NMQ Protocol

ISO 27001 control map

Static mapping from GRC gap template IDs to ISO/IEC 27001:2022 Annex A codes (read-only).

Gap template IDISO 27001 Annex ANote
iso27001-accessA.5.15, A.5.16, A.5.18Access control, identity management, privileged access
iso27001-auditA.8.15, A.8.16Logging and monitoring of knowledge operations
internal-classificationA.5.12, A.5.13Classification of information and labelling
gdpr-ropaA.5.34Privacy and protection of PII (RoPA alignment)
gdpr-international-transfersA.5.34, A.8.24Transfer mechanisms and cryptography in transit
gdpr-breachA.5.24, A.5.26Incident management planning and assessment
ai-act-loggingA.8.15, A.8.16Automatic logging for high-risk AI use
dora-ict-riskA.5.1, A.8.1ICT risk management overlay for financial tenants

Read-only reference map. Update gap evidence in GRC gap workspace.