NMQ Protocol
ISO 27001 control map
Static mapping from GRC gap template IDs to ISO/IEC 27001:2022 Annex A codes (read-only).
| Gap template ID | ISO 27001 Annex A | Note |
|---|---|---|
| iso27001-access | A.5.15, A.5.16, A.5.18 | Access control, identity management, privileged access |
| iso27001-audit | A.8.15, A.8.16 | Logging and monitoring of knowledge operations |
| internal-classification | A.5.12, A.5.13 | Classification of information and labelling |
| gdpr-ropa | A.5.34 | Privacy and protection of PII (RoPA alignment) |
| gdpr-international-transfers | A.5.34, A.8.24 | Transfer mechanisms and cryptography in transit |
| gdpr-breach | A.5.24, A.5.26 | Incident management planning and assessment |
| ai-act-logging | A.8.15, A.8.16 | Automatic logging for high-risk AI use |
| dora-ict-risk | A.5.1, A.8.1 | ICT risk management overlay for financial tenants |
Read-only reference map. Update gap evidence in GRC gap workspace.
