Skip to content

compliance

Applicability Map

15 questions. Annex A heatmap. Hashed SoA JSON. Aligning, not certified.

Answers map onto ISO/IEC 27001:2022 Annex A (93). Maturity 1–5 analogue.

Renamed from “Open SoA playground / compliance daemon”. Form + live catalog.

Open console board

ISO/IEC 27001:2022 Annex A — 93 controls. Aligning, not certified. Physical defaults N/A for SaaS unless you say you run cages.

  1. 1. MFA or WebAuthn on the operator door?

    A.5.17 · A.8.5

  2. 2. Role-based access and tenant isolation (RLS / origin boxes)?

    A.5.15 · A.5.18 · A.8.2 · A.8.3

  3. 3. Hash-chained or append-only audit of privileged actions?

    A.5.28 · A.5.33 · A.8.15

  4. 4. Encryption in transit; secrets not in the client bundle?

    A.8.24 · A.5.14

  5. 5. Tenant backup export/import you have actually run?

    A.8.13 · A.5.29 · A.5.30

  6. 6. Named incident owner and a 24h-class response path?

    A.5.24 · A.5.26 · A.6.8

  7. 7. Subprocessor / vendor inventory with a DPA where needed?

    A.5.19 · A.5.20 · A.5.21

  8. 8. PII minimisation and redaction on this origin?

    A.5.34 · A.8.10 · A.8.11 · A.8.12

  9. 9. Change / upgrade dual-control on production?

    A.8.9 · A.8.32 · A.5.8

  10. 10. Vulnerability intake (STRIDE or equivalent) on new surfaces?

    A.8.8 · A.5.7

  11. 11. Do you operate your own physical datacenter cages?

    A.7.1 · A.7.2 · A.7.4

  12. 12. Operator security awareness for anyone with console access?

    A.6.3 · A.6.1

  13. 13. Continuity: the old stack stays live through cutover (MSP pattern)?

    A.5.30 · A.5.29

  14. 14. Access reviews at least quarterly analogue?

    A.5.18 · A.8.2

  15. 15. Observability / logging that cannot be silently dropped?

    A.8.15 · A.8.16 · A.5.25

Maturity

2 / 5

Coverage

21%

Implemented

0/79

SHA-256

efb7ac5f7718

Organizational

0/37 of 37

People

0/8 of 8

Physical

0/0 of 14

Technological

0/34 of 34

All tools·Start console