You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Make vsms technically ready to operate inside a VAAM ISO/IEC 27001:2022-certified ISMS by producing enforceable product controls and repeatable audit evidence.
ISO/IEC 27001 certification applies to the organisation's scoped ISMS, not to this repository alone. This epic therefore covers vsms engineering controls/evidence only and feeds the organisation's risk assessment, risk-treatment plan and Statement of Applicability (SoA).
The control set must ultimately be selected through the organisation's risk process; Annex A is a reference set, not a checklist that this repo can declare applicable by itself.
every claimed control has a repeatable evidence source (test, CI result, configuration, log, runbook or drill);
the repository never claims that completing this epic equals ISO/IEC 27001 certification.
Out of scope / required organisation-wide ISMS work
Separate VAAM-level work is still required for certification, including: ISMS scope/context and interested parties; information-security policy and objectives; risk methodology/register and treatment plan; Statement of Applicability; organisation-wide asset and supplier registers; HR/onboarding/offboarding controls; access-review governance; legal/contractual requirements; security awareness; incident-management governance; business impact analysis/continuity objectives; internal audit; management review; nonconformity/corrective-action process; certification-body Stage 1/Stage 2 audits and ongoing surveillance.
Goal
Make vsms technically ready to operate inside a VAAM ISO/IEC 27001:2022-certified ISMS by producing enforceable product controls and repeatable audit evidence.
ISO/IEC 27001 certification applies to the organisation's scoped ISMS, not to this repository alone. This epic therefore covers vsms engineering controls/evidence only and feeds the organisation's risk assessment, risk-treatment plan and Statement of Applicability (SoA).
The control set must ultimately be selected through the organisation's risk process; Annex A is a reference set, not a checklist that this repo can declare applicable by itself.
Stories
Recommended order:
Definition of done
This epic is complete when:
Out of scope / required organisation-wide ISMS work
Separate VAAM-level work is still required for certification, including: ISMS scope/context and interested parties; information-security policy and objectives; risk methodology/register and treatment plan; Statement of Applicability; organisation-wide asset and supplier registers; HR/onboarding/offboarding controls; access-review governance; legal/contractual requirements; security awareness; incident-management governance; business impact analysis/continuity objectives; internal audit; management review; nonconformity/corrective-action process; certification-body Stage 1/Stage 2 audits and ongoing surveillance.