ISO/IEC 27001:2022 — Information Security Management Annex A + Clauses 4-10

ISO/IEC 27001:2022 — Information Security Management Annex A + Clauses 4-10 — 79% of in-scope requirements covered.

118 requirements · 118 in scope (83 enforced · 6 designed · 29 advisory). The 79% is weighted over the in-scope base.

Source: ISO/IEC 27001:2022 Annex A (93 controls, 4 themes): mirrors ISO/IEC 27002:2022 control catalogue. Main-body clauses 4-10 (Context, Leadership, Planning, Support, Operation, Performance evaluation, Improvement) added 2026-05-29 (Wave-Ralph-B) for a regulator-grade ISMS-level deep-mapping. · License: ISO — control text is copyrighted; KYE™ registry paraphrases each control's intent and cites the official identifier for mapping purposes only.

By category

CategoryReqsEnforcedDesignedAdvisoryDeferredCoverage
A.5 Organisational controls373214091%
A.6 People controls8314056%
A.7 Physical controls142012036%
A.8 Technological controls342635085%
Clause 4 Context of the organisation4202063%
Clause 5 Leadership33000100%
Clause 6 Planning5401085%
Clause 7 Support5401085%
Clause 8 Operation33000100%
Clause 9 Performance evaluation3210083%
Clause 10 Improvement22000100%

Every requirement → the KYE™ artefact that enforces it

IDTitleStatusKYE™ enforcement
iso-27001.A.5.1Policies for information securityenforcedaudit_events: kye.signal.tool.compiled.v1
engines: internal
workers: kye-rules-gateway-worker
constitution_refs: constitution/00-INDEX.md
iso-27001.A.5.2Information security roles and responsibilitiesenforcedaudit_events: kye.authority.grant.v1, kye.evidence.decision_map.v1, kye.purpose.permission.v1
engines: internal, internal
workers: kye-pdp
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
iso-27001.A.5.3Segregation of dutiesenforcedaudit_events: kye.authority.grant.v1, kye.evidence.decision_map.v1, kye.purpose.permission.v1
engines: internal, internal
workers: kye-pdp
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
iso-27001.A.5.4Management responsibilitiesenforcedaudit_events: kye.governedui.approval.v1, kye.evidence.pack.v1
engines: internal, internal
constitution_refs: constitution/36-GOVERNEDUI.md
iso-27001.A.5.5Contact with authoritiesadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.5.6Contact with special interest groupsadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.5.7Threat intelligenceenforcedaudit_events: kye.signal.drift.detected.v1, kye.signal.stable_drift.detected.v1
engines: internal
workers: kye-drift-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
iso-27001.A.5.8Information security in project managementenforcedaudit_events: kye.governedui.approval.v1, kye.evidence.pack.v1
engines: internal, internal
constitution_refs: constitution/36-GOVERNEDUI.md
iso-27001.A.5.9Inventory of information and other associated assetsenforcedaudit_events: kye.risk.authority_register.v1, kye.evidence.decision_map.v1
engines: internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
iso-27001.A.5.10Acceptable use of information and other associated assetsenforcedaudit_events: kye.purpose.permission.v1, kye.evidence.decision_map.v1
engines: internal
workers: kye-pdp
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
iso-27001.A.5.11Return of assetsenforcedaudit_events: kye.revocation.event.v1, kye.signal.revocation.cascaded.v1
engines: internal
workers: kye-authority-revocation-orchestrator
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
iso-27001.A.5.12Classification of informationenforcedaudit_events: kye.evidence.decision_map.v1, kye.federation.cross_org_delegation.v1
engines: internal, internal
constitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md
iso-27001.A.5.13Labelling of informationenforcedaudit_events: kye.evidence.decision_map.v1, kye.federation.cross_org_delegation.v1
engines: internal, internal
constitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md
iso-27001.A.5.14Information transferenforcedaudit_events: kye.evidence.decision_map.v1, kye.federation.cross_org_delegation.v1
engines: internal, internal
constitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md
iso-27001.A.5.15Access controlenforcedaudit_events: kye.authority.grant.v1, kye.evidence.decision_map.v1, kye.purpose.permission.v1
engines: internal, internal
workers: kye-pdp
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
iso-27001.A.5.16Identity managementenforcedaudit_events: kye.authority.grant.v1, kye.evidence.decision_map.v1, kye.purpose.permission.v1
engines: internal, internal
workers: kye-pdp
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
iso-27001.A.5.17Authentication informationenforcedaudit_events: kye.signing.multisig_envelope.v1
engines: internal, internal, internal
constitution_refs: constitution/51-NO-SPOF.md
iso-27001.A.5.18Access rightsenforcedaudit_events: kye.authority.grant.v1, kye.evidence.decision_map.v1, kye.purpose.permission.v1
engines: internal, internal
workers: kye-pdp
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
iso-27001.A.5.19Information security in supplier relationshipsenforcedaudit_events: kye.federation.cross_org_delegation.v1
engines: internal
constitution_refs: constitution/51-NO-SPOF.md
iso-27001.A.5.20Addressing information security within supplier agreementsenforcedaudit_events: kye.federation.cross_org_delegation.v1
engines: internal
constitution_refs: constitution/51-NO-SPOF.md
iso-27001.A.5.21Managing information security in the ICT supply chainadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.5.22Monitoring, review and change management of supplier servicesenforcedaudit_events: kye.federation.cross_org_delegation.v1
engines: internal
constitution_refs: constitution/51-NO-SPOF.md
iso-27001.A.5.23Information security for use of cloud servicesenforcedaudit_events: kye.evidence.decision_map.v1, kye.federation.cross_org_delegation.v1
engines: internal, internal
constitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md
iso-27001.A.5.24Information security incident management planning and preparationenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
iso-27001.A.5.25Assessment and decision on information security eventsenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
iso-27001.A.5.26Response to information security incidentsenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
iso-27001.A.5.27Learning from information security incidentsenforced 1 unverified citationaudit_events: kye.audit.event.appended.v1 unverified citation, kye.evidence.pack.v1, kye.compliance.attestation.v1
engines: internal, internal
workers: kye-audit-archiver
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
iso-27001.A.5.28Collection of evidenceenforced 1 unverified citationaudit_events: kye.audit.event.appended.v1 unverified citation, kye.evidence.pack.v1, kye.compliance.attestation.v1
engines: internal, internal
workers: kye-audit-archiver
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
iso-27001.A.5.29Information security during disruptionenforcedaudit_events: kye.spof.path_to_full.v1
constitution_refs: constitution/51-NO-SPOF.md
engines: internal, internal
workers: kye-gateway
iso-27001.A.5.30ICT readiness for business continuitydesignedaudit_events: kye.spof.path_to_full.v1
constitution_refs: constitution/51-NO-SPOF.md
iso-27001.A.5.31Legal, statutory, regulatory and contractual requirementsenforcedaudit_events: kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/00-INDEX.md
iso-27001.A.5.32Intellectual property rightsadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.5.33Protection of recordsenforced 1 unverified citationaudit_events: kye.audit.event.appended.v1 unverified citation, kye.evidence.pack.v1, kye.compliance.attestation.v1
engines: internal, internal
workers: kye-audit-archiver
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
iso-27001.A.5.34Privacy and protection of PIIenforcedaudit_events: kye.evidence.decision_map.v1, kye.federation.cross_org_delegation.v1
engines: internal, internal
constitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md
iso-27001.A.5.35Independent review of information securityenforced 1 unverified citationaudit_events: kye.audit.event.appended.v1 unverified citation, kye.evidence.pack.v1, kye.compliance.attestation.v1
engines: internal, internal
workers: kye-audit-archiver
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
iso-27001.A.5.36Compliance with policies, rules and standards for information securityenforcedaudit_events: kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/00-INDEX.md
iso-27001.A.5.37Documented operating proceduresenforcedaudit_events: kye.risk.authority_register.v1, kye.evidence.decision_map.v1
engines: internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
iso-27001.A.6.1Screeningadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.6.2Terms and conditions of employmentadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.6.3Information security awareness, education and trainingdesignedaudit_events: kye.training.completion.v1
constitution_refs: constitution/10-PARTNER.md
iso-27001.A.6.4Disciplinary processadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.6.5Responsibilities after termination or change of employmentenforcedaudit_events: kye.revocation.event.v1, kye.signal.revocation.cascaded.v1
engines: internal
workers: kye-authority-revocation-orchestrator
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
iso-27001.A.6.6Confidentiality or non-disclosure agreementsadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.6.7Remote workingenforcedaudit_events: kye.authority.grant.v1, kye.evidence.decision_map.v1, kye.purpose.permission.v1
engines: internal, internal
workers: kye-pdp
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
iso-27001.A.6.8Information security event reportingenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
iso-27001.A.7.1Physical security perimetersadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.7.2Physical entryadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.7.3Securing offices, rooms and facilitiesadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.7.4Physical security monitoringadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.7.5Protecting against physical and environmental threatsadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.7.6Working in secure areasadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.7.7Clear desk and clear screenadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.7.8Equipment siting and protectionadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.7.9Security of assets off-premisesadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.7.10Storage mediaenforced 1 unverified citationaudit_events: kye.audit.event.appended.v1 unverified citation, kye.evidence.pack.v1, kye.compliance.attestation.v1
engines: internal, internal
workers: kye-audit-archiver
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
iso-27001.A.7.11Supporting utilitiesadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.7.12Cabling securityadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.7.13Equipment maintenanceadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.7.14Secure disposal or re-use of equipmentenforced 1 unverified citationaudit_events: kye.audit.event.appended.v1 unverified citation, kye.evidence.pack.v1, kye.compliance.attestation.v1
engines: internal, internal
workers: kye-audit-archiver
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
iso-27001.A.8.1User end point devicesadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.8.2Privileged access rightsenforcedaudit_events: kye.authority.grant.v1, kye.evidence.decision_map.v1, kye.purpose.permission.v1
engines: internal, internal
workers: kye-pdp
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
iso-27001.A.8.3Information access restrictionenforcedaudit_events: kye.authority.grant.v1, kye.evidence.decision_map.v1, kye.purpose.permission.v1
engines: internal, internal
workers: kye-pdp
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
iso-27001.A.8.4Access to source codeenforcedaudit_events: kye.authority.grant.v1, kye.evidence.decision_map.v1, kye.purpose.permission.v1
engines: internal, internal
workers: kye-pdp
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
iso-27001.A.8.5Secure authenticationenforcedaudit_events: kye.signing.multisig_envelope.v1
engines: internal, internal, internal
constitution_refs: constitution/51-NO-SPOF.md
iso-27001.A.8.6Capacity managementadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.8.7Protection against malwaredesignedaudit_events: kye.evidence.tool_call_pin.v1, kye.agent.mcp_allow_list.v1
constitution_refs: constitution/52-DELEGATED-AGENT-BINDING.md
iso-27001.A.8.8Management of technical vulnerabilitiesenforcedaudit_events: kye.signal.drift.detected.v1, kye.signal.stable_drift.detected.v1
engines: internal
workers: kye-drift-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
iso-27001.A.8.9Configuration managementenforcedaudit_events: kye.signal.drift.detected.v1
constitution_refs: constitution/34-RECONCILIATION-ENGINE.md
engines: internal, internal
workers: kye-gateway
iso-27001.A.8.10Information deletionenforced 1 unverified citationaudit_events: kye.audit.event.appended.v1 unverified citation, kye.evidence.pack.v1, kye.compliance.attestation.v1
engines: internal, internal
workers: kye-audit-archiver
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
iso-27001.A.8.11Data maskingenforcedaudit_events: kye.evidence.decision_map.v1, kye.federation.cross_org_delegation.v1
engines: internal, internal
constitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md
iso-27001.A.8.12Data leakage preventionenforcedaudit_events: kye.evidence.decision_map.v1, kye.federation.cross_org_delegation.v1
engines: internal, internal
constitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md
iso-27001.A.8.13Information backupenforcedaudit_events: kye.compliance.attestation.v1
engines: internal
workers: kye-audit-archiver
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
iso-27001.A.8.14Redundancy of information processing facilitiesenforcedaudit_events: kye.spof.path_to_full.v1
constitution_refs: constitution/51-NO-SPOF.md
engines: internal, internal
workers: kye-gateway
iso-27001.A.8.15Loggingenforced 1 unverified citationaudit_events: kye.audit.event.appended.v1 unverified citation, kye.evidence.pack.v1, kye.compliance.attestation.v1
engines: internal, internal
workers: kye-audit-archiver
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
rule_packs: kye:rule-pack:public-sector-governance
iso-27001.A.8.16Monitoring activitiesenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
iso-27001.A.8.17Clock synchronisationadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.8.18Use of privileged utility programsdesignedaudit_events: kye.evidence.tool_call_pin.v1, kye.agent.mcp_allow_list.v1
constitution_refs: constitution/52-DELEGATED-AGENT-BINDING.md
iso-27001.A.8.19Installation of software on operational systemsenforcedaudit_events: kye.signal.drift.detected.v1
constitution_refs: constitution/34-RECONCILIATION-ENGINE.md
engines: internal, internal
workers: kye-gateway
iso-27001.A.8.20Networks securityenforcedaudit_events: kye.evidence.decision_map.v1, kye.signal.decision.admitted.v1
engines: internal, internal
workers: kye-gateway, kye-edge-arbiter
constitution_refs: constitution/25-EDGE-GOVERNANCE.md
iso-27001.A.8.21Security of network servicesenforcedaudit_events: kye.evidence.decision_map.v1, kye.signal.decision.admitted.v1
engines: internal, internal
workers: kye-gateway, kye-edge-arbiter
constitution_refs: constitution/25-EDGE-GOVERNANCE.md
iso-27001.A.8.22Segregation of networksenforcedaudit_events: kye.evidence.decision_map.v1, kye.signal.decision.admitted.v1
engines: internal, internal
workers: kye-gateway, kye-edge-arbiter
constitution_refs: constitution/25-EDGE-GOVERNANCE.md
iso-27001.A.8.23Web filteringadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.8.24Use of cryptographyenforcedaudit_events: kye.signing.multisig_envelope.v1
engines: internal, internal, internal
constitution_refs: constitution/51-NO-SPOF.md
iso-27001.A.8.25Secure development life cycleenforcedaudit_events: kye.ci.failure.classified.v1
constitution_refs: constitution/00-INDEX.md, constitution/42-CONSTITUTION-KIT.md
engines: internal, internal
workers: kye-gateway
iso-27001.A.8.26Application security requirementsenforcedaudit_events: kye.ci.failure.classified.v1
constitution_refs: constitution/00-INDEX.md, constitution/42-CONSTITUTION-KIT.md
engines: internal, internal
workers: kye-gateway
iso-27001.A.8.27Secure system architecture and engineering principlesenforcedaudit_events: kye.ci.failure.classified.v1
constitution_refs: constitution/00-INDEX.md, constitution/42-CONSTITUTION-KIT.md
engines: internal, internal
workers: kye-gateway
iso-27001.A.8.28Secure codingdesignedaudit_events: kye.ci.failure.classified.v1
constitution_refs: constitution/00-INDEX.md, constitution/42-CONSTITUTION-KIT.md
iso-27001.A.8.29Security testing in development and acceptanceenforcedaudit_events: kye.ci.failure.classified.v1
constitution_refs: constitution/00-INDEX.md, constitution/42-CONSTITUTION-KIT.md
engines: internal, internal
workers: kye-gateway
iso-27001.A.8.30Outsourced developmentadvisoryconstitution_refs: constitution/00-INDEX.md
iso-27001.A.8.31Separation of development, test and production environmentsenforcedaudit_events: kye.ci.failure.classified.v1
constitution_refs: constitution/00-INDEX.md, constitution/42-CONSTITUTION-KIT.md
engines: internal, internal
workers: kye-gateway
iso-27001.A.8.32Change managementenforcedaudit_events: kye.governedui.approval.v1, kye.evidence.pack.v1
engines: internal, internal
constitution_refs: constitution/36-GOVERNEDUI.md
iso-27001.A.8.33Test informationenforcedaudit_events: kye.evidence.decision_map.v1, kye.federation.cross_org_delegation.v1
engines: internal, internal
constitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md
iso-27001.A.8.34Protection of information systems during audit testingenforced 1 unverified citationaudit_events: kye.audit.event.appended.v1 unverified citation, kye.evidence.pack.v1, kye.compliance.attestation.v1
engines: internal, internal
workers: kye-audit-archiver
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
iso-27001.cl-4.1Understanding the organisation and its context — determine external and internal issues relevant to the ISMS purpose that affect its ability to achieve the intended outcomes.advisoryaudit_events: kye.risk.authority_register.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
iso-27001.cl-4.2Understanding the needs and expectations of interested parties — determine relevant interested parties and their requirements that relate to information security.advisoryaudit_events: kye.compliance.attestation.v1, kye.subprocessor.v1
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
iso-27001.cl-4.3Determining the scope of the information security management system — determine the boundaries and applicability of the ISMS taking the context, interested parties and interfaces into account.enforcedaudit_events: kye.compliance.attestation.v1
registries: internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
iso-27001.cl-4.4Information security management system — establish, implement, maintain and continually improve an ISMS, including the processes needed and their interactions, in accordance with the requirements of this document.enforcedaudit_events: kye.compliance.attestation.v1, kye.reconciliation.verdict.v1
engines: internal
constitution_refs: constitution/00-INDEX.md, constitution/34-RECONCILIATION-ENGINE.md
iso-27001.cl-5.1Leadership and commitment — top management demonstrates leadership and commitment with respect to the ISMS.enforcedaudit_events: kye.governedui.approval.v1, kye.compliance.attestation.v1
governedui_modules: kye.governedui.module.action_approval.v1, kye.governedui.module.approval_queue.v1
constitution_refs: constitution/36-GOVERNEDUI.md
iso-27001.cl-5.2Policy — top management establishes an information security policy appropriate to the purpose of the organisation, including objectives or framework for setting objectives, commitment to satisfy applicable requirements, and commitment to continual improvement.enforcedaudit_events: kye.compliance.attestation.v1
registries: internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
iso-27001.cl-5.3Organisational roles, responsibilities and authorities — top management assigns and communicates roles and authorities relevant to information security.enforcedaudit_events: kye.authority.grant.v1, kye.risk.authority_register.v1
engines: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
iso-27001.cl-6.1.1Actions to address risks and opportunities — general — plan actions to address risks and opportunities to ensure the ISMS can achieve its intended outcomes and to achieve continual improvement.enforcedaudit_events: kye.risk.score.v1, kye.risk.authority_register.v1, kye.risk_assessment.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
iso-27001.cl-6.1.2Information security risk assessment — define and apply an information security risk-assessment process that establishes and maintains risk criteria, ensures repeatability of results, identifies risks, analyses and evaluates them.enforcedaudit_events: kye.risk_assessment.v1, kye.risk.score.v1, kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
iso-27001.cl-6.1.3Information security risk treatment — define and apply an information security risk-treatment process to select appropriate options, determine controls, compare to Annex A, produce a Statement of Applicability, and obtain risk-owner approval.enforcedaudit_events: kye.compliance.attestation.v1, kye.governedui.approval.v1
engines: internal, internal
constitution_refs: constitution/36-GOVERNEDUI.md, constitution/40-IMPLEMENTATION-CANONICAL.md
iso-27001.cl-6.2Information security objectives and planning to achieve them — establish information security objectives at relevant functions and levels, consistent with the policy and measurable.advisoryaudit_events: kye.compliance.attestation.v1
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
iso-27001.cl-6.3Planning of changes — when the organisation determines the need for changes to the ISMS, the changes shall be carried out in a planned manner.enforcedaudit_events: kye.change_calendar.v1, kye.governedui.approval.v1, kye.reconciliation.verdict.v1
engines: internal
constitution_refs: constitution/34-RECONCILIATION-ENGINE.md, constitution/53-COHESION-CASCADE.md
iso-27001.cl-7.1Resources — determine and provide the resources needed for the establishment, implementation, maintenance and continual improvement of the ISMS.advisoryaudit_events: kye.compliance.attestation.v1
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
iso-27001.cl-7.2Competence — determine the necessary competence of persons doing work under the organisation's control that affects the ISMS performance, ensure competence on the basis of education, training or experience, and retain documented information as evidence of competence.enforcedaudit_events: kye.training.completion.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/10-PARTNER.md, constitution/49-UNIVERSAL-ENGAGEMENT-RAIL.md
iso-27001.cl-7.3Awareness — persons doing work under the organisation's control are aware of the information security policy, their contribution to the effectiveness of the ISMS, and the implications of not conforming.enforcedaudit_events: kye.training.completion.v1, kye.comms.dispatched.v1
engines: internal
constitution_refs: constitution/38-COMMS-RAIL.md, constitution/39-LEARN-RAIL.md
iso-27001.cl-7.4Communication — determine the need for internal and external communications relevant to the ISMS, including what, when, with whom, and how to communicate.enforcedaudit_events: kye.comms.dispatched.v1
engines: internal
constitution_refs: constitution/38-COMMS-RAIL.md
iso-27001.cl-7.5Documented information — the ISMS shall include documented information required by this document and documented information determined by the organisation as being necessary; documented information shall be controlled regarding distribution, access, retrieval, use, storage, preservation, change control and disposition.enforcedaudit_events: kye.audit_retention_policy.v1, kye.audit.event.v1
engines: internal, internal
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md, constitution/43-MACHINE-READABLE-BY-DEFAULT.md
iso-27001.cl-8.1Operational planning and control — plan, implement and control the processes needed to meet requirements and to implement the actions to address risks and opportunities; control planned changes and review unintended changes.enforcedaudit_events: kye.evidence.decision_map.v1, kye.reconciliation.verdict.v1, kye.signal.drift.detected.v1
engines: internal, internal
constitution_refs: constitution/34-RECONCILIATION-ENGINE.md
iso-27001.cl-8.2Information security risk assessment — perform information security risk assessments at planned intervals or when significant changes are proposed or occur, retaining documented information of the results.enforcedaudit_events: kye.risk_assessment.v1, kye.signal.scenario_run.completed.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
iso-27001.cl-8.3Information security risk treatment — implement the information security risk-treatment plan and retain documented information of the results.enforcedaudit_events: kye.compliance.attestation.v1, kye.reconciliation.verdict.v1
engines: internal
constitution_refs: constitution/34-RECONCILIATION-ENGINE.md, constitution/40-IMPLEMENTATION-CANONICAL.md
iso-27001.cl-9.1Monitoring, measurement, analysis and evaluation — evaluate the information security performance and the effectiveness of the ISMS; determine what to monitor, the methods, when, by whom, and when results are analysed.enforcedaudit_events: kye.audit.event.v1, kye.signal.drift.detected.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/35-STREAMING-LOGS.md
iso-27001.cl-9.2Internal audit — conduct internal audits at planned intervals to provide information on whether the ISMS conforms to the requirements and is effectively implemented and maintained.enforcedaudit_events: kye.assurance.audit_pilot.v1, kye.assurance.audit_replay_report.v1
engines: internal, internal
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
iso-27001.cl-9.3Management review — top management shall review the ISMS at planned intervals to ensure its continuing suitability, adequacy and effectiveness.designedaudit_events: kye.governedui.approval.v1, kye.compliance.attestation.v1
governedui_modules: kye.governedui.module.action_approval.v1, kye.governedui.module.evidence_timeline.v1
constitution_refs: constitution/36-GOVERNEDUI.md
iso-27001.cl-10.1Continual improvement — continually improve the suitability, adequacy and effectiveness of the ISMS.enforcedaudit_events: kye.reconciliation.verdict.v1, kye.signal.drift.detected.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/34-RECONCILIATION-ENGINE.md, constitution/53-COHESION-CASCADE.md
iso-27001.cl-10.2Nonconformity and corrective action — when a nonconformity occurs, the organisation shall react, evaluate the need for action to eliminate the causes, implement the action, review effectiveness, and retain documented information.enforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1, kye.ci.failure.classified.v1, kye.signal.revocation.cascaded.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/41-ERROR-HORIZONS.md

Canonical KYE™ surfaces referenced on this page: KYE Protocol™.