Skip to content

docs: add ISO cloud services evidence gates#1336

Open
catcherintheroad-hub wants to merge 1 commit into
UnitOneAI:mainfrom
catcherintheroad-hub:improve/iso27001-cloud-services-evidence
Open

docs: add ISO cloud services evidence gates#1336
catcherintheroad-hub wants to merge 1 commit into
UnitOneAI:mainfrom
catcherintheroad-hub:improve/iso27001-cloud-services-evidence

Conversation

@catcherintheroad-hub

Copy link
Copy Markdown

Summary

Adds an ISO 27001 A.5.23 cloud services evidence gate to iso27001-gap so cloud services cannot be marked conforming from supplier names or provider certificates alone.

Changes

  • Added ISO-CLOUD-01 through ISO-CLOUD-08 for cloud service inventory, shared responsibility, supplier assurance, configuration evidence, data lifecycle, exit readiness, change notifications, and customer-managed controls.
  • Added evidence requirements for service registers, shared responsibility matrices, supplier assurance packs, cloud baselines, data lifecycle proof, and exit/continuity plans.
  • Added false-positive guards for provider attestations, SaaS carve-outs, services without IaC, multi-region deployments, and unjustified scope exclusions.
  • Added SoA traceability fields for cloud services.
  • Added a common pitfall about treating provider attestations as complete A.5.23 evidence.
  • Added ISO 27017 and CSA CCM references.
  • Added edge-case fixtures for provider certificates without customer controls, carve-out subservice organizations, and untested critical cloud exit plans.

Validation

  • git diff --check
  • Added-line non-ASCII scan
  • Added-line prompt-injection marker scan
  • CSA Cloud Controls Matrix reference URL returned HTTP 200

Related issue

Created from review issue: #1335

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e8596fffd2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

handling, data portability, and exit.

```
ISO-CLOUD-01: Cloud service inventory lacks owner, data classification, region, or business purpose

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Avoid presenting synthetic IDs as ISO findings

When this gate is followed, the skill now points the reviewer to ISO-CLOUD-* identifiers even though the same skill’s constraints require only real ISO 27001 clauses/Annex A control IDs and prohibit fabricated IDs. Because these labels are introduced without clarifying that they are internal checklist codes, reports driven by the new edge cases can emit non-auditable ISO-looking identifiers instead of tracing the finding back to A.5.23 and related Annex A controls; please either label these as internal checks or make the expected finding identifier the real ISO control mapping.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant