Spaces:
Sleeping
Sleeping
Create ISO_27001_LIGHTWEIGHT_CONTROLS.md
Browse files
ISO_27001_LIGHTWEIGHT_CONTROLS.md
ADDED
|
@@ -0,0 +1,68 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
# ISO/IEC 27001 β Lightweight Control Mapping
|
| 2 |
+
|
| 3 |
+
## Scope
|
| 4 |
+
|
| 5 |
+
This document maps **Federal FOIA Intelligence Search** to relevant ISO 27001 controls,
|
| 6 |
+
scaled appropriately for a public, read-only research tool.
|
| 7 |
+
|
| 8 |
+
---
|
| 9 |
+
|
| 10 |
+
## A.5 Information Security Policies
|
| 11 |
+
|
| 12 |
+
β Public security posture documented
|
| 13 |
+
β No confidential data handled
|
| 14 |
+
|
| 15 |
+
---
|
| 16 |
+
|
| 17 |
+
## A.6 Organization of Information Security
|
| 18 |
+
|
| 19 |
+
β Single maintainer accountability
|
| 20 |
+
β Clear governance boundaries
|
| 21 |
+
|
| 22 |
+
---
|
| 23 |
+
|
| 24 |
+
## A.8 Asset Management
|
| 25 |
+
|
| 26 |
+
| Asset | Classification |
|
| 27 |
+
|----|----|
|
| 28 |
+
| FOIA URLs | Public |
|
| 29 |
+
| Metadata | Public |
|
| 30 |
+
| User input | Ephemeral |
|
| 31 |
+
|
| 32 |
+
---
|
| 33 |
+
|
| 34 |
+
## A.9 Access Control
|
| 35 |
+
|
| 36 |
+
β No accounts
|
| 37 |
+
β No authentication
|
| 38 |
+
β No authorization layers
|
| 39 |
+
|
| 40 |
+
---
|
| 41 |
+
|
| 42 |
+
## A.12 Operations Security
|
| 43 |
+
|
| 44 |
+
β No background processing
|
| 45 |
+
β No scheduled jobs
|
| 46 |
+
β Stateless execution
|
| 47 |
+
|
| 48 |
+
---
|
| 49 |
+
|
| 50 |
+
## A.13 Communications Security
|
| 51 |
+
|
| 52 |
+
β HTTPS only
|
| 53 |
+
β No external data ingestion
|
| 54 |
+
|
| 55 |
+
---
|
| 56 |
+
|
| 57 |
+
## A.18 Compliance
|
| 58 |
+
|
| 59 |
+
β FOIA-compliant
|
| 60 |
+
β Copyright-safe (link-out only)
|
| 61 |
+
β Open-source transparency
|
| 62 |
+
|
| 63 |
+
---
|
| 64 |
+
|
| 65 |
+
## ISO Summary
|
| 66 |
+
|
| 67 |
+
This system qualifies as **low-complexity, low-risk** under ISO 27001,
|
| 68 |
+
with controls appropriate to scope.
|