""
@@ -385,10 +398,11 @@ Implementation:
385398
samm2:
386399
- O-EM-1-A
387400
iso27001-2017:
388-
- not explicitly covered by ISO 27001 - too specific
401+
- Not explicitly covered by ISO 27001 - too specific
389402
- 17.1.3
390403
iso27001-2022:
391-
- ISO 27001:2022 mapping is missing
404+
- Not explicitly covered by ISO 27001 - too specific
405+
- 5.29
392406
isImplemented: false
393407
evidence: ""
394408
comments: ""
@@ -432,7 +446,7 @@ Implementation:
432446
iso27001-2017:
433447
- 10.1
434448
iso27001-2022:
435-
- ISO 27001:2022 mapping is missing
449+
- 8.24
436450
isImplemented: false
437451
evidence: ""
438452
comments: ""
@@ -454,7 +468,7 @@ Implementation:
454468
iso27001-2017:
455469
- 10.1
456470
iso27001-2022:
457-
- ISO 27001:2022 mapping is missing
471+
- 8.24
458472
isImplemented: false
459473
evidence: ""
460474
comments: ""
@@ -477,7 +491,7 @@ Implementation:
477491
iso27001-2017:
478492
- 10.1
479493
iso27001-2022:
480-
- ISO 27001:2022 mapping is missing
494+
- 8.24
481495
isImplemented: false
482496
evidence: ""
483497
comments: ""
@@ -526,11 +540,13 @@ Implementation:
526540
samm2:
527541
- O-EM-1-A
528542
iso27001-2017:
529-
- not explicitly covered by ISO 27001 - too specific
543+
- Not explicitly covered by ISO 27001 - too specific
530544
- 12.1.4
531545
- 17.2.1
532546
iso27001-2022:
533-
- ISO 27001:2022 mapping is missing
547+
- Not explicitly covered by ISO 27001 - too specific
548+
- 8.31
549+
- 8.14
534550
isImplemented: false
535551
evidence: ""
536552
comments: ""
@@ -552,12 +568,15 @@ Implementation:
552568
samm2:
553569
- O-EM-1-A
554570
iso27001-2017:
555-
- virtual environments are not explicitly covered by ISO 27001 - too specific
571+
- Virtual environments are not explicitly covered by ISO 27001 - too specific
556572
- 12.1.3
557573
- 13.1.3
558574
- 17.2.1
559575
iso27001-2022:
560-
- ISO 27001:2022 mapping is missing
576+
- Virtual environments are not explicitly covered by ISO 27001 - too specific
577+
- 8.6
578+
- 8.22
579+
- 8.14
561580
isImplemented: false
562581
evidence: ""
563582
comments: ""

0 commit comments

Comments
 (0)