﻿# Osolix · ISO/IEC 27001:2022 Statement of Applicability (SoA) — v1.0

> **Owner:** CISO
> **Co-owners:** Chief Compliance Officer (CCO) · CISA Manager · CTO
> **Standard:** ISO/IEC 27001:2022 (ISMS requirements) + ISO/IEC 27002:2022 (Annex A control set, 93 controls / 4 themes)
> **Audit dimension:** #11 Security · #13 Compliance & regulatory
> **Status (2026-06-12):** SoA **v1.0** — ISMS document suite complete (`docs/142`–`docs/146`,
> Decision 0069); awaiting founder ratification signatures. Certification body not yet appointed.
> **Pairs with:** `docs/wave-g-soc2-type2-engagement.md` (SOC 2 Type II). This SoA **reuses the same
> control implementations and evidence library** — see §7 cross-reference to avoid duplicated work.

---

## 1 · ISMS scope statement

**In scope:** The Osolix multi-tenant SaaS Fixed-Asset Management platform — the production
application (ASP.NET Core 10 backend, React 19 frontend), its supporting cloud infrastructure
(Azure: App Service, SQL Server with TDE, Blob Storage, Key Vault, Front Door/CDN/WAF), the
CI/CD pipeline (GitHub Actions), and the organizational processes that develop, operate, secure,
and support it. Covers all customer data (tenant business records + PII) processed by the platform
across all active regions (UAE North, UK South; plus Wave-D/E/F/G regions as they go GA per
`docs/103-data-residency-policy.md`).

**Out of scope (boundaries):**
- **Customer-operated systems** — the customer's ERP (Oracle/SAP/Dynamics/Odoo), the customer's own
  Azure Key Vault under CMEK, and customer endpoints. Osolix secures only the **integration surface**.
- **Third-party sub-processors' internal operations** — Anthropic, Stripe, SendGrid, Cloudflare,
  Microsoft Azure. Governed via DPAs + vendor-risk management (`docs/111`); their own certifications
  are relied upon (A.5.19–A.5.22 supplier controls), not re-audited.
- **Physical/environmental data-centre controls** — inherited from Azure's ISO 27001 / SOC 2
  (see Physical theme §3.3, mostly "implemented by cloud provider").

**Interested parties & requirements:** enterprise/government customers (security questionnaires,
data-residency, sovereignty), regulators (GDPR, UAE PDPL, KSA PDPL), and the AICPA SOC 2 framework
(run in parallel — see `docs/wave-g-soc2-type2-engagement.md`).

**ISMS clause-4–10 artefacts (the management-system shell around Annex A):**

| ISO 27001 clause | Artefact | Status |
|---|---|---|
| 4 — Context & scope | This §1 | ✅ |
| 5 — Leadership & policy | Information Security Policy `docs/146` | ✅ drafted · 🔏 founder signature pending |
| 6 — Planning / risk assessment | Risk register `docs/142` — populated (15 risks) | ✅ (3 acceptances need sign-off, `docs/142` §2) |
| 7 — Support (resources, competence, awareness) | `docs/30-team-job-descriptions.md`; awareness procedure `docs/143` §3 | ✅ documented · acknowledgement log starts at ratification |
| 8 — Operation | The platform + runbooks (`docs/64`, `docs/46`, `docs/45`) | ✅ |
| 9 — Performance evaluation | Internal audit + access-review programme `docs/144`; `/admin/audit` continuous audit; quarterly SOX walkthrough (`docs/31` §5) | ✅ programme formalised · first audit IA-2026-01 due 2026-09 |
| 10 — Improvement | Corrective-action tracker (`docs/144` §5) + management-letter workflow | ✅ |

---

## 2 · Risk-treatment approach

| Element | Approach |
|---|---|
| **Methodology** | Asset/threat/vulnerability-based risk assessment. Likelihood × impact on a 5×5 matrix; risk owner = the relevant lens owner from `docs/30`. |
| **Risk acceptance criteria** | Residual risk ≤ "Medium" accepted by CISO; "High"/"Critical" require treatment plan + CCO sign-off before acceptance. |
| **Treatment options** | Treat (apply Annex A control) · Tolerate (accept, documented) · Transfer (insurance / sub-processor DPA) · Terminate (remove the activity). |
| **Control selection** | Annex A 2022 (93 controls) is the baseline catalogue; each control is included or excluded with justification in §3. Additional controls beyond Annex A may be added to the register where a risk warrants. |
| **Linkage to defects** | The risk register is `docs/142`. The financial-engine defects (`decisions/0022` D1–D5) were **remediated and test-verified 2026-06-01** (decisions 0023–0026; 10/10 integration tests green) and are recorded as closed in `docs/142` §1. CMEK and `DataRetentionService` have since **shipped**; the one remaining build gap (cross-region failover execution) is risk R-06, under treatment with Q4 2026 target. |
| **Re-assessment cadence** | Annual full re-assessment + on any major change (new region, new sub-processor, major architecture change) per the change-management control A.8.32. |

> **Statement of Applicability rule:** the SoA must give, for **every** Annex A control, (a)
> applicability (yes/no), (b) justification, and (c) implementation status + reference. The tables in
> §3 do exactly that. "Not applicable" is used sparingly and only with a real reason (e.g. controls
> for on-prem physical media Osolix does not hold).

---

## 3 · Annex A control themes — applicability & justification

Status legend: ✅ implemented · 🔄 partial / in build · ⛔ to do · ⚪ cloud-provider-inherited · N/A not applicable.
Where a control maps to an existing artefact, the real code path / doc is cited so a certification
auditor can verify, not take on faith.

### 3.1 Organizational controls (A.5.1 – A.5.37) — 37 controls

| Control | Title (abridged) | Applicable | Justification & Osolix implementation | Status |
|---|---|---|---|---|
| A.5.1 | Policies for information security | Yes | Information Security Policy authored (`docs/146`) binding all topic-specific policies; platform rules codified in `CLAUDE.md` §5 non-negotiables | ✅ (signature pending) |
| A.5.2 | Information security roles & responsibilities | Yes | `docs/30-team-job-descriptions.md` (CISA Mgr, CISO, Automation Mgr, etc.) | ✅ |
| A.5.3 | Segregation of duties | Yes | `SegregationOfDutiesValidator.cs` — server-side 409 on forbidden permission pairs; SoD conflict matrix in `docs/31` §3 | ✅ |
| A.5.4 | Management responsibilities | Yes | Leadership oversight via quarterly walkthrough (`docs/31` §5) | ✅ |
| A.5.5 | Contact with authorities | Yes | Breach-notification path (GDPR Art. 33/34) in `docs/107` §6; CVD policy `docs/124` | ✅ |
| A.5.6 | Contact with special interest groups | Yes | OWASP alignment (`knowledge/standards/security/owasp-asvs.md`); CVE feeds in CI | ✅ |
| A.5.7 | Threat intelligence *(new in 2022)* | Yes | Documented procedure `docs/148` §1 — CI-automated tactical layer (CVE gates, gitleaks) + monthly strategic review + 5-day risk-register escalation path | ✅ |
| A.5.8 | Information security in project management | Yes | Panel decision records (`decisions/`) + ADRs gate architecture changes; security-review skill on PRs | ✅ |
| A.5.9 | Inventory of information & other assets | Yes | The Fixed-Asset Register itself + `OsolixDbContext` 438 DbSets; data-classification table `docs/103` §2 | ✅ |
| A.5.10 | Acceptable use of assets | Yes | Acceptable-use rules `docs/148` §2 (bound annex of the ISP `docs/146` §5); enforced via RBAC + audit logging | ✅ |
| A.5.11 | Return of assets | Yes | Offboarding revokes access (A.5.18); asset-retirement workflow `RetirementsController` | ✅ |
| A.5.12 | Classification of information | Yes | `docs/103` §2 data-classification (personal/business/telemetry) | ✅ |
| A.5.13 | Labelling of information | Yes | `[PersonalData]` attribute marks PII for GDPR erasure; field-level access filter | ✅ |
| A.5.14 | Information transfer | Yes | TLS 1.2+ everywhere; encrypted exports audited; data-portability `docs/110` | ✅ |
| A.5.15 | Access control | Yes | Capability-based RBAC `RequiresPermissionAttribute.cs`; ADR-013; RBAC test matrix `docs/63` | ✅ |
| A.5.16 | Identity management | Yes | ASP.NET Identity + SSO (`SsoTenantConfig`) + SCIM (`ScimController`) | ✅ |
| A.5.17 | Authentication information | Yes | bcrypt/PBKDF2 password hashing; secrets in Key Vault; TOTP MFA | ✅ |
| A.5.18 | Access rights (provision/review/revoke) | Yes | Refresh-token rotation/revocation; inactive-user lockout (ITGC-A4/A5); quarterly access-review procedure `docs/144` §4 — **system of record shipped 2026-06-12**: `/admin/access-reviews` campaigns (`AccessReviewsController`, snapshot → certify/revoke → evidence bundle, SoD reviewer ≠ revoker) | ✅ |
| A.5.19–A.5.22 | Supplier / cloud-service security | Yes | Sub-processor list + DPAs `docs/103` §4; vendor-risk mgmt `docs/111` | ✅ |
| A.5.23 | Information security for cloud services *(new)* | Yes | Azure managed-identity, no human keys (`docs/107` §3); CMEK shipped — `TenantEncryptionKeyController` configure/rotate/revoke with audit rows | ✅ |
| A.5.24–A.5.28 | Incident management (planning → evidence) | Yes | Incident runbook `docs/64` §incident; CVD `docs/124`; whistleblower + management-letter workflow; forensics via `[audit].[AuditLogs]` | ✅ |
| A.5.29 | Information security during disruption | Yes | DR/BCP `docs/121`; restore drill `docs/64` | ✅ |
| A.5.30 | ICT readiness for business continuity *(new)* | Yes | Cross-region failover design `docs/46`; RTO/RPO targets | 🔄 (execution Q4) |
| A.5.31 | Legal, statutory, regulatory requirements | Yes | GDPR/UAE PDPL/KSA PDPL pack `knowledge/standards/welcome/Company/privacy/gdpr-pdpl.md`; DPIA `docs/65` | ✅ |
| A.5.32 | Intellectual property rights | Yes | License-compliance CI gate + `NOTICE.md` | ✅ |
| A.5.33 | Protection of records | Yes | Immutable audit trail (`AuditInterceptor`); soft-delete (DG-2); retention policy | ✅ |
| A.5.34 | Privacy & protection of PII | Yes | `[PersonalData]` marking; right-to-erasure via `DataRetentionService` (shipped, unit-tested); DPIA `docs/65` | ✅ |
| A.5.35 | Independent review of information security | Yes | Annual external pen-test `docs/34`; SOC 2 Type II (`docs/wave-g-soc2-type2-engagement.md`) | ✅ (pen-test pack ready; engagement Q3/Q4) |
| A.5.36 | Compliance with policies/standards | Yes | CI gates enforce coding/security/a11y standards; `IgnoreQueryFiltersCallSiteGuardTests` enforces tenant-filter discipline | ✅ |
| A.5.37 | Documented operating procedures | Yes | Runbooks `docs/45`/`docs/64`/`docs/46`; `CLAUDE.md` engineering procedures | ✅ |

### 3.2 People controls (A.6.1 – A.6.8) — 8 controls

| Control | Title | Applicable | Justification & implementation | Status |
|---|---|---|---|---|
| A.6.1 | Screening | Yes | Procedure `docs/143` §1 (identity, right-to-work, references, record checks for privileged roles); zero population until first hire | ✅ documented |
| A.6.2 | Terms & conditions of employment | Yes | Mandatory contract clauses defined `docs/143` §2 (NDA, IP, policy compliance, return-of-assets) | ✅ documented |
| A.6.3 | Information security awareness, education & training | Yes | Onboarding + annual + role-specific cadence `docs/143` §3; acknowledgement log = evidence EV-44 | ✅ documented |
| A.6.4 | Disciplinary process | Yes | Graduated process `docs/143` §4 (investigate → classify → outcome → record) | ✅ documented |
| A.6.5 | Responsibilities after termination | Yes | Offboarding revokes access instantly (`docs/107` §3 revocation) | ✅ |
| A.6.6 | Confidentiality / NDA | Yes | Staff + vendor NDAs (`docs/34` §3.3 deal-breaker requires vendor NDA) | ✅ |
| A.6.7 | Remote working | Yes | Remote-work rules `docs/143` §6; managed-identity + TLS enforce technical side | ✅ documented |
| A.6.8 | Information security event reporting | Yes | Whistleblower portal + management-letter workflow; CVD `docs/124` | ✅ |

> **People theme (updated 2026-06-12):** all A.6 procedures are now documented in `docs/143`.
> Remaining: founder ratification + first operating evidence (acknowledgement log at ratification;
> hire-related controls have zero population until the first hire — recorded honestly as such).

### 3.3 Physical controls (A.7.1 – A.7.14) — 14 controls

Osolix is cloud-native with **no owned data centre and no on-prem media**. Most physical controls are
**inherited from Azure** (carve-in via Azure's own ISO 27001 / SOC 2). Office/endpoint controls apply
to Osolix staff.

| Control | Title | Applicable | Justification & implementation | Status |
|---|---|---|---|---|
| A.7.1 | Physical security perimeters | Yes (inherited) | Azure data-centre perimeters | ⚪ provider |
| A.7.2 | Physical entry | Yes (inherited) | Azure access controls | ⚪ provider |
| A.7.3 | Securing offices, rooms & facilities | Yes | Remote-first, no Osolix premises — honest posture documented `docs/148` §4 with lease-signing trigger for a future office procedure | ✅ documented |
| A.7.4 | Physical security monitoring | Yes (inherited) | Azure facility monitoring | ⚪ provider |
| A.7.5 | Protecting against physical & environmental threats | Yes (inherited) | Azure multi-AZ + environmental | ⚪ provider |
| A.7.6 | Working in secure areas | Yes | No secure areas exist (remote-first) — `docs/148` §4; remote/clear-desk rules apply (`docs/143` §6–§7) | ✅ documented |
| A.7.7 | Clear desk & clear screen | Yes | Clear desk/screen + endpoint baseline `docs/143` §7 | ✅ documented |
| A.7.8 | Equipment siting & protection | Yes (inherited) | Azure | ⚪ provider |
| A.7.9 | Security of assets off-premises | Yes | Endpoint baseline + FDE + no-local-prod-data + loss-reporting path — `docs/148` §4, `docs/143` §7 | ✅ |
| A.7.10 | Storage media | **N/A** | Osolix holds no removable storage media; all data in Azure-managed services | N/A |
| A.7.11 | Supporting utilities | Yes (inherited) | Azure power/cooling redundancy | ⚪ provider |
| A.7.12 | Cabling security | Yes (inherited) | Azure | ⚪ provider |
| A.7.13 | Equipment maintenance | Yes (inherited) | Azure | ⚪ provider |
| A.7.14 | Secure disposal/re-use of equipment | Yes (inherited) | Azure media sanitisation; for Osolix data, logical erasure via key revocation (CMEK revoke = crypto-shred, `TenantEncryptionKeyController`; `docs/107` §4) | ⚪ provider + ✅ |

### 3.4 Technological controls (A.8.1 – A.8.34) — 34 controls

This is Osolix's **strongest theme** — most controls map directly to shipped code.

| Control | Title | Applicable | Justification & implementation | Status |
|---|---|---|---|---|
| A.8.1 | User endpoint devices | Yes | Endpoint baseline (`docs/143` §7) + annual attestation (`docs/148` §3, form `docs/149` §6); MDM deliberately not claimed — re-assess at ≥ 5 endpoints | ✅ |
| A.8.2 | Privileged access rights | Yes | RBAC + SoD; SystemOwner/OsolixStaff role tiers; managed-identity (no human cloud keys) | ✅ |
| A.8.3 | Information access restriction | Yes | **Fail-closed tenant query filter (decision 0016)**; field-level column access | ✅ |
| A.8.4 | Access to source code | Yes | GitHub + branch protection on `main` + CODEOWNERS; gitleaks blocks committed secrets | ✅ |
| A.8.5 | Secure authentication | Yes | JWT + MFA (TOTP) + SSO (OIDC/SAML); session regen on login (ASVS V3.2.1) | ✅ |
| A.8.6 | Capacity management | Yes | k6 perf suite + per-region budgets `docs/131`; rate limiter | ✅ |
| A.8.7 | Protection against malware | Yes | Layered: endpoint AV/EDR attested per device (`docs/148` §3); server-side CVE gates + gitleaks + file-upload magic-byte validation (`docs/34` §1.1) | ✅ |
| A.8.8 | Management of technical vulnerabilities | Yes | Annual pen-test `docs/34`; vuln-gate + gitleaks CI; CVE feeds | ✅ |
| A.8.9 | Configuration management | Yes | Azure Bicep IaC `deployment/azure/`; EF migrations; appsettings-in-Key-Vault | ✅ |
| A.8.10 | Information deletion | Yes | Soft-delete (DG-2) + retention purge via `DataRetentionService` (shipped, `DataRetentionServiceTests`) | ✅ |
| A.8.11 | Data masking | Yes | Field-level column access; data-anonymisation/cohort `docs/137` (k-anonymity ≥5) | ✅ |
| A.8.12 | Data leakage prevention | Yes | Tenant isolation + audit on every export + egress over TLS only | ✅ |
| A.8.13 | Information backup | Yes | Daily full + 5-min tx-log backups, geo-replicated, AES-256 (`docs/64`) | ✅ |
| A.8.14 | Redundancy of information processing | Yes | Multi-AZ; cross-region failover design `docs/46` | 🔄 (cross-region exec Q4) |
| A.8.15 | Logging | Yes | **`AuditInterceptor`** → `[audit].[AuditLogs]` on every write; Serilog structured logs | ✅ |
| A.8.16 | Monitoring activities | Yes | Failed-login lockout; AI-governance alerts; status page; observability dashboard `docs/128` | ✅ |
| A.8.17 | Clock synchronisation | Yes | UTC `DateTimeOffset.UtcNow` everywhere; Azure NTP | ✅ |
| A.8.18 | Use of privileged utility programs | Yes | No out-of-band SQL ALTER (EF migrations only, ITGC-C3); restricted prod access | ✅ |
| A.8.19 | Software on operational systems | Yes | CI/CD-only deploys; no manual prod changes | ✅ |
| A.8.20 | Networks security | Yes | WAF + CDN + TLS; private endpoints for SQL | ✅ |
| A.8.21 | Security of network services | Yes | Rate limiter (4 policies); IP-allowlist option | ✅ |
| A.8.22 | Segregation of networks | Yes | Per-region isolation; tenant data never crosses region (`docs/113` §5) | ✅ |
| A.8.23 | Web filtering | Yes | CSP/security-headers middleware; egress to known sub-processors only | ✅ |
| A.8.24 | Use of cryptography | Yes | TDE AES-256; TLS 1.2+; DataProtection for secrets; CMEK shipped (`TenantEncryptionKeyController`, `docs/107`); key policy `docs/45` | ✅ |
| A.8.25 | Secure development life cycle | Yes | ADRs + panel decisions + `CLAUDE.md` non-negotiables + CI gates | ✅ |
| A.8.26 | Application security requirements | Yes | OWASP ASVS L2 target (`knowledge/standards/security/owasp-asvs.md`) | ✅ |
| A.8.27 | Secure system architecture & engineering | Yes | Multi-tenant fail-closed design (decision 0016); defence-in-depth | ✅ |
| A.8.28 | Secure coding | Yes | Parameterised EF queries (no string-concat SQL); `FindAsync` ban (AGC-7); code-review + tenancy guard tests | ✅ |
| A.8.29 | Security testing in development & acceptance | Yes | Unit/integration/tenancy/E2E/a11y tests in CI; cross-tenant probe `docs/108` | ✅ |
| A.8.30 | Outsourced development | **N/A** | Development is in-house; no outsourced dev | N/A |
| A.8.31 | Separation of dev/test/prod | Yes | Separate environments; synthetic Demo tenant for testing; prod secrets excluded from source | ✅ |
| A.8.32 | Change management | Yes | Git + PR + 6-job CI gate + EF migrations + audit re-attestation | ✅ |
| A.8.33 | Test information | Yes | Synthetic seed data (`LifecycleHistoryDemoSeeder`); no prod data in test (`docs/34` §1.3 ⛔ no real data) | ✅ |
| A.8.34 | Protection of information systems during audit testing | Yes | Read-only DB user for auditors; Demo tenant only (`docs/34` §5) | ✅ |

---

## 4 · Applicability summary

| Theme | Controls | Applicable | N/A | ✅ implemented | 🔄 partial | ⛔ to do | ⚪ inherited |
|---|---|---|---|---|---|---|---|
| A.5 Organizational | 37 | 37 | 0 | 36 | 1 | 0 | 0 |
| A.6 People | 8 | 8 | 0 | 8 | 0 | 0 | 0 |
| A.7 Physical | 14 | 13 | 1 | 4 | 0 | 0 | 9 |
| A.8 Technological | 34 | 32 | 2 | 31 | 1 | 0 | 0 |
| **Total** | **93** | **90** | **3** | **79** | **2** | **0** | **9** |

> Updated 2026-06-12 (second pass — `docs/148` operational procedures + `docs/149` templates,
> following the `docs/142`–`146` suite). The **only** remaining 🔄 controls are A.5.30 and
> A.8.14 — both the single underlying gap of cross-region failover execution (risk R-06, Q4 2026,
> founder infra-spend decision). Every other applicable control is implemented, documented, or
> provider-inherited. "✅ documented" controls convert to operated evidence per `docs/145` §4
> during the operating period.

---

## 5 · Certification roadmap (Stage 1 / Stage 2)

ISO 27001 certification is a two-stage external audit by an accredited certification body, preceded by
internal readiness.

| Phase | Window | Activities | Exit criteria |
|---|---|---|---|
| **Internal readiness** | 2026-06 → 2026-08 | ✅ DONE 2026-06-12 (docs authored: ISP `docs/146`, risk register `docs/142`, People procedures `docs/143`, audit programme `docs/144`, evidence library `docs/145`; SoA at v1.0). Remaining in window: founder signatures; appoint certification body; collect cloud-provider certs (`docs/145` §3) | SoA v1.0 **signed**; cert body appointed |
| **Internal audit + management review** | 2026-09 | Internal ISMS audit (clause 9.2) + management review (clause 9.3); close major nonconformities | Clean internal-audit report |
| **Stage 1 audit (documentation review)** | 2026-10 | Certification body reviews ISMS docs, SoA, risk register, scope; identifies readiness gaps | No "major" Stage-1 findings; cleared to proceed |
| **Operating period** | 2026-10 → 2026-12 | ISMS demonstrably operating (overlaps SOC 2 Type II window — shared evidence) | Evidence of controls operating accrues |
| **Stage 2 audit (certification / effectiveness)** | 2027-01 | On-site/remote audit of control operation + evidence sampling; nonconformity write-ups | Zero major nonconformities; minors with corrective-action plan |
| **Certification decision** | 2027-02 | Certification body issues ISO/IEC 27001:2022 certificate (3-year cycle) | **Certificate issued** |
| **Surveillance** | 2027-08, 2028-08 | Annual surveillance audits | Maintained certification |
| **Recertification** | 2030-Q1 | Full recertification | New 3-year cycle |

> **Timeline alignment with SOC 2:** Stage 2 (2027-01) is deliberately co-scheduled with SOC 2 Type II
> fieldwork (`docs/wave-g-soc2-type2-engagement.md` §5). Same evidence library, same operating period,
> two reports — minimising duplicated auditor effort and engineering disruption.

---

## 6 · Readiness gaps — status at v1.0 (2026-06-12)

| Gap (from kickoff) | Status |
|---|---|
| People-process documentation | ✅ **CLOSED** — `docs/143` (Decision 0069) |
| Information Security Policy (clause 5) | ✅ authored `docs/146` · 🔏 **founder signature pending** |
| Risk register (clause 6) | ✅ **CLOSED** — populated `docs/142` (15 risks; 3 acceptances need sign-off) |
| CMEK workflow | ✅ **CLOSED** — shipped (`TenantEncryptionKeyController` + `TenantEncryptionKeys` table) |
| `DataRetentionService` | ✅ **CLOSED** — shipped + unit-tested |
| Cross-region failover execution | 🔄 OPEN — risk R-06, Q4 2026, infra spend = founder decision |
| Internal-audit programme + access-review cadence | ✅ **CLOSED** — `docs/144`; first execution IA-2026-01 due 2026-09 |
| Cloud-provider certs into evidence library | 🔄 OPEN — checklist ready (`docs/145` §3); retrieval is a founder/CISO portal task |

**Remaining founder-gated actions (cannot be done by engineering):**
1. Sign `docs/146`, `docs/143`, and this SoA; sign risk acceptances (`docs/142` §2).
2. Appoint an accredited certification body (and decide on external internal-audit support, `docs/144` §1.2).
3. Download cloud-provider certificates per `docs/145` §3.
4. Run IA-2026-01 + first management review (2026-09).
5. Decide Q4 cross-region failover spend (closes R-06).
6. Operate the ISMS through the Oct–Dec evidence window → Stage 1 (2026-10) → Stage 2 (2027-01).

---

## 7 · Cross-reference to SOC 2 — shared evidence (no duplication)

This SoA and the SOC 2 Type II plan draw from **one evidence library**. The mapping below lets the
ISO auditor and the SOC 2 auditor pull the same artefacts. Full SOC 2 control matrix in
`docs/wave-g-soc2-type2-engagement.md` §3; SOC 2↔SOX inheritance in its §6.

| Annex A control(s) | SOC 2 control (Type II) | SOX control | Shared evidence artefact |
|---|---|---|---|
| A.5.3 | OSX-PI-04 | FRC-3/4/7 | `SegregationOfDutiesValidator.cs`; `docs/31` §3 SoD matrix; approval audit rows |
| A.5.15–A.5.18, A.8.2, A.8.5 | OSX-SEC-01/02/03/04 | ITGC-A1–A5 | `RequiresPermissionAttribute.cs`; auth audit rows; `docs/63` RBAC matrix |
| A.8.3 | OSX-CONF-01 | ITGC-A6 | `OsolixDbContext` tenant filter; `CrossTenantIsolationTests`; `docs/108` probe |
| A.8.24, A.7.14 | OSX-CONF-02/03 | ITGC-D3, §4 enc. inventory | `docs/107`; `docs/45`; `IErpCredentialProtector` |
| A.8.15 | OSX-PI-01 | ITGC-C5, FRC-2 | `AuditInterceptor.cs` → `[audit].[AuditLogs]` |
| A.8.32, A.8.28, A.8.4 | OSX-CHG-01/02/03 | ITGC-C1–C4, D2 | `.github/workflows/ci.yml`; `__EFMigrationsHistory`; gitleaks + vuln-gate artefacts |
| A.8.13, A.5.29, A.5.30 | OSX-OPS-02/03 | ITGC-D4 | `docs/64`; `docs/46`; `docs/dr-drill-runs/*.json` |
| A.8.8, A.5.35 | OSX-OPS-04 | ITGC-D5 | `docs/34` pen-test pack + engagement-close letter |
| A.5.31, A.5.34, A.8.11 | OSX-PRIV-01/02/03 | — | `docs/65` DPIA; `gdpr-pdpl.md`; `/api/me/export`; `docs/137` anonymisation |
| A.5.19–A.5.23 | OSX-VEN-01 | — | `docs/103` §4 sub-processors; `docs/111` vendor-risk |

---

## 8 · Sign-off

By signing this SoA v1.0 the CISO + CCO + CISA Manager + CTO confirm: the ISMS document suite
(`docs/142`–`146`) accurately describes the controls as implemented; the risk register (`docs/142`)
is the live record of risks under treatment (R-06 cross-region failover remains open to Q4);
"✅ documented" People controls convert to operating evidence during the Oct–Dec window; and
Stage 2 stays co-scheduled with SOC 2 Type II to share one evidence library (`docs/145`).

**Latest sign-off:** _pending CISO + CCO signature_ · SoA version: **1.0 (2026-06-12, Decision 0069)** ·
Target certificate: **2027-Q1**.
