Skip to content

feat: add ISO/IEC 27017:2015 and ISO/IEC 27018:2019 SP 800-53 Rev 5 mappings - #14

Open
felipechalegre-spec wants to merge 3 commits into
opensecurityarchitecture:mainfrom
felipechalegre-spec:main
Open

feat: add ISO/IEC 27017:2015 and ISO/IEC 27018:2019 SP 800-53 Rev 5 mappings#14
felipechalegre-spec wants to merge 3 commits into
opensecurityarchitecture:mainfrom
felipechalegre-spec:main

Conversation

@felipechalegre-spec

@felipechalegre-spec felipechalegre-spec commented May 28, 2026

Copy link
Copy Markdown

Summary

Adds SP 800-53 Rev 5 cross-reference mappings for two cloud-focused ISO standards not yet covered in the OSA dataset:

ISO/IEC 27017:2015 — Information security controls for cloud services

  • 47 clauses: 37 ISO 27002:2013 controls adapted for cloud service context + 7 cloud-specific CLD.* controls
  • Cloud-specific controls: CLD.6.3.1 (shared responsibility), CLD.8.1.5 (asset removal), CLD.9.5.1 (virtual segregation), CLD.9.5.2 (VM hardening), CLD.12.1.5 (admin ops security), CLD.12.4.5 (cloud monitoring), CLD.13.1.4 (virtual network security)
  • Average SP 800-53 coverage: 84.4% (29 fully addressed ≥85%, 17 substantially addressed 65–84%, 1 partially addressed)

ISO/IEC 27018:2019 — Protection of PII in public clouds

  • 27 clauses: 16 ISO 27002:2013 controls adapted for PII processing + 11 extended Annex A privacy controls
  • Annex A controls (A.1–A.11) map primarily to the SP 800-53 PT-* (Privacy) family: PT-01 through PT-08, PM-25/26/27/28
  • Average SP 800-53 coverage: 75.9% (intentionally lower for Annex A — SP 800-53 has weaker alignment with PII principal rights compared to GDPR/LGPD concepts)

Note on nist-ai-rmf-1.json

This PR currently also includes nist-ai-rmf-1.json. Per reviewer request, NIST AI RMF is being separated into a dedicated upstream PR. That file will be removed from this PR once the separate PR is open.

Format

Both ISO files follow the existing framework-coverage.schema.json schema exactly, with id, title, controls[], coverage_pct, rationale, and gaps per clause, plus a summary block.

Source

Mappings derived from publicly available ISO/IEC crosswalks and NIST guidance. Validated in production use.

@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant