FOIA_Doc_Search / ISO_27001_LIGHTWEIGHT_CONTROLS.md
GodsDevProject's picture
Create ISO_27001_LIGHTWEIGHT_CONTROLS.md
d034d84 verified

A newer version of the Gradio SDK is available: 6.13.0

Upgrade

ISO/IEC 27001 – Lightweight Control Mapping

Scope

This document maps Federal FOIA Intelligence Search to relevant ISO 27001 controls, scaled appropriately for a public, read-only research tool.


A.5 Information Security Policies

βœ” Public security posture documented
βœ” No confidential data handled


A.6 Organization of Information Security

βœ” Single maintainer accountability
βœ” Clear governance boundaries


A.8 Asset Management

Asset Classification
FOIA URLs Public
Metadata Public
User input Ephemeral

A.9 Access Control

βœ” No accounts
βœ” No authentication
βœ” No authorization layers


A.12 Operations Security

βœ” No background processing
βœ” No scheduled jobs
βœ” Stateless execution


A.13 Communications Security

βœ” HTTPS only
βœ” No external data ingestion


A.18 Compliance

βœ” FOIA-compliant
βœ” Copyright-safe (link-out only)
βœ” Open-source transparency


ISO Summary

This system qualifies as low-complexity, low-risk under ISO 27001, with controls appropriate to scope.