Skip to content

feat(content): control-level depth for NIST 800-53 r5, NIS2 and DORA — and lock every catalogue count in a test #809

Description

@alex-dembele

Problem

An auditor or a CISO who imports NIST 800-53 into OpenRisk gets 20 rows, not the roughly 1,000 controls the standard defines. They cannot run an assessment on that, and it is the first thing a buyer checks against Vanta, Drata or ServiceNow.

Rows per catalogue in backend/pkg/compliance/catalog_*.go on 2026-09-25:

Catalogue Rows What the rows are Real granularity
iso27001-2022 93 Annex A controls 93 ✅
nist-800-53-r5 20 control families (AC, AU, …) about 1,000 controls and enhancements
cis-v8 18 top-level controls 153 safeguards
pci-dss-4.0 12 principal requirements about 250 sub-requirements
nis2-2022-2555 12 Art. 21(2) measures Art. 21(2) plus Implementing Reg. (EU) 2024/2690 annex
dora-2022-2554 19 articles articles plus RTS on ICT risk management
sox-2002 10 sections —

TestExpectedControlCounts does not cover the three African catalogues either (see claim C-005), so none of these counts is locked.

Licensing — checked before any content is written

Depth is not only a matter of effort:

  • NIST SP 800-53 r5 is a US Government work, and NIST publishes an official OSCAL catalogue. It can be imported, not transcribed.
  • NIS2 and DORA are EU law; the official text in EUR-Lex can be cited.
  • CIS Controls v8 is licensed CC BY-NC-ND 4.0. Shipping safeguard text in a product sold under LICENSE.commercial probably needs CIS permission.
  • PCI DSS text is copyrighted by PCI SSC.

So CIS and PCI are not in this issue's scope. Whether to ship reference-only rows (identifier plus our own wording) or to seek permission goes to the owner as D-057 in docs/DECISIONS.md (licensing).

Acceptance criteria

  1. nist-800-53-r5 is generated from NIST's official OSCAL JSON (moderate baseline at minimum; the PR records which baseline). A script under backend/cmd/ or scripts/ regenerates it, and each row keeps its control id (AC-2, AC-2(1), …) plus the source URL.
  2. nis2-2022-2555 covers every item of Art. 21(2)(a)-(j), Art. 23 (reporting) and the technical requirements of the annex to Implementing Regulation (EU) 2024/2690. Each row cites its article or paragraph.
  3. dora-2022-2554 covers the ICT risk-management framework articles (Art. 5-16), incident reporting (Art. 17-23), resilience testing (Art. 24-27) and third-party risk (Art. 28-30). Each row cites its article.
  4. TestExpectedControlCounts locks the count of every catalogue, the three African ones included (closes the first gap noted on C-005).
  5. The existing crosswalks (internal/domain/control_crosswalk.go) still resolve after the import. Tenants who already imported the old 20-row NIST catalogue keep their data, and the upgrade path (additive import, no deletion) is tested.
  6. No row is written from memory: each one points to the official source text (the D-002 rule).

Definition of Done

A user can import NIST 800-53 (moderate), NIS2 or DORA and assess at control level. The counts are locked by a green test, and the command and its output are pasted on this issue.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:backendGo, /internal, /pkgarea:grcGovernance, risk and compliancecomplianceCompliancecontentRegulatory framework libraries and mappingspriority:P1Highpriority:P1-highBlocks a milestonestatus:readyMeets the ready definitiontier:1-product-engineProduct engine: the canonical model and the data planetype:featureNew user-facing capability

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions