A customized, framework-mapped Information Security Management System control library. This is the control set behind the live ISMS governance dashboard at jamesgrc.com/isms (the dashboard runs on synthetic data).
The control library is split into nine domains.
| File | Domain |
|---|---|
Domain1_Govern.md |
Govern |
Domain2_Identify.md |
Identify |
Domain3_Protect.md |
Protect |
Domain4_Detect.md |
Detect |
Domain5_Respond.md |
Respond |
Domain6_Recover.md |
Recover |
Domain7_AppSec.md |
Application Security |
Domain8_AI_Third_Party.md |
Third-Party / Acquired AI |
Domain9_AI_Internally_Developed.md |
Internally Developed AI |
Within each domain, controls are grouped into categories (e.g. GOV.OC — Organisational Context) and given a unique ID (e.g. GOV.OC-01). Every control documents:
- Applies To — the assets, records, and entities in scope
- Control Details — the implementation requirements
- Control Mapping — the authoritative standards, regulations, and frameworks the control satisfies (ISO/IEC 27001, NIST CSF 2.0, EU NIS 2, OWASP materials, TISAX, and others)
ISMS References.md — the consolidated source list: every authoritative reference cited across the domain control mappings, ordered by the mapping hierarchy (certification standards first, then regulations, frameworks, taxonomies, and industry control sets). Exported from the dashboard's References tab.
ISO/IEC 27001 & 27002 · NIST CSF 2.0 · EU NIS 2 · EU GDPR · EU Cyber Resilience Act · TISAX · EU AI Act · ISO/IEC 42001 · NIST AI RMF · MITRE ATT&CK & ATLAS · OECD AI Principles · NIST SP 800-53 / 800-161 · OWASP — numerous materials; see ISMS References.md for the full list.
A reference and portfolio artifact demonstrating a standards-based, measurable approach to ISMS design — not a turnkey policy pack. Controls are written to be assessed and matured on a regular cadence, and to be evidenced to auditors, executives, and a board.