Espacio Jose

Matriz de Requisitos

Mapeo regulatorio a nivel de requisito en DORA, NIS2, GDPR, EU AI Act, ENS e ISO 27001. Úsalo para rastrear solapamiento, cobertura y presión de implementación sin aplanar la jerarquía legal entre legislación de la UE y marcos de aseguramiento.

28 AFOs·7 regulations·96.1% average coverage
AFO IDRequirementDORANIS2BSIENSISO 27001GDPREU AI ActFilesCoverage
A_25339TLS 1.3 configurationArt. 9(2)Art. 21(2)(e)CON.1.A13CCN-804.A12A.8.24infrastructure/zeta-guard.yaml
100%
A_25406ZETA header validationArt. 9(2)Art. 21(2)(e)APP.3.1.A4CCN-804.A15api/src/middleware/zetaHeaders.ts
100%
A_25667DPoP validation sidecarArt. 9(4)(c)Art. 21(2)(d)ORP.4CCN-804.A8infrastructure/zeta-guard.yaml
100%
A_25668Token audience validationArt. 9(4)(c)Art. 21(2)(d)CON.1CCN-804.A14infrastructure/pep-auth/tokenVerifier.ts
100%
A_25669Step-up auth (401 not 403)Art. 9(2)Art. 21(2)(d)ORP.4.A8CCN-804.A9api/src/middleware/zetaHeaders.ts
100%
A_25701mTLS between servicesArt. 9(2)Art. 21(2)(e)CON.1.A12CCN-804.A11infrastructure/service-mesh/mtls-config.yaml
100%
A_25702Network segmentation policyArt. 21(2)(e)NET.1.1.A9CCN-804.A16A.8.22infrastructure/network/segmentation.tf
95%
A_25715Secrets rotation < 90 daysArt. 9(4)(b)Art. 21(2)(d)CON.1.A15CCN-804.A13infrastructure/vault/rotation-policy.hcl
100%
A_25720Incident detection < 5 minArt. 17(1)Art. 23(1)DER.1.A7CCN-804.A20monitoring/siem/detection-rules.yaml
92%
A_25721Incident notification < 24hArt. 19(1)Art. 23(1)DER.2.1.A1CCN-804.A21monitoring/incident-response/notify.ts
80%
A_25730SBOM generation per releaseArt. 21(2)(a)APP.6.A1CCN-804.A17ci/sbom-generator.yaml,scripts/generate-sbom.sh
100%
A_25735Access review quarterlyArt. 9(4)(a)Art. 21(2)(i)ORP.4.A5CCN-804.A6A.5.15iam/access-review/quarterly-audit.ts
100%
A_25740Data encryption at rest (AES-256)Art. 9(2)Art. 21(2)(e)CON.1.A6CCN-804.A10A.8.24infrastructure/encryption/at-rest.tf
100%
A_25745Backup integrity verificationArt. 12(1)Art. 21(2)(c)CON.3.A5CCN-804.A18infrastructure/backup/verify-integrity.sh
98%
A_25750Vulnerability scan weeklyArt. 25(1)Art. 21(2)(e)OPS.1.1.A15CCN-804.A19A.8.8ci/vulnerability-scan.yaml
100%
A_25755Log retention >= 12 monthsArt. 12(3)Art. 21(2)(g)OPS.1.1.A18CCN-804.A22A.8.15infrastructure/logging/retention-policy.tf
100%
A_25760MFA enforcement all usersArt. 9(4)(c)Art. 21(2)(j)ORP.4.A9CCN-804.A7A.8.5iam/mfa/enforcement-policy.ts
100%
A_25765AI model risk assessmentCCN-804.A25Art. 9(1)ai/risk-assessment/model-audit.py
88%
A_25770AI transparency documentationCCN-804.A26Art. 13(1)ai/transparency/model-card-generator.ts
91%
A_25775AI human oversight controlsCCN-804.A27Art. 14(1)ai/oversight/human-in-loop.ts
85%
A_25780Penetration test annualArt. 26(1)Art. 21(2)(e)DER.3.A3CCN-804.A23security/pentest/annual-scope.yaml
100%
A_25785Third-party risk assessmentArt. 28(1)Art. 21(2)(e)OPS.2.1.A4CCN-804.A24vendor/risk-assessment/framework.ts
94%
A_25790Disaster recovery test biannualArt. 26(2)Art. 21(2)(c)DER.4.A7CCN-804.A28infrastructure/dr/test-runbook.yaml
97%
A_25795Information security policy reviewCCN-804.A29A.5.1Art. 24governance/isms/policy-review.ts
100%
A_25800Data processing records (ROPA)A.5.12Art. 30governance/gdpr/ropa-generator.ts
94%
A_25805Data subject access request automationArt. 15-20governance/gdpr/dsar-workflow.ts
88%
A_25810Asset inventory managementArt. 8(1)Art. 21(2)(a)ORP.1.A1CCN-804.A30A.5.9governance/isms/asset-inventory.ts
97%
A_25815Business continuity planningArt. 11(1)Art. 21(2)(c)DER.4.A1CCN-804.A31A.5.30governance/isms/bcp-framework.ts
92%