RegCompiler Logo
RegCompilerRegulation as Code
RegCompiler Logo

© 2026 RegCompiler. Deterministic Statutory Enforcement.

SurveillanceCompiler StudioTerms of ServicePrivacy Policy
DashboardRegulations DirectoryISO/IEC 27001:2022
GLOBAL JurisdictionEnforceable Ruleset6 Active Controls

ISO/IEC 27001:2022

Authentic statutory obligations decomposed into atomic machine-actionable conditions, actions, and verification standards.

Official Legal Text
Highobligation98% AI Match

Control 5.1: Policies for Information Security

Information security policy and topic-specific policies shall be defined, approved by management, published, communicated to and acknowledged by relevant personnel and interested parties.

Required Actions & Enforcement

Statutory verification and compliance logging required.

Trigger Conditions (AST Logic)

{
  "annual_executive_review": true,
  "all_staff_acknowledgement": true
}
Highobligation98% AI Match

Control 8.28: Secure Coding

Secure coding principles shall be applied to software development to maintain information security throughout the software development life cycle.

Required Actions & Enforcement

Statutory verification and compliance logging required.

Trigger Conditions (AST Logic)

{
  "peer_review_mandatory": true,
  "sast_dast_in_pipeline": true
}
Criticalobligation98% AI Match

Control 8.24: Use of Cryptography

Rules for the effective use of cryptography, including cryptographic key management, shall be defined and implemented.

Required Actions & Enforcement

Statutory verification and compliance logging required.

Trigger Conditions (AST Logic)

{
  "kms_key_rotation_annual": true,
  "strong_ciphers_mandated": true
}
Highobligation98% AI Match

Control 5.23: Information Security for Use of Cloud Services

Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organization's information security requirements.

Required Actions & Enforcement

Statutory verification and compliance logging required.

Trigger Conditions (AST Logic)

{
  "exit_strategy_defined": true,
  "cloud_governance_framework": true
}
Criticalobligation98% AI Match

Control 5.15: Access Control

Rules to control physical and logical access to information and other associated assets shall be established and implemented based on business and information security requirements.

Required Actions & Enforcement

Statutory verification and compliance logging required.

Trigger Conditions (AST Logic)

{
  "rbac_matrix": true,
  "privilege_segregation": true
}
Criticalobligation98% AI Match

Control 8.8: Management of Technical Vulnerabilities

Information about technical vulnerabilities of information systems being used shall be obtained, the organization's exposure evaluated and appropriate measures taken.

Required Actions & Enforcement

Statutory verification and compliance logging required.

Trigger Conditions (AST Logic)

{
  "critical_sla_14_days": true,
  "weekly_vulnerability_scans": true
}