{
  "catalog_version": "0.3.0",
  "statuses": [
    "Compliant",
    "Non-Compliant",
    "NotApplicable",
    "Pending",
    "Error"
  ],
  "status_meaning": {
    "Compliant": "The device meets the baseline value.",
    "Non-Compliant": "The device does not meet the baseline value.",
    "NotApplicable": "The check does not apply to this device or OS, or an opt-in check is switched off.",
    "Pending": "Needs a later step: classification by the auditor model, or an unanswered organisational question.",
    "Error": "The value could not be read (for example the collector was not run as administrator/root)."
  },
  "sections": [
    {
      "id": "baseline",
      "title": "COMPLIANCE RESULTS"
    },
    {
      "id": "gdpr",
      "title": "GDPR TECHNICAL CONTROLS"
    },
    {
      "id": "aiact",
      "title": "EU AI ACT CONTROLS"
    },
    {
      "id": "org",
      "title": "ORGANISATIONAL CONTROLS"
    }
  ],
  "references": {
    "iso27001": {
      "A.5.9": "Inventory of information and other associated assets",
      "A.5.12": "Classification of information",
      "A.5.15": "Access control",
      "A.5.16": "Identity management",
      "A.5.17": "Authentication information",
      "A.5.18": "Access rights",
      "A.5.20": "Addressing information security within supplier agreements",
      "A.5.24": "Information security incident management planning and preparation",
      "A.5.26": "Response to information security incidents",
      "A.5.34": "Privacy and protection of PII",
      "A.6.3": "Information security awareness, education and training",
      "A.6.7": "Remote working",
      "A.7.7": "Clear desk and clear screen",
      "A.7.10": "Storage media",
      "A.8.1": "User endpoint devices",
      "A.8.2": "Privileged access rights",
      "A.8.5": "Secure authentication",
      "A.8.7": "Protection against malware",
      "A.8.8": "Management of technical vulnerabilities",
      "A.8.12": "Data leakage prevention",
      "A.8.13": "Information backup",
      "A.8.15": "Logging",
      "A.8.17": "Clock synchronization",
      "A.8.19": "Installation of software on operational systems",
      "A.8.20": "Networks security",
      "A.8.24": "Use of cryptography"
    },
    "gdpr": {
      "Art. 5(1)(c)": "Data minimisation",
      "Art. 5(1)(e)": "Storage limitation",
      "Art. 5(1)(f)": "Integrity and confidentiality",
      "Art. 25": "Data protection by design and by default",
      "Art. 28": "Processor",
      "Art. 30": "Records of processing activities",
      "Art. 32(1)(a)": "Security of processing: pseudonymisation and encryption",
      "Art. 32(1)(b)": "Security of processing: confidentiality, integrity, availability and resilience",
      "Art. 32(1)(c)": "Security of processing: restore availability and access after an incident",
      "Art. 32(1)(d)": "Security of processing: regular testing and evaluation",
      "Art. 33": "Notification of a personal data breach to the supervisory authority",
      "Art. 34": "Communication of a personal data breach to the data subject",
      "Art. 35": "Data protection impact assessment",
      "Art. 44": "General principle for transfers"
    },
    "ai_act": {
      "Art. 4": "AI literacy",
      "Art. 5": "Prohibited AI practices",
      "Art. 6": "Classification rules for high-risk AI systems",
      "Art. 14": "Human oversight",
      "Art. 26": "Obligations of deployers of high-risk AI systems",
      "Art. 26(6)": "Deployers: keep automatically generated logs for at least six months",
      "Art. 50": "Transparency obligations for providers and deployers of certain AI systems",
      "Annex III": "High-risk AI systems referred to in Article 6(2)"
    }
  },
  "checks": [
    {
      "id": "password.min_length",
      "section": "baseline",
      "name": "Minimum password length",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "PASSWORD_MIN_LENGTH"
      ],
      "rule": "Configured minimum length >= PASSWORD_MIN_LENGTH.",
      "controls": {
        "iso27001": [
          "A.5.17",
          "A.8.5"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "password.history",
      "section": "baseline",
      "name": "Password history",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "PASSWORD_HISTORY"
      ],
      "rule": "Remembered passwords >= PASSWORD_HISTORY.",
      "controls": {
        "iso27001": [
          "A.5.17",
          "A.8.5"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "password.expiration",
      "section": "baseline",
      "name": "Password expiration",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "PASSWORD_MAX_AGE_DAYS"
      ],
      "rule": "Passwords expire after 1..PASSWORD_MAX_AGE_DAYS days (0 in the baseline = expiry not required).",
      "controls": {
        "iso27001": [
          "A.5.17"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "password.min_age",
      "section": "baseline",
      "name": "Minimum password age",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "PASSWORD_MIN_AGE_DAYS"
      ],
      "rule": "Minimum age >= PASSWORD_MIN_AGE_DAYS days. macOS has no such setting (NotApplicable).",
      "controls": {
        "iso27001": [
          "A.5.17"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "password.complexity",
      "section": "baseline",
      "name": "Password complexity",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "PASSWORD_COMPLEXITY"
      ],
      "rule": "Complexity enforced (mixed character classes).",
      "controls": {
        "iso27001": [
          "A.5.17",
          "A.8.5"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "lockout.threshold",
      "section": "baseline",
      "name": "Account lockout threshold",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "LOCKOUT_THRESHOLD_MAX"
      ],
      "rule": "Lockout after 1..LOCKOUT_THRESHOLD_MAX failed attempts (0 = never locks).",
      "controls": {
        "iso27001": [
          "A.8.5"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "lockout.duration",
      "section": "baseline",
      "name": "Account lockout duration",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "LOCKOUT_DURATION_MIN_MINUTES"
      ],
      "rule": "Locked for >= LOCKOUT_DURATION_MIN_MINUTES minutes, or until an administrator unlocks.",
      "controls": {
        "iso27001": [
          "A.8.5"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "lockout.observation",
      "section": "baseline",
      "name": "Lockout observation period",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "LOCKOUT_OBSERVATION_MIN_MINUTES"
      ],
      "rule": "Failed-attempt counter kept for >= LOCKOUT_OBSERVATION_MIN_MINUTES minutes.",
      "controls": {
        "iso27001": [
          "A.8.5"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "malware.antivirus",
      "section": "baseline",
      "name": "Antivirus",
      "os": [
        "windows",
        "linux",
        "macos",
        "android"
      ],
      "baseline_keys": [],
      "rule": "An enabled, up-to-date antivirus product is present. Android: Google Play Protect scanning is on.",
      "controls": {
        "iso27001": [
          "A.8.7"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      },
      "names": {
        "android": "Google Play Protect"
      }
    },
    {
      "id": "malware.service",
      "section": "baseline",
      "name": "Malware protection service",
      "names": {
        "windows": "Microsoft Defender Antimalware",
        "linux": "ClamAV malware protection service",
        "macos": "Apple malware protection service"
      },
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [],
      "rule": "The platform malware protection service is running.",
      "controls": {
        "iso27001": [
          "A.8.7"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "malware.realtime",
      "section": "baseline",
      "name": "Real-time protection",
      "os": [
        "windows"
      ],
      "baseline_keys": [],
      "rule": "Defender real-time protection is on.",
      "controls": {
        "iso27001": [
          "A.8.7"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "malware.on_access",
      "section": "baseline",
      "name": "On-access malware protection",
      "names": {
        "windows": "On-access protection"
      },
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [],
      "rule": "Files are scanned when opened. macOS: NotApplicable unless a third-party scanner provides it.",
      "controls": {
        "iso27001": [
          "A.8.7"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "malware.tamper",
      "section": "baseline",
      "name": "Tamper protection",
      "os": [
        "windows"
      ],
      "baseline_keys": [],
      "rule": "Defender tamper protection is on.",
      "controls": {
        "iso27001": [
          "A.8.7"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "malware.signatures",
      "section": "baseline",
      "name": "Malware signatures",
      "names": {
        "windows": "Security intelligence",
        "macos": "Malware protection signatures"
      },
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "SIGNATURE_MAX_AGE_DAYS",
        "MACOS_XPROTECT_MAX_AGE_DAYS"
      ],
      "rule": "Signatures no older than SIGNATURE_MAX_AGE_DAYS (macOS XProtect: MACOS_XPROTECT_MAX_AGE_DAYS).",
      "controls": {
        "iso27001": [
          "A.8.7",
          "A.8.8"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "malware.signature_updates",
      "section": "baseline",
      "name": "Malware signature updates",
      "names": {
        "macos": "Malware security updates"
      },
      "os": [
        "linux",
        "macos"
      ],
      "baseline_keys": [],
      "rule": "Automatic signature/security-data updates are enabled.",
      "controls": {
        "iso27001": [
          "A.8.7",
          "A.8.8"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "firewall.enabled",
      "section": "baseline",
      "name": "Firewall",
      "os": [
        "linux",
        "macos"
      ],
      "baseline_keys": [],
      "rule": "A host firewall is active.",
      "controls": {
        "iso27001": [
          "A.8.20",
          "A.8.1"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "firewall.inbound",
      "section": "baseline",
      "name": "Firewall inbound policy",
      "os": [
        "linux",
        "macos"
      ],
      "baseline_keys": [],
      "rule": "Unsolicited inbound traffic is blocked by default (macOS: firewall on with stealth mode).",
      "controls": {
        "iso27001": [
          "A.8.20"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "firewall.outbound",
      "section": "baseline",
      "name": "Firewall outbound policy",
      "os": [
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "FIREWALL_OUTBOUND"
      ],
      "rule": "Default outbound policy equals FIREWALL_OUTBOUND.",
      "controls": {
        "iso27001": [
          "A.8.20"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "firewall.domain.enabled",
      "section": "baseline",
      "name": "Domain firewall",
      "os": [
        "windows"
      ],
      "baseline_keys": [],
      "rule": "Domain profile enabled.",
      "controls": {
        "iso27001": [
          "A.8.20",
          "A.8.1"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "firewall.domain.inbound",
      "section": "baseline",
      "name": "Domain inbound",
      "os": [
        "windows"
      ],
      "baseline_keys": [],
      "rule": "Domain profile default inbound action is Block.",
      "controls": {
        "iso27001": [
          "A.8.20"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "firewall.domain.outbound",
      "section": "baseline",
      "name": "Domain outbound",
      "os": [
        "windows"
      ],
      "baseline_keys": [
        "FIREWALL_OUTBOUND"
      ],
      "rule": "Domain profile default outbound action equals FIREWALL_OUTBOUND.",
      "controls": {
        "iso27001": [
          "A.8.20"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "firewall.private.enabled",
      "section": "baseline",
      "name": "Private firewall",
      "os": [
        "windows"
      ],
      "baseline_keys": [],
      "rule": "Private profile enabled.",
      "controls": {
        "iso27001": [
          "A.8.20",
          "A.8.1"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "firewall.private.inbound",
      "section": "baseline",
      "name": "Private inbound",
      "os": [
        "windows"
      ],
      "baseline_keys": [],
      "rule": "Private profile default inbound action is Block.",
      "controls": {
        "iso27001": [
          "A.8.20"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "firewall.private.outbound",
      "section": "baseline",
      "name": "Private outbound",
      "os": [
        "windows"
      ],
      "baseline_keys": [
        "FIREWALL_OUTBOUND"
      ],
      "rule": "Private profile default outbound action equals FIREWALL_OUTBOUND.",
      "controls": {
        "iso27001": [
          "A.8.20"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "firewall.public.enabled",
      "section": "baseline",
      "name": "Public firewall",
      "os": [
        "windows"
      ],
      "baseline_keys": [],
      "rule": "Public profile enabled.",
      "controls": {
        "iso27001": [
          "A.8.20",
          "A.8.1"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "firewall.public.inbound",
      "section": "baseline",
      "name": "Public inbound",
      "os": [
        "windows"
      ],
      "baseline_keys": [],
      "rule": "Public profile default inbound action is Block.",
      "controls": {
        "iso27001": [
          "A.8.20"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "firewall.public.outbound",
      "section": "baseline",
      "name": "Public outbound",
      "os": [
        "windows"
      ],
      "baseline_keys": [
        "FIREWALL_OUTBOUND"
      ],
      "rule": "Public profile default outbound action equals FIREWALL_OUTBOUND.",
      "controls": {
        "iso27001": [
          "A.8.20"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "screen_lock.enabled",
      "section": "baseline",
      "name": "Screen lock",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "baseline_keys": [],
      "rule": "The screen locks when idle (Windows: machine inactivity limit or a password-protected screen saver). Phones: a passcode / PIN / password screen lock is set.",
      "controls": {
        "iso27001": [
          "A.8.1",
          "A.7.7"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      },
      "names": {
        "ios": "Passcode",
        "android": "Screen lock"
      }
    },
    {
      "id": "screen_lock.timeout",
      "section": "baseline",
      "name": "Screen lock timeout",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "baseline_keys": [
        "SCREEN_LOCK_MAX_SECONDS"
      ],
      "rule": "Idle time before lock (including any grace delay) is 1..SCREEN_LOCK_MAX_SECONDS seconds (baseline: 300 = 5 minutes). Phones: Auto-Lock / screen timeout.",
      "controls": {
        "iso27001": [
          "A.8.1",
          "A.7.7"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      },
      "names": {
        "ios": "Auto-Lock",
        "android": "Screen timeout"
      }
    },
    {
      "id": "screen_lock.password",
      "section": "baseline",
      "name": "Screen lock password requirement",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [],
      "rule": "A password is required to unlock (macOS: within 5 seconds of the screen locking).",
      "controls": {
        "iso27001": [
          "A.8.1",
          "A.7.7",
          "A.8.5"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "mobile.passcode_strength",
      "section": "baseline",
      "name": "Passcode strength",
      "os": [
        "ios",
        "android"
      ],
      "names": {
        "ios": "Passcode strength",
        "android": "Screen lock strength"
      },
      "baseline_keys": [
        "MOBILE_PASSCODE_MIN_DIGITS"
      ],
      "rule": "Passcode / PIN has at least MOBILE_PASSCODE_MIN_DIGITS digits, or is alphanumeric. Android pattern or swipe locks do not comply.",
      "controls": {
        "iso27001": [
          "A.5.17",
          "A.8.5"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "mobile.jailbreak_root",
      "section": "baseline",
      "name": "Operating system integrity",
      "os": [
        "ios",
        "android"
      ],
      "names": {
        "ios": "Not jailbroken",
        "android": "Not rooted"
      },
      "baseline_keys": [],
      "rule": "The phone is not jailbroken (iOS) or rooted / bootloader-unlocked (Android).",
      "controls": {
        "iso27001": [
          "A.8.1",
          "A.8.7",
          "A.8.19"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "mobile.app_sources",
      "section": "baseline",
      "name": "App sources restricted",
      "os": [
        "ios",
        "android"
      ],
      "names": {
        "ios": "Apps only from the App Store",
        "android": "Install unknown apps blocked"
      },
      "baseline_keys": [],
      "rule": "Apps are installed only from the official store (no alternative marketplaces, web distribution or unknown sources).",
      "controls": {
        "iso27001": [
          "A.8.1",
          "A.8.7",
          "A.8.19"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "mobile.usb_debugging",
      "section": "baseline",
      "name": "USB debugging off",
      "os": [
        "android"
      ],
      "baseline_keys": [],
      "rule": "Developer options / USB debugging are off.",
      "controls": {
        "iso27001": [
          "A.8.1",
          "A.8.19"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "mobile.find_my_device",
      "section": "baseline",
      "name": "Find and erase a lost device",
      "os": [
        "ios",
        "android"
      ],
      "names": {
        "ios": "Find My iPhone",
        "android": "Find My Device"
      },
      "baseline_keys": [],
      "rule": "Find My iPhone / Find My Device is on, so a lost phone can be located, locked and erased.",
      "controls": {
        "iso27001": [
          "A.5.9",
          "A.8.1"
        ],
        "gdpr": [
          "Art. 32(1)(b)",
          "Art. 32(1)(c)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "usb.device_access",
      "section": "baseline",
      "name": "USB storage device access",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "USB_DEVICE_ACCESS"
      ],
      "rule": "Whether USB mass storage devices can connect at all equals USB_DEVICE_ACCESS (allow/deny): driver, device-installation policy, USBGuard or MDM restriction.",
      "controls": {
        "iso27001": [
          "A.7.10",
          "A.8.12"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "usb.read",
      "section": "baseline",
      "name": "USB storage read",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "USB_READ"
      ],
      "rule": "Effective USB storage read access equals USB_READ (allow/deny).",
      "controls": {
        "iso27001": [
          "A.7.10",
          "A.8.12"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "usb.write",
      "section": "baseline",
      "name": "USB storage write",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "USB_WRITE"
      ],
      "rule": "Effective USB storage write access equals USB_WRITE (allow/deny).",
      "controls": {
        "iso27001": [
          "A.7.10",
          "A.8.12"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "admin.approved",
      "section": "baseline",
      "name": "Approved IT administrator",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "APPROVED_ADMINS"
      ],
      "rule": "At least one account listed in APPROVED_ADMINS is an enabled administrator.",
      "controls": {
        "iso27001": [
          "A.8.2",
          "A.5.15"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "admin.unauthorized",
      "section": "baseline",
      "name": "Unauthorized employee administrator accounts",
      "names": {
        "windows": "Unauthorized employee local administrator accounts"
      },
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "APPROVED_ADMINS",
        "ALLOW_DISABLED_BUILTIN_ADMIN"
      ],
      "rule": "No administrator accounts other than APPROVED_ADMINS (and the disabled built-in Administrator on Windows).",
      "controls": {
        "iso27001": [
          "A.8.2",
          "A.5.18"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "encryption.feature",
      "section": "baseline",
      "name": "BitLocker",
      "os": [
        "windows"
      ],
      "baseline_keys": [],
      "rule": "BitLocker is turned on for the system drive.",
      "controls": {
        "iso27001": [
          "A.8.24",
          "A.8.1"
        ],
        "gdpr": [
          "Art. 32(1)(a)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "encryption.enabled",
      "section": "baseline",
      "name": "Encryption",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "baseline_keys": [],
      "rule": "The system disk is fully encrypted (BitLocker / LUKS / FileVault). Phones: iOS data protection is on when a passcode is set; Android 10+ encrypts by default.",
      "controls": {
        "iso27001": [
          "A.8.24",
          "A.8.1"
        ],
        "gdpr": [
          "Art. 32(1)(a)"
        ],
        "ai_act": []
      },
      "names": {
        "ios": "Data protection (encryption)",
        "android": "Device encryption"
      }
    },
    {
      "id": "encryption.protection",
      "section": "baseline",
      "name": "Disk encryption protection",
      "names": {
        "windows": "BitLocker protection"
      },
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [],
      "rule": "Encryption protection is active (not suspended or in progress) with a strong cipher.",
      "controls": {
        "iso27001": [
          "A.8.24"
        ],
        "gdpr": [
          "Art. 32(1)(a)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "encryption.recovery",
      "section": "baseline",
      "name": "Disk encryption recovery",
      "names": {
        "windows": "BitLocker recovery"
      },
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [],
      "rule": "A recovery key or second unlock method exists.",
      "controls": {
        "iso27001": [
          "A.8.24",
          "A.8.13"
        ],
        "gdpr": [
          "Art. 32(1)(a)",
          "Art. 32(1)(c)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "user.account_type",
      "section": "baseline",
      "name": "Signed-in user account type",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "APPROVED_ADMINS"
      ],
      "rule": "The everyday signed-in user is a Standard account (not an administrator), unless listed in APPROVED_ADMINS.",
      "controls": {
        "iso27001": [
          "A.8.2",
          "A.5.15"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "vuln.pending_updates",
      "section": "baseline",
      "name": "Pending security updates",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "baseline_keys": [
        "MAX_PENDING_SECURITY_UPDATES",
        "MOBILE_PATCH_MAX_AGE_DAYS"
      ],
      "rule": "Security updates offered by the OS vendor but not yet installed <= MAX_PENDING_SECURITY_UPDATES. Phones: iOS is at the latest security release known to the vulnerability data; Android security patch level is at most MOBILE_PATCH_MAX_AGE_DAYS old.",
      "controls": {
        "iso27001": [
          "A.8.8"
        ],
        "gdpr": [
          "Art. 32(1)(b)",
          "Art. 32(1)(d)"
        ],
        "ai_act": []
      },
      "names": {
        "ios": "iOS security updates",
        "android": "Android security update"
      }
    },
    {
      "id": "vuln.outdated_apps",
      "section": "baseline",
      "name": "Outdated third-party applications",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "baseline_keys": [
        "MAX_OUTDATED_APPS"
      ],
      "rule": "Installed third-party applications with a newer version available <= MAX_OUTDATED_APPS (Windows: winget; macOS: app versions; Linux: snap/flatpak and packages). Phones: automatic app updates are on.",
      "controls": {
        "iso27001": [
          "A.8.8",
          "A.8.19"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      },
      "names": {
        "ios": "App updates",
        "android": "App updates"
      }
    },
    {
      "id": "vuln.known_vulnerabilities",
      "section": "baseline",
      "name": "Known vulnerabilities in installed software",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios"
      ],
      "baseline_keys": [
        "MAX_CRITICAL_HIGH_VULNERABILITIES"
      ],
      "rule": "Installed software versions matched against an offline copy of the OSV/NVD vulnerability data: critical or high vulnerabilities <= MAX_CRITICAL_HIGH_VULNERABILITIES. iOS: the iOS version is matched against NVD iOS/iPadOS records.",
      "controls": {
        "iso27001": [
          "A.8.8"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      },
      "names": {
        "ios": "Known vulnerabilities in iOS"
      }
    },
    {
      "id": "gdpr.auto_updates",
      "section": "gdpr",
      "name": "Automatic security updates",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "baseline_keys": [],
      "rule": "Security updates are downloaded and installed automatically.",
      "controls": {
        "iso27001": [
          "A.8.8"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      },
      "names": {
        "ios": "Automatic iOS updates",
        "android": "Automatic system updates"
      }
    },
    {
      "id": "gdpr.updates_recent",
      "section": "gdpr",
      "name": "Security updates installed recently",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "UPDATES_MAX_AGE_DAYS"
      ],
      "rule": "Last successful update/package change within UPDATES_MAX_AGE_DAYS days.",
      "controls": {
        "iso27001": [
          "A.8.8"
        ],
        "gdpr": [
          "Art. 32(1)(b)",
          "Art. 32(1)(d)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "gdpr.os_supported",
      "section": "gdpr",
      "name": "Supported operating system version",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "baseline_keys": [
        "WINDOWS_MIN_BUILD",
        "MACOS_MIN_MAJOR",
        "UBUNTU_MIN_VERSION",
        "DEBIAN_MIN_VERSION",
        "RHEL_MIN_VERSION",
        "IOS_MIN_MAJOR",
        "ANDROID_MIN_MAJOR"
      ],
      "rule": "The OS version still receives security updates (minimums in the baseline). Phones: IOS_MIN_MAJOR / ANDROID_MIN_MAJOR.",
      "controls": {
        "iso27001": [
          "A.8.8"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "gdpr.security_logging",
      "section": "gdpr",
      "name": "Security event logging",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [],
      "rule": "Logon and account-change events are recorded (Windows audit policy, Linux auditd, macOS unified log).",
      "controls": {
        "iso27001": [
          "A.8.15"
        ],
        "gdpr": [
          "Art. 32(1)(d)",
          "Art. 33"
        ],
        "ai_act": []
      }
    },
    {
      "id": "gdpr.time_sync",
      "section": "gdpr",
      "name": "Time synchronisation",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "baseline_keys": [],
      "rule": "The clock is synchronised from a time server.",
      "controls": {
        "iso27001": [
          "A.8.17"
        ],
        "gdpr": [
          "Art. 33"
        ],
        "ai_act": []
      },
      "names": {
        "ios": "Date & time set automatically",
        "android": "Date & time set automatically"
      }
    },
    {
      "id": "gdpr.backup_configured",
      "section": "gdpr",
      "name": "Backup configured",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "baseline_keys": [],
      "rule": "A backup solution is configured for user data.",
      "controls": {
        "iso27001": [
          "A.8.13"
        ],
        "gdpr": [
          "Art. 32(1)(c)"
        ],
        "ai_act": []
      },
      "names": {
        "ios": "iCloud Backup",
        "android": "Google backup"
      }
    },
    {
      "id": "gdpr.backup_recent",
      "section": "gdpr",
      "name": "Recent backup",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "BACKUP_MAX_AGE_DAYS"
      ],
      "rule": "Last backup within BACKUP_MAX_AGE_DAYS days (Pending when the date cannot be read).",
      "controls": {
        "iso27001": [
          "A.8.13"
        ],
        "gdpr": [
          "Art. 32(1)(c)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "gdpr.removable_encryption",
      "section": "gdpr",
      "name": "Removable media encryption",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [],
      "rule": "Data cannot be written to unencrypted removable drives.",
      "controls": {
        "iso27001": [
          "A.7.10",
          "A.8.24"
        ],
        "gdpr": [
          "Art. 32(1)(a)",
          "Art. 34"
        ],
        "ai_act": []
      }
    },
    {
      "id": "gdpr.guest_account",
      "section": "gdpr",
      "name": "Guest account disabled",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [],
      "rule": "No enabled guest login.",
      "controls": {
        "iso27001": [
          "A.5.16",
          "A.8.5"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "gdpr.remote_access",
      "section": "gdpr",
      "name": "Remote access services restricted",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "APPROVED_REMOTE_SERVICES"
      ],
      "rule": "Only remote access services listed in APPROVED_REMOTE_SERVICES are enabled.",
      "controls": {
        "iso27001": [
          "A.8.20",
          "A.6.7"
        ],
        "gdpr": [
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "gdpr.telemetry",
      "section": "gdpr",
      "name": "Diagnostic data minimised",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "baseline_keys": [],
      "rule": "OS diagnostic/usage data sharing is at the minimum level.",
      "controls": {
        "iso27001": [
          "A.5.34"
        ],
        "gdpr": [
          "Art. 5(1)(c)",
          "Art. 25"
        ],
        "ai_act": []
      },
      "names": {
        "ios": "Analytics sharing minimised",
        "android": "Usage & diagnostics sharing minimised"
      }
    },
    {
      "id": "gdpr.lock_screen_previews",
      "section": "gdpr",
      "name": "Notification content hidden on the lock screen",
      "os": [
        "ios",
        "android"
      ],
      "names": {
        "ios": "Notification previews hidden when locked",
        "android": "Sensitive notifications hidden when locked"
      },
      "baseline_keys": [],
      "rule": "Message and email previews are not shown on the locked screen.",
      "controls": {
        "iso27001": [
          "A.7.7",
          "A.8.1"
        ],
        "gdpr": [
          "Art. 5(1)(f)",
          "Art. 32(1)(b)"
        ],
        "ai_act": []
      }
    },
    {
      "id": "gdpr.personal_data_discovery",
      "section": "gdpr",
      "name": "Personal data discovery",
      "os": [
        "windows",
        "linux",
        "macos"
      ],
      "baseline_keys": [
        "PERSONAL_DATA_SCAN"
      ],
      "rule": "Opt-in scan of user folders for personal data patterns (counts and paths only). Not implemented in stage 1: NotApplicable.",
      "controls": {
        "iso27001": [
          "A.5.34",
          "A.5.12"
        ],
        "gdpr": [
          "Art. 5(1)(c)",
          "Art. 5(1)(e)",
          "Art. 30"
        ],
        "ai_act": []
      }
    },
    {
      "id": "aiact.inventory",
      "section": "aiact",
      "name": "AI software inventory",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "baseline_keys": [],
      "rule": "AI apps, local AI services and local model folders are listed (Compliant = inventory taken).",
      "controls": {
        "iso27001": [
          "A.5.9"
        ],
        "gdpr": [
          "Art. 30"
        ],
        "ai_act": [
          "Art. 26"
        ]
      }
    },
    {
      "id": "aiact.unapproved",
      "section": "aiact",
      "name": "Unapproved AI tools (shadow AI)",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "baseline_keys": [
        "APPROVED_AI_TOOLS"
      ],
      "rule": "Every AI tool found is listed in APPROVED_AI_TOOLS.",
      "controls": {
        "iso27001": [
          "A.5.9",
          "A.8.19"
        ],
        "gdpr": [
          "Art. 28",
          "Art. 44"
        ],
        "ai_act": [
          "Art. 26"
        ]
      }
    },
    {
      "id": "aiact.risk_classification",
      "section": "aiact",
      "name": "AI system risk classification",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "baseline_keys": [],
      "rule": "Each AI tool found is classified (prohibited / high-risk / limited / minimal). Done by the auditor model: Pending in the collector output, NotApplicable when no AI tool is found.",
      "controls": {
        "iso27001": [
          "A.5.9"
        ],
        "gdpr": [],
        "ai_act": [
          "Art. 5",
          "Art. 6",
          "Annex III"
        ]
      }
    },
    {
      "id": "aiact.os_ai_features",
      "section": "aiact",
      "name": "Operating system AI features restricted",
      "names": {
        "windows": "Windows Recall / Copilot data analysis disabled",
        "macos": "Apple Intelligence external integrations restricted",
        "ios": "Apple Intelligence external integrations restricted",
        "android": "AI assistant access restricted"
      },
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "baseline_keys": [],
      "rule": "OS-level AI features that capture or send user data are disabled by policy. NotApplicable where the OS has none. Phones: external AI integrations (ChatGPT in Apple Intelligence, assistant access to screen content) are off unless approved.",
      "controls": {
        "iso27001": [
          "A.5.34"
        ],
        "gdpr": [
          "Art. 5(1)(c)",
          "Art. 25"
        ],
        "ai_act": [
          "Art. 26"
        ]
      }
    },
    {
      "id": "aiact.log_retention",
      "section": "aiact",
      "name": "AI usage log retention",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "baseline_keys": [],
      "rule": "Logs kept >= 6 months if a high-risk AI system is used. Pending until classification; NotApplicable when no AI tool is found.",
      "controls": {
        "iso27001": [
          "A.8.15"
        ],
        "gdpr": [],
        "ai_act": [
          "Art. 26(6)"
        ]
      }
    },
    {
      "id": "org.ropa",
      "section": "org",
      "name": "Record of processing activities",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "answer_key": "ORG_ROPA",
      "question": "Is there a current record of processing activities (RoPA)?",
      "baseline_keys": [],
      "rule": "Answer yes = Compliant, no/partial = Non-Compliant, n/a = NotApplicable, unanswered = Pending.",
      "controls": {
        "iso27001": [
          "A.5.34"
        ],
        "gdpr": [
          "Art. 30"
        ],
        "ai_act": []
      }
    },
    {
      "id": "org.dpia",
      "section": "org",
      "name": "Data protection impact assessment",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "answer_key": "ORG_DPIA",
      "question": "Has a DPIA been done for every high-risk processing activity?",
      "baseline_keys": [],
      "rule": "As above.",
      "controls": {
        "iso27001": [
          "A.5.34"
        ],
        "gdpr": [
          "Art. 35"
        ],
        "ai_act": []
      }
    },
    {
      "id": "org.breach_procedure",
      "section": "org",
      "name": "Breach response procedure",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "answer_key": "ORG_BREACH_PROCEDURE",
      "question": "Is there a tested procedure to report a personal data breach within 72 hours?",
      "baseline_keys": [],
      "rule": "As above.",
      "controls": {
        "iso27001": [
          "A.5.24",
          "A.5.26"
        ],
        "gdpr": [
          "Art. 33",
          "Art. 34"
        ],
        "ai_act": []
      }
    },
    {
      "id": "org.processor_agreements",
      "section": "org",
      "name": "Data processing agreements",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "answer_key": "ORG_PROCESSOR_AGREEMENTS",
      "question": "Are data processing agreements signed with all processors, including AI providers?",
      "baseline_keys": [],
      "rule": "As above.",
      "controls": {
        "iso27001": [
          "A.5.20"
        ],
        "gdpr": [
          "Art. 28"
        ],
        "ai_act": []
      }
    },
    {
      "id": "org.ai_register",
      "section": "org",
      "name": "AI register",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "answer_key": "ORG_AI_REGISTER",
      "question": "Is there a register of the AI systems the organisation uses?",
      "baseline_keys": [],
      "rule": "As above.",
      "controls": {
        "iso27001": [
          "A.5.9"
        ],
        "gdpr": [],
        "ai_act": [
          "Art. 26"
        ]
      }
    },
    {
      "id": "org.ai_literacy",
      "section": "org",
      "name": "AI literacy training",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "answer_key": "ORG_AI_LITERACY",
      "question": "Have staff who use AI received AI literacy training?",
      "baseline_keys": [],
      "rule": "As above.",
      "controls": {
        "iso27001": [
          "A.6.3"
        ],
        "gdpr": [],
        "ai_act": [
          "Art. 4"
        ]
      }
    },
    {
      "id": "org.human_oversight",
      "section": "org",
      "name": "Human oversight for high-risk AI",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "answer_key": "ORG_HUMAN_OVERSIGHT",
      "question": "Is a trained person assigned to oversee each high-risk AI system?",
      "baseline_keys": [],
      "rule": "As above.",
      "controls": {
        "iso27001": [],
        "gdpr": [],
        "ai_act": [
          "Art. 14",
          "Art. 26"
        ]
      }
    },
    {
      "id": "org.ai_transparency",
      "section": "org",
      "name": "AI transparency to users",
      "os": [
        "windows",
        "linux",
        "macos",
        "ios",
        "android"
      ],
      "answer_key": "ORG_AI_TRANSPARENCY",
      "question": "Are people told when they interact with AI or receive AI-generated content?",
      "baseline_keys": [],
      "rule": "As above.",
      "controls": {
        "iso27001": [],
        "gdpr": [],
        "ai_act": [
          "Art. 50"
        ]
      }
    }
  ]
}
