{
  "component-definition": {
    "uuid": "fdcfa9d3-3872-51ef-bb23-f8f22b0a9505",
    "metadata": {
      "title": "Allod Solutions AB - OSCAL Component Definition",
      "published": "2026-06-28T00:00:00Z",
      "last-modified": "2026-07-21T06:54:45Z",
      "version": "0.1",
      "oscal-version": "1.1.2",
      "parties": [
        {
          "uuid": "3597580a-dc3b-5f3a-883c-155f53247a2c",
          "type": "organization",
          "name": "Allod Solutions AB",
          "links": [
            {
              "href": "https://allod.solutions",
              "rel": "website"
            }
          ]
        }
      ]
    },
    "components": [
      {
        "uuid": "0831c5c2-52b7-5ce3-99a2-2c6b6c1c59a6",
        "type": "policy",
        "title": "Allod Solutions AB",
        "description": "Allod Solutions AB ISMS covering all organizational assets, processes, and services under ISO/IEC 27001:2022 scope.",
        "responsible-roles": [
          {
            "role-id": "asset-owner",
            "party-uuids": [
              "3597580a-dc3b-5f3a-883c-155f53247a2c"
            ]
          }
        ],
        "control-implementations": [
          {
            "uuid": "8daff107-1e91-58df-b70d-489fe5e9615b",
            "source": "https://www.iso.org/standard/82875.html",
            "description": "ISO/IEC 27001:2022 Annex A controls applicable to Allod Solutions AB ISMS.",
            "implemented-requirements": [
              {
                "uuid": "40ff8672-d283-5ae8-8dcb-a77ea777f646",
                "control-id": "a.5.1",
                "description": "Mandatory per ISO 27001. Information security policy established.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "70eb5c35-7589-5753-bc57-6de62ac048e6",
                "control-id": "a.5.2",
                "description": "Roles and responsibilities defined in the information security policy, allocated to named individuals across CEO, CTO, CISO and DevOps roles.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "4ed6e924-8832-52f9-95b3-0fb7e7db38d1",
                "control-id": "a.5.3",
                "description": "Full personnel SoD is not possible in a single-person company. Technical compensating controls are implemented: signing keys reside exclusively in the build server (inaccessible from developer workstations), the build fails automatically on known vulnerabilities so signing never occurs, and all signing events are logged. Residual risk is documented and accepted by management (R-02).",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "32d324de-d631-5966-af25-a3c154fe9117",
                "control-id": "a.5.4",
                "description": "Management has an explicit commitment to the ISMS per the information security policy.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "db6513e0-2002-568e-bbbe-db42bdcc4317",
                "control-id": "a.5.5",
                "description": "Relevant for security incidents and GDPR reporting to the supervisory authority (IMY).",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "04c707ce-6560-521d-b453-5a88c65ef857",
                "control-id": "a.5.6",
                "description": "Relevant for threat landscape monitoring, e.g. CERT-SE.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "9fe69b2b-82f8-5bef-93ec-cbe1a3ed74d1",
                "control-id": "a.5.7",
                "description": "Monitoring supply-chain threats and vulnerabilities in dependencies.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "fcc8d816-9abe-5c95-9df7-41e05a6036f7",
                "control-id": "a.5.8",
                "description": "Security must be considered in product development from the outset.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "8921f897-05e4-5cfc-a67f-895cabbfbd1f",
                "control-id": "a.5.9",
                "description": "Asset inventory is part of the risk assessment.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "81cbe5ea-e1bd-5837-aa5a-08678e31a905",
                "control-id": "a.5.10",
                "description": "Rules for handling source code, certificates and production systems.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "4e44bd38-ab10-54fe-ac91-d1e06c0d0735",
                "control-id": "a.5.11",
                "description": "Relevant upon termination of employment - access to the Git instance, pipeline and certificates must be revoked.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "689a98ac-d039-56da-bcdb-e230fc3ece12",
                "control-id": "a.5.12",
                "description": "Information classified as Public, Internal or Confidential.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "a75b5ea8-0a4b-5b2c-bcd4-c9bfa6d635b6",
                "control-id": "a.5.13",
                "description": "Documents and code must be labelled according to the classification scheme.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "a9524398-7ea6-5698-a4ee-d89b2363fed0",
                "control-id": "a.5.14",
                "description": "Communication with customers and the licence server must be encrypted.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "92be523e-cd55-5561-91e5-b39e78bb2f24",
                "control-id": "a.5.15",
                "description": "Least privilege applied to all systems within scope.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "a6287ed8-606c-5723-9f26-df368698484f",
                "control-id": "a.5.16",
                "description": "All user accounts must be personal and traceable.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "9009a9ec-18ad-5196-9f0f-fabfeef5a290",
                "control-id": "a.5.17",
                "description": "Password policy and MFA requirements for all systems within scope.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "1bd8c0c1-c793-5dff-961e-07fb016a3b0c",
                "control-id": "a.5.18",
                "description": "Access rights reviewed regularly and revoked when no longer needed.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "61aefa1f-43d2-5fd7-b5a6-96bcd8658883",
                "control-id": "a.5.19",
                "description": "Hosting providers and certificate providers are in scope.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "15236aa1-61cc-596c-8940-2962b8f28e33",
                "control-id": "a.5.20",
                "description": "Security requirements must be included in contracts with hosting providers.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "4a498182-435f-5de8-89e7-14b63fc41c22",
                "control-id": "a.5.21",
                "description": "Supply-chain risks managed via SBOM and dependency scanning.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "d7e22313-e588-5498-b4a1-93bcc4124439",
                "control-id": "a.5.22",
                "description": "Security levels of hosting providers reviewed regularly.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "dc27fdbb-e3bd-5bea-8a07-5a9e54187415",
                "control-id": "a.5.23",
                "description": "All hosting is with Swedish providers - security requirements must be specified.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "43489aa7-7046-5f8b-a40e-111bb501cae0",
                "control-id": "a.5.24",
                "description": "Incident handling process required to fulfil the commitment to proactive communication.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "8bb7a543-5c24-5b9f-8e2a-2320feadd323",
                "control-id": "a.5.25",
                "description": "Classification of incidents for correct escalation and communication.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "55d3aa73-3190-55fd-9838-19cb7d4cf39a",
                "control-id": "a.5.26",
                "description": "Procedures for handling and remedying incidents.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "1d048792-1659-5a32-9fc1-080e73a9edbb",
                "control-id": "a.5.27",
                "description": "Incidents must lead to improvements in the ISMS.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "8b5d385e-4c0f-5957-84b0-12b8672d844e",
                "control-id": "a.5.28",
                "description": "Logging and evidence handling for security incidents.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "2fbfd6b8-ac29-5959-bb29-b34a38bf9720",
                "control-id": "a.5.29",
                "description": "Business continuity planning for the licence server and critical infrastructure.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "3bf1f1d1-a7e8-5280-9cf0-567812e8cc77",
                "control-id": "a.5.30",
                "description": "Technical readiness to restore critical systems following a disaster.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "a8402a09-f5d6-57e4-b434-6a00960b8b09",
                "control-id": "a.5.31",
                "description": "GDPR, ISO 27001, customer contracts and code-signing provider requirements.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "53921c5c-f36b-50c3-8447-2babd3a8c9d5",
                "control-id": "a.5.32",
                "description": "Source code and product constitute intellectual assets that must be protected.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "07289d74-54a7-5bb2-9e21-88149ca05a47",
                "control-id": "a.5.33",
                "description": "Documentation and logs must be protected against unauthorised access and loss.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "ad024bf1-9874-51a6-a28a-1eb3dff13192",
                "control-id": "a.5.34",
                "description": "GDPR compliance for personal data in communication.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "b71db953-ed14-51ee-8c03-3207366a336b",
                "control-id": "a.5.35",
                "description": "Internal audit of the ISMS at least once per year.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "e03335cd-64c0-56f7-93e8-44d907f21dff",
                "control-id": "a.5.36",
                "description": "Compliance with this SoA and the information security policy is monitored.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "d1199df2-ceb5-5fcb-93e8-6b03b0ed582c",
                "control-id": "a.5.37",
                "description": "Procedures for operating the licence server, pipeline and mail server must be documented.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "57189996-d1dd-5585-bb1c-74385c33b219",
                "control-id": "a.6.1",
                "description": "Background checks for personnel with access to critical systems.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "283181c6-8fff-5b9f-9a16-7d968e8556fc",
                "control-id": "a.6.2",
                "description": "NDAs and security responsibilities must be included in employment contracts.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "81020d47-e19c-5624-8610-87e52df49842",
                "control-id": "a.6.3",
                "description": "All staff must receive training in information security, phishing and social engineering.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "983c65c0-2d9b-55c2-9601-c6c72cb2da0a",
                "control-id": "a.6.4",
                "description": "Consequences for breaching security policies must be defined.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "e38f6d53-6205-576f-9072-36f9f35e1bc4",
                "control-id": "a.6.5",
                "description": "Access to all systems revoked immediately upon termination of employment.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "e660c61d-e085-545e-8c5d-1626c934dacc",
                "control-id": "a.6.6",
                "description": "NDAs signed with all staff.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "e883fdb7-2f67-56ba-bf42-fd46e1a6d1ff",
                "control-id": "a.6.7",
                "description": "Security requirements for remote work - encrypted connection, disk encryption.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "a7dd0b08-1d93-5597-846a-9d6e7903398e",
                "control-id": "a.6.8",
                "description": "Procedures for staff to report suspected incidents.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "d0c4f3a7-f55c-58fe-b924-f919171213b9",
                "control-id": "a.7.1",
                "description": "Applicable to the hosting provider's data centre - security requirements to be included in contracts.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "4b4196ae-6662-5e02-a6f4-98841c01bc28",
                "control-id": "a.7.2",
                "description": "Access control to data centres managed by the hosting provider - verified via contracts and audits.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "9fc18207-8f6d-5815-a8ba-04f6b2683c58",
                "control-id": "a.7.3",
                "description": "Physical equipment located at a third-party data centre. Physical security of the facility is enforced via DC contract and the DC's own certifications. No office premises.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "916f3c68-c596-5fde-9db6-e1add350370f",
                "control-id": "a.7.4",
                "description": "Surveillance and physical security monitoring at the data centre managed by the DC operator - verified via contract and audits.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "3b3868ab-fa04-5897-8fce-aa331b863a75",
                "control-id": "a.7.5",
                "description": "Fire suppression, climate control and physical threat protection managed by the DC operator - requirements specified in contract.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "c540522b-5c94-576c-b224-84d62607bfcb",
                "control-id": "a.7.6",
                "description": "Only authorised personnel may access the data centre. No external visits permitted. Physical access logged by the DC operator.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "3daba8d0-1850-58b4-bb87-aea35a1e44cf",
                "control-id": "a.7.7",
                "description": "Staff must lock screens and handle physical documents securely.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "898425fe-0048-5e54-b098-5ff5f957325b",
                "control-id": "a.7.8",
                "description": "Staff workstations must be protected against unauthorised access.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "dc4cc0ea-85ca-5eb0-a3b5-62956c7979c0",
                "control-id": "a.7.9",
                "description": "Laptops and mobile devices must be protected with disk encryption and passwords.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "d8eca52f-1cf1-52a0-8472-97025e2d7b6b",
                "control-id": "a.7.10",
                "description": "External storage media used for backup must be encrypted.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "ce0867c2-40f4-547f-a7a1-6bd4dc700571",
                "control-id": "a.7.11",
                "description": "Power supply and network connectivity for the hosting provider's data centre - requirements in contracts.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "47caa0b8-4887-554c-9923-354927a33e88",
                "control-id": "a.7.12",
                "description": "Physical equipment located at a third-party data centre. Cabling security enforced via DC contract and weekly visual inspection of cabling by authorised personnel.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "e342b8b0-09d6-5cc0-92ff-0ddd4d4f742a",
                "control-id": "a.7.13",
                "description": "Maintenance of staff workstations - updates and patching.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "02f2235a-efce-580d-aee5-36ff927e7e2b",
                "control-id": "a.7.14",
                "description": "Secure erasure of data when disposing of workstations.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "31d78dcb-6de6-54e7-9b6b-0ab832330868",
                "control-id": "a.8.1",
                "description": "Disk encryption, up-to-date software and MFA on all workstations.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "be1bf30b-2fc3-58fd-b631-ea9f07613a57",
                "control-id": "a.8.2",
                "description": "Administrative access to the licence server and Git instance strictly limited.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "94823fcf-1eea-5b77-8a08-c11f94e9e90d",
                "control-id": "a.8.3",
                "description": "Access to source code, secrets and production systems restricted to authorised personnel.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "d2b465af-68f4-5157-96df-b8fa97bb8991",
                "control-id": "a.8.4",
                "description": "Access to the Git repository controlled via branch protection and role-based permissions.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "a5e3aad6-0eef-570f-b502-93a298cd8a88",
                "control-id": "a.8.5",
                "description": "MFA required on all systems within scope.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "02b6e6f5-6490-5314-8d01-3f289cabaf55",
                "control-id": "a.8.6",
                "description": "Licence server capacity monitored to ensure availability.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "174a4c03-b4e1-5c75-91cb-ecb5f1b0b924",
                "control-id": "a.8.7",
                "description": "Antivirus protection and automated vulnerability scanning in the pipeline.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "610e5783-1ad9-5d20-970d-f82143a2201f",
                "control-id": "a.8.8",
                "description": "Dependencies pinned and scanned; servers and workstations patched.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "f67ea378-724a-5fe9-a434-165d52538185",
                "control-id": "a.8.9",
                "description": "Infrastructure configuration version-controlled and reviewed.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "7ec99aab-f6ab-5151-8de1-f0d6db943f15",
                "control-id": "a.8.10",
                "description": "Secure erasure of data when decommissioning systems or equipment.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "fbcc9ea6-ada5-520d-b47b-321ea83e4963",
                "control-id": "a.8.12",
                "description": "Source code and certificates must not be able to leak via external services. Allod SWG is deployed internally to enforce web filtering and DLP policies on outbound traffic.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "a9d54a1a-76c4-5ac7-80d6-cbc4162004b5",
                "control-id": "a.8.13",
                "description": "Automated mirroring of the Git repository and backup of licence server data.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "c114d6fc-4a99-5f9e-914c-57df1c0cf8f6",
                "control-id": "a.8.14",
                "description": "Existing installations continue to operate without the licence server (graceful degradation). Recovery from backup per backuprutin within documented RTO.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "66e03417-6ae5-54f2-a523-5a53476ff5d4",
                "control-id": "a.8.15",
                "description": "Audit logging enabled on the Git instance, licence server and mail server.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "ab773cb7-3af3-51ca-b5d1-02e4b44166cd",
                "control-id": "a.8.16",
                "description": "Logs reviewed regularly to detect anomalies.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "4b5302b1-8427-59e8-952d-7f343f265b8e",
                "control-id": "a.8.17",
                "description": "All systems must use NTP for consistent log timestamps.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "d7024d88-19b8-58c8-8483-1324aa528f63",
                "control-id": "a.8.18",
                "description": "Administration tools for servers and pipeline managed with strict permissions.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "1c01e36b-ece2-52d3-8e94-dd3fa468cc3b",
                "control-id": "a.8.19",
                "description": "Only approved software installed on production systems.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "1c072ce3-c5e0-5519-847c-97edca83999b",
                "control-id": "a.8.20",
                "description": "Administration interfaces not exposed to the internet; network segmentation applied.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "6f628b6d-270b-50b8-8c1b-a1352701efe0",
                "control-id": "a.8.21",
                "description": "Security requirements for network services at the hosting provider specified in contracts.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "3479ed33-deac-51e5-8f80-0a633cd934f2",
                "control-id": "a.8.22",
                "description": "Production and development environments must be separated.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "8b826de9-b33e-56d1-8ac1-001edbef22b9",
                "control-id": "a.8.23",
                "description": "Web filtering enforced centrally via Allod SWG deployed internally.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "92e44d93-3a62-5ebf-a161-9b17eb731a1c",
                "control-id": "a.8.24",
                "description": "Encryption in transit (TLS) for licence server communication; AES-256 in the product.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "7a2fb5c2-b34b-5537-8a5d-da94e8f7a2cb",
                "control-id": "a.8.25",
                "description": "Security integrated into the development process - review, testing and scanning in the pipeline.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "7064bfac-ba4c-51ee-8611-8455be6314d3",
                "control-id": "a.8.26",
                "description": "Security requirements defined for the licence server and product.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "522cbf3f-534f-5149-a748-ca9fa340a335",
                "control-id": "a.8.27",
                "description": "Security principles applied in design of the licence server and product architecture.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "5a0c7202-fb74-5e8e-86a6-d3b2cc2e22e0",
                "control-id": "a.8.28",
                "description": "Secure coding guidelines applied and reviewed via pull requests.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "c669cbf7-9dd3-5ee3-a00f-c3c76be66f97",
                "control-id": "a.8.29",
                "description": "Automated vulnerability scanning (govuln, cargo audit) and manual review in CI/CD pipeline. Private bug bounty program provides continuous adversarial testing by external researchers.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "10f5273a-60b4-581f-8506-3d6a61ee2401",
                "control-id": "a.8.31",
                "description": "Development and production must be separated environments.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "29297ed8-0583-547e-aa12-9b73659948b2",
                "control-id": "a.8.32",
                "description": "All changes to source code and infrastructure managed via the standard change management process in the Git instance.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "b158aaf7-8449-540c-b9ca-a06eddcc0e66",
                "control-id": "a.8.33",
                "description": "Production data not used in test environments.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "bcff6394-0252-51e7-9175-3ff9886b85ca",
                "control-id": "a.8.34",
                "description": "Bug bounty program operates with defined scope and rules of engagement that prohibit production disruption, data destruction and DoS.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "partial"
                  }
                ]
              }
            ]
          }
        ]
      },
      {
        "uuid": "ac45a2ca-27fb-5104-8d92-c4fb4171751d",
        "type": "software",
        "title": "Allod Secure Web Gateway",
        "description": "Allod SWG is a transparent forward proxy providing web filtering, TLS inspection, threat intelligence integration (MISP), DLP, and audit logging for enterprise networks.",
        "responsible-roles": [
          {
            "role-id": "asset-owner",
            "party-uuids": [
              "3597580a-dc3b-5f3a-883c-155f53247a2c"
            ]
          }
        ],
        "control-implementations": [
          {
            "uuid": "640e60e0-bfd3-5f75-beee-e0577b46986d",
            "source": "https://www.iso.org/standard/82875.html",
            "description": "ISO/IEC 27001:2022 Annex A controls implemented by Allod SWG.",
            "implemented-requirements": [
              {
                "uuid": "ade32dcc-8bb2-5f48-84cb-79e5fbe8806a",
                "control-id": "a.8.5",
                "description": "SWG enforces authenticated access; integrates with identity providers for user-based policy."
              },
              {
                "uuid": "6c854f26-6088-5827-9a02-ad817059d9e3",
                "control-id": "a.8.7",
                "description": "SWG blocks known malware and offensive-tooling indicators via JA3/JA4/JARM fingerprint matching against known C2 frameworks (Cobalt Strike, Sliver, Meterpreter, and others), and detects disguised executables via magic-byte file-type/extension mismatch."
              },
              {
                "uuid": "6db77005-0002-552f-98b8-2ea815a35805",
                "control-id": "a.8.8",
                "description": "SWG binary is built with dependency pinning and automated vulnerability scanning in CI pipeline."
              },
              {
                "uuid": "97cdb813-8774-57da-ade1-54693f70c045",
                "control-id": "a.8.15",
                "description": "SWG produces structured audit logs of all proxied requests including user, URL, policy decision, and timestamps."
              },
              {
                "uuid": "0400ce4e-ec0c-5781-a074-98b7b7ec0b26",
                "control-id": "a.8.16",
                "description": "SWG exposes metrics and logs for integration with monitoring and SIEM systems."
              },
              {
                "uuid": "dcaf9591-28b8-57cc-92e7-b6c3872a6bbd",
                "control-id": "a.8.20",
                "description": "SWG is the network security enforcement point; admin interfaces are not exposed to the internet."
              },
              {
                "uuid": "3edd0ae2-aed1-5bf0-8712-2c4658846ad0",
                "control-id": "a.8.23",
                "description": "SWG enforces domain/URL category filtering and real-time threat-intelligence lookups (MISP) to block access to malicious and non-compliant websites."
              },
              {
                "uuid": "46612062-d903-52c5-a5c9-c4be75cf6194",
                "control-id": "a.8.24",
                "description": "SWG performs full TLS inspection using AES-256; customer CA keys are managed under customer control."
              }
            ]
          },
          {
            "uuid": "157189c7-cfeb-5077-a72e-65578a2a0704",
            "source": "https://doi.org/10.6028/NIST.SP.800-53r5",
            "description": "NIST SP 800-53 Rev. 5 controls implemented by Allod SWG.",
            "implemented-requirements": [
              {
                "uuid": "86f34a69-508b-5997-86e7-77efee2fdcab",
                "control-id": "ac-4",
                "description": "SWG enforces information flow policy via domain/category/IP/region firewall rules and DLP content rules (filename, body, entropy, PII/PCI patterns) rather than default-allow.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "2012398d-b959-5c82-9ec0-a337a54710ef",
                "control-id": "ac-4.4",
                "description": "TLS interception (dynamic per-host leaf certificates signed by a locally generated root CA) lets AC-4 flow-control policy apply to encrypted traffic, not just plaintext.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "93371e89-00f5-5ca6-ad86-6402a4e64cc7",
                "control-id": "sc-7",
                "description": "SWG is the sole network egress enforcement point; all HTTP/1.1, HTTP/2, HTTP/3, and SMTP/SMTPS/STARTTLS traffic is proxied and evaluated against firewall and DLP policy before reaching its destination.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "e86a3209-b24d-54b9-8de3-f097ee540cf8",
                "control-id": "sc-7.8",
                "description": "All monitored egress traffic is routed through the SWG forward proxy; known public DoH resolvers are forced through inspection so DNS-layer proxy bypass is not possible.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "0139a454-ceec-532d-82c9-8fb5771f37ca",
                "control-id": "sc-7.10",
                "description": "DLP content rules and DNS-exfiltration heuristics (query entropy, label/FQDN length, query rate) block or alert on data leaving via HTTP, SMTP, SaaS chat APIs, DNS, clipboard-correlated uploads, and removable media.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "9bcc6e73-eb07-511f-ba7c-e1fead066061",
                "control-id": "si-4",
                "description": "TLS/HTTP/SSH client and TLS server fingerprinting (JA4, JA4H, HASSH, JARM), DGA detection, and typosquat detection continuously monitor connections for malicious or anomalous indicators.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "d2a9eff0-9e13-5542-b246-7319aea00e46",
                "control-id": "si-4.18",
                "description": "A dedicated DNS-exfiltration detector scores every DNS query on label entropy, label/FQDN length, record type, and per-apex query rate to catch covert-channel tunneling independent of any single signature.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "e9b8a47e-b55a-5a69-9fa4-e06ef63bd516",
                "control-id": "si-3",
                "description": "JA4 and JA3 fingerprint lookups identify known C2 frameworks (Cobalt Strike, Sliver, Meterpreter, and others) and malware families; file-type/extension mismatch detection catches executables disguised with a benign extension.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "1bcd8f7b-4a7b-59d8-b6e4-d947027c5a36",
                "control-id": "au-13",
                "description": "The DLP engine inspects outbound content across web upload/download, SMTP/webmail, SaaS chat APIs, clipboard-to-file correlation, and removable media for indicators of unauthorized disclosure, including regulated data patterns (payment card numbers, IBAN, national ID numbers). For certificate-pinned hosts, where the exception path means no content is ever inspected, a rate-limited live query to the agent checks for a currently open, previously-tagged sensitivity file as a compensating alert-only signal - a lookup against files already flagged elsewhere, not a fresh scan of new content.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "14029614-df52-541b-a527-53d57c12c51e",
                "control-id": "mp-7",
                "description": "A cross-platform agent hook (Windows, Linux, macOS) inspects file writes to USB and other removable volumes through the same DLP rule engine used for network egress, and can block the write.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "8dd239fb-b766-5cf3-ab0e-47765c9f4a8f",
                "control-id": "ra-10",
                "description": "Live traffic (domain, IP, JA3, JARM, JA4, User-Agent, URI, filename, SHA-256, port) is continuously checked against MISP and static OSINT threat-intelligence feeds.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "a20d84ef-6bbe-5789-ad53-90aa3396f0ae",
                "control-id": "ac-2",
                "description": "SaaS account/identity resolution attributes observed SaaS actions to real accounts; shared-account detection flags any non-IdP personal-tier account used by three or more employees as an unsanctioned or shared credential.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "c662a0aa-98d4-5d50-9c02-ceacd430c651",
                "control-id": "ac-20",
                "description": "CASB tenant restriction extracts and enforces an allow-list of organizational SaaS tenants per application, and can block personal-tier accounts outright.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "0bb37f06-2730-551b-b96d-e504d899cf0a",
                "control-id": "sc-8",
                "description": "SMTP, SMTPS, and STARTTLS sessions are intercepted and inspected before delivery; a certificate-pinning exception path narrowly and temporarily relaxes inspection only for the specific host and duration needed to keep pinned applications functional.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "ed9cc1bf-1a25-5052-b6e7-988acbb2ab13",
                "control-id": "ac-17",
                "description": "ZTNA access-control rules default-deny raw TCP CONNECT to internal CIDR:port destinations, scoped by device, user, and group, unless explicitly allowed.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "1f3e7993-ed26-5be1-a0ab-0aeae011e857",
                "control-id": "ir-4",
                "description": "Indicators generated by SWG's own detections (fingerprint blocklists, threat feeds, DGA and typosquat blocks) are exported to CrowdStrike Falcon as custom prevent-IOCs.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "43ff0da2-c0eb-570c-9f44-0c62bbaeae1d",
                "control-id": "ca-7",
                "description": "Device compliance/posture signal (external MDM pass, fail, or unknown) is evaluated as a live condition on both firewall and DLP rules, not only at enrollment time.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              }
            ]
          },
          {
            "uuid": "499236d1-3715-5b9e-90fe-41c4f41faa60",
            "source": "https://www.cisecurity.org/controls/v8",
            "description": "CIS Controls v8 Safeguards implemented by Allod SWG.",
            "implemented-requirements": [
              {
                "uuid": "25ac353c-a570-51df-b9f5-7360570fe49f",
                "control-id": "cis-13.5",
                "description": "Firewall and DLP rules can require a live external MDM/posture signal (pass, fail, or unknown) before allowing a connection or content flow, tying enforcement to known, managed devices.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "a8c5f644-6e34-5ed8-8cee-4e144b410ff2",
                "control-id": "cis-3.3",
                "description": "CASB tenant restriction applies access-control-list-style enforcement to SaaS applications: it allow-lists approved organizational tenants per application and blocks personal-tier accounts outright.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "e470d67f-7076-5027-9a52-9cbf0c5c51b9",
                "control-id": "cis-3.12",
                "description": "ZTNA access-control rules default-deny raw TCP CONNECT to internal CIDR:port destinations unless explicitly allowed, segmenting which internal systems a given device, user, or group can reach.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "74d8ae9a-2cb8-580c-91b0-ada68b8c0a77",
                "control-id": "cis-3.13",
                "description": "A DLP rule engine inspects filename, content-type, body content, and entropy across web upload/download, SMTP/webmail, SaaS chat APIs, clipboard-to-file correlation, removable media, and transfer-size policy, with built-in detectors for regulated data patterns and AI-assisted content classification as a second opinion. Certificate-pinned hosts, otherwise fully exempt from content inspection, still get a live compensating check against files already tagged by that rule engine elsewhere - it cannot flag content it has never seen before.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "dadd763d-4a15-5e48-bcfd-38f212933fc8",
                "control-id": "cis-4.1",
                "description": "Certificate-pinning exceptions are handled as a narrow, time-limited configuration override (24 hours, specific host) rather than a blanket policy change, and device posture is treated as a live configuration input to policy rather than a one-time enrollment check.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "2f69680a-3f4c-52f6-8886-b034ba97a48d",
                "control-id": "cis-4.9",
                "description": "Admin-configured DNS servers can be scoped to an internal zone (split DNS) or forced for every query, routing DNS resolution through enterprise-designated servers instead of whatever the OS already has configured.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "53f25693-1675-54f8-a1cf-68fe654ddc98",
                "control-id": "cis-5.1",
                "description": "SaaS account resolution attributes observed SaaS actions to real accounts; shared-account detection flags any non-IdP personal-tier account used by three or more employees; SCIM sync pulls IdP group membership into the same account picture.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "ee690e7e-a8be-51f0-8fc1-d74b9df7a360",
                "control-id": "cis-6.1",
                "description": "Accounts and tenants used outside the normal IdP-governed access-granting process - unsanctioned personal-tier accounts shared across employees - are surfaced automatically rather than relying on manual review.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "13367593-a0c3-5098-9163-f6f3aa534882",
                "control-id": "cis-6.7",
                "description": "SaaS account resolution and CASB tenant restriction give a single, centralized enforcement point for which SaaS accounts and tenants are permitted, independent of each SaaS application's own native access controls.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "894214f3-11b1-5fd9-ad1c-bb7190282784",
                "control-id": "cis-6.8",
                "description": "Pulled IdP group membership acts as an AND-condition on both firewall and DLP rules, letting policy be scoped by role or group rather than by individual user.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "c0679add-4da0-5a56-a038-bea03b852dff",
                "control-id": "cis-9.2",
                "description": "DNS queries are scored for exfiltration risk (entropy, label/FQDN length, query rate), algorithmically-generated domains are flagged, known public DoH resolvers are forced through inspection rather than allowed to bypass it, and static OSINT feeds contribute additional domain-level indicators.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "083b8a18-da6f-55b6-a0d6-61fd1ceb611c",
                "control-id": "cis-9.3",
                "description": "Domain and URL-based policy (category, glob, AI-assisted fallback categorization, and typosquat/lookalike detection) is enforced at the network layer for every HTTP/1.1, HTTP/2, HTTP/3, and SaaS chat API request, including detection of credential submission to lookalike or unapproved destinations.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "947063af-1808-58c8-bceb-7c6c9092d19b",
                "control-id": "cis-9.6",
                "description": "Filename-based DLP rules match against every email attachment name, not just the message itself, closing what would otherwise be a silent bypass for file-type policy on the email channel.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "72412db3-b59e-5725-982f-0d17ee91e766",
                "control-id": "cis-3.13",
                "description": "SMTP, SMTPS, and STARTTLS sessions are intercepted and the full message body is inspected and can be blocked by the DLP engine before the message is allowed to proceed to delivery, extending DLP enforcement to email as an active blocking point rather than passive monitoring.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "b4f5ac54-f3ce-5cdb-9527-5bc53e67d9f7",
                "control-id": "cis-10.1",
                "description": "Client TLS fingerprints are checked against a database of known offensive-framework fingerprints (Cobalt Strike, Sliver, Meterpreter, and others), and live traffic indicators are continuously checked against MISP threat-intelligence feeds.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "afb2c1b1-4fe5-5abb-9f1a-662a5bdbeb4d",
                "control-id": "cis-10.7",
                "description": "Magic-byte detection identifies when a file's real type contradicts its declared extension or Content-Type - a behavioral check that catches disguised executables regardless of whether a specific malware signature exists for them.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "f5b04ca4-463d-5cd7-8a5e-f9efa6e25337",
                "control-id": "cis-12.2",
                "description": "Internal network reachability is governed by an explicit-allow access model (default-deny raw TCP CONNECT to internal CIDR:port destinations) rather than a flat, implicitly-trusted internal network.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "d299a4c7-63f5-5493-94e3-f64000b3c213",
                "control-id": "cis-13.8",
                "description": "TLS, HTTP, and SSH client fingerprints (JA4, JA4H, HASSH) and TLS server fingerprints (JARM) are usable as live block conditions on both firewall and DLP rules, not just passive logging.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "7516da1f-3690-5740-8c6c-15c7c99fcaa0",
                "control-id": "cis-13.10",
                "description": "Firewall policy operates at the application layer (domain, category, IP, region, and TLS/HTTP fingerprint), and TLS interception extends that filtering to encrypted traffic rather than stopping at the TCP/IP layer.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "be82059d-538a-55a8-95a0-f61dbb93175f",
                "control-id": "cis-13.11",
                "description": "Fingerprint- and indicator-based detections (JA4DB, SSLBL, MISP, and static OSINT threat feeds) are evaluated per-connection against continuously updated indicator sets rather than a fixed, unmaintained blocklist.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "525e90b8-07c9-59c3-8f17-198fac4e6f87",
                "control-id": "cis-14.2",
                "description": "Credential-harvest detection acts as a technical backstop to security-awareness training, flagging when a corporate credential or a typosquat/lookalike destination is involved in a login-form submission regardless of whether the employee recognized the phishing attempt.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              },
              {
                "uuid": "a73e924c-badc-595c-8222-f22c91a7062f",
                "control-id": "cis-13.1",
                "description": "Indicators generated by the gateway's own detections (fingerprint blocklists, threat feeds, DGA and typosquat blocks) are exported to CrowdStrike Falcon as custom prevent-IOCs, centralizing gateway-generated security events into the broader EDR/security-alerting stack for correlation.",
                "props": [
                  {
                    "name": "implementation-status",
                    "ns": "https://csrc.nist.gov/ns/oscal",
                    "value": "implemented"
                  }
                ]
              }
            ]
          }
        ]
      },
      {
        "uuid": "c04a6061-0288-580c-a063-c4613651e45c",
        "type": "software",
        "title": "Allod DAM",
        "description": "Allod DAM (Digital Asset Manager) is a vendor trust and supply-chain visibility platform. It imports OSCAL documents, tracks SBOM data, monitors vendor security posture, and integrates threat intelligence.",
        "responsible-roles": [
          {
            "role-id": "asset-owner",
            "party-uuids": [
              "3597580a-dc3b-5f3a-883c-155f53247a2c"
            ]
          }
        ],
        "control-implementations": [
          {
            "uuid": "17d3bbe0-4686-54ef-8958-c0dd0a2260e0",
            "source": "https://www.iso.org/standard/82875.html",
            "description": "ISO/IEC 27001:2022 Annex A controls implemented by Allod DAM.",
            "implemented-requirements": [
              {
                "uuid": "1c27ca6e-8f6b-586f-b591-039d4aeec1ef",
                "control-id": "a.5.9",
                "description": "DAM maintains an inventory of tracked vendor systems and their security-relevant assets."
              },
              {
                "uuid": "566119c1-8148-54c1-86fd-0fb71ca932e6",
                "control-id": "a.5.22",
                "description": "DAM facilitates continuous security monitoring of supplier relationships through automated OSCAL probing and trust scoring."
              },
              {
                "uuid": "29cd07f6-12b0-5bae-962d-a10b5365bd14",
                "control-id": "a.5.21",
                "description": "DAM imports and tracks SBOM data (SPDX, CycloneDX) from vendors to surface supply-chain risks."
              },
              {
                "uuid": "a3edfed6-9fc1-5b1e-9759-c02d78a5e431",
                "control-id": "a.8.5",
                "description": "DAM's admin UI requires OIDC/SSO federation (or a local password fallback) before granting access, and service-to-service calls (e.g. from allodswg) are authenticated with a rotatable per-customer bearer token."
              },
              {
                "uuid": "3829035e-6e42-5809-a048-868f7a37c2ce",
                "control-id": "a.8.3",
                "description": "DAM enforces per-tenant isolation, restricting each tenant's data and API access to its own scope."
              }
            ]
          }
        ]
      }
    ]
  }
}
