AAOAAO ABDULLAH AL OWASI

System and client guide

Scope, evidence and decisions.

Generated from the current route and data contracts.

Read the complete guide and diagrams on GitHub ↗

D01 · Corporate governance & accountability

Named owners, decisions and review dates

  • Board mandate and delegated authority recorded
  • Named accountable owners assigned
  • Decision rationale and review cadence approved

ISO/IEC 27001 clauses 4–6 · NIST SP 800-53 PM

Open project and readiness review →
D02 · Enterprise risk & appetite

Likelihood, impact, treatment and acceptance

  • Risk appetite and tolerance documented
  • Inherent and residual assessments recorded
  • Treatment and escalation owner assigned

NIST SP 800-53 RA · ISO/IEC 27001 clause 6

Open project and readiness review →
D03 · Regulatory applicability & change

Jurisdiction, applicable requirement and effective date

  • Jurisdiction and applicability determined
  • Obligation-to-control mappings reviewed
  • Regulatory change owner and review date assigned

GDPR · EU AI Act · NIST SP 800-53 PL

Open project and readiness review →
D04 · Policy lifecycle

Version, ownership and attestation

  • Policy scope and approval owner recorded
  • Version and effective date controlled
  • Attestations and exceptions reviewed

ISO/IEC 27001 clause 7 · NIST SP 800-53 PL

Open project and readiness review →
D05 · Control implementation & ownership

Requirement → control → owner

  • Implementation and control owner recorded
  • Operating evidence and test procedure linked
  • Exceptions and compensating controls reviewed

NIST SP 800-53 · ISO/IEC 27001 Annex A · SOC 2 TSC

Open project and readiness review →
D06 · Internal audit & independence

Plan, finding and corrective action

  • Audit independence and mandate documented
  • Risk-based scope and sampling approved
  • Findings and management actions assigned

ISO/IEC 27001 clause 9 · NIST SP 800-53 CA

Open project and readiness review →
D07 · External audit & certification readiness

Reviewed tests and dated evidence

  • Audit scope and reporting period agreed
  • Control evidence and reviewer recorded
  • Readiness gaps and retest dates assigned

SOC 2 TSC · ISO/IEC 27001 clauses 9–10

Open project and readiness review →
D08 · Continuous assurance & remediation

Evidence expiry, failed tests and treatment

  • Monitoring criteria and frequency defined
  • Failed or expired evidence routed to an owner
  • Closure evidence and retest decision reviewed

NIST SP 800-53 CA-7 · SOC 2 CC4

Open project and readiness review →
D09 · Supplier lifecycle & concentration

Tier, dependencies and exit conditions

  • Supplier criticality and concentration assessed
  • Due diligence and contractual evidence reviewed
  • Exit plan and reassessment triggers documented

NIST SP 800-53 SR · ISO/IEC 27001 Annex A

Open project and readiness review →
D10 · Procurement & customer assurance

Requirements and evidence-backed answers

  • Customer requirement and disclosure scope agreed
  • Each response linked to approved evidence
  • External response approved by accountable reviewer

SOC 2 CC9 · NIST SP 800-53 SR

Open project and readiness review →
D11 · Privacy & individual rights

Purpose, retention and impact review

  • Purpose and lawful basis documented
  • Rights handling and retention process reviewed
  • DPIA applicability and privacy owner recorded

GDPR Articles 5, 12–22, 25, 35

Open project and readiness review →
D12 · Processors & cross-border transfers

DPA, subprocessors and transfer mechanism

  • Processor agreement and subprocessors reviewed
  • Transfer mechanism and jurisdiction assessed
  • Changes and ongoing processor reviews assigned

GDPR Articles 28, 30, 44–49

Open project and readiness review →
D13 · Data classification & retention

Data owner, classification and deletion review

  • Data classification and inventory recorded
  • Retention and deletion rules documented
  • Access and disposal evidence reviewed

GDPR Article 5 · NIST SP 800-53 MP, PT

Open project and readiness review →
D14 · AI inventory & lifecycle authorization

Inventory, evaluation and deployment decision

  • AI purpose and system inventory recorded
  • Impact assessment and deployment boundary reviewed
  • Release owner and human oversight assigned

NIST AI RMF · ISO/IEC 42001

Open project and readiness review →
D15 · AI fairness, safety & oversight

Evaluation findings and human review gates

  • Evaluation methodology and test population recorded
  • Fairness and safety failures assigned treatments
  • Human intervention and escalation tested

NIST AI RMF MEASURE/MANAGE · ISO/IEC 42001

Open project and readiness review →
D16 · AI transparency & content provenance

Disclosure decision and evidence

  • AI transparency applicability determined
  • Disclosure and content provenance tested
  • Release approval and evidence retained

EU AI Act Article 50

Open project and readiness review →
D17 · Shadow AI & acceptable use

Use-case intake and egress review

  • Approved tools and acceptable use policy recorded
  • Data egress and sensitive-use boundaries reviewed
  • Exceptions and remediation owners assigned

NIST AI RMF · ISO/IEC 27001 Annex A

Open project and readiness review →
D18 · Continuity, recovery & crisis readiness

Critical services, recovery objectives and exercise evidence

  • Critical services and recovery objectives recorded
  • Recovery exercise evidence reviewed
  • Dependency and crisis escalation owners assigned

NIST SP 800-53 CP · ISO/IEC 27001 Annex A

Open project and readiness review →
D19 · Incident governance & reporting

Incident owner, escalation and corrective action

  • Incident classification and escalation documented
  • Notification applicability and deadlines assessed
  • Containment and post-incident actions assigned

NIST SP 800-53 IR · GDPR Articles 33–34

Open project and readiness review →
D20 · Workforce, physical & organizational security

Control and review records; specialist assessment required

  • Joiner mover leaver responsibilities documented
  • Security training and access reviews evidenced
  • Physical access and personnel exceptions reviewed

NIST SP 800-53 AT, PS, PE · ISO/IEC 27001 Annex A

Open project and readiness review →
D21 · Financial, fraud & ethical conduct risk

Exposure and risk decisions; specialist assessment required

  • Financial approval limits and segregation defined
  • Fraud and conflict-of-interest controls reviewed
  • Escalation and investigation ownership assigned

NIST SP 800-53 PM, RA

Open project and readiness review →
D22 · Sector, market & contractual obligations

Applicability review; sector-specific controls require scoping

  • Sector and contractual applicability recorded
  • Baseline and market-entry requirements mapped
  • Exceptions and evidence requests assigned

FedRAMP Rev5 when in scope

Open project and readiness review →
D23 · Security scope & authorization boundary

Asset scope and system boundary; deployment architecture review

  • System assets data flows and interfaces inventoried
  • Trust boundaries and excluded scope documented
  • Authorization owner and boundary changes reviewed

NIST RMF · NIST SP 800-53 PL-2, CA-3

Open project and readiness review →
D24 · Identity, least privilege & segregation

IAM evidence and authorization policy source

  • Identity and privilege inventory recorded
  • Least privilege and segregation reviewed
  • Access recertification and revocation evidenced

NIST SP 800-53 AC, IA · SOC 2 CC6

Open project and readiness review →
D25 · Cloud configuration & change

Configuration events and control decisions

  • Configuration baseline and change owner recorded
  • Change impact and rollback evidence reviewed
  • Drift and unauthorized changes routed to review

NIST SP 800-53 CM · SOC 2 CC8

Open project and readiness review →
D26 · Threat, vulnerability & supply-chain assurance

Alert normalization and remediation priorities

  • Threat and vulnerability inventory recorded
  • Supplier dependencies and patch priorities assessed
  • Remediation and retest evidence reviewed

NIST SP 800-53 RA-5, SI-2, SR

Open project and readiness review →
D27 · Logging, evidence integrity & provenance

Source timestamps and evidence validation

  • Log sources timestamps and retention defined
  • Evidence integrity and provenance verified
  • Evidence access and custody ownership assigned

NIST SP 800-53 AU · SOC 2 CC7

Open project and readiness review →
D28 · Agent, tool & data authorization

Agent/tool authorization policies and human escalation

  • Agent identity tools and data permissions scoped
  • Tool actions and human approval gates defined
  • Revocation and decision logging tested

NIST SP 800-53 AC · NIST AI RMF

Open project and readiness review →
D29 · Assessment, authorization & ongoing monitoring

Review packages; authorization remains with designated authority

  • Assessment scope and authorization package recorded
  • Authority decision and exceptions documented
  • Monitoring cadence and reauthorization triggers assigned

NIST SP 800-53 CA-2, CA-6, CA-7 · FedRAMP Rev5

Open project and readiness review →

Present the decision trail.

  1. Choose the client’s system and review boundary.
  2. Inspect framework applicability and prerequisites.
  3. Change evidence validity and show which gate moves.
  4. Identify the accountable reviewer and export the findings.
  5. Agree integration scope and measurable acceptance criteria.
Open operating workspace →