docs: add ISO 27001 SoA traceability gates#1414
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2ead44953c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| residual_risk_acceptance: CISO 2026-06-30 | ||
| last_reviewed: 2026-06-30 |
There was a problem hiding this comment.
Avoid accepting future-dated SoA evidence
This "complete" passing fixture uses 2026-06-30 for both residual-risk acceptance and the last review, which is in the future relative to the commit/current review date of June 6, 2026. If this case is used to validate the skill, it teaches the gate to accept future-dated approvals/reviews as complete evidence, even though an auditor would treat those as not yet performed; use past dates or make the expected result flag the record as incomplete until those dates have occurred.
Useful? React with 👍 / 👎.
Created from review issue: #1412
Summary
iso27001-gapValidation
git diff --check