Base CTM requirements and evidence that remain reusable across every expansion path.
189 controls371 evidence asks22 domainsFrameworks are now tracked as reproducible versions with requirements, controls, and evidence requirements split into separate objects.
CTM evidence is split into classical, cloud, OT, and AI-security obligations before it is reused into SOC 2, ISO 27001, and ISO 42001 expansion work.
Base CTM requirements and evidence that remain reusable across every expansion path.
189 controls371 evidence asks22 domainsCloud-specific extension obligations that strengthen ISO 27001 and SOC 2 cloud scope.
49 controls98 evidence asks18 domainsOperational-technology obligations for critical infrastructure and cyber-physical estates.
59 controls116 evidence asks21 domainsAI-security obligations that form the local evidence bridge into ISO 42001 AIMS work.
37 controls71 evidence asks15 domainsSuch practices include establishing mechanisms for: – The organisation to provide necessary security information about its AI systems to users and other relevant stakeholders, e.g., acceptable use policy of the AI systems in the organisation; and – Employees and external parties to report AI security concerns of the AI systems in the organisation.
manual_task2 evidenceThe organisation has defined and allocated roles and responsibilities for AI security due to the multidisciplinary nature of AI, which can cut across various organisational functions, e.g., functions overseeing ethics, legal matters, and risk areas.
manual_task2 evidenceThe Board and/or senior management should have sufficient expertise in AI security to make appropriate business decisions that take into consideration the implications associated with the specific risks of AI, e.g., over-reliance on AI.
manual_task2 evidenceThis includes identifying and documenting the objectives to guide the secure use of AI system(s) and ensuring these system(s) are used according to the intended purposes.
manual_task2 evidenceThe cybersecurity committee/forum has implemented measures to stay updated on fast-evolving AI security practices and governance landscapes, e.g., participating in AI special interest groups.
manual_task2 evidenceAs part of secure configuration, the organisation has considered AI model complexity and the appropriateness of the model for the intended use case, as complex models may involve additional software packages or libraries, which expand the attack surface.
connector_check2 evidence| Framework | Status | Jurisdiction | Requirements | Controls | Evidence | Retrieved |
|---|---|---|---|---|---|---|
| Cyber Trust mark self-assessment checklist v202504 CSA-CTM-self-assessment-v202504 | active | SG | 189 | 189 | 371 | 2026-06-06 00:00:00Z |
Tenant evidence is resolved through the authored crosswalk before standalone SOC 2, ISO 27001, or ISO 42001 modules are sold.
GOV-1
1 evidenceIR-2
2 evidenceASM-1
1 evidenceLOG-1
2 evidenceDP-1
2 evidenceAC-1
2 evidenceGOV-1
1 evidenceAC-1, ASM-1
3 evidenceDP-1
2 evidenceLOG-1
2 evidenceIR-2
2 evidenceScores combine source method, freshness, result state, human review, parser confidence, integrity, and scope traceability before evidence is reused for SOC 2, ISO 27001, or ISO 42001.
tnt_demo/manual/GOV-1/governance-charter-2026.pdf
45/100tnt_demo/manual/DP-1/encryption-and-backup-policy.pdf
50/100okta:access_review
69/100okta:mfa_privileged
69/100aws:asset_inventory
69/100crowdstrike:device_encryption
69/100Evidence is tracked by source, freshness, review state, parser confidence, and hash/receipt proof before it is reused in CTM, SOC 2, ISO 27001, or ISO 42001 packs.
connector - Expiring in 16d
69 score- parser0 artifacts0 receiptsconnector - Fresh for 85d
69 score- parser0 artifacts0 receiptsconnector - Fresh for 83d
69 score- parser0 artifacts0 receiptsconnector - Fresh for 86d
69 score- parser0 artifacts0 receiptsmanual - Fresh for 340d
50 score- parser0 artifacts0 receiptsmanual - Open-ended
45 score- parser0 artifacts0 receiptsconnector - Fresh for 86d
69 score- parser0 artifacts0 receiptsCTM evidence is translated into an expansion offer: reuse potential, weak or stale proof, reviewer workload, net-new collection, auditor questions, and export readiness.
ISMS expansion bridge - ISO27001:2022
CTM to ISO 27001: 100% of target requirements have CTM evidence reuse potential. 0 are export-ready, 0 need refresh or strengthening, 6 need reviewer sign-off, and 0 are net-new.
GOV-1 - Compliance lead
45/100IR-2 - Security operations
73/100ASM-1 - Infrastructure owner
69/100LOG-1 - Infrastructure owner
73/100Type II readiness bridge - SOC2-TSC
CTM to SOC 2: 100% of target requirements have CTM evidence reuse potential. 0 are export-ready, 0 need refresh or strengthening, 5 need reviewer sign-off, and 0 are net-new.
GOV-1 - Compliance lead
45/100AC-1, ASM-1 - IT / IAM owner
69/100DP-1 - IT / IAM owner
69/100LOG-1 - Security operations
73/100AI Governance Add-on - ISO42001:2023
CTM to ISO 42001 / AI Governance Add-on is visible as a roadmap offer, but ISO42001:2023 needs authored requirements and reviewed CTM mappings before CyberG7 should quote a readiness plan.
No authored crosswalk rows are loaded for this target framework yet; build the framework object model and reviewed mappings before estimating net-new evidence.
The ledger separates point-in-time readiness from observation-window evidence: recurring checks, missed checks, sample populations, selected samples, exceptions, and management responses.
AC-1, ASM-1
3/6 checks3 samples4 exceptionsDP-1
2/6 checks2 samples3 exceptionsLOG-1
2/6 checks2 samples3 exceptionsIR-2
2/6 checks2 samples3 exceptionsGOV-1
1/2 checks1 samples2 exceptionsWorkflow families connect operating-period evidence to the records auditors usually sample: access reviews, terminations, incidents, vulnerability remediation, change management, vendor risk, and security awareness.
CC7.1, CC7.2 · ASM-1, LOG-1
monthly3/6 periods3 missed0 exceptions3 evidence3 samples6 gapsCC9.2 · mapping required
annual0/1 periods1 missed0 exceptions0 evidence0 samples1 gapsCC6.1 · AC-1, ASM-1
quarterly3/2 periods0 missed0 exceptions3 evidence3 samples6 gapsCC6.1 · AC-1, ASM-1
event driven3/3 periods0 missed0 exceptions3 evidence3 samples6 gapsCC7.3 · IR-2
event driven2/2 periods0 missed0 exceptions2 evidence2 samples4 gapsCC2.2 · GOV-1
annual1/1 periods0 missed0 exceptions1 evidence1 samples2 gapsISO 27001 readiness needs more than Annex A evidence. This view tracks scope, risk, treatment, SoA, policy lifecycle, internal audit, management review, and CAPA records.
10.1 · ASM-1, B.12.6, B.21.4, IR-2, LOG-1
not started0 workbench0 risks0 SoA0 overdue2 evidence2 samples3 gaps9.2 · B.3.6, GOV-1, LOG-1
not started0 workbench0 risks0 SoA0 overdue0 evidence0 samples2 gaps4.1, 4.2, 4.3 · ASM-1, B.3.6, B.8.3, GOV-1
not started0 workbench0 risks0 SoA0 overdue0 evidence0 samples2 gaps9.3 · B.21.4, GOV-1, IR-2
not started0 workbench0 risks0 SoA0 overdue0 evidence0 samples2 gaps5.2, 7.5, A.5.1 · B.3.6, GOV-1
not started0 workbench0 risks0 SoA0 overdue0 evidence0 samples2 gaps6.1.2 · ASM-1, B.3.6, GOV-1
not started0 workbench0 risks0 SoA0 overdue0 evidence0 samples2 gapsThe organisation has established and implemented practices to develop the importance of cybersecurity within its business context and communicate this to all relevant stakeholders, such as employees, customers and partners.
Approved governance, strategy, policy, or procedure document
row 7Communication, review, and approval evidence from accountable leadership
row 7