compliance
Applicability Map
15 questions. Annex A heatmap. Hashed SoA JSON. Aligning, not certified.
Answers map onto ISO/IEC 27001:2022 Annex A (93). Maturity 1–5 analogue.
Renamed from “Open SoA playground / compliance daemon”. Form + live catalog.
ISO/IEC 27001:2022 Annex A — 93 controls. Aligning, not certified. Physical defaults N/A for SaaS unless you say you run cages.
1. MFA or WebAuthn on the operator door?
A.5.17 · A.8.5
2. Role-based access and tenant isolation (RLS / origin boxes)?
A.5.15 · A.5.18 · A.8.2 · A.8.3
3. Hash-chained or append-only audit of privileged actions?
A.5.28 · A.5.33 · A.8.15
4. Encryption in transit; secrets not in the client bundle?
A.8.24 · A.5.14
5. Tenant backup export/import you have actually run?
A.8.13 · A.5.29 · A.5.30
6. Named incident owner and a 24h-class response path?
A.5.24 · A.5.26 · A.6.8
7. Subprocessor / vendor inventory with a DPA where needed?
A.5.19 · A.5.20 · A.5.21
8. PII minimisation and redaction on this origin?
A.5.34 · A.8.10 · A.8.11 · A.8.12
9. Change / upgrade dual-control on production?
A.8.9 · A.8.32 · A.5.8
10. Vulnerability intake (STRIDE or equivalent) on new surfaces?
A.8.8 · A.5.7
11. Do you operate your own physical datacenter cages?
A.7.1 · A.7.2 · A.7.4
12. Operator security awareness for anyone with console access?
A.6.3 · A.6.1
13. Continuity: the old stack stays live through cutover (MSP pattern)?
A.5.30 · A.5.29
14. Access reviews at least quarterly analogue?
A.5.18 · A.8.2
15. Observability / logging that cannot be silently dropped?
A.8.15 · A.8.16 · A.5.25
Maturity
2 / 5
Coverage
21%
Implemented
0/79
SHA-256
efb7ac5f7718
Organizational
0/37 of 37
People
0/8 of 8
Physical
0/0 of 14
Technological
0/34 of 34
