Skip to content

EPIC: ISO/IEC 27001 engineering readiness for vsms #383

Description

@stephane-segning

Goal

Make vsms technically ready to operate inside a VAAM ISO/IEC 27001:2022-certified ISMS by producing enforceable product controls and repeatable audit evidence.

ISO/IEC 27001 certification applies to the organisation's scoped ISMS, not to this repository alone. This epic therefore covers vsms engineering controls/evidence only and feeds the organisation's risk assessment, risk-treatment plan and Statement of Applicability (SoA).

The control set must ultimately be selected through the organisation's risk process; Annex A is a reference set, not a checklist that this repo can declare applicable by itself.

Stories

Recommended order:

Definition of done

This epic is complete when:

Out of scope / required organisation-wide ISMS work

Separate VAAM-level work is still required for certification, including: ISMS scope/context and interested parties; information-security policy and objectives; risk methodology/register and treatment plan; Statement of Applicability; organisation-wide asset and supplier registers; HR/onboarding/offboarding controls; access-review governance; legal/contractual requirements; security awareness; incident-management governance; business impact analysis/continuity objectives; internal audit; management review; nonconformity/corrective-action process; certification-body Stage 1/Stage 2 audits and ongoing surveillance.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions