Repository navigation
feat(compliance): migrate the ISO 27001 mapping pack to ISO/IEC 27001:2022 (#358) - #368
Merged
ritiksah141 merged 1 commit intoOct 3, 2026
Merged
Conversation
…:2022 (OWASP#358) The 2013 edition's transition period ended on 31 October 2025, so a report citing it references controls auditors no longer assess against. - remap all 144 rules in compliance/frameworks/iso27001.json to the 2022 Annex A using the published 2013-to-2022 correspondence; bump the pack to 2.0.0 and the framework to ISO/IEC 27001:2022 - use controls new in 2022 where they describe a rule better than its direct successor: A.8.16 Monitoring activities for alerting and detection coverage (AZ-IDN-009, AZ-IDN-023, AZ-BAK-006, AZ-SECOPS-008, AZ-SECOPS-009) and A.8.9 Configuration management for Azure Policy governance on AKS (AZ-AKS-005) - keep every entry pending_review and leave the four N/A storage non-mappings and the PQC not_applicable entries as they were - update each rule's own ISO27001 value to match the pack, and the descriptions that cited a 2013 control by number - add tests that pin the pack to 2022 Annex A, reject leftover 2013 numbering, and fail when a rule's ISO27001 value drifts from the pack - update docs, examples, the rules table and the compliance diagram Older scans keep their stored mapping snapshot, so they still report against the 2013 controls they were scored with. The 2013 pack is not kept as a legacy file, as decided in OWASP#358. Closes OWASP#358 Signed-off-by: parthrohit22 <parthrohit60@gmail.com>
parthrohit22
requested review from
SHAURYAKSHARMA24,
TFT444,
Vishnu2707 and
ritiksah141
as code owners
September 30, 2026 23:17
TFT444
approved these changes
Oct 3, 2026
ritiksah141
approved these changes
Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
Remaps the ISO 27001 mapping pack from ISO/IEC 27001:2013 to the 2022 Annex A. The 2013 transition period ended on 31 October 2025, so a report citing 2013 controls references a control set auditors no longer assess against.
Type of change
What changed
compliance/frameworks/iso27001.json: all 144 rules moved to 2022 controls. Framework is nowISO/IEC 27001:2022,version2022,published2022-10,mapping_pack_version2.0.0 (new edition, so a major bump).N/A-STOR-*non-mappings and the PQCnot_applicableentries keep their status. Every entry stayspending_review, so nothing starts counting towards a score.FRAMEWORKS["ISO27001"](131 files inscanner/rules/) now matches the pack. Findings show that value, so it has to agree with what is scored. Before this PR the two agreed for all 144 rules.docs/compliance-mapping-pack.md, the rules table, CONTRIBUTING/adding-a-rule/API examples, two blog posts and the compliance diagram.Historical reports
Scans saved with a full mapping snapshot keep reporting against the 2013 controls they were scored with, since
get_compliance_scorereads the snapshot and not the file. A scan saved before full snapshots existed falls back to the pack on disk, and itsmapping_provenancealready says so. The 2013 pack is not kept as alegacyfile, as decided in #358.docs/compliance-mapping-pack.mdpreviously said older packs should be kept, so I added a section explaining this exception.Testing
tests/test_iso27001_2022_pack.py(9 tests): every control ID is a real 2022 Annex A control or a declared non-mapping, no 2013 numbering or edition label survives, names are consistent per control, and each rule's own ISO value equals the pack. Checked that they fail against the old pack and against a drifted rule.validate_mapping_pack.pypassesruff checkandruff format --checkare clean.verify-siteneeds a CMS OAuth client ID from the CI environment, so I left that to CI.Not in this PR
compliance/assurance/physical_layer.jsonand the Physical Layer Assurance API use ISO 27001:2013 A.11 physical controls as their own catalogue. That is a separate feature and a follow-up.iso27001.json. fix(compliance): make framework reports evidence-based and non-certifying #310 has merged. feat: add enterprise governance and tenant controls #292 and Feat (ci-rules) : Add AZ-CI-001..004 CI/CD workflow security rules (issue #259 PR 1/3) #280 are still open, so whichever lands second needs a rebase. New rules must now use 2022 control IDs, and the new test fails if a rule's ISO value drifts from the pack.Related issue
Closes #358
Checklist
Signed-off-bytrailer