{"catalog":{"uuid":"00000000-0000-4000-8000-000000000001","metadata":{"title":"Joopler Control Catalog","last-modified":"1970-01-01T00:00:00.000Z","version":"0.1.0","oscal-version":"1.1.2"},"groups":[{"id":"soc2","class":"framework","title":"SOC 2 (Trust Services Criteria)","controls":[{"id":"cc1-1","title":"Integrity and ethical values","props":[{"name":"code","value":"CC1.1"}]},{"id":"cc2-1","title":"Communication of information","props":[{"name":"code","value":"CC2.1"}]},{"id":"cc6-1","title":"Logical and physical access controls","props":[{"name":"code","value":"CC6.1"}]},{"id":"cc6-2","title":"Access provisioning and authorization","props":[{"name":"code","value":"CC6.2"}]},{"id":"cc6-3","title":"Access removal and least privilege","props":[{"name":"code","value":"CC6.3"}]},{"id":"cc6-6","title":"Network security boundaries","props":[{"name":"code","value":"CC6.6"}]},{"id":"cc6-7","title":"Encryption of data in transit","props":[{"name":"code","value":"CC6.7"}]},{"id":"cc7-1","title":"Vulnerability detection","props":[{"name":"code","value":"CC7.1"}]},{"id":"cc7-2","title":"Security monitoring","props":[{"name":"code","value":"CC7.2"}]},{"id":"cc7-3","title":"Security incident evaluation","props":[{"name":"code","value":"CC7.3"}]},{"id":"cc8-1","title":"Change management","props":[{"name":"code","value":"CC8.1"}]},{"id":"cc1-2","title":"Board independence and oversight of internal control","props":[{"name":"code","value":"CC1.2"}]},{"id":"cc1-3","title":"Management establishes structures, reporting lines, and authorities","props":[{"name":"code","value":"CC1.3"}]},{"id":"cc1-4","title":"Commitment to attract, develop, and retain competent individuals","props":[{"name":"code","value":"CC1.4"}]},{"id":"cc1-5","title":"Individuals are held accountable for internal control responsibilities","props":[{"name":"code","value":"CC1.5"}]},{"id":"cc2-2","title":"Internal communication of information to support internal control","props":[{"name":"code","value":"CC2.2"}]},{"id":"cc2-3","title":"Communication with external parties on matters affecting internal control","props":[{"name":"code","value":"CC2.3"}]},{"id":"cc3-1","title":"Objectives are specified to enable identification and assessment of risk","props":[{"name":"code","value":"CC3.1"}]},{"id":"cc3-2","title":"Risks are identified and analyzed as a basis for how they are managed","props":[{"name":"code","value":"CC3.2"}]},{"id":"cc3-3","title":"Potential for fraud is considered in assessing risks","props":[{"name":"code","value":"CC3.3"}]},{"id":"cc3-4","title":"Significant changes are identified and assessed for impact on the system","props":[{"name":"code","value":"CC3.4"}]},{"id":"cc4-1","title":"Ongoing and separate evaluations of internal control are performed","props":[{"name":"code","value":"CC4.1"}]},{"id":"cc4-2","title":"Internal control deficiencies are evaluated and communicated for corrective action","props":[{"name":"code","value":"CC4.2"}]},{"id":"cc5-1","title":"Control activities are selected and developed to mitigate risk","props":[{"name":"code","value":"CC5.1"}]},{"id":"cc5-2","title":"General control activities over technology are selected and developed","props":[{"name":"code","value":"CC5.2"}]},{"id":"cc5-3","title":"Control activities are deployed through policies and procedures","props":[{"name":"code","value":"CC5.3"}]},{"id":"cc6-4","title":"Physical access to facilities and protected information assets is restricted","props":[{"name":"code","value":"CC6.4"}]},{"id":"cc6-5","title":"Logical and physical protections over data are removed upon disposal","props":[{"name":"code","value":"CC6.5"}]},{"id":"cc6-8","title":"Controls prevent or detect unauthorized or malicious software","props":[{"name":"code","value":"CC6.8"}]},{"id":"cc7-4","title":"Response to identified security incidents is executed","props":[{"name":"code","value":"CC7.4"}]},{"id":"cc7-5","title":"Recovery from identified security incidents is implemented","props":[{"name":"code","value":"CC7.5"}]},{"id":"cc9-1","title":"Risk mitigation activities for business disruptions and vendors are identified and developed","props":[{"name":"code","value":"CC9.1"}]},{"id":"cc9-2","title":"Vendors and business partners are assessed and managed for risk","props":[{"name":"code","value":"CC9.2"}]}]},{"id":"hipaa","class":"framework","title":"HIPAA Security Rule","controls":[{"id":"164-308-a-1-ii-d","title":"Information system activity review","props":[{"name":"code","value":"164.308(a)(1)(ii)(D)"}]},{"id":"164-308-a-5-ii-c","title":"Log-in monitoring","props":[{"name":"code","value":"164.308(a)(5)(ii)(C)"}]},{"id":"164-312-a-1","title":"Access control","props":[{"name":"code","value":"164.312(a)(1)"}]},{"id":"164-312-a-2-iv","title":"Encryption and decryption","props":[{"name":"code","value":"164.312(a)(2)(iv)"}]},{"id":"164-312-b","title":"Audit controls","props":[{"name":"code","value":"164.312(b)"}]},{"id":"164-312-c-1","title":"Integrity","props":[{"name":"code","value":"164.312(c)(1)"}]},{"id":"164-312-e-1","title":"Transmission security","props":[{"name":"code","value":"164.312(e)(1)"}]},{"id":"164-308-b-1","title":"Business associate contracts and other arrangements","props":[{"name":"code","value":"164.308(b)(1)"}]},{"id":"164-308-a-1-i","title":"Security management process","props":[{"name":"code","value":"164.308(a)(1)(i)"}]},{"id":"164-308-a-1-ii-a","title":"Risk analysis","props":[{"name":"code","value":"164.308(a)(1)(ii)(A)"}]},{"id":"164-308-a-1-ii-b","title":"Risk management","props":[{"name":"code","value":"164.308(a)(1)(ii)(B)"}]},{"id":"164-308-a-1-ii-c","title":"Sanction policy","props":[{"name":"code","value":"164.308(a)(1)(ii)(C)"}]},{"id":"164-308-a-2","title":"Assigned security responsibility","props":[{"name":"code","value":"164.308(a)(2)"}]},{"id":"164-308-a-3-i","title":"Workforce security","props":[{"name":"code","value":"164.308(a)(3)(i)"}]},{"id":"164-308-a-3-ii-a","title":"Authorization and/or supervision","props":[{"name":"code","value":"164.308(a)(3)(ii)(A)"}]},{"id":"164-308-a-3-ii-b","title":"Workforce clearance procedure","props":[{"name":"code","value":"164.308(a)(3)(ii)(B)"}]},{"id":"164-308-a-3-ii-c","title":"Termination procedures","props":[{"name":"code","value":"164.308(a)(3)(ii)(C)"}]},{"id":"164-308-a-4-i","title":"Information access management","props":[{"name":"code","value":"164.308(a)(4)(i)"}]},{"id":"164-308-a-4-ii-a","title":"Isolating health care clearinghouse functions","props":[{"name":"code","value":"164.308(a)(4)(ii)(A)"}]},{"id":"164-308-a-4-ii-b","title":"Access authorization","props":[{"name":"code","value":"164.308(a)(4)(ii)(B)"}]},{"id":"164-308-a-4-ii-c","title":"Access establishment and modification","props":[{"name":"code","value":"164.308(a)(4)(ii)(C)"}]},{"id":"164-308-a-5-i","title":"Security awareness and training","props":[{"name":"code","value":"164.308(a)(5)(i)"}]},{"id":"164-308-a-5-ii-a","title":"Security reminders","props":[{"name":"code","value":"164.308(a)(5)(ii)(A)"}]},{"id":"164-308-a-5-ii-b","title":"Protection from malicious software","props":[{"name":"code","value":"164.308(a)(5)(ii)(B)"}]},{"id":"164-308-a-5-ii-d","title":"Password management","props":[{"name":"code","value":"164.308(a)(5)(ii)(D)"}]},{"id":"164-308-a-6-i","title":"Security incident procedures","props":[{"name":"code","value":"164.308(a)(6)(i)"}]},{"id":"164-308-a-6-ii","title":"Response and reporting","props":[{"name":"code","value":"164.308(a)(6)(ii)"}]},{"id":"164-308-a-7-i","title":"Contingency plan","props":[{"name":"code","value":"164.308(a)(7)(i)"}]},{"id":"164-308-a-7-ii-a","title":"Data backup plan","props":[{"name":"code","value":"164.308(a)(7)(ii)(A)"}]},{"id":"164-308-a-7-ii-b","title":"Disaster recovery plan","props":[{"name":"code","value":"164.308(a)(7)(ii)(B)"}]},{"id":"164-308-a-7-ii-c","title":"Emergency mode operation plan","props":[{"name":"code","value":"164.308(a)(7)(ii)(C)"}]},{"id":"164-308-a-7-ii-d","title":"Testing and revision procedures","props":[{"name":"code","value":"164.308(a)(7)(ii)(D)"}]},{"id":"164-308-a-7-ii-e","title":"Applications and data criticality analysis","props":[{"name":"code","value":"164.308(a)(7)(ii)(E)"}]},{"id":"164-308-a-8","title":"Evaluation","props":[{"name":"code","value":"164.308(a)(8)"}]},{"id":"164-308-b-2","title":"Subcontractor written assurances","props":[{"name":"code","value":"164.308(b)(2)"}]},{"id":"164-308-b-3","title":"Written contract or other arrangement","props":[{"name":"code","value":"164.308(b)(3)"}]},{"id":"164-310-a-1","title":"Facility access controls","props":[{"name":"code","value":"164.310(a)(1)"}]},{"id":"164-310-a-2-i","title":"Contingency operations","props":[{"name":"code","value":"164.310(a)(2)(i)"}]},{"id":"164-310-a-2-ii","title":"Facility security plan","props":[{"name":"code","value":"164.310(a)(2)(ii)"}]},{"id":"164-310-a-2-iii","title":"Access control and validation procedures","props":[{"name":"code","value":"164.310(a)(2)(iii)"}]},{"id":"164-310-a-2-iv","title":"Maintenance records","props":[{"name":"code","value":"164.310(a)(2)(iv)"}]},{"id":"164-310-b","title":"Workstation use","props":[{"name":"code","value":"164.310(b)"}]},{"id":"164-310-c","title":"Workstation security","props":[{"name":"code","value":"164.310(c)"}]},{"id":"164-310-d-1","title":"Device and media controls","props":[{"name":"code","value":"164.310(d)(1)"}]},{"id":"164-310-d-2-i","title":"Disposal","props":[{"name":"code","value":"164.310(d)(2)(i)"}]},{"id":"164-310-d-2-ii","title":"Media re-use","props":[{"name":"code","value":"164.310(d)(2)(ii)"}]},{"id":"164-310-d-2-iii","title":"Accountability","props":[{"name":"code","value":"164.310(d)(2)(iii)"}]},{"id":"164-310-d-2-iv","title":"Data backup and storage","props":[{"name":"code","value":"164.310(d)(2)(iv)"}]},{"id":"164-312-a-2-i","title":"Unique user identification","props":[{"name":"code","value":"164.312(a)(2)(i)"}]},{"id":"164-312-a-2-ii","title":"Emergency access procedure","props":[{"name":"code","value":"164.312(a)(2)(ii)"}]},{"id":"164-312-a-2-iii","title":"Automatic logoff","props":[{"name":"code","value":"164.312(a)(2)(iii)"}]},{"id":"164-312-c-2","title":"Mechanism to authenticate electronic protected health information","props":[{"name":"code","value":"164.312(c)(2)"}]},{"id":"164-312-d","title":"Person or entity authentication","props":[{"name":"code","value":"164.312(d)"}]},{"id":"164-312-e-2-i","title":"Integrity controls","props":[{"name":"code","value":"164.312(e)(2)(i)"}]},{"id":"164-312-e-2-ii","title":"Encryption","props":[{"name":"code","value":"164.312(e)(2)(ii)"}]},{"id":"164-316-a","title":"Policies and procedures","props":[{"name":"code","value":"164.316(a)"}]},{"id":"164-316-b-1","title":"Documentation","props":[{"name":"code","value":"164.316(b)(1)"}]},{"id":"164-316-b-2-i","title":"Time limit","props":[{"name":"code","value":"164.316(b)(2)(i)"}]},{"id":"164-316-b-2-ii","title":"Availability","props":[{"name":"code","value":"164.316(b)(2)(ii)"}]},{"id":"164-316-b-2-iii","title":"Updates","props":[{"name":"code","value":"164.316(b)(2)(iii)"}]},{"id":"164-404","title":"Notification to individuals","props":[{"name":"code","value":"164.404"}]},{"id":"164-406","title":"Notification to the media","props":[{"name":"code","value":"164.406"}]},{"id":"164-408","title":"Notification to the Secretary","props":[{"name":"code","value":"164.408"}]},{"id":"164-410","title":"Notification by a business associate","props":[{"name":"code","value":"164.410"}]},{"id":"164-412","title":"Law enforcement delay","props":[{"name":"code","value":"164.412"}]},{"id":"164-502","title":"Uses and disclosures of PHI: general rules","props":[{"name":"code","value":"164.502"}]},{"id":"164-504-e","title":"Business associate contracts (organizational requirements)","props":[{"name":"code","value":"164.504(e)"}]},{"id":"164-514-d","title":"Minimum necessary requirements","props":[{"name":"code","value":"164.514(d)"}]}]},{"id":"iso27001","class":"framework","title":"ISO/IEC 27001:2022 (Annex A)","controls":[{"id":"a-5-15","title":"Access control","props":[{"name":"code","value":"A.5.15"}]},{"id":"a-5-16","title":"Identity management","props":[{"name":"code","value":"A.5.16"}]},{"id":"a-5-18","title":"Access rights","props":[{"name":"code","value":"A.5.18"}]},{"id":"a-5-24","title":"Information security incident management planning","props":[{"name":"code","value":"A.5.24"}]},{"id":"a-6-3","title":"Information security awareness, education and training","props":[{"name":"code","value":"A.6.3"}]},{"id":"a-8-2","title":"Privileged access rights","props":[{"name":"code","value":"A.8.2"}]},{"id":"a-8-5","title":"Secure authentication","props":[{"name":"code","value":"A.8.5"}]},{"id":"a-8-8","title":"Management of technical vulnerabilities","props":[{"name":"code","value":"A.8.8"}]},{"id":"a-8-15","title":"Logging","props":[{"name":"code","value":"A.8.15"}]},{"id":"a-8-16","title":"Monitoring activities","props":[{"name":"code","value":"A.8.16"}]},{"id":"a-8-20","title":"Networks security","props":[{"name":"code","value":"A.8.20"}]},{"id":"a-8-24","title":"Use of cryptography","props":[{"name":"code","value":"A.8.24"}]},{"id":"a-8-32","title":"Change management","props":[{"name":"code","value":"A.8.32"}]},{"id":"a-5-1","title":"Policies for information security","props":[{"name":"code","value":"A.5.1"}]},{"id":"a-5-2","title":"Information security roles and responsibilities","props":[{"name":"code","value":"A.5.2"}]},{"id":"a-5-3","title":"Segregation of duties","props":[{"name":"code","value":"A.5.3"}]},{"id":"a-5-4","title":"Management responsibilities","props":[{"name":"code","value":"A.5.4"}]},{"id":"a-5-5","title":"Contact with authorities","props":[{"name":"code","value":"A.5.5"}]},{"id":"a-5-6","title":"Contact with special interest groups","props":[{"name":"code","value":"A.5.6"}]},{"id":"a-5-7","title":"Threat intelligence","props":[{"name":"code","value":"A.5.7"}]},{"id":"a-5-8","title":"Information security in project management","props":[{"name":"code","value":"A.5.8"}]},{"id":"a-5-9","title":"Inventory of information and other associated assets","props":[{"name":"code","value":"A.5.9"}]},{"id":"a-5-10","title":"Acceptable use of information and other associated assets","props":[{"name":"code","value":"A.5.10"}]},{"id":"a-5-11","title":"Return of assets","props":[{"name":"code","value":"A.5.11"}]},{"id":"a-5-12","title":"Classification of information","props":[{"name":"code","value":"A.5.12"}]},{"id":"a-5-13","title":"Labelling of information","props":[{"name":"code","value":"A.5.13"}]},{"id":"a-5-14","title":"Information transfer","props":[{"name":"code","value":"A.5.14"}]},{"id":"a-5-17","title":"Authentication information","props":[{"name":"code","value":"A.5.17"}]},{"id":"a-5-19","title":"Information security in supplier relationships","props":[{"name":"code","value":"A.5.19"}]},{"id":"a-5-20","title":"Addressing information security within supplier agreements","props":[{"name":"code","value":"A.5.20"}]},{"id":"a-5-21","title":"Managing information security in the ICT supply chain","props":[{"name":"code","value":"A.5.21"}]},{"id":"a-5-22","title":"Monitoring, review and change management of supplier services","props":[{"name":"code","value":"A.5.22"}]},{"id":"a-5-23","title":"Information security for use of cloud services","props":[{"name":"code","value":"A.5.23"}]},{"id":"a-5-25","title":"Assessment and decision on information security events","props":[{"name":"code","value":"A.5.25"}]},{"id":"a-5-26","title":"Response to information security incidents","props":[{"name":"code","value":"A.5.26"}]},{"id":"a-5-27","title":"Learning from information security incidents","props":[{"name":"code","value":"A.5.27"}]},{"id":"a-5-28","title":"Collection of evidence","props":[{"name":"code","value":"A.5.28"}]},{"id":"a-5-29","title":"Information security during disruption","props":[{"name":"code","value":"A.5.29"}]},{"id":"a-5-30","title":"ICT readiness for business continuity","props":[{"name":"code","value":"A.5.30"}]},{"id":"a-5-31","title":"Legal, statutory, regulatory and contractual requirements","props":[{"name":"code","value":"A.5.31"}]},{"id":"a-5-32","title":"Intellectual property rights","props":[{"name":"code","value":"A.5.32"}]},{"id":"a-5-33","title":"Protection of records","props":[{"name":"code","value":"A.5.33"}]},{"id":"a-5-34","title":"Privacy and protection of personal identifiable information (PII)","props":[{"name":"code","value":"A.5.34"}]},{"id":"a-5-35","title":"Independent review of information security","props":[{"name":"code","value":"A.5.35"}]},{"id":"a-5-36","title":"Compliance with policies, rules and standards for information security","props":[{"name":"code","value":"A.5.36"}]},{"id":"a-5-37","title":"Documented operating procedures","props":[{"name":"code","value":"A.5.37"}]},{"id":"a-6-1","title":"Screening","props":[{"name":"code","value":"A.6.1"}]},{"id":"a-6-2","title":"Terms and conditions of employment","props":[{"name":"code","value":"A.6.2"}]},{"id":"a-6-4","title":"Disciplinary process","props":[{"name":"code","value":"A.6.4"}]},{"id":"a-6-5","title":"Responsibilities after termination or change of employment","props":[{"name":"code","value":"A.6.5"}]},{"id":"a-6-6","title":"Confidentiality or non-disclosure agreements","props":[{"name":"code","value":"A.6.6"}]},{"id":"a-6-7","title":"Remote working","props":[{"name":"code","value":"A.6.7"}]},{"id":"a-6-8","title":"Information security event reporting","props":[{"name":"code","value":"A.6.8"}]},{"id":"a-7-1","title":"Physical security perimeters","props":[{"name":"code","value":"A.7.1"}]},{"id":"a-7-2","title":"Physical entry","props":[{"name":"code","value":"A.7.2"}]},{"id":"a-7-3","title":"Securing offices, rooms and facilities","props":[{"name":"code","value":"A.7.3"}]},{"id":"a-7-4","title":"Physical security monitoring","props":[{"name":"code","value":"A.7.4"}]},{"id":"a-7-5","title":"Protecting against physical and environmental threats","props":[{"name":"code","value":"A.7.5"}]},{"id":"a-7-6","title":"Working in secure areas","props":[{"name":"code","value":"A.7.6"}]},{"id":"a-7-7","title":"Clear desk and clear screen","props":[{"name":"code","value":"A.7.7"}]},{"id":"a-7-8","title":"Equipment siting and protection","props":[{"name":"code","value":"A.7.8"}]},{"id":"a-7-9","title":"Security of assets off-premises","props":[{"name":"code","value":"A.7.9"}]},{"id":"a-7-10","title":"Storage media","props":[{"name":"code","value":"A.7.10"}]},{"id":"a-7-11","title":"Supporting utilities","props":[{"name":"code","value":"A.7.11"}]},{"id":"a-7-12","title":"Cabling security","props":[{"name":"code","value":"A.7.12"}]},{"id":"a-7-13","title":"Equipment maintenance","props":[{"name":"code","value":"A.7.13"}]},{"id":"a-7-14","title":"Secure disposal or re-use of equipment","props":[{"name":"code","value":"A.7.14"}]},{"id":"a-8-1","title":"User endpoint devices","props":[{"name":"code","value":"A.8.1"}]},{"id":"a-8-3","title":"Information access restriction","props":[{"name":"code","value":"A.8.3"}]},{"id":"a-8-4","title":"Access to source code","props":[{"name":"code","value":"A.8.4"}]},{"id":"a-8-6","title":"Capacity management","props":[{"name":"code","value":"A.8.6"}]},{"id":"a-8-7","title":"Protection against malware","props":[{"name":"code","value":"A.8.7"}]},{"id":"a-8-9","title":"Configuration management","props":[{"name":"code","value":"A.8.9"}]},{"id":"a-8-10","title":"Information deletion","props":[{"name":"code","value":"A.8.10"}]},{"id":"a-8-11","title":"Data masking","props":[{"name":"code","value":"A.8.11"}]},{"id":"a-8-12","title":"Data leakage prevention","props":[{"name":"code","value":"A.8.12"}]},{"id":"a-8-13","title":"Information backup","props":[{"name":"code","value":"A.8.13"}]},{"id":"a-8-14","title":"Redundancy of information processing facilities","props":[{"name":"code","value":"A.8.14"}]},{"id":"a-8-17","title":"Clock synchronization","props":[{"name":"code","value":"A.8.17"}]},{"id":"a-8-18","title":"Use of privileged utility programs","props":[{"name":"code","value":"A.8.18"}]},{"id":"a-8-19","title":"Installation of software on operational systems","props":[{"name":"code","value":"A.8.19"}]},{"id":"a-8-21","title":"Security of network services","props":[{"name":"code","value":"A.8.21"}]},{"id":"a-8-22","title":"Segregation of networks","props":[{"name":"code","value":"A.8.22"}]},{"id":"a-8-23","title":"Web filtering","props":[{"name":"code","value":"A.8.23"}]},{"id":"a-8-25","title":"Secure development life cycle","props":[{"name":"code","value":"A.8.25"}]},{"id":"a-8-26","title":"Application security requirements","props":[{"name":"code","value":"A.8.26"}]},{"id":"a-8-27","title":"Secure system architecture and engineering principles","props":[{"name":"code","value":"A.8.27"}]},{"id":"a-8-28","title":"Secure coding","props":[{"name":"code","value":"A.8.28"}]},{"id":"a-8-29","title":"Security testing in development and acceptance","props":[{"name":"code","value":"A.8.29"}]},{"id":"a-8-30","title":"Outsourced development","props":[{"name":"code","value":"A.8.30"}]},{"id":"a-8-31","title":"Separation of development, test and production environments","props":[{"name":"code","value":"A.8.31"}]},{"id":"a-8-33","title":"Test information","props":[{"name":"code","value":"A.8.33"}]},{"id":"a-8-34","title":"Protection of information systems during audit testing","props":[{"name":"code","value":"A.8.34"}]}]},{"id":"pci","class":"framework","title":"PCI DSS v4.0","controls":[{"id":"1-3","title":"Network access to the cardholder data environment is restricted","props":[{"name":"code","value":"1.3"}]},{"id":"3-5","title":"Primary account number is secured wherever stored","props":[{"name":"code","value":"3.5"}]},{"id":"4-2","title":"PAN is protected with strong cryptography during transmission","props":[{"name":"code","value":"4.2"}]},{"id":"6-5","title":"Changes to system components are managed securely","props":[{"name":"code","value":"6.5"}]},{"id":"7-2","title":"Access is assigned by job classification and least privilege","props":[{"name":"code","value":"7.2"}]},{"id":"8-2","title":"User identification and accounts are managed","props":[{"name":"code","value":"8.2"}]},{"id":"8-3","title":"Strong authentication for users is established","props":[{"name":"code","value":"8.3"}]},{"id":"10-2","title":"Audit logs support anomaly detection","props":[{"name":"code","value":"10.2"}]},{"id":"10-4","title":"Audit logs are reviewed to identify anomalies","props":[{"name":"code","value":"10.4"}]},{"id":"11-3","title":"Vulnerabilities are regularly identified and addressed","props":[{"name":"code","value":"11.3"}]},{"id":"12-6","title":"Security awareness education is ongoing","props":[{"name":"code","value":"12.6"}]},{"id":"12-10","title":"Security incidents are responded to","props":[{"name":"code","value":"12.10"}]},{"id":"1-1","title":"Processes and mechanisms for installing and maintaining network security controls are defined and understood","props":[{"name":"code","value":"1.1"}]},{"id":"1-2","title":"Network security controls (NSCs) are configured and maintained","props":[{"name":"code","value":"1.2"}]},{"id":"1-4","title":"Network connections between trusted and untrusted networks are controlled","props":[{"name":"code","value":"1.4"}]},{"id":"1-5","title":"Risks to the CDE from computing devices able to connect to both untrusted networks and the CDE are mitigated","props":[{"name":"code","value":"1.5"}]},{"id":"2-1","title":"Processes and mechanisms for applying secure configurations to all system components are defined and understood","props":[{"name":"code","value":"2.1"}]},{"id":"2-2","title":"System components are configured and managed securely","props":[{"name":"code","value":"2.2"}]},{"id":"2-3","title":"Wireless environments are configured and managed securely","props":[{"name":"code","value":"2.3"}]},{"id":"3-1","title":"Processes and mechanisms for protecting stored account data are defined and understood","props":[{"name":"code","value":"3.1"}]},{"id":"3-2","title":"Storage of account data is kept to a minimum","props":[{"name":"code","value":"3.2"}]},{"id":"3-3","title":"Sensitive authentication data (SAD) is not stored after authorization","props":[{"name":"code","value":"3.3"}]},{"id":"3-4","title":"Access to displays of full PAN and ability to copy PAN is restricted","props":[{"name":"code","value":"3.4"}]},{"id":"3-6","title":"Cryptographic keys used to protect stored account data are secured","props":[{"name":"code","value":"3.6"}]},{"id":"3-7","title":"Where cryptography is used to protect stored account data, key management processes and procedures covering all aspects of the key lifecycle are defined and implemented","props":[{"name":"code","value":"3.7"}]},{"id":"4-1","title":"Processes and mechanisms for protecting cardholder data with strong cryptography during transmission over open, public networks are defined and understood","props":[{"name":"code","value":"4.1"}]},{"id":"5-1","title":"Processes and mechanisms for protecting all systems and networks from malicious software are defined and understood","props":[{"name":"code","value":"5.1"}]},{"id":"5-2","title":"Malicious software (malware) is prevented, or detected and addressed","props":[{"name":"code","value":"5.2"}]},{"id":"5-3","title":"Anti-malware mechanisms and processes are active, maintained, and monitored","props":[{"name":"code","value":"5.3"}]},{"id":"5-4","title":"Anti-phishing mechanisms protect users against phishing attacks","props":[{"name":"code","value":"5.4"}]},{"id":"6-1","title":"Processes and mechanisms for developing and maintaining secure systems and software are defined and understood","props":[{"name":"code","value":"6.1"}]},{"id":"6-2","title":"Bespoke and custom software are developed securely","props":[{"name":"code","value":"6.2"}]},{"id":"6-3","title":"Security vulnerabilities are identified and addressed","props":[{"name":"code","value":"6.3"}]},{"id":"6-4","title":"Public-facing web applications are protected against attacks","props":[{"name":"code","value":"6.4"}]},{"id":"7-1","title":"Processes and mechanisms for restricting access to system components and cardholder data by business need to know are defined and understood","props":[{"name":"code","value":"7.1"}]},{"id":"7-3","title":"Access to system components and data is managed via an access control system(s)","props":[{"name":"code","value":"7.3"}]},{"id":"8-1","title":"Processes and mechanisms for identifying users and authenticating access to system components are defined and understood","props":[{"name":"code","value":"8.1"}]},{"id":"8-4","title":"Multi-factor authentication (MFA) is implemented to secure access into the CDE","props":[{"name":"code","value":"8.4"}]},{"id":"8-5","title":"Multi-factor authentication (MFA) systems are configured to prevent misuse","props":[{"name":"code","value":"8.5"}]},{"id":"8-6","title":"Use of application and system accounts and associated authentication factors is strictly managed","props":[{"name":"code","value":"8.6"}]},{"id":"9-1","title":"Processes and mechanisms for restricting physical access to cardholder data are defined and understood","props":[{"name":"code","value":"9.1"}]},{"id":"9-2","title":"Physical access controls manage entry into facilities and systems containing cardholder data","props":[{"name":"code","value":"9.2"}]},{"id":"9-3","title":"Physical access for personnel and visitors is authorized and managed","props":[{"name":"code","value":"9.3"}]},{"id":"9-4","title":"Media with cardholder data is securely stored, accessed, distributed, and destroyed","props":[{"name":"code","value":"9.4"}]},{"id":"9-5","title":"Point-of-interaction (POI) devices are protected from tampering and unauthorized substitution","props":[{"name":"code","value":"9.5"}]},{"id":"10-1","title":"Processes and mechanisms for logging and monitoring all access to system components and cardholder data are defined and understood","props":[{"name":"code","value":"10.1"}]},{"id":"10-3","title":"Audit logs are protected from destruction and unauthorized modifications","props":[{"name":"code","value":"10.3"}]},{"id":"10-5","title":"Audit log history is retained and available for analysis","props":[{"name":"code","value":"10.5"}]},{"id":"10-6","title":"Time-synchronization mechanisms support consistent time settings across all systems","props":[{"name":"code","value":"10.6"}]},{"id":"10-7","title":"Failures of critical security control systems are detected, reported, and responded to promptly","props":[{"name":"code","value":"10.7"}]},{"id":"11-1","title":"Processes and mechanisms for regularly testing security of systems and networks are defined and understood","props":[{"name":"code","value":"11.1"}]},{"id":"11-2","title":"Wireless access points are identified and monitored, and unauthorized wireless access points are addressed","props":[{"name":"code","value":"11.2"}]},{"id":"11-4","title":"External and internal penetration testing is regularly performed, and exploitable vulnerabilities and security weaknesses are corrected","props":[{"name":"code","value":"11.4"}]},{"id":"11-5","title":"Network intrusions and unexpected file changes are detected and responded to","props":[{"name":"code","value":"11.5"}]},{"id":"11-6","title":"Unauthorized changes on payment pages are detected and responded to","props":[{"name":"code","value":"11.6"}]},{"id":"12-1","title":"A comprehensive information security policy that governs and provides direction for protection of the entity's information assets is known and current","props":[{"name":"code","value":"12.1"}]},{"id":"12-2","title":"Acceptable use policies for end-user technologies are defined and implemented","props":[{"name":"code","value":"12.2"}]},{"id":"12-3","title":"Risks to the cardholder data environment are formally identified, evaluated, and managed","props":[{"name":"code","value":"12.3"}]},{"id":"12-4","title":"PCI DSS compliance is managed","props":[{"name":"code","value":"12.4"}]},{"id":"12-5","title":"PCI DSS scope is documented and validated","props":[{"name":"code","value":"12.5"}]},{"id":"12-7","title":"Personnel are screened to reduce risks from insider threats","props":[{"name":"code","value":"12.7"}]},{"id":"12-8","title":"Risk to information assets associated with third-party service provider (TPSP) relationships is managed","props":[{"name":"code","value":"12.8"}]},{"id":"12-9","title":"Third-party service providers (TPSPs) support their customers' PCI DSS compliance","props":[{"name":"code","value":"12.9"}]}]},{"id":"iso42001","class":"framework","title":"ISO/IEC 42001:2023 (AI management)","controls":[{"id":"42001-a-3-2","title":"AI roles and responsibilities","props":[{"name":"code","value":"42001:A.3.2"}]},{"id":"42001-a-6-2-8","title":"AI system event logging","props":[{"name":"code","value":"42001:A.6.2.8"}]},{"id":"42001-a-9-2","title":"Processes for responsible use of AI systems","props":[{"name":"code","value":"42001:A.9.2"}]},{"id":"42001-a-10-4","title":"Third-party and supplier AI relationships","props":[{"name":"code","value":"42001:A.10.4"}]},{"id":"42001-a-2-2","title":"AI policy","props":[{"name":"code","value":"42001:A.2.2"}]},{"id":"42001-a-2-3","title":"Alignment with other organizational policies","props":[{"name":"code","value":"42001:A.2.3"}]},{"id":"42001-a-2-4","title":"Review of the AI policy","props":[{"name":"code","value":"42001:A.2.4"}]},{"id":"42001-a-3-3","title":"Reporting of concerns","props":[{"name":"code","value":"42001:A.3.3"}]},{"id":"42001-a-4-2","title":"Resource documentation","props":[{"name":"code","value":"42001:A.4.2"}]},{"id":"42001-a-4-3","title":"Data resources","props":[{"name":"code","value":"42001:A.4.3"}]},{"id":"42001-a-4-4","title":"Tooling resources","props":[{"name":"code","value":"42001:A.4.4"}]},{"id":"42001-a-4-5","title":"System and computing resources","props":[{"name":"code","value":"42001:A.4.5"}]},{"id":"42001-a-4-6","title":"Human resources","props":[{"name":"code","value":"42001:A.4.6"}]},{"id":"42001-a-5-2","title":"AI system impact assessment process","props":[{"name":"code","value":"42001:A.5.2"}]},{"id":"42001-a-5-3","title":"Documentation of AI system impact assessments","props":[{"name":"code","value":"42001:A.5.3"}]},{"id":"42001-a-5-4","title":"Assessing AI system impact on individuals or groups of individuals","props":[{"name":"code","value":"42001:A.5.4"}]},{"id":"42001-a-5-5","title":"Assessing societal impacts of AI systems","props":[{"name":"code","value":"42001:A.5.5"}]},{"id":"42001-a-6-1-2","title":"Objectives for responsible development of AI systems","props":[{"name":"code","value":"42001:A.6.1.2"}]},{"id":"42001-a-6-1-3","title":"Processes for responsible design and development of AI systems","props":[{"name":"code","value":"42001:A.6.1.3"}]},{"id":"42001-a-6-2-2","title":"AI system requirements and specification","props":[{"name":"code","value":"42001:A.6.2.2"}]},{"id":"42001-a-6-2-3","title":"Documentation of AI system design and development","props":[{"name":"code","value":"42001:A.6.2.3"}]},{"id":"42001-a-6-2-4","title":"AI system verification and validation","props":[{"name":"code","value":"42001:A.6.2.4"}]},{"id":"42001-a-6-2-5","title":"AI system deployment","props":[{"name":"code","value":"42001:A.6.2.5"}]},{"id":"42001-a-6-2-6","title":"AI system operation and monitoring","props":[{"name":"code","value":"42001:A.6.2.6"}]},{"id":"42001-a-6-2-7","title":"AI system technical documentation","props":[{"name":"code","value":"42001:A.6.2.7"}]},{"id":"42001-a-7-2","title":"Data for development and enhancement of AI systems","props":[{"name":"code","value":"42001:A.7.2"}]},{"id":"42001-a-7-3","title":"Acquisition of data","props":[{"name":"code","value":"42001:A.7.3"}]},{"id":"42001-a-7-4","title":"Quality of data for AI systems","props":[{"name":"code","value":"42001:A.7.4"}]},{"id":"42001-a-7-5","title":"Data provenance","props":[{"name":"code","value":"42001:A.7.5"}]},{"id":"42001-a-7-6","title":"Data preparation","props":[{"name":"code","value":"42001:A.7.6"}]},{"id":"42001-a-8-2","title":"System documentation and information for users","props":[{"name":"code","value":"42001:A.8.2"}]},{"id":"42001-a-8-3","title":"External reporting","props":[{"name":"code","value":"42001:A.8.3"}]},{"id":"42001-a-8-4","title":"Communication of incidents","props":[{"name":"code","value":"42001:A.8.4"}]},{"id":"42001-a-8-5","title":"Information for interested parties","props":[{"name":"code","value":"42001:A.8.5"}]},{"id":"42001-a-9-3","title":"Objectives for responsible use of AI systems","props":[{"name":"code","value":"42001:A.9.3"}]},{"id":"42001-a-9-4","title":"Intended use of the AI system","props":[{"name":"code","value":"42001:A.9.4"}]},{"id":"42001-a-10-2","title":"Allocating responsibilities","props":[{"name":"code","value":"42001:A.10.2"}]},{"id":"42001-a-10-3","title":"Suppliers","props":[{"name":"code","value":"42001:A.10.3"}]}]},{"id":"nistairmf","class":"framework","title":"NIST AI RMF 1.0","controls":[{"id":"govern-2-1","title":"AI roles, responsibilities, and lines of communication are documented and clear","props":[{"name":"code","value":"GOVERN 2.1"}]},{"id":"map-4-1","title":"Third-party AI technology and data risks are mapped and documented","props":[{"name":"code","value":"MAP 4.1"}]},{"id":"measure-2-7","title":"AI system security and resilience are evaluated and documented","props":[{"name":"code","value":"MEASURE 2.7"}]},{"id":"manage-4-1","title":"Post-deployment AI system monitoring is implemented","props":[{"name":"code","value":"MANAGE 4.1"}]},{"id":"govern-1-1","title":"Legal and regulatory requirements involving AI are understood, managed, and documented","props":[{"name":"code","value":"GOVERN 1.1"}]},{"id":"govern-1-2","title":"The characteristics of trustworthy AI are integrated into organizational policies, processes, and procedures","props":[{"name":"code","value":"GOVERN 1.2"}]},{"id":"govern-1-3","title":"Processes are in place to determine the needed level of risk management activities based on risk tolerance","props":[{"name":"code","value":"GOVERN 1.3"}]},{"id":"govern-1-4","title":"The risk management process and its outcomes are established through transparent policies and controls","props":[{"name":"code","value":"GOVERN 1.4"}]},{"id":"govern-1-5","title":"Ongoing monitoring and periodic review of the risk management process and its outcomes are planned","props":[{"name":"code","value":"GOVERN 1.5"}]},{"id":"govern-1-6","title":"Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities","props":[{"name":"code","value":"GOVERN 1.6"}]},{"id":"govern-1-7","title":"Processes are in place for decommissioning and phasing out AI systems safely","props":[{"name":"code","value":"GOVERN 1.7"}]},{"id":"govern-2-2","title":"Personnel and partners receive AI risk management training","props":[{"name":"code","value":"GOVERN 2.2"}]},{"id":"govern-2-3","title":"Executive leadership takes responsibility for decisions about risks of AI development and deployment","props":[{"name":"code","value":"GOVERN 2.3"}]},{"id":"govern-3-1","title":"Decision-making related to mapping, measuring, and managing AI risks is informed by a diverse team","props":[{"name":"code","value":"GOVERN 3.1"}]},{"id":"govern-3-2","title":"Policies define and differentiate roles for human-AI configurations and oversight of AI systems","props":[{"name":"code","value":"GOVERN 3.2"}]},{"id":"govern-4-1","title":"Policies and practices foster a critical thinking and safety-first mindset across the AI lifecycle","props":[{"name":"code","value":"GOVERN 4.1"}]},{"id":"govern-4-2","title":"Teams document the risks and potential impacts of the AI technology they build and use","props":[{"name":"code","value":"GOVERN 4.2"}]},{"id":"govern-4-3","title":"Organizational practices enable AI testing, identification of incidents, and information sharing","props":[{"name":"code","value":"GOVERN 4.3"}]},{"id":"govern-5-1","title":"Policies and practices collect, consider, prioritize, and integrate external feedback on AI impacts","props":[{"name":"code","value":"GOVERN 5.1"}]},{"id":"govern-5-2","title":"Mechanisms enable AI actors to incorporate adjudicated feedback into system design and implementation","props":[{"name":"code","value":"GOVERN 5.2"}]},{"id":"govern-6-1","title":"Policies address AI risks associated with third-party entities","props":[{"name":"code","value":"GOVERN 6.1"}]},{"id":"govern-6-2","title":"Contingency processes handle failures or incidents in third-party data or AI systems","props":[{"name":"code","value":"GOVERN 6.2"}]},{"id":"map-1-1","title":"Intended purpose, beneficial uses, context laws, and deployment settings are documented","props":[{"name":"code","value":"MAP 1.1"}]},{"id":"map-1-2","title":"Inter-disciplinary AI actors and competencies reflect diversity and broad expertise; participation is documented","props":[{"name":"code","value":"MAP 1.2"}]},{"id":"map-1-3","title":"The mission and relevant goals for the AI technology are understood and documented","props":[{"name":"code","value":"MAP 1.3"}]},{"id":"map-1-4","title":"The business value or context of business use has been clearly defined or re-evaluated","props":[{"name":"code","value":"MAP 1.4"}]},{"id":"map-1-5","title":"Organizational risk tolerances are determined and documented","props":[{"name":"code","value":"MAP 1.5"}]},{"id":"map-1-6","title":"System requirements are elicited and understood; design decisions account for socio-technical implications","props":[{"name":"code","value":"MAP 1.6"}]},{"id":"map-2-1","title":"The specific task, and methods used to implement it, that the AI system will support is defined","props":[{"name":"code","value":"MAP 2.1"}]},{"id":"map-2-2","title":"Information about the AI system knowledge limits and human oversight of output is documented","props":[{"name":"code","value":"MAP 2.2"}]},{"id":"map-2-3","title":"Scientific integrity and TEVV considerations are identified and documented","props":[{"name":"code","value":"MAP 2.3"}]},{"id":"map-3-1","title":"Potential benefits of intended AI system functionality and performance are examined and documented","props":[{"name":"code","value":"MAP 3.1"}]},{"id":"map-3-2","title":"Potential costs from expected or realized AI errors or trustworthiness gaps are examined and documented","props":[{"name":"code","value":"MAP 3.2"}]},{"id":"map-3-3","title":"Targeted application scope is specified and documented based on capability, context, and categorization","props":[{"name":"code","value":"MAP 3.3"}]},{"id":"map-3-4","title":"Processes for operator and practitioner proficiency with AI system performance are defined and documented","props":[{"name":"code","value":"MAP 3.4"}]},{"id":"map-3-5","title":"Processes for human oversight are defined, assessed, and documented per GOVERN policies","props":[{"name":"code","value":"MAP 3.5"}]},{"id":"map-4-2","title":"Internal risk controls for AI system components, including third-party technologies, are identified and documented","props":[{"name":"code","value":"MAP 4.2"}]},{"id":"map-5-1","title":"Likelihood and magnitude of each identified impact are identified and documented","props":[{"name":"code","value":"MAP 5.1"}]},{"id":"map-5-2","title":"Practices and personnel for engagement with relevant AI actors and integrating impact feedback are in place","props":[{"name":"code","value":"MAP 5.2"}]},{"id":"measure-1-1","title":"Approaches and metrics for measuring mapped AI risks are selected, starting with the most significant risks","props":[{"name":"code","value":"MEASURE 1.1"}]},{"id":"measure-1-2","title":"Appropriateness of AI metrics and effectiveness of existing controls are regularly assessed and updated","props":[{"name":"code","value":"MEASURE 1.2"}]},{"id":"measure-1-3","title":"Internal experts and/or independent assessors are involved in regular assessments and updates","props":[{"name":"code","value":"MEASURE 1.3"}]},{"id":"measure-2-1","title":"Test sets, metrics, and details about the tools used during TEVV are documented","props":[{"name":"code","value":"MEASURE 2.1"}]},{"id":"measure-2-2","title":"Evaluations involving human subjects meet applicable requirements and are representative","props":[{"name":"code","value":"MEASURE 2.2"}]},{"id":"measure-2-3","title":"AI system performance or assurance criteria are measured and demonstrated for deployment-like conditions","props":[{"name":"code","value":"MEASURE 2.3"}]},{"id":"measure-2-4","title":"The functionality and behavior of the AI system and its components are monitored when in production","props":[{"name":"code","value":"MEASURE 2.4"}]},{"id":"measure-2-5","title":"The AI system is demonstrated valid and reliable; limitations of generalizability are documented","props":[{"name":"code","value":"MEASURE 2.5"}]},{"id":"measure-2-6","title":"The AI system is regularly evaluated for safety risks and able to fail safely","props":[{"name":"code","value":"MEASURE 2.6"}]},{"id":"measure-2-8","title":"Risks associated with transparency and accountability are examined and documented","props":[{"name":"code","value":"MEASURE 2.8"}]},{"id":"measure-2-9","title":"The AI model is explained, validated, and documented, and system output is interpreted within its context","props":[{"name":"code","value":"MEASURE 2.9"}]},{"id":"measure-2-10","title":"Privacy risk of the AI system is examined and documented","props":[{"name":"code","value":"MEASURE 2.10"}]},{"id":"measure-2-11","title":"Fairness and bias are evaluated and results are documented","props":[{"name":"code","value":"MEASURE 2.11"}]},{"id":"measure-2-12","title":"Environmental impact and sustainability of AI model training and management activities are assessed","props":[{"name":"code","value":"MEASURE 2.12"}]},{"id":"measure-2-13","title":"Effectiveness of the employed TEVV metrics and processes is evaluated and documented","props":[{"name":"code","value":"MEASURE 2.13"}]},{"id":"measure-3-1","title":"Approaches and documentation are in place to regularly identify and track existing and emergent AI risks","props":[{"name":"code","value":"MEASURE 3.1"}]},{"id":"measure-3-2","title":"Risk tracking approaches are considered where AI risks are hard to assess with current techniques","props":[{"name":"code","value":"MEASURE 3.2"}]},{"id":"measure-3-3","title":"Feedback processes for end users and impacted communities to report problems are established and integrated","props":[{"name":"code","value":"MEASURE 3.3"}]},{"id":"measure-4-1","title":"Measurement approaches for identifying AI risks are connected to deployment contexts and documented","props":[{"name":"code","value":"MEASURE 4.1"}]},{"id":"measure-4-2","title":"Measurement results on trustworthiness in deployment context are informed by domain experts and documented","props":[{"name":"code","value":"MEASURE 4.2"}]},{"id":"measure-4-3","title":"Measurable performance improvements or declines based on consultations and field data are identified","props":[{"name":"code","value":"MEASURE 4.3"}]},{"id":"manage-1-1","title":"A determination is made whether the AI system achieves its intended purpose and whether to proceed","props":[{"name":"code","value":"MANAGE 1.1"}]},{"id":"manage-1-2","title":"Treatment of documented AI risks is prioritized based on impact, likelihood, or available resources","props":[{"name":"code","value":"MANAGE 1.2"}]},{"id":"manage-1-3","title":"Responses to high-priority AI risks identified by the Map function are developed, planned, and documented","props":[{"name":"code","value":"MANAGE 1.3"}]},{"id":"manage-1-4","title":"Negative residual risks to downstream acquirers and end users are documented","props":[{"name":"code","value":"MANAGE 1.4"}]},{"id":"manage-2-1","title":"Resources required to manage AI risks are accounted for, along with viable non-AI alternatives","props":[{"name":"code","value":"MANAGE 2.1"}]},{"id":"manage-2-2","title":"Mechanisms are in place and applied to sustain the value of deployed AI systems","props":[{"name":"code","value":"MANAGE 2.2"}]},{"id":"manage-2-3","title":"Procedures are followed to respond to and recover from a previously unknown risk when identified","props":[{"name":"code","value":"MANAGE 2.3"}]},{"id":"manage-2-4","title":"Mechanisms are in place, with responsibilities assigned, to supersede, disengage, or deactivate AI systems","props":[{"name":"code","value":"MANAGE 2.4"}]},{"id":"manage-3-1","title":"AI risks and benefits from third-party resources are regularly monitored and risk controls applied","props":[{"name":"code","value":"MANAGE 3.1"}]},{"id":"manage-3-2","title":"Pre-trained models used for development are monitored as part of regular monitoring and maintenance","props":[{"name":"code","value":"MANAGE 3.2"}]},{"id":"manage-4-2","title":"Measurable activities for continual improvement are integrated into AI system updates","props":[{"name":"code","value":"MANAGE 4.2"}]},{"id":"manage-4-3","title":"Incidents and errors are communicated to relevant AI actors and affected communities; processes are followed","props":[{"name":"code","value":"MANAGE 4.3"}]}]},{"id":"euaiact","class":"framework","title":"EU AI Act (Regulation 2024/1689)","controls":[{"id":"art-12","title":"Record-keeping: automatic logging of events over the AI system lifetime","props":[{"name":"code","value":"Art. 12"}]},{"id":"art-15","title":"Accuracy, robustness, and cybersecurity of AI systems","props":[{"name":"code","value":"Art. 15"}]},{"id":"art-25","title":"Responsibilities along the AI value chain","props":[{"name":"code","value":"Art. 25"}]},{"id":"art-26","title":"Obligations of deployers of high-risk AI systems","props":[{"name":"code","value":"Art. 26"}]},{"id":"art-5","title":"Prohibited AI practices","props":[{"name":"code","value":"Art. 5"}]},{"id":"art-9","title":"Risk management system","props":[{"name":"code","value":"Art. 9"}]},{"id":"art-10","title":"Data and data governance","props":[{"name":"code","value":"Art. 10"}]},{"id":"art-11","title":"Technical documentation","props":[{"name":"code","value":"Art. 11"}]},{"id":"art-13","title":"Transparency and provision of information to deployers","props":[{"name":"code","value":"Art. 13"}]},{"id":"art-14","title":"Human oversight","props":[{"name":"code","value":"Art. 14"}]},{"id":"art-16","title":"Obligations of providers of high-risk AI systems","props":[{"name":"code","value":"Art. 16"}]},{"id":"art-17","title":"Quality management system","props":[{"name":"code","value":"Art. 17"}]},{"id":"art-18","title":"Documentation keeping","props":[{"name":"code","value":"Art. 18"}]},{"id":"art-19","title":"Automatically generated logs","props":[{"name":"code","value":"Art. 19"}]},{"id":"art-20","title":"Corrective actions and duty of information","props":[{"name":"code","value":"Art. 20"}]},{"id":"art-21","title":"Cooperation with competent authorities","props":[{"name":"code","value":"Art. 21"}]},{"id":"art-22","title":"Authorised representatives of providers","props":[{"name":"code","value":"Art. 22"}]},{"id":"art-23","title":"Obligations of importers","props":[{"name":"code","value":"Art. 23"}]},{"id":"art-24","title":"Obligations of distributors","props":[{"name":"code","value":"Art. 24"}]},{"id":"art-27","title":"Fundamental rights impact assessment","props":[{"name":"code","value":"Art. 27"}]},{"id":"art-43","title":"Conformity assessment","props":[{"name":"code","value":"Art. 43"}]},{"id":"art-47","title":"EU declaration of conformity","props":[{"name":"code","value":"Art. 47"}]},{"id":"art-48","title":"CE marking","props":[{"name":"code","value":"Art. 48"}]},{"id":"art-49","title":"Registration","props":[{"name":"code","value":"Art. 49"}]},{"id":"art-50","title":"Transparency obligations for providers and deployers of certain AI systems","props":[{"name":"code","value":"Art. 50"}]},{"id":"art-51","title":"Classification of GPAI models as having systemic risk","props":[{"name":"code","value":"Art. 51"}]},{"id":"art-52","title":"Procedure for GPAI systemic-risk classification and notification","props":[{"name":"code","value":"Art. 52"}]},{"id":"art-53","title":"Obligations for providers of general-purpose AI models","props":[{"name":"code","value":"Art. 53"}]},{"id":"art-54","title":"Authorised representatives of providers of GPAI models","props":[{"name":"code","value":"Art. 54"}]},{"id":"art-55","title":"Obligations for providers of GPAI models with systemic risk","props":[{"name":"code","value":"Art. 55"}]},{"id":"art-61","title":"Voluntary codes of conduct","props":[{"name":"code","value":"Art. 61"}]},{"id":"art-72","title":"Post-market monitoring by providers","props":[{"name":"code","value":"Art. 72"}]},{"id":"art-73","title":"Reporting of serious incidents","props":[{"name":"code","value":"Art. 73"}]},{"id":"art-86","title":"Right to explanation of individual decision-making","props":[{"name":"code","value":"Art. 86"}]}]}]}}