Corporate governance & accountability
Corporate governance & accountability
Named owners, decisions and review dates. Connect scoped requirements, dated evidence and accountable treatment.
ISO/IEC 27001 clauses 4–6 · NIST SP 800-53 PM

ABDULLAH AL OWASIConnected GRC operating workspace / AI · vendor · assurance
Explore connected AI, supplier and assurance records. Inspect evidence gaps, review gates and exportable decisions.
29 projects
Corporate governance & accountability
Named owners, decisions and review dates. Connect scoped requirements, dated evidence and accountable treatment.
ISO/IEC 27001 clauses 4–6 · NIST SP 800-53 PM
Enterprise risk & appetite
Likelihood, impact, treatment and acceptance. Connect scoped requirements, dated evidence and accountable treatment.
NIST SP 800-53 RA · ISO/IEC 27001 clause 6
Regulatory applicability & change
Jurisdiction, applicable requirement and effective date. Connect scoped requirements, dated evidence and accountable treatment.
GDPR · EU AI Act · NIST SP 800-53 PL
Policy lifecycle
Version, ownership and attestation. Connect scoped requirements, dated evidence and accountable treatment.
ISO/IEC 27001 clause 7 · NIST SP 800-53 PL
Control implementation & ownership
Requirement → control → owner. Connect scoped requirements, dated evidence and accountable treatment.
NIST SP 800-53 · ISO/IEC 27001 Annex A · SOC 2 TSC
Internal audit & independence
Plan, finding and corrective action. Connect scoped requirements, dated evidence and accountable treatment.
ISO/IEC 27001 clause 9 · NIST SP 800-53 CA
External audit & certification readiness
Reviewed tests and dated evidence. Connect scoped requirements, dated evidence and accountable treatment.
SOC 2 TSC · ISO/IEC 27001 clauses 9–10
Continuous assurance & remediation
Evidence expiry, failed tests and treatment. Connect scoped requirements, dated evidence and accountable treatment.
NIST SP 800-53 CA-7 · SOC 2 CC4
Supplier lifecycle & concentration
Tier, dependencies and exit conditions. Connect scoped requirements, dated evidence and accountable treatment.
NIST SP 800-53 SR · ISO/IEC 27001 Annex A
Procurement & customer assurance
Requirements and evidence-backed answers. Connect scoped requirements, dated evidence and accountable treatment.
SOC 2 CC9 · NIST SP 800-53 SR
Privacy & individual rights
Purpose, retention and impact review. Connect scoped requirements, dated evidence and accountable treatment.
GDPR Articles 5, 12–22, 25, 35
Processors & cross-border transfers
DPA, subprocessors and transfer mechanism. Connect scoped requirements, dated evidence and accountable treatment.
GDPR Articles 28, 30, 44–49
Data classification & retention
Data owner, classification and deletion review. Connect scoped requirements, dated evidence and accountable treatment.
GDPR Article 5 · NIST SP 800-53 MP, PT
AI inventory & lifecycle authorization
Inventory, evaluation and deployment decision. Connect scoped requirements, dated evidence and accountable treatment.
NIST AI RMF · ISO/IEC 42001
AI fairness, safety & oversight
Evaluation findings and human review gates. Connect scoped requirements, dated evidence and accountable treatment.
NIST AI RMF MEASURE/MANAGE · ISO/IEC 42001
AI transparency & content provenance
Disclosure decision and evidence. Connect scoped requirements, dated evidence and accountable treatment.
EU AI Act Article 50
Shadow AI & acceptable use
Use-case intake and egress review. Connect scoped requirements, dated evidence and accountable treatment.
NIST AI RMF · ISO/IEC 27001 Annex A
Continuity, recovery & crisis readiness
Critical services, recovery objectives and exercise evidence. Connect scoped requirements, dated evidence and accountable treatment.
NIST SP 800-53 CP · ISO/IEC 27001 Annex A
Incident governance & reporting
Incident owner, escalation and corrective action. Connect scoped requirements, dated evidence and accountable treatment.
NIST SP 800-53 IR · GDPR Articles 33–34
Workforce, physical & organizational security
Control and review records; specialist assessment required. Connect scoped requirements, dated evidence and accountable treatment.
NIST SP 800-53 AT, PS, PE · ISO/IEC 27001 Annex A
Financial, fraud & ethical conduct risk
Exposure and risk decisions; specialist assessment required. Connect scoped requirements, dated evidence and accountable treatment.
NIST SP 800-53 PM, RA
Sector, market & contractual obligations
Applicability review; sector-specific controls require scoping. Connect scoped requirements, dated evidence and accountable treatment.
FedRAMP Rev5 when in scope
Security scope & authorization boundary
Asset scope and system boundary; deployment architecture review. Connect scoped requirements, dated evidence and accountable treatment.
NIST RMF · NIST SP 800-53 PL-2, CA-3
Identity, least privilege & segregation
IAM evidence and authorization policy source. Connect scoped requirements, dated evidence and accountable treatment.
NIST SP 800-53 AC, IA · SOC 2 CC6
Cloud configuration & change
Configuration events and control decisions. Connect scoped requirements, dated evidence and accountable treatment.
NIST SP 800-53 CM · SOC 2 CC8
Threat, vulnerability & supply-chain assurance
Alert normalization and remediation priorities. Connect scoped requirements, dated evidence and accountable treatment.
NIST SP 800-53 RA-5, SI-2, SR
Logging, evidence integrity & provenance
Source timestamps and evidence validation. Connect scoped requirements, dated evidence and accountable treatment.
NIST SP 800-53 AU · SOC 2 CC7
Agent, tool & data authorization
Agent/tool authorization policies and human escalation. Connect scoped requirements, dated evidence and accountable treatment.
NIST SP 800-53 AC · NIST AI RMF
Assessment, authorization & ongoing monitoring
Review packages; authorization remains with designated authority. Connect scoped requirements, dated evidence and accountable treatment.
NIST SP 800-53 CA-2, CA-6, CA-7 · FedRAMP Rev5